{
  "id": "approval-scope-check",
  "name": "Supplied approval scope comparison",
  "description": "Compare a structured caller-supplied approval receipt to a proposed action: exact actor and scope, declared data-class subset, payload digest, caller time window, revocation and use count. Does not authenticate or grant authorization.",
  "category": "workflow-assurance",
  "priceUsd": "0.005",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.005",
    "sixDecimalTokenBaseUnits": "5000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "Detect scope drift or expiry in an offline human-approval receipt",
    "Compare a proposed action with an exact structured approval artifact before human review"
  ],
  "whenToUse": [
    "Detect scope drift or expiry in an offline human-approval receipt",
    "Compare a proposed action with an exact structured approval artifact before human review"
  ],
  "whenNotToUse": [
    "Executing tools, sending messages, retrying effects, restoring state, or contacting live services",
    "Authenticating evidence, verifying signatures or identities, granting permission, or enforcing authorization",
    "Inferring facts omitted from the supplied artifact snapshot or guaranteeing exactly-once execution"
  ],
  "capabilities": [
    "approval-scope-v1 profile",
    "Exact scope and payload digest comparison with declared data-class subset",
    "Exclusive expiry and usage-count assertions; authorizationGranted=false and identityVerified=false",
    "Advisory only; authorizationGranted=false; identityVerified=false; execution=false; externalRequests=0"
  ],
  "limits": {
    "inputBytes": 100000,
    "outputBytes": 400000,
    "jsonNodes": 12000,
    "depth": 20,
    "findings": 200,
    "events": 256,
    "actors": 32,
    "traceSteps": 128,
    "observations": 256,
    "dataClassesPerScope": 16,
    "scopeMatching": "exact case-sensitive strings; no wildcards"
  },
  "related": [
    "checkpoint-handoff-check",
    "json-canonicalize"
  ],
  "errorCodes": [
    "INPUT_LIMIT",
    "OUTPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "INVALID_NUMBER",
    "INVALID_UNICODE",
    "UNSAFE_KEY",
    "ACTOR_LIMIT"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "approval-scope-check",
      "operation.category": "workflow-assurance",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 400000,
      "limit.jsonDepth": 20,
      "limit.jsonNodes": 12000,
      "coordination.profile": "approval-scope-v1",
      "coordination.advisoryOnly": true,
      "coordination.authorizationGranted": false,
      "coordination.identityVerified": false,
      "coordination.currentTimeLookup": false,
      "coordination.executesRecovery": false,
      "coordination.persistentState": false,
      "coordination.exactlyOnceGuarantee": false,
      "coordination.omissionDetectionComplete": false,
      "approvalScope.maxDataClasses": 16,
      "approvalScope.matching": "exact-case-sensitive-no-wildcards",
      "approvalScope.revocationLookup": false,
      "approvalScope.usagePersistence": false,
      "jsonDigest.profile": "sorted-json-sha256-v1",
      "jsonDigest.rfc8785": false,
      "input.asOfMs.maximum": 9007199254740991,
      "input.asOfMs.minimum": 0
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/approval-scope-check.md",
  "serviceContract": "/reference/services/approval-scope-check.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/approval-scope-check",
    "mpp": "/v1/mpp/approval-scope-check"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "asOfMs": {
        "type": "integer",
        "minimum": 0,
        "maximum": 9007199254740991
      },
      "approval": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 100
          },
          "actor": {
            "type": "string",
            "minLength": 1,
            "maxLength": 100
          },
          "scope": {
            "type": "object",
            "properties": {
              "operation": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "recipient": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "resource": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "purpose": {
                "type": "string",
                "minLength": 1,
                "maxLength": 200
              },
              "dataClasses": {
                "maxItems": 16,
                "type": "array",
                "items": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 100
                }
              }
            },
            "required": [
              "operation",
              "recipient",
              "resource",
              "purpose",
              "dataClasses"
            ],
            "additionalProperties": false
          },
          "payloadSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "issuedAtMs": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "expiresAtMs": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "revoked": {
            "type": "boolean"
          },
          "maxUses": {
            "type": "integer",
            "minimum": 1,
            "maximum": 1000000
          },
          "priorUses": {
            "type": "integer",
            "minimum": 0,
            "maximum": 1000000
          }
        },
        "required": [
          "id",
          "actor",
          "scope",
          "payloadSha256",
          "issuedAtMs",
          "expiresAtMs",
          "revoked",
          "maxUses",
          "priorUses"
        ],
        "additionalProperties": false
      },
      "proposal": {
        "type": "object",
        "properties": {
          "actor": {
            "type": "string",
            "minLength": 1,
            "maxLength": 100
          },
          "scope": {
            "type": "object",
            "properties": {
              "operation": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "recipient": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "resource": {
                "type": "string",
                "minLength": 1,
                "maxLength": 100
              },
              "purpose": {
                "type": "string",
                "minLength": 1,
                "maxLength": 200
              },
              "dataClasses": {
                "maxItems": 16,
                "type": "array",
                "items": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 100
                }
              }
            },
            "required": [
              "operation",
              "recipient",
              "resource",
              "purpose",
              "dataClasses"
            ],
            "additionalProperties": false
          },
          "payload": {
            "$ref": "#/$defs/__schema0"
          }
        },
        "required": [
          "actor",
          "scope",
          "payload"
        ],
        "additionalProperties": false
      }
    },
    "required": [
      "asOfMs",
      "approval",
      "proposal"
