{
  "id": "artifact-manifest-check",
  "name": "Supplied Artifact Manifest Check