Acquire buyer-mandate 0.5.0 without Git credentials and without the private repository.

publicationStatus: candidate
hostedAcquisitionVerified: false
launched: false
paymentAuthority: none
claimAuthority: none

A matching decision is an envelope. It is not permission to spend.
A refused operation is a result. --pay exits 2.

Node.js 22. Root is not required. Do not point npm at a private git remote.

  curl -fsSL -o buyer-mandate-0.5.0.tar.gz \
    https://neomorphic.io/downloads/buyer-mandate/0.5.0/buyer-mandate-0.5.0.tar.gz
  tar -xzf buyer-mandate-0.5.0.tar.gz
  cd buyer-mandate-0.5.0
  sh cold-install.sh

cold-install.sh is:

  npm ci --ignore-scripts --no-audit --no-fund
  npm ci --ignore-scripts --no-audit --no-fund --prefix packages/route-lock
  npm ci --ignore-scripts --no-audit --no-fund --prefix experiments/buyer-mandate-20260930

The three installs use the public npm registry and the public GitHub archive
URLs already pinned in the lockfiles. They do not clone a private repository.

Current-time decision, resume, later task, and seeded refusals:

  node experiments/buyer-mandate-public-delivery-100192/bin/handoff.mjs run

The focused source graph, after those installs:

  node --test --test-concurrency=1 experiments/buyer-mandate-20260930/test/*.test.mjs

Prepared-request compatibility. This does not execute a payment or recover a
durable spend. The caller supplies the binding. Absent that binding, omitted
query metadata is refused.

  node experiments/buyer-mandate-20260930/bin/buyer-mandate.mjs prepare \
    --input experiments/buyer-mandate-20260930/examples/prepared-request/omitted-query.json

hostedAcquisitionVerified stays false until Root reads these bytes from the
public origin. A loopback GET is not hosted acceptance. This pack does not
publish npm, open checkout, or create a SKU.
