ballast_required
HTTP 403 · Ludion-Error: ballast_required
What happened
Section titled “What happened”Your signature verified, but this route asks for an active Ballast and your Staple does not show one (or you sent no Staple).
Ballast is Ludion’s name for accountability backing. Today, in v0, it is a set of public commitments by the operator, and nothing more:
- respond to complaints about the agent within 24 hours (spec §14);
- consent to revocation if the commitments are broken;
- consent to signed receipts (Glass) of the agent’s actions.
The Registry measures how operators keep these commitments and publishes the response record on the agent’s Card. Ballast v0 is not insurance and does not move money.
Why this site asks
Section titled “Why this site asks”A site opening a sensitive route to agents wants someone to answer when something goes wrong. Ballast v0 makes that someone reachable and on the record.
How to fix it
Section titled “How to fix it”- Register your Diver when registration opens and accept the Ballast v0 commitments. Your Staple then carries
ballast.status: active. - Send the Staple with every request:
npx ludion signand the SDK include it, andnpx ludion staplerefreshes it.
Get verified in 3 minutes
Section titled “Get verified in 3 minutes”Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.
Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.
-
Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.
Terminal window npx ludion init --name "My Agent" --contact mailto:you@example.com -
Publish the public files it wrote at your
Signature-Agentorigin over HTTPS:.well-known/http-message-signatures-directory(your keys, served asapplication/http-message-signatures-directory+json) andcard(who you are). Your own domain works; so willdvr-….agents.ludion.aionce registration opens. -
Sign each request. This prints a ready-to-run
curlwith theSignature-Agent,Signature-InputandSignatureheaders; a signature lives 60 seconds (spec §10.4), so make a new one per request.Terminal window npx ludion sign GET https://shop.example/checkout --curl -
Check yourself.
doctorfetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.Terminal window npx ludion doctor
A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.