    ],
    "additionalProperties": false,
    "$defs": {
      "__schema0": {
        "anyOf": [
          {
            "type": "string"
          },
          {
            "type": "number"
          },
          {
            "type": "boolean"
          },
          {
            "type": "null"
          },
          {
            "type": "array",
            "items": {
              "$ref": "#/$defs/__schema0"
            }
          },
          {
            "type": "object",
            "propertyNames": {
              "type": "string"
            },
            "additionalProperties": {
              "$ref": "#/$defs/__schema0"
            }
          }
        ]
      }
    }
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "approval-scope-check",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "profile": {
            "type": "string",
            "const": "approval-scope-v1"
          },
          "matchesSuppliedApproval": {
            "type": "boolean"
          },
          "advisoryOnly": {
            "type": "boolean",
            "const": true
          },
          "authorizationGranted": {
            "type": "boolean",
            "const": false
          },
          "identityVerified": {
            "type": "boolean",
            "const": false
          },
          "approvalId": {
            "type": "string",
            "minLength": 1,
            "maxLength": 100
          },
          "payloadSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "digestProfile": {
            "type": "string",
            "const": "sorted-json-sha256-v1"
          },
          "checks": {
            "type": "object",
            "properties": {
              "actor": {
                "type": "boolean"
              },
              "operation": {
                "type": "boolean"
              },
              "recipient": {
                "type": "boolean"
              },
              "resource": {
                "type": "boolean"
              },
              "purpose": {
                "type": "boolean"
              },
              "dataClasses": {
                "type": "boolean"
              },
              "payload": {
                "type": "boolean"
              },
              "timeWindow": {
                "type": "boolean"
              },
              "notRevoked": {
                "type": "boolean"
              },
              "usesRemaining": {
                "type": "boolean"
              }
            },
            "required": [
              "actor",
              "operation",
              "recipient",
              "resource",
              "purpose",
              "dataClasses",
              "payload",
              "timeWindow",
              "notRevoked",
              "usesRemaining"
            ],
            "additionalProperties": false
          },
          "limitations": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "findings": {
            "maxItems": 200,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "severity": {
                  "type": "string",
                  "enum": [
                    "error",
                    "warning"
                  ]
                },
                "path": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "relatedIds": {
                  "maxItems": 8,
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 100
                  }
                }
              },
              "required": [
                "code",
                "severity",
                "path",
                "message",
                "relatedIds"
              ],
              "additionalProperties": false
            }
          },
          "findingCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "errorCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "truncated": {
            "type": "boolean"
          }
        },
        "required": [
          "profile",
          "matchesSuppliedApproval",
          "advisoryOnly",
          "authorizationGranted",
          "identityVerified",
          "approvalId",
          "payloadSha256",
          "digestProfile",
          "checks",
          "limitations",
          "findings",
          "findingCount",
          "errorCount",
          "truncated"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "asOfMs": 100,
    "approval": {
      "id": "approval-1",
      "actor": "agent-1",
      "scope": {
        "operation": "send-note",
        "recipient": "team@example.test",
        "resource": "thread-1",
        "purpose": "status-update",
        "dataClasses": [
          "business-contact"
        ]
      },
      "payloadSha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "issuedAtMs": 0,
      "expiresAtMs": 1000,
      "revoked": false,
      "maxUses": 1,
      "priorUses": 0
    },
    "proposal": {
      "actor": "agent-1",
      "scope": {
        "operation": "send-note",
        "recipient": "team@example.test",
        "resource": "thread-1",
        "purpose": "status-update",
        "dataClasses": [
          "business-contact"
        ]
      },
      "payload": {}
    }
  },
  "exampleResponse": {
    "operation": "approval-scope-check",
    "version": "0.29.0",
    "result": {
      "profile": "approval-scope-v1",
      "matchesSuppliedApproval": true,
      "advisoryOnly": true,
      "authorizationGranted": false,
      "identityVerified": false,
      "approvalId": "approval-1",
      "payloadSha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "digestProfile": "sorted-json-sha256-v1",
      "checks": {
        "actor": true,
        "operation": true,
        "recipient": true,
        "resource": true,
        "purpose": true,
        "dataClasses": true,
        "payload": true,
        "timeWindow": true,
        "notRevoked": true,
        "usesRemaining": true
      },
      "limitations": [
        "All approval, identity, revocation, usage and time inputs are unverified caller assertions.",
        "This is an offline comparison and never grants or substitutes for required human approval or an authorization service.",
        "Scope strings are exact and case-sensitive; no wildcards, URL equivalence, delegation, or implicit recipient expansion.",
        "Proposal data classes must be a subset of the declared approved classes; their truth is not inferred from payload contents.",
        "The payload digest uses the custom sorted-json-sha256-v1 profile, not a signature or general canonical JSON standard."
      ],
      "findings": [],
      "findingCount": 0,
      "errorCount": 0,
      "truncated": false
    },
    "provenance": {
      "inputSha256": "1dad1a8fc0a2aa96d0cc1216c1f6ba3500c4f2d51b51098c2ef5dba80d4ee048",
      "outputSha256": "01cfe41c857b2418ca2e408aed082517f8dbfcfea2e59f557c77bfebd62c823a",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/approval-scope-check.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
