Commodities.
Metal in a vault, a receipt on a screen, and an agent asking for the lot.
Commodity markets already run on signed paper: assays, warehouse receipts, warrants. The missing certificate is the one behind the buyer.
The chain of custody has names.
A tokenized commodity is a claim on physical held by someone, graded by someone, listed by someone. These are the someones.
Mines, grows, or refines the physical. Gets paid when the lot changes hands, long after it left the gate.
Holds the physical and issues the receipt that stands in for it. That receipt is the market's working truth.
Certifies grade and weight. Every downstream price leans on that certificate.
Lists the receipt-backed instrument and keeps the book. Probably you.
Stands between the two sides of a trade so a default lands on capital, not on counterparties.
The end buyer with a plant to feed. Wants the metal, not the paperwork.
PRODUCER
ships the lot
WAREHOUSE
issues the receipt
ASSAYER
certifies grade
VENUE
keeps the book
CLEARING
guarantees the trade
OFFTAKER
takes delivery
agents enter at the venue · one gate · receipts filed
The chain is signed. The buyer isn't.
A tokenized lot is a chain of documents. The assay says what it is, the warehouse receipt says where it sits, the listing says it may trade. Every link carries a signature someone can stand behind.
Then the buyer arrives, and it's software holding an API key. A key is access, not accountability: it names no firm behind the agent, and it expires when someone remembers to rotate it.
When a lot goes bad — a contested assay, a receipt pledged twice — every party in the chain produces its signature. The buyer's side of the file is an access log.
Every link in the chain is signed. The newest link isn't.
The same five checks, in commodity terms.
The agent trades under an identity the venue issued, tied to the member firm that answers for it. Revocable the moment something smells wrong.
A mandate with edges: which metals, what lot size, what daily notional, what expiry. Enforced at the gate, not requested in a prompt.
Orders are signed inside the boundary. The keys never sit in the agent's context, so a hijacked agent can't sign a thing.
The fill happens on the venue's own book, under the clearing arrangements human flow already uses.
The action files a signed record naming the lot, the mandate, and the outcome. One more certificate, in a market made of them.
What the record looks like here.
This is the certificate the newest party in the chain finally gets to carry. The digest below is computed at build over exactly these fields.
Verify one yourself- ACTION
- Buy 2,000 oz · warehouse-receipt gold lot WR-AU-0117
- MANDATE
- Warehouse-receipt metals only · ≤ $250,000/day · expires 2026-11-30
- VENUE
- Order admitted · agent identity ag-3c91 · mandate check passed
- OUTCOME
- Filled 2,000 oz @ 2,412.20 · warrant transfer T+1 · receipt filed
Illustrative specimen of an Accords action receipt. The bundle hash is the real SHA-256 of this specimen’s fields — recompute it yourself. Signed receipts are what the runtime emits; this specimen claims the shape.
Asked, answered.
Does this require the commodity itself to be tokenized?
No. Accords governs the agent, not the asset. If your venue lists warehouse-receipt-backed instruments in any digital form, the agent-facing edge is what changes; custody of the physical stays exactly where it is.
Who issues the agent's identity in a commodity market?
The venue, tied to a member firm that answers for it — the same way access works for human traders. A wallet address or an API key is not an identity.
What shows up in the receipt for a physical-delivery trade?
The action, the mandate it ran under, the venue’s checks, and the outcome, including the lot identifier. The receipt covers the governed action at the venue; warehouse and assay records remain the documents they already are.