USDC budgets, payment amounts, receipts, proof records and operator dashboards.
Grant review package
Kestrel is a production control plane for agentic money movement.
This page gives reviewers one clean path through the product: run the agentic workflow, inspect the proof, confirm Circle integration status, and see how Arc-native money movement becomes an application layer for agents: balances, payments, FX routes, hidden gas and policy controls.
Reviewer console
One place for the grant review.
Reviewer mode
Four clicks to understand the product.
Circle and Arc fit
Integration status matrix.
Server execution boundary, one-time policy grants and developer-controlled signer adapter are implemented and fail closed without production credentials.
One agent-facing account surface for USDC spending, EURC invoices, FX-ready routes, card-like controls, CCTP and gas abstraction states.
Proof records now include invoice, agent, customer and batch references so a transaction hash can be reconciled by downstream systems.
The Money Movement console uses App Kit estimateSpend/spend with auto-allocation, forwarding, custom fees and resumable error handling.
Arc Testnet USDC/EURC Swap executes behind a server-only signer and Kit Key, with slippage, approve strategy and a disclosed developer fee.
Signed offer and receipt architecture for machine-to-machine API payment flows.
Oracle risk signal model uses Arc Testnet CCIP Router 0xdE4E...eab8 and chain selector 3034092155422581607 for reviewable route/data evidence.
Load-aware states keep network congestion, retry scheduling and deferred settlement separate from product failures and agent reputation.
App Kit Bridge uses CCTP for supported Arc Testnet routes and preserves retryable step state, hashes and explorer URLs.
Kestrel Gas models sponsored transactions, per-agent limits and USDC-funded execution policies.
Escrow, reputation and settlement contracts are ready for Arc deployment when production endpoints are available.
End-to-end workflow
Policy check to proof, with settlement evidence when configured.
The demo joins Treasury budget enforcement, Shield risk screening, Marketplace access, Chainlink oracle/CCIP readiness, Provider receipt validation and Reputation updates into one auditable operation. Wallet OS turns the same primitives into one account-style interface instead of exposing raw settlement mechanics to every operator.
Ecosystem fit
Built around the latest Arc direction.
Kestrel maps this into Interop: CCIP route evidence, oracle risk hashes, feed freshness and proof-gated settlement states.
Wallet OS follows the same app-layer pattern: one account surface for USDC/EURC balances, payments, FX-ready routes and hidden gas/CCTP state.
Proof now treats memo context as first-class evidence, so settlement evidence can map back to invoices, jobs, customers and batches.
Kestrel uses the official App Kit SDK for Unified Balance, Swap, Bridge and Send while keeping low-level routing complexity behind one product flow.
The roadmap now includes private-credit style deal lifecycle, compliance evidence and liquidity-aware stablecoin routes for provider settlement.
Ops and Interop separate network congestion from product failure, so jobs can retry or defer settlement without damaging agent reputation.
Arc docs alignment
Mapped to primitives reviewers already care about.
Next build order
What we should implement next.
Measurable milestones
What grant progress will be measured against.
3 design partners · Operator, API provider and treasury team using the same execution flow.
1,000 testnet operations · Send, Bridge, Swap and Unified Balance executions with unique trace IDs.
10,000 USDC · Cumulative testnet volume before a production rollout decision.
> 99% · Settled operations with policy, fee, hash, explorer and receipt evidence.
> 95% · Operations reaching a terminal state without manual intervention.
< 10 minutes · Resumable destination-mint failures retried before attestation expiration.
75 bps · Disclosed fee; 90% of the custom fee routes to Kestrel and 10% to Arc.
p95 < 3 seconds · Route and fee estimate returned before a wallet signature is requested.
Roadmap
What the grant unlocks.
Validate the live App Kit flow, persist transaction proofs, add route telemetry and complete the first 100 wallet-signed testnet operations.
Add Turnkey-backed agent signing, a provider-neutral risk adapter and fail-closed checks before quote confirmation.
Stream onchain events through Goldsky, reconcile App Kit operations and expose success, latency, volume and fee dashboards.
Onboard three design partners, cross 1,000 testnet operations and validate the 75 bps execution-fee model.
Current status
What is live today.
Production web MVP deployed on Vercel with Supabase-backed APIs.
Proof pages connect workflow id, policy checks, x402 receipt and settlement evidence.
Production monitor, Sentry runtime and Ops Health surface are active.
Kestrel separates policy approval, receipt evidence and settlement recording so temporary Arc Testnet congestion does not corrupt reputation or access decisions.
Wallet OS now models Arc-native money movement as one operational account instead of raw wallet/chain mechanics.
Proof pages now attach business context to payment evidence: invoice, agent, customer and batch references.
The Money Movement console imports the official App Kit SDK and exposes live estimate/execute paths for Unified Balance, Bridge, Swap and Send.
Every live execution now requires a fresh wallet signature, recipient allowlist approval, Circle compliance screening, amount-cap validation and a server-issued policy proof.
A 75 bps developer fee is disclosed before signature, with the 90% Kestrel / 10% Arc split shown explicitly.
Wallet OS exposes source wallet, token lookup and balance readiness before any policy-gated transfer is attempted.
Grant unlocks live Arc deployment, Circle Wallets expansion, CCTP and contract work.
Known limits
Clear scope, no inflated claims.
- Arc mainnet deployment is pending external availability and grant scope.
- Server App Kit execution remains fail-closed until the production signer, execution secret and provider keys are configured.
- Provider receipts include a demo provider signature for review until external providers onboard.