Artifact derivation lineage check
Check a supplied artifact derivation graph for parent-digest and media-type agreement, missing or cyclic ancestry, and required/forbidden ancestor or depth constraints. Inspect only supplied manifests; no artifact bytes, derivations, identities or source authenticity are verified.
workflow-assurance · Operation ID: artifact-lineage-check
Choose this operation when
- Validate artifact parent digests and transformation media contracts
- Check required or forbidden source ancestry before accepting an agent artifact
Outside this profile
- Live negotiation, message delivery, queue consumption, remote pagination, artifact fetching or migration execution
- Authentication, signed provenance, authorization, schema compatibility proofs, or exactly-once guarantees
- Inferring absent versions, server state, missing history, semantic equivalence, or market uniqueness
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"artifacts": {
"maxItems": 128,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"sha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"kind": {
"type": "string",
"enum": [
"source",
"derived"
]
},
"mediaType": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"parents": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"expectedSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
}
},
"required": [
"id",
"expectedSha256"
],
"additionalProperties": false
}
},
"derivation": {
"type": "object",
"properties": {
"operation": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"version": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"inputMediaTypes": {
"minItems": 1,
"maxItems": 16,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"outputMediaType": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"required": [
"operation",
"version",
"inputMediaTypes",
"outputMediaType"
],
"additionalProperties": false
}
},
"required": [
"id",
"sha256",
"kind",
"mediaType",
"parents"
],
"additionalProperties": false
}
},
"targets": {
"minItems": 1,
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"artifactId": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"expectedSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"requiredAncestors": {
"maxItems": 32,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"forbiddenAncestors": {
"maxItems": 32,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"maximumDepth": {
"type": "integer",
"minimum": 0,
"maximum": 127
}
},
"required": [
"artifactId",
"requiredAncestors",
"forbiddenAncestors",
"maximumDepth"
],
"additionalProperties": false
}
}
},
"required": [
"artifacts",
"targets"
],
"additionalProperties": false
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "artifact-lineage-check",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"profile": {
"type": "string",
"const": "artifact-derivation-lineage-v1"
},
"consistent": {
"type": "boolean"
},
"targets": {
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"artifactId": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"matchesRequirements": {
"type": "boolean"
},
"ancestors": {
"maxItems": 127,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"rootSources": {
"maxItems": 128,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
},
"depth": {
"anyOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "null"
}
]
},
"completeSuppliedLineage": {
"type": "boolean"
}
},
"required": [
"artifactId",
"matchesRequirements",
"ancestors",
"rootSources",
"depth",
"completeSuppliedLineage"
],
"additionalProperties": false
}
},
"findings": {
"maxItems": 200,
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"error",
"warning"
]
},
"path": {
"type": "string"
},
"message": {
"type": "string"
},
"relatedIds": {
"maxItems": 8,
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 100
}
}
},
"required": [
"code",
"severity",
"path",
"message",
"relatedIds"
],
"additionalProperties": false
}
},
"findingCount": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"errorCount": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"truncated": {
"type": "boolean"
},
"advisoryOnly": {
"type": "boolean",
"const": true
},
"execution": {
"type": "boolean",
"const": false
},
"authorizationGranted": {
"type": "boolean",
"const": false
}
},
"required": [
"profile",
"consistent",
"targets",
"findings",
"findingCount",
"errorCount",
"truncated",
"advisoryOnly",
"execution",
"authorizationGranted"
],
"additionalProperties": false
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"artifacts": [
{
"id": "source",
"sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"kind": "source",
"mediaType": "text/plain",
"parents": []
},
{
"id": "summary",
"sha256": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"kind": "derived",
"mediaType": "application/json",
"parents": [
{
"id": "source",
"expectedSha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
}
],
"derivation": {
"operation": "extract",
"version": "1",
"inputMediaTypes": [
"text/plain"
],
"outputMediaType": "application/json"
}
}
],
"targets": [
{
"artifactId": "summary",
"expectedSha256": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"requiredAncestors": [
"source"
],
"forbiddenAncestors": [],
"maximumDepth": 2
}
]
}
Example response
{
"operation": "artifact-lineage-check",
"version": "0.29.0",
"result": {
"profile": "artifact-derivation-lineage-v1",
"consistent": true,
"targets": [
{
"artifactId": "summary",
"matchesRequirements": true,
"ancestors": [
"source"
],
"rootSources": [
"source"
],
"depth": 1,
"completeSuppliedLineage": true
}
],
"findings": [],
"findingCount": 0,
"errorCount": 0,
"truncated": false,
"advisoryOnly": true,
"execution": false,
"authorizationGranted": false
},
"provenance": {
"inputSha256": "507af5b7f2bc18266841de2aad66dd74e0e46d7281b89d47ccc6c5e05c8c4882",
"outputSha256": "f67df918a8b3a3f449b877066a50d72013446c94a2e48a1c9d6f42ee9fefd167",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 100000,
"outputBytes": 400000,
"jsonNodes": 12000,
"depth": 20,
"findings": 200,
"artifacts": 128,
"parentsPerArtifact": 16,
"targets": 32,
"ancestorsPerConstraint": 32
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.005",
"sixDecimalTokenBaseUnits": "5000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/artifact-lineage-check",
"mpp": "/v1/mpp/artifact-lineage-check"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.