Forward Deployed Engineer – Identity, UCP & Wallets (TypeScript)

Recurring Decimal

  • Phoenix, AZ
  • Today
  • Contractor
  • Full-time

Highlights

This role carries a verified loyalty identity through the agent handshake on Google's Universal Commerce Protocol (UCP) and on a protocol-agnostic rail, and builds a wallet-held Verifiable Credential proof of concept.

Numbers & Facts

LocationPhoenix, AZ
Job TypeContractor, Full-time
Company Size11 - 50
Year Founded2012
HeadquartersPhoenix, AZ, US
Websitehttps://recurringdecimal.com

Description

This role carries a verified loyalty identity through the agent handshake on Google's Universal Commerce Protocol (UCP) and on a protocol-agnostic rail, and builds a wallet-held Verifiable Credential proof of concept.

Job Responsibilities

First 90 days

  • Implement the UCP side. This means a namespaced agent_trust signal with a loyalty block on a platform agent, and a mock UCP merchant that verifies it, resolves eligibility server-to-server, applies member pricing and reserved-inventory holds in the Checkout object, and records pending earn on the Order. It steps up to OAuth (PKCE) identity linking only for redeem/transfer.
  • Build the protocol-agnostic rail: an X-Agent-Trust header contract, a Cloudflare Worker edge verifier with JWKS caching and spoof-header stripping, and Node/TypeScript merchant middleware exposing a loyalty context to handlers.
    Build the VC POC.
  • Issue an Agent Trust credential over OID4VCI to a holder wallet (Credo or equivalent), present it via OID4VP with selective disclosure (SD-JWT first, BBS+ predicate as a stretch goal), verify it at the merchant, and prove no PII reaches the agent.
  • Implement and run the loyalty-fraud test suite on both rails, covering replay across merchants, token reuse, enumeration, ATO-pattern redeem, and scalper hold-and-abandon.
  • Write the merchant integration guides for the rail and the UCP path, and build the demo storefront beats.

Deliverables
UCP signal schema + platform-agent reference · Mock UCP merchant with loyalty tiers · Header contract + edge verifier + middleware SDK · VC issuer/wallet/verifier POC · Fraud test suite · Integration guides · Demo beats

Qualifications

Must have

  • 5+ years of TypeScript/Node (Node 22, Next.js or similar), strong HTTP fundamentals, and comfort writing both a spec-conformant server and a reference client.
  • Identity engineering: OAuth 2.0 Authorization Code + PKCE, OIDC, JWT/JWS (ES256, EdDSA), JWKS rotation, and replay controls (aud, jti, TTL), with production experience implementing token verification.
  • Hands-on Verifiable Credentials work: W3C VC 2.0 data model, OID4VCI/OID4VP, and SD-JWT VC, plus familiarity with DID methods (did:web, did:key) and at least one wallet SDK.
  • Edge development on Cloudflare Workers (or equivalent) with KV/Durable Objects, including header verification and injection, and rate limiting.
    Precise reading of protocol specs (UCP, RFC 9421, RFC 8693, OpenID specs) with section-level citations, and delivery from acceptance criteria without supervision.

 

Nice to have

  • BBS+ / zero-knowledge predicate tooling · Google UCP or Merchant Center integrations · Loyalty-programme or promotions systems · Enough Python to pair on the Claude blueprint binding · 
  • E-commerce fraud or bot-management experience

 

Skills

  • Type script
  • Node.js
  • Next.js
  • OAuth 2.0
  • DID methods
  • W3C VC2.0 data model
  • Cloudfare workers

Similar Jobs

See more jobs