{"lexicon":1,"id":"money.atmosphere.payment.defs","defs":{"fiatMinor":{"type":"object","description":"A nonnegative fiat value expressed in the ISO 4217 currency's normative minor unit. This shared tagged definition is reused by money.atmosphere payment records; the applicable payment profile supplies the semantic currency grammar and writer conversion rules.","required":["amountMinor","currency"],"properties":{"amountMinor":{"type":"integer","minimum":0,"maximum":9007199254740991,"description":"Final fiat amount in the ISO 4217 currency's minor unit according to that currency's ISO exponent (for example, cents for USD). Bounded to the JavaScript-safe integer range."},"currency":{"type":"string","minLength":3,"maxLength":3,"description":"Uppercase ISO 4217 alphabetic code (for example, USD or EUR). Character-class validation is supplied by the applicable payment profile; Lexicon supplies only the byte-length boundary."}}},"assetAtomic":{"type":"object","description":"A nonnegative fungible-asset value expressed in the asset's atomic unit. This shared tagged definition is reusable by future money.atmosphere records; the applicable payment profile supplies the canonical decimal and asset-identity grammars.","required":["amountAtomic","asset"],"properties":{"amountAtomic":{"type":"string","minLength":1,"maxLength":78,"description":"Canonical nonnegative base-10 integer atomic-unit amount: exactly 0, or a positive integer with no leading zero. No sign, decimal point, exponent, or whitespace; value MUST be at most 2^256-1. A string preserves exact integers beyond the AT Protocol/JavaScript safe-integer range."},"asset":{"type":"string","minLength":11,"maxLength":179,"description":"Exact case-sensitive network-qualified fungible-asset identifier using the frozen CAIP-19 asset-type grammar supplied by the applicable payment profile (for example, eip155:1/erc20:0x...). This exact string, not a ticker symbol, is the asset identity. Display symbol, decimals, issuer, and branding are registry metadata and are not value fields."}}},"attestedSettlement":{"type":"object","description":"Broker-attested settlement evidence independent of payment rail. The exact (authority, transactionId) pair owns the unchanged business-settlement deduplication namespace; it is distinct from cross-location receipt replay identity. The money-atmosphere-v1 attested profile requires a matching-authority broker proof. The retired #processorSettlement tag is not an alias. This vocabulary change implements no new rail or independently verifiable chain/Zone evidence; those require later reviewed adapters or evidence profiles. The branch names #chainSettlement and #zoneSettlement and the domain atm-settlement-intent-v1 remain reserved in prose only for later reviewed profiles; this cut defines no chain/Zone branch, intent algorithm, or execution claim. This is a claimed settlement form; its type alone does not imply the verifier has returned an attested outcome.","required":["authority","transactionId"],"properties":{"authority":{"type":"string","format":"did","description":"DID whose namespace owns transactionId. Producers freeze the canonical accepted-settlement authority and include at least one proof whose authenticated author DID and proof-URI repository authority both equal this DID. Before claiming the business-settlement binding, a consumer independently verifies a matching broker proof under its explicit allowed-broker and role policy. Only exact referenced proofs of this committed broker are lifecycle candidates; a recipient acknowledgment or unrelated attester cannot acquire that role through a trust flag. Authenticated authorship, business-settlement binding and qualified lifecycle currentness remain separate checks."},"transactionId":{"type":"string","minLength":1,"maxLength":64,"description":"Opaque public identifier unique per settlement in authority's namespace: exactly 1 through 64 visible ASCII characters, full match ^[\\x21-\\x7E]{1,64}$, with no spaces, normalization or case folding. Lexicon supplies only the byte-length boundary. Never a raw processor identifier, bearer, session token or hiding secret."}}},"purchaseContext":{"type":"object","description":"Optional historical purchase-context references belonging to the enclosing recipient. Not a public line-item breakdown, quantity claim, allocation or live access grant. The applicable profile requires at least one recognized reference field, preserves admitted extension bytes, and supplies aggregate work limits.","properties":{"price":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"Optional strongRef to the public posted terms (for example a money.atmosphere.price record) associated with this purchase context. It is committed exactly like an entitlements entry: when a verifier accepts a trusted proof for the receipt, the exact committed uri and cid are bound to the historical settlement assertion, so the purchase context is explainable against the referenced terms by separately dereferencing, authenticating, and validating them. The payment proof