{"service":"ohm","region":"us-east-1","limits":[{"claim":"Mid-stream provider handoff after the first byte is NOT supported","verify":"GET /ready → mvp.mid_stream_failover=false (pre-first-byte retry IS shipped)"},{"claim":"Caching is exact-match identical-request replay only — no semantic cache","verify":"GET /v1/compliance/policy → cache_purpose"},{"claim":"Named cache trees (X-Ohm-Cache-Tree) scope exact-replay only — not semantic merge, not a database branch (see docs/CACHE_TREES.md)","verify":"GET /v1/compliance/policy → cache_ops + cache_tree_default"},{"claim":"Savings figures are estimates, never a guarantee","verify":"GET /v1/savings → estimate_only=true on every payload"},{"claim":"model=\"dms\" (Dynamic Model Selection) tiers X-Ohm-Energy: high and flow are not yet distinct routing mechanisms — v1 silently falls back to the same Rung 2 cost-floor lookup as Economical. You are billed at the tier you requested; the mechanism that actually ran is reported separately, never conflated with the billed tier","verify":"GET /v1/ledger → events[].dms_tier (requested) vs. events[].dms_mechanism (executed, e.g. rung2_cost_floor)"}],"refusals":[{"claim":"HTTP 402 pay-per-crawl is honored — Ohm never auto-pays or evades","verify":"GET /v1/compliance/policy → pay_per_crawl=surface_402_no_autopay"},{"claim":"robots.txt is respected fail-closed; 401/403 revocations end the fetch","verify":"GET /v1/compliance/policy → respect_robots, rules"},{"claim":"The cache is never exported as a training corpus","verify":"GET /v1/compliance/policy → allow_cache_training=false"},{"claim":"The Merkle clock is a supplier-side timestamp, not a citizen-vs-state receipt. Leaves are hashes of Ed25519 signatures, never payloads or patient data. A signature still does not prove when until the slot root is committed outside Metrecept.","verify":"GET /v1/public/clock → leaf_algo, commitment; python scripts/verify_clock.py"}],"proofs":{"cache_hit_receipts":{"enabled":true,"header":"X-Ohm-Receipt","header_aliases":["X-Metrecept-Receipt"],"format":"compact JWS (EdDSA/Ed25519)","keys":"/.well-known/http-message-signatures-directory","docs":"docs/RECEIPTS.md"},"merkle_clock":{"enabled":true,"leaf_algo":"sha256(ed25519_sig)","tree_algo":"rfc6962-sha256","slot_seconds":3600,"endpoint":"/v1/public/clock","page":"https://metrecept.co.uk/clock","docs":"docs/CLOCK.md","genesis_slot":"20260827T02Z","genesis_root_sha256":"f8ce0d45bcf9a34b02e7110797a5f5dc0f2c55a280d610f7bc5463f191e5085d","note":"Not a chain product. Open slots are our log; only a committed root is a public clock. Leaves are hashes of Ed25519 signatures, never payloads or patient data."},"web_bot_auth":{"enabled":true,"protocol":"rfc9421-http-message-signatures","keys":"/.well-known/http-message-signatures-directory"},"nightly_golden_path":"https://github.com/iwasinnam2/ohm/actions/workflows/golden-path.yml"},"note":"If a claim here stops being true, that is an incident, not a copy edit."}