Bounded Retry Schedule Plan
Produce a deterministic hypothetical retry wait plan from explicit replay-safety assertions, HTTP status, backoff limits and waiting budget. Supports delta-seconds/IMF-fixdate Retry-After with explicit reference time. Stops for payment uncertainty and unknown/unsafe replay; never sends requests or authorizes repayment.
workflow-assurance · Operation ID: retry-schedule-plan
Choose this operation when
- Calculate capped retry backoff under a fixed waiting budget
- Respect Retry-After without clipping the server's minimum wait
Outside this profile
- Automatically retrying payment uncertainty or assuming idempotency
- Live scheduling, random jitter, traffic synchronization prevention, or complete HTTP-date parsing
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"outcome": {
"type": "string",
"enum": [
"http-response",
"transport-uncertain",
"payment-uncertain"
]
},
"replaySafety": {
"type": "string",
"enum": [
"safe",
"unsafe",
"unknown"
]
},
"statusCode": {
"type": "integer",
"minimum": 100,
"maximum": 599
},
"retryAfter": {
"type": "string",
"maxLength": 128
},
"nowEpochMs": {
"type": "integer",
"minimum": 0,
"maximum": 4102444800000
},
"retryableStatuses": {
"default": [
408,
429,
500,
502,
503,
504
],
"maxItems": 20,
"type": "array",
"items": {
"type": "integer",
"minimum": 100,
"maximum": 599
}
},
"maxRetries": {
"default": 3,
"type": "integer",
"minimum": 0,
"maximum": 10
},
"baseDelayMs": {
"default": 1000,
"type": "integer",
"minimum": 1,
"maximum": 60000
},
"multiplier": {
"default": 2,
"type": "number",
"minimum": 1,
"maximum": 10
},
"maxDelayMs": {
"default": 60000,
"type": "integer",
"minimum": 1,
"maximum": 3600000
},
"budgetMs": {
"type": "integer",
"minimum": 0,
"maximum": 86400000
}
},
"required": [
"outcome",
"replaySafety",
"budgetMs"
],
"additionalProperties": false
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "retry-schedule-plan",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"profile": {
"type": "string",
"const": "bounded-retry-plan-v1"
},
"eligible": {
"type": "boolean"
},
"reason": {
"type": "string",
"enum": [
"planned",
"payment_reconciliation_required",
"replay_safety_not_established",
"status_not_retryable",
"no_retries_requested",
"budget_exhausted",
"delay_limit_exceeded"
]
},
"serverMinimumFirstDelayMs": {
"anyOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "null"
}
]
},
"plan": {
"type": "array",
"items": {
"type": "object",
"properties": {
"retry": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"delayMs": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"cumulativeDelayMs": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"retry",
"delayMs",
"cumulativeDelayMs"
],
"additionalProperties": false
}
},
"totalDelayMs": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"unplannedRetries": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"assumptions": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"profile",
"eligible",
"reason",
"serverMinimumFirstDelayMs",
"plan",
"totalDelayMs",
"unplannedRetries",
"assumptions"
],
"additionalProperties": false
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"outcome": "http-response",
"replaySafety": "safe",
"statusCode": 429,
"retryAfter": "3",
"maxRetries": 3,
"baseDelayMs": 1000,
"multiplier": 2,
"maxDelayMs": 10000,
"budgetMs": 10000
}
Example response
{
"operation": "retry-schedule-plan",
"version": "0.29.0",
"result": {
"profile": "bounded-retry-plan-v1",
"eligible": true,
"reason": "planned",
"serverMinimumFirstDelayMs": 3000,
"plan": [
{
"retry": 1,
"delayMs": 3000,
"cumulativeDelayMs": 3000
},
{
"retry": 2,
"delayMs": 2000,
"cumulativeDelayMs": 5000
},
{
"retry": 3,
"delayMs": 4000,
"cumulativeDelayMs": 9000
}
],
"totalDelayMs": 9000,
"unplannedRetries": 0,
"assumptions": [
"Caller must establish replay safety; this plan grants no permission",
"No requests, payments, sleeps, or retries are executed",
"Hypothetical repeated failures; Retry-After applies only to the first retry",
"Budget counts waiting only; excludes execution time and has no jitter"
]
},
"provenance": {
"inputSha256": "a0d7ca9aaa8f91ec282225d6df1edc726e7034f4e317744fc540a2ba2ceef469",
"outputSha256": "d257e017c93ed0a51a5b49ecdf7bf20e7ca5190c89ad50c66ae46db72e17ada5",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 100000,
"outputBytes": 400000,
"jsonNodes": 8000,
"depth": 20,
"findings": 200,
"quoteSearchCharacters": 4000000,
"quoteOccurrenceEvaluations": 200000,
"maxRetries": 10,
"maxDelayMs": 3600000,
"budgetMs": 86400000
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.003",
"sixDecimalTokenBaseUnits": "3000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/retry-schedule-plan",
"mpp": "/v1/mpp/retry-schedule-plan"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.