does not prove the target exists or authenticate its author, repository, schema, or meaning. The reference carries no quantity, tax, or line-item breakdown, does not restate the amount (value remains the single authoritative settled obligation), and its absence asserts nothing about how the value was computed. The cid is the referenced record's canonical AT repository-record CID string (lowercase unpadded base32 CIDv1, DAG-CBOR, SHA-256/32). The payment proof does not establish that the referenced terms produced the value or that the value derives from them. For recurringReceipt, these references are bound only to the historical initial-settlement assertion for this recurring relationship; the proof establishes neither a renewal nor current subscription or term standing. It is a terms snapshot for that initial settlement only: automatic renewals, later price changes, and a later end of the offer neither create nor update this record, and the reference says nothing about what any later cycle charged. The recurring association includes the stated cadence of that initial settlement, not a later cycle."},"discounts":{"type":"array","minLength":1,"maxLength":100,"items":{"type":"ref","ref":"com.atproto.repo.strongRef"},"description":"Optional strongRefs to public discount offer terms associated with this purchase context (for example money.atmosphere.discount records). It is committed exactly like an entitlements entry: when a verifier accepts a trusted proof for the receipt, the exact committed uri and cid are bound to the historical settlement assertion, so a reduced or zero value is explainable by separately dereferencing, authenticating, and validating the referenced terms. The payment proof does not prove the target exists or authenticate its author, repository, schema, or meaning. The reference carries no customer-facing code, eligibility fact, or redemption state (codes and their counters stay private), and its absence asserts nothing about whether a discount applied. The cid is the referenced record's canonical AT repository-record CID string (lowercase unpadded base32 CIDv1, DAG-CBOR, SHA-256/32). The payment proof does not establish that the referenced terms were applied or that the value derives from them. Array order and duplicate entries are committed data, not repeated application or redemption authority. For recurringReceipt, these references are bound only to the historical initial-settlement assertion for this recurring relationship; the proof establishes neither a renewal nor current subscription or term standing. It is a terms snapshot for that initial settlement only: automatic renewals, a later end of the offer, and later price changes neither create nor update this record, and the reference says nothing about what any later cycle charged."},"entitlements":{"type":"array","minLength":1,"maxLength":100,"items":{"type":"ref","ref":"com.atproto.repo.strongRef"},"description":"Optional purchase-context strongRefs whose exact committed URI and CID values, when a verifier accepts a trusted proof for the receipt, are bound to the historical settlement assertion so an application can use them as purchase evidence after separately authenticating and validating each referenced record; the payment proof does not prove the target exists or authenticate its author, repository, schema, or meaning, does not make a handle authority durable, and the references are not live entitlement grants or bearer credentials (any lexicon). Every cid is the referenced record's canonical AT repository-record CID string (lowercase unpadded base32 CIDv1, DAG-CBOR, SHA-256/32). By themselves, these references never establish current, unconsumed, unexpired, or unrevoked access; an independent current entitlement authority or source of truth must make access decisions. Line-item detail (quantities, unit prices, per-item tax) is deliberately not public. For recurringReceipt, these references are bound only to the historical initial-settlement assertion for this recurring relationship; the proof establishes neither a renewal nor current subscription or term standing."}}},"recipientScope":{"type":"object","description":"A recipient-scoped payment assertion, with optional purchase context. The recipient is not automatically the product author, fulfilment provider, charge-owning account or owner of the entire settlement value. A transfer need not name a product or price. The applicable profile determines supported recipient cardinality and acknowledgment policy.","required":["recipient"],"properties":{"recipient":{"type":"string","format":"did","description":"DID of the payment recipient in this scope. No per-recipient amount or payout success is asserted by this field."},"contexts":{"type":"array","minLength":1,"maxLength":100,"items":{"type":"ref","ref":"money.atmosphere.payment.defs#purchaseContext"},"description":"Optional associated purchase contexts. Absence makes no assertion that catalog terms or discounts did not exist. The applicable profile bounds the combined contexts and reference occurrences."}}}}}