Eleven surfaces are cataloged below. The first five went onto this docroot in one night and nothing pointed at them — they served to anyone who knew the URL and to no one else; the six that followed landed the same way. They are the newest tier of the product: run a whole agent from one document, talk to it for nothing, put it on your own site, bring your own face or body, and read the contracts the files obey. Every one is a candidate — served, working, and carrying its own noindex; that is what the candidate chip means on the cards below.
Load a joined nsv-agent-1 document and it becomes a wearing, captioned, talking agent — locally, with nothing leaving the machine. Six lane documents are one click away, one per engine: Basic (ascii) · Nova (svg) · Dean (sketch) · Ticker (kinetic) · Sana (hybrid) · Probe (live-vrm). Both halves are re-verified before anything runs — the join gate, the whole-doc seal, the body pins re-hashed against the real package bytes.
ProvesThe join is not paperwork: one document really does produce a running agent. And the two rungs that cannot wear yet — ascii and live-vrm — refuse by name and run mind-only, instead of pretending.
/alive-site/agent-run.html
You have an agent; this page puts it on your website. Three ways in — a ready package off the shelf, a .alive.json you exported, or a joined agent document — all ending at one file your site will host. It shows the real element wearing the real package before you ship, hands back your JSON byte-for-byte so the digests stay true, and writes your two lines to paste.
ProvesPutting an agent on your own site is a copy-paste — from your own site today. Loading line one from NetShow is blocked until a header ships, and the page says so on the choice itself rather than in a footnote.
/alive-site/embed-kit.html
You already have the face — or the body. One guided page walks both roads: a photo becomes a sealed, portable package; a .vrm model becomes a 3D body kept in your own browser's model library.
ProvesEach road is walked to a wearing result, including the plain part — the photo route's lab is a crew door today, and the page says so before you start rather than at the login prompt.
/alive-site/bring-your-own.html
Wear a sealed .alive.json, then talk. The default lane is the offline rule-based agent — zero network, zero spend. A pass gate opens a real billed voice turn, asked for on every load and never started on its own.
ProvesThere is a $0 way to talk to a face you just sealed. It names its own scope: kinetic-typography, svg and hybrid are worn today; sketch-line and ascii join as their seal and wear repairs land.
/alive-site/nsv-converse-stage.html
The orb wearing the expression clock on a real line: pick the SDP proxy or the ephemeral-secret line, meet the spend gate and the pass gate, and the adapter is built on click with the browser’s own microphone and WebRTC. The session config and the provider key never leave the server; the page only ever talks to /api/realtime/… on this origin.
ProvesU06 and U05 join on a served page with one dynamics loop, and the same-origin endpoints answer exactly what the adapter’s contract demands — {value, expires_at} and nothing else, application/sdp and nothing else. Until the server restart lights the grant, the line refuses by name.
/alive-site/live-agents.html#orbLive
open · filesno directory index
The three JSON Schemas that define what actually travels — the joined agent document, the sealed package, and the face-lab handoff — plus nsv-validate.mjs, a command-line tool that detects the format by its own discriminator, validates it, and then recomputes the hashes.
ProvesThe formats are written down, not just implemented. The validator does the half a schema cannot: a well-shaped stale hash passes the schema and fails here. Note the URL — /alive-site/schemas/ has no directory index and returns 404, so these four files are the door.
/alive-site/schemas/…
open · $0orb lane · local-only
A creator surface for the orb face: shape the dynamics, watch it move, and export a .alive.json orb package. Everything runs in the page — nothing is uploaded and no account is asked for.
ProvesThe orb face is authored, not only rendered. Its export is the package the orb CLI verifies by digest, so what leaves the studio is what the embed kit wears.
/alive-site/demo/orb-face-studio/
A published Alive agent presented through the host’s verified publication and realtime owner wiring, wearing the orb face. Three modules on one page: orb-face dynamics, the published-agent owner wiring, and the Realtime face host.
ProvesThe three orb modules join end to end on a NetShow-owned surface. Presence is when you choose — nothing live starts on its own.
/alive-site/demo/published-orb-face/
open · $0installable · offline
Load the bundled sample or choose an .alive.json from your own device and meet it privately: only a verified package is accepted, the file stays in this page’s memory, and it is never uploaded or cached. A fixed event demo runs listening, thinking, speaking, captions and interruption without opening a microphone.
ProvesAn agent package is a real portable document: once the shell has loaded once, supported browsers reopen the demonstration with no connection, and an unverified package is refused before anything wears it.
/alive-site/demo/alive-pwa/
One guided run in the order a first-time creator needs: choose a starter or a blank SVG, shape the presence, preview the tier, validate, export, download, hand off. Every starter is a real sealed .alive.json; draft state stays in the tab, and no authored package is uploaded.
ProvesThe floor above is walkable in one sitting by someone who has never seen it, with the seal authority left where it lives — the renderer stays the face authority; the Studio only shapes the frame and the exported intent.
/alive-site/studio-launch/
open · $0receipts · proof adapter
One package walked from draft to revocation — validate, export locally, publish with a receipt, share for a bounded time, revoke — with an exact receipt required at every milestone. It runs on a deterministic proof adapter: no live calls, and no credential or signed URL ever enters the page.
ProvesA package has a commercial life, not only a technical one. The export ledger keeps three deliberately distinct hashes — file, canonical package, payload — and publication identity is a fourth, so a receipt can be checked later against real bytes.
/alive-site/commercial-lifecycle/