UD

UNIV Deploy

Release portability gate

Checking WebMCP

For platform, release, and security teams

Approve one release. Prove it behaved the same everywhere.

A browser agent turns one approved, digest-pinned WASI release into verified target capsules, runs two unrelated hosts, and returns a durable proof link—without receiving arbitrary code-execution authority.

actual runtimes
durable proof
0arbitrary code
01

release intent

BOUND
02

target proof

PENDING
03

safe handoff

PENDING
04

runtime witness

PENDING
05

durable evidence

PENDING

01 / Release candidate

Choose the gate policy

dogfooded release

SeemoreCodez / UNIV Deploy v3

RC

Digest-pinned WASI release inspector · two governed execution targets

repo / seemorecodez/univ-witness-webmcp

policy / closed-manifest-pinned-artifacts

Approved workloaddigest pinned
univ-portable-workload-v1

02 / Release decision

Loading registered target passports

LOADING

Release policy

portable-release-v1

Intent sha256

not created

Compiled program

not created

Evidence record

pending

Target passport

browser-wasi

DISCOVERING

binding /

passport / not created

certificate / not created

capsule / not created

runtime hash / pending

output / pending

Target passport

sites-edge-wasi

DISCOVERING

binding /

passport / not created

certificate / not created

capsule / not created

runtime hash / pending

output / pending

Portability frontier + runtime witness

0 target passports satisfy the finite compile-time proof. Runtime equivalence is withheld until both execute.

PENDING
proof clauses
capsules bound
same output
durable proof

Compiled + enforced

One closed intent is checked against target passports. Only verified, digest-bound execution capsules enter the five-minute handoff.

Actively observed

Reserved for facts emitted by real target executions; no portability claim is made yet.

Edge-side deterministic verification

Runs only after both actual target receipts exist; it cannot manufacture missing runtime evidence.

External attestation / outside this proof

No outside signer or hardware root of trust is claimed. Integrity, edge verification, and durable storage are real; authenticated approval is future work.

View exact intent → capsules → receipt JSON
{
  "plan": null,
  "handoff": null,
  "receipt": null,
  "durableEvidence": null
}

03 / Agent + reviewer

Release-gate activity

live provenance

Judge this with one prompt

Use this site’s WebMCP tools to inspect its capabilities, compile network-bound-release-v1 and explain the refusal, then compile portable-release-v1, create its integrity-bound handoff, deploy it to both actual WASI targets, and retrieve the durable evidence by the returned evidence ID.

A call is labeled via WebMCP only when a registered tool callback invokes it. Human controls remain labeled via human.
  1. Waiting for WebMCP registration or a deployment action…

Authority the agent never receives

component upload · shell · native · OCI · worker · daemon · QEMU · arbitrary URL · arbitrary bytes