Compose an HTTP request signature base
Compose inert ASCII RFC 9421 request signature-base and Signature-Input artifacts from ordered, supplied non-secret field examples and explicit context. Does not sign, verify, authorize or send requests.
protocol-assurance · Operation ID: http-signature-base-compose
Choose this operation when
- Build an inert signature-base example from supplied request context and ordered ASCII field lines
- Compare raw and binary-wrapped field boundaries before using an external signer
Outside this profile
- Signing, verification, keys, credentials, authentication, authorization, payment, or live HTTP requests
- Responses, trailers, CONNECT, query-parameter selection, Structured Field parsing, Unicode or obs-text fields
- Secret or production request payloads, including secrets in targets, free text or key identifiers
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"request": {
"type": "object",
"properties": {
"method": {
"type": "string",
"minLength": 1,
"maxLength": 32,
"pattern": "^[!#$%&'*+.^_`|~0-9A-Za-z-]+$(?![\\s\\S])"
},
"scheme": {
"type": "string",
"enum": [
"http",
"https"
]
},
"authority": {
"type": "string",
"minLength": 1,
"maxLength": 259,
"pattern": "^[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?(?::[1-9][0-9]{0,4})?$(?![\\s\\S])"
},
"target": {
"type": "string",
"minLength": 1,
"maxLength": 1024,
"pattern": "^\\/(?:[A-Za-z0-9._~!$&'()*+,;=:@/-]|%[0-9A-Fa-f]{2})*(?:\\?(?:[A-Za-z0-9._~!$&'()*+,;=:@/?-]|%[0-9A-Fa-f]{2})*)?$(?![\\s\\S])"
},
"headers": {
"maxItems": 64,
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"pattern": "^[!#$%&'*+.^_`|~0-9A-Za-z-]+$(?![\\s\\S])"
},
"value": {
"type": "string",
"maxLength": 1024,
"pattern": "^[\\x09\\x20-\\x7e]*$(?![\\s\\S])"
}
},
"required": [
"name",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"method",
"scheme",
"authority",
"target",
"headers"
],
"additionalProperties": false
},
"label": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"pattern": "^[a-z*][a-z0-9_.*-]*$(?![\\s\\S])"
},
"components": {
"maxItems": 32,
"type": "array",
"items": {
"anyOf": [
{
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "derived"
},
"name": {
"type": "string",
"enum": [
"@method",
"@scheme",
"@authority",
"@target-uri",
"@path",
"@query"
]
}
},
"required": [
"type",
"name"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "field"
},
"name": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"pattern": "^[!#$%&'*+.^_`|~0-9a-z-]+$(?![\\s\\S])"
},
"mode": {
"type": "string",
"enum": [
"raw",
"binary"
]
}
},
"required": [
"type",
"name",
"mode"
],
"additionalProperties": false
}
]
}
},
"parameters": {
"minItems": 1,
"maxItems": 6,
"type": "array",
"items": {
"anyOf": [
{
"type": "object",
"properties": {
"name": {
"type": "string",
"enum": [
"created",
"expires"
]
},
"value": {
"type": "string",
"maxLength": 15,
"pattern": "^(?:0|[1-9][0-9]{0,14})$(?![\\s\\S])"
}
},
"required": [
"name",
"value"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"name": {
"type": "string",
"enum": [
"keyid",
"nonce",
"tag"
]
},
"value": {
"type": "string",
"minLength": 1,
"maxLength": 256,
"pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
}
},
"required": [
"name",
"value"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"name": {
"type": "string",
"const": "alg"
},
"value": {
"type": "string",
"enum": [
"rsa-pss-sha512",
"rsa-v1_5-sha256",
"hmac-sha256",
"ecdsa-p256-sha256",
"ecdsa-p384-sha384",
"ed25519"
]
}
},
"required": [
"name",
"value"
],
"additionalProperties": false
}
]
}
}
},
"required": [
"request",
"label",
"components",
"parameters"
],
"additionalProperties": false
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "http-signature-base-compose",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"profile": {
"type": "string",
"const": "http-sig-rfc9421-request-ascii-v1"
},
"signatureBase": {
"type": "string",
"minLength": 1,
"maxLength": 8192,
"pattern": "^[\\x09\\x0a\\x20-\\x7e]*$(?![\\s\\S])"
},
"byteLength": {
"type": "integer",
"minimum": 1,
"maximum": 8192
},
"sha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$(?![\\s\\S])"
},
"signatureInput": {
"type": "object",
"properties": {
"name": {
"type": "string",
"const": "signature-input"
},
"value": {
"type": "string",
"minLength": 1,
"maxLength": 4096,
"pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
},
"byteLength": {
"type": "integer",
"minimum": 1,
"maximum": 4096
},
"sha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$(?![\\s\\S])"
}
},
"required": [
"name",
"value",
"byteLength",
"sha256"
],
"additionalProperties": false
},
"components": {
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"identifier": {
"type": "string",
"minLength": 1,
"maxLength": 69,
"pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
},
"value": {
"type": "string",
"maxLength": 8192,
"pattern": "^[\\x09\\x20-\\x7e]*$(?![\\s\\S])"
},
"headerIndexes": {
"maxItems": 64,
"type": "array",
"items": {
"type": "integer",
"minimum": 0,
"maximum": 63
}
}
},
"required": [
"identifier",
"value",
"headerIndexes"
],
"additionalProperties": false
}
}
},
"required": [
"profile",
"signatureBase",
"byteLength",
"sha256",
"signatureInput",
"components"
],
"additionalProperties": false
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"request": {
"method": "POST",
"scheme": "https",
"authority": "api.example.com",
"target": "/v1/items?limit=10",
"headers": [
{
"name": "Content-Type",
"value": "application/json"
},
{
"name": "Cache-Control",
"value": "max-age=60"
},
{
"name": "cache-control",
"value": " no-transform "
}
]
},
"label": "demo",
"components": [
{
"type": "derived",
"name": "@method"
},
{
"type": "derived",
"name": "@authority"
},
{
"type": "derived",
"name": "@path"
},
{
"type": "derived",
"name": "@query"
},
{
"type": "field",
"name": "content-type",
"mode": "raw"
},
{
"type": "field",
"name": "cache-control",
"mode": "raw"
}
],
"parameters": [
{
"name": "created",
"value": "1700000000"
},
{
"name": "keyid",
"value": "demo-key"
}
]
}
Example response
{
"operation": "http-signature-base-compose",
"version": "0.29.0",
"result": {
"profile": "http-sig-rfc9421-request-ascii-v1",
"signatureBase": "\"@method\": POST\n\"@authority\": api.example.com\n\"@path\": /v1/items\n\"@query\": ?limit=10\n\"content-type\": application/json\n\"cache-control\": max-age=60, no-transform\n\"@signature-params\": (\"@method\" \"@authority\" \"@path\" \"@query\" \"content-type\" \"cache-control\");created=1700000000;keyid=\"demo-key\"",
"byteLength": 289,
"sha256": "65400d9ddc9e40a9d916cf84f6fcb158dd7a0eda5ac3aab66d0edfd12b01eb0d",
"signatureInput": {
"name": "signature-input",
"value": "demo=(\"@method\" \"@authority\" \"@path\" \"@query\" \"content-type\" \"cache-control\");created=1700000000;keyid=\"demo-key\"",
"byteLength": 113,
"sha256": "5f6fb3f5e0453d1599d8ae03a24e9e6052ff9180b2e0fd4533afe79e35ed5cbd"
},
"components": [
{
"identifier": "\"@method\"",
"value": "POST",
"headerIndexes": []
},
{
"identifier": "\"@authority\"",
"value": "api.example.com",
"headerIndexes": []
},
{
"identifier": "\"@path\"",
"value": "/v1/items",
"headerIndexes": []
},
{
"identifier": "\"@query\"",
"value": "?limit=10",
"headerIndexes": []
},
{
"identifier": "\"content-type\"",
"value": "application/json",
"headerIndexes": [
0
]
},
{
"identifier": "\"cache-control\"",
"value": "max-age=60, no-transform",
"headerIndexes": [
1,
2
]
}
]
},
"provenance": {
"inputSha256": "4c566ce40d6d3390f029304d7fea2ae98b0f787afa766c0168a44f5132a73e57",
"outputSha256": "fb2b84b135aa6b57b8b49279f1c9ce1b410a052b89201d78f4322d82c88b3df3",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 16384,
"jsonNodes": 1024,
"depth": 12,
"outputBytes": 200000,
"headerLines": 64,
"headerNameBytes": 64,
"headerValueBytes": 1024,
"aggregateHeaderValueBytes": 4096,
"targetBytes": 1024,
"authorityBytes": 259,
"components": 32,
"parameters": 6,
"labelBytes": 64,
"signatureBaseBytes": 8192,
"signatureInputBytes": 4096
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.006",
"sixDecimalTokenBaseUnits": "6000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/http-signature-base-compose",
"mpp": "/v1/mpp/http-signature-base-compose"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.