Inline OCI artifact manifest composer
WHEN TO USE: Build a supplied-input OCI 1.1.1 artifact manifest with SHA-256 digests, exact decoded sizes and inline Base64 bytes for every ordered file layer. Caller declares artifactType and media types; fixed empty JSON config and title-only annotations. No enclosing manifest digest, image build, filesystem layout, registry contact, upload, signature or authenticity guarantee.
structured · Operation ID: oci-artifact-compose
Choose this operation when
- Compose an OCI 1.1.1 artifact manifest from supplied binary or UTF-8 evidence files
- Compute content-addressed inline layer descriptors with exact file bytes and source mapping
Outside this profile
- OCI image building, registry access, pushing or pulling, tar/layout generation, signatures, provenance truth or publisher authenticity
- Enclosing manifest digest without exact serialized bytes, inferred timestamps, executable config, platform or subject
- Uploading, executing artifacts, contacting agents or registries, publishing, or changing remote state
- Verifying semantic truth, source authenticity, permissions, target API acceptance or signatures
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"artifactType": {
"type": "string",
"minLength": 3,
"maxLength": 127,
"pattern": "^[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*\\/[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*$"
},
"files": {
"minItems": 1,
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"mediaType": {
"type": "string",
"minLength": 3,
"maxLength": 127,
"pattern": "^[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*\\/[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*$"
},
"encoding": {
"type": "string",
"enum": [
"utf8",
"base64"
]
},
"data": {
"type": "string",
"maxLength": 80000
}
},
"required": [
"name",
"mediaType",
"encoding",
"data"
],
"additionalProperties": false
}
}
},
"required": [
"artifactType",
"files"
],
"additionalProperties": false
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "oci-artifact-compose",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"manifest": {
"type": "object",
"properties": {
"schemaVersion": {
"type": "number",
"const": 2
},
"mediaType": {
"type": "string",
"const": "application/vnd.oci.image.manifest.v1+json"
},
"artifactType": {
"type": "string",
"minLength": 3,
"maxLength": 127,
"pattern": "^[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*\\/[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*$"
},
"config": {
"type": "object",
"properties": {
"mediaType": {
"type": "string",
"const": "application/vnd.oci.empty.v1+json"
},
"digest": {
"type": "string",
"const": "sha256:44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a"
},
"size": {
"type": "number",
"const": 2
},
"data": {
"type": "string",
"const": "e30="
}
},
"required": [
"mediaType",
"digest",
"size",
"data"
],
"additionalProperties": false
},
"layers": {
"minItems": 1,
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"mediaType": {
"type": "string",
"minLength": 3,
"maxLength": 127,
"pattern": "^[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*\\/[A-Za-z0-9][A-Za-z0-9!#$&^_.+\\-]*$"
},
"digest": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"size": {
"type": "integer",
"minimum": 0,
"maximum": 60000
},
"data": {
"type": "string",
"maxLength": 80000
},
"annotations": {
"type": "object",
"properties": {
"org.opencontainers.image.title": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"org.opencontainers.image.title"
],
"additionalProperties": false
}
},
"required": [
"mediaType",
"digest",
"size",
"data",
"annotations"
],
"additionalProperties": false
}
}
},
"required": [
"schemaVersion",
"mediaType",
"artifactType",
"config",
"layers"
],
"additionalProperties": false
},
"sourceMap": {
"minItems": 1,
"maxItems": 32,
"type": "array",
"items": {
"type": "object",
"properties": {
"inputIndex": {
"type": "integer",
"minimum": 0,
"maximum": 31
},
"layerIndex": {
"type": "integer",
"minimum": 0,
"maximum": 31
}
},
"required": [
"inputIndex",
"layerIndex"
],
"additionalProperties": false
}
}
},
"required": [
"manifest",
"sourceMap"
],
"additionalProperties": false
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"artifactType": "application/vnd.example.release.v1",
"files": [
{
"name": "notes.txt",
"mediaType": "text/plain",
"encoding": "utf8",
"data": "abc"
}
]
}
Example response
{
"operation": "oci-artifact-compose",
"version": "0.29.0",
"result": {
"manifest": {
"schemaVersion": 2,
"mediaType": "application/vnd.oci.image.manifest.v1+json",
"artifactType": "application/vnd.example.release.v1",
"config": {
"mediaType": "application/vnd.oci.empty.v1+json",
"digest": "sha256:44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
"size": 2,
"data": "e30="
},
"layers": [
{
"mediaType": "text/plain",
"digest": "sha256:ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad",
"size": 3,
"data": "YWJj",
"annotations": {
"org.opencontainers.image.title": "notes.txt"
}
}
]
},
"sourceMap": [
{
"inputIndex": 0,
"layerIndex": 0
}
]
},
"provenance": {
"inputSha256": "3bdff892ccc8769982df4a4d86508659e0fa7b5f8e1e7ec87dea660821348835",
"outputSha256": "36a3b667aea34e198c52ff1e2bd46e6ff7a8117d7f9e8b01ad250d831100b91f",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 100000,
"outputBytes": 400000,
"jsonNodes": 12000,
"depth": 20,
"profile": "oci-1.1-inline-artifact-v1",
"files": 32,
"nameUnits": 128,
"mediaTypeBytes": 127,
"payloadBytes": 60000,
"manifestBytes": 100000,
"enclosingManifestDigest": "not returned",
"mediaTypeProfile": "RFC6838 restricted ASCII type/subtype; no parameters"
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.005",
"sixDecimalTokenBaseUnits": "5000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/oci-artifact-compose",
"mpp": "/v1/mpp/oci-artifact-compose"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.