Job Description
Carry a verified loyalty identity through the agent handshake on UCP and on a protocol-agnostic rail, and build the wallet-held Verifiable Credential proof of concept.
What you will do in the first 90 days
- Implement the UCP side: trust signal with a loyalty block on a platform agent, and a mock UCP merchant that verifies it, resolves eligibility server-to-server, applies member pricing and reserved-inventory holds in the Checkout object, records pending earn on the Order, and steps up to OAuth (PKCE) identity linking only for redeem/transfer.
- Build the protocol-agnostic rail: X-Agent-Trust header contract, a Cloudflare Worker edge verifier with JWKS caching and spoof-header stripping, and Node/TypeScript merchant middleware exposing a loyalty context to handlers.
- Build the VC POC: issue an Agent Trust credential over OID4VCI to a holder wallet (Credo or equivalent), present via OID4VP with selective disclosure (SD-JWT first, BBS+ predicate as stretch), verify at the merchant, and prove that no PII reaches the agent.
- Implement and run the loyalty-fraud test suite (replay across merchants, token reuse, enumeration, ATO-pattern redeem, scalper hold-and-abandon) on both rails.
- Write the merchant integration guide for the rail and the UCP path; build the demo storefront beats.
Must have
- 5+ years TypeScript/Node (Node 22, Next.js or similar); strong HTTP fundamentals; comfortable writing both a spec-conformant server and a reference client.
- Identity engineering: OAuth 2.0 Authorization Code + PKCE, OIDC, JWT/JWS (ES256, EdDSA), JWKS rotation, replay controls (aud, jti, TTL); has implemented token verification in production.
- Verifiable Credentials hands-on: W3C VC 2.0 data model, OID4VCI/OID4VP, SD-JWT VC; familiarity with DID methods (did:web, did:key) and at least one wallet SDK.
- Edge development: Cloudflare Workers (or equivalent) with KV/Durable Objects; header verification and injection; rate limiting.
- Reads protocol specifications precisely (UCP, RFC 9421, RFC 8693, OpenID specs) and cites the section; delivers from acceptance criteria without supervision.
Nice to have
- BBS+ / zero-knowledge predicate tooling; Google UCP or Merchant Center integrations; loyalty-programme or promotions systems; Python enough to pair with Role 2 on the blueprint binding; e-commerce fraud or bot-management experience.