Explicit structural JSON redaction
Remove object members or replace selected JSON subtrees with caller-supplied scalars using bounded typed selectors. Original-snapshot matching, expected-count guards and overlap rejection make edits atomic. Optional audit omission; no secret discovery, PII inference, anonymization or safe-to-share guarantee.
structured · Operation ID: json-selector-redact
Choose this operation when
- Caller knows which structural fields must be removed or replaced
- Guard a repeated-record cleanup with exact match counts and simultaneous edits
Outside this profile
- Discover secrets or infer personal information from meaning
- Guarantee anonymity or that remaining data is safe to share
- Apply arbitrary JSONPath, regex, recursive descent or scripts
- Remove array elements or reorder their identity
- Known exact-pointer edits already fit JSON Patch
- Read files, send documents, fetch data or change external state
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"document": {
"$ref": "#/$defs/__schema0"
},
"rules": {
"minItems": 1,
"maxItems": 64,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"pattern": "^[\\s\\S]{1,64}(?![\\s\\S])"
},
"select": {
"maxItems": 20,
"type": "array",
"items": {
"anyOf": [
{
"type": "object",
"properties": {
"key": {
"type": "string"
}
},
"required": [
"key"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"index": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"index"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"anyKey": {
"type": "boolean",
"const": true
}
},
"required": [
"anyKey"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"anyIndex": {
"type": "boolean",
"const": true
}
},
"required": [
"anyIndex"
],
"additionalProperties": false
}
]
}
},
"action": {
"anyOf": [
{
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "replace"
},
"value": {
"type": [
"string",
"number",
"boolean",
"null"
]
}
},
"required": [
"type",
"value"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "remove"
}
},
"required": [
"type"
],
"additionalProperties": false
}
]
},
"minMatches": {
"type": "integer",
"minimum": 0,
"maximum": 2000
},
"maxMatches": {
"type": "integer",
"minimum": 0,
"maximum": 2000
}
},
"required": [
"id",
"select",
"action",
"minMatches",
"maxMatches"
],
"additionalProperties": false
}
},
"includeAudit": {
"type": "boolean"
}
},
"required": [
"document",
"rules"
],
"additionalProperties": false,
"$defs": {
"__schema0": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"$ref": "#/$defs/__schema0"
}
},
{
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"$ref": "#/$defs/__schema0"
}
}
]
}
}
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "json-selector-redact",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"anyOf": [
{
"type": "object",
"properties": {
"document": {
"$ref": "#/properties/result/$defs/__schema0"
}
},
"required": [
"document"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"document": {
"$ref": "#/properties/result/$defs/__schema1"
},
"audit": {
"maxItems": 2000,
"type": "array",
"items": {
"type": "object",
"properties": {
"ruleId": {
"type": "string"
},
"path": {
"type": "string"
},
"action": {
"type": "string",
"enum": [
"replace",
"remove"
]
}
},
"required": [
"ruleId",
"path",
"action"
],
"additionalProperties": false
}
},
"counts": {
"minItems": 1,
"maxItems": 64,
"type": "array",
"items": {
"type": "object",
"properties": {
"ruleId": {
"type": "string"
},
"matches": {
"type": "integer",
"minimum": 0,
"maximum": 2000
}
},
"required": [
"ruleId",
"matches"
],
"additionalProperties": false
}
}
},
"required": [
"document",
"audit",
"counts"
],
"additionalProperties": false
}
],
"$defs": {
"__schema0": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"$ref": "#/properties/result/$defs/__schema0"
}
},
{
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"$ref": "#/properties/result/$defs/__schema0"
}
}
]
},
"__schema1": {
"anyOf": [
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
},
{
"type": "array",
"items": {
"$ref": "#/properties/result/$defs/__schema1"
}
},
{
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"$ref": "#/properties/result/$defs/__schema1"
}
}
]
}
}
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"document": {
"users": [
{
"email": "a@example.invalid",
"name": "A"
},
{
"email": "b@example.invalid",
"name": "B"
}
]
},
"rules": [
{
"id": "email",
"select": [
{
"key": "users"
},
{
"anyIndex": true
},
{
"key": "email"
}
],
"action": {
"type": "replace",
"value": "[REDACTED]"
},
"minMatches": 2,
"maxMatches": 2
}
]
}
Example response
{
"operation": "json-selector-redact",
"version": "0.29.0",
"result": {
"document": {
"users": [
{
"email": "[REDACTED]",
"name": "A"
},
{
"email": "[REDACTED]",
"name": "B"
}
]
},
"audit": [
{
"ruleId": "email",
"path": "/users/0/email",
"action": "replace"
},
{
"ruleId": "email",
"path": "/users/1/email",
"action": "replace"
}
],
"counts": [
{
"ruleId": "email",
"matches": 2
}
]
},
"provenance": {
"inputSha256": "c13cf62b63cbaafe9d7c6aa847143adc63520cd1abf7abf76ac9b552aa4de723",
"outputSha256": "3cb2f0624e5a91719650e702ddc997419a88216846b14e80be844bb1119eb33c",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 100000,
"outputBytes": 400000,
"jsonNodes": 12000,
"depth": 20,
"rules": 64,
"selectorTokens": 20,
"selectedTargets": 2000,
"selectorVisits": 250000,
"profile": "explicit-structural-redaction-v1",
"ruleIdScalars": 64,
"selectorIndexMaximum": 9007199254740991
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.005",
"sixDecimalTokenBaseUnits": "5000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/json-selector-redact",
"mpp": "/v1/mpp/json-selector-redact"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.