HERMAI your own devnet Your own devnet, built for this visit. A shared public sandbox with disposable identities: nothing here is private, and nothing real is ever sent.

Live, against a real service, right now

An operator hands an agent a signed permit. The rail refuses the send that goes past it.

Every number, timestamp, signature and refusal below was read back from a Postage Protocol devnet running behind this page, not pre-recorded. Enforcement is sender-side: the recipient never sees this permit and cannot verify it.

  1. 01 Permit
  2. 02 Every send spends
  3. 03 The refusal
  4. 04 The remedy
  5. 05 Revocation
  6. 06 More agents

Operator

key

Sponsored postage in the operator's wallet

units

Sponsored by the local issuer. An agent never holds any of its own: it spends out of this number.

The permit not issued
state
No permit yet. Set the ceilings and sign one.
The signed permit, verbatim

        

The ceilings, the reissue and the revocation are all the operator's. The agent cannot change any of them, and asking nicely is not a mechanism.

Agent

not created yet key

Sends left in this window

of per 24h window

The permit's rolling-window ceiling, counted by the service in the same transaction as the spend.

This agent's outbox

empty

Custody state is evidence that devices signed for ciphertext and relays moved it. It is never evidence that anyone read anything.

The service's last answer, verbatim

wallet – · window – · permit not issued

Waiting for the first action

Nothing has been asked of the service yet on this page.

What this means

Sender-side enforcement

The ceiling is enforced where the message is made, before an envelope exists. That is why a refusal is exact: the service already holds the numbers.