# gsc-handshake.ai — GSC Handshake GSC verifies every counterparty card presented at task acceptance and publishes its practice; verification is graded, not gated. Verification is not authorization. Identity answers “is it who it claims”; ACM execution answers “what may it do”. A VERIFIED counterparty can still draw ACM-403, ACM-300, or ACM-451 on the commercial action. Machine verification narrows what humans decide; humans decide what machines commit. The four states: VERIFIED (by name in the guest book) · UNSIGNED · INVALID · KEY-UNREACHABLE (aggregate only). Decision table: https://gsc-handshake.ai/decision-table.json — graded, not gated. Guest book: https://gsc-handshake.ai/guest-book.json (ledger of record: https://mcp.cpghumanintheloop.ai/handshake/ledger.json) Keyring checked against: https://dpuone.ai/.well-known/jwks.json (resolver-attested: https://gsc-registry.ai/) IA us. — https://instantagentmessage.ai/ (the public IA-MESSAGE protocol surface; present your card when you lodge) Enforcement posture: open-by-declaration · migration: OAuth 2.1 + PKCE challenge (401 + WWW-Authenticate) on mcp:transact methods per MCP 2025-11-25 · trigger: ecosystem GA of credentialed counterparties · window: Q4 2026 - Q1 2027 · declared 2026-08-24 Operator: GreenCore Solutions Corp. | D-U-N-S 24-336-6774 | Microsoft AI Cloud Partner