BMP defines a signed command envelope and three verification tiers. A robot, lock, drone, or vending machine that receives a BMP message can prove locally who sent it, that it paid a real fee, and that the BSV ledger keeps it — without trusting any server.
Every command is an 85-byte envelope signed with secp256k1 by a registered authority key. One ECDSA check, works on a microcontroller. Physical transports (a camera, a radio) supply the presence proof; the signature supplies the identity.
The command is anchored in a fee-paying BSV transaction. From the transaction plus its ancestor evidence, a device verifies the input signatures offline — proving the command was paid for without asking any node. Freshness rules stop replay.
A standard BEEF package (BRC-62) with a BUMP merkle path (BRC-74) proves the anchored command sits in a block whose proof-of-work the device checks against locally held headers. Now the whole network arbitrates double-spends, not the device.
Stable means two independent implementations (Python + browser JavaScript) pass the published golden vectors with bit-identical results. Live mainnet proofs ship frozen in the repo — every claim is replayable offline.
A real anchored command — "HELLO, CHAIN. This command paid its own way." — verified layer-by-layer in your browser, frozen evidence or fresh from the chain.
Web Bluetooth page that reassembles and verifies a fragmented command from raw advertising packets — the radio last-mile, no pairing.
How BMP's L3 objects compose with the BEEF multicast plane (BRC-148/149): wide-area distribution meets the physical last mile.
The flagship product: visual matrix codes that stream BMP payloads as light — browser transmitter, camera scanner, and a live sticker campaign paying real sats.
The envelope and verification stack are bearer-agnostic. Reserved next: BMP-RFID, BMP-LoRa. Spec process documented in BMP-0000.