# RH2 review uses one origin with Market and core

Status: Accepted. Date: 2026-09-30. Card t_ad153e0a, task t_bc198486.

Market authenticates browser and agent requests through RH2 at the incoming origin under `/api/v3`. A review World
that starts only core cannot reproduce that boundary. The owner requested including Market in the recipe, and a
real Machine attachment through local Teams for the Machine acts the review needs.

The cookbook recipe takes `RH2_ROOT` and an owner address. The World owns database, media, Workers and ingress;
the recipe owns migration, local credentials and API seeding. The ingress preserves paths, Host, cookies and
WebSocket upgrades, routing `/market` and its descendants to Market and everything else to core. Both Workers
share the World's disposable database and origin.

The optional Machine lane uses a task-owned local Teams server and a machine consumer with a separate home and
terminal socket. Teams trusts this World's RH2 issuer. Credentials come from these local services' ordinary doors;
Machine acts are real. This adds a recipe, without another runtime orchestration mechanism or changes to RH2.

Construction is covered by the arc's build rule; execution and independent review wait for the final slate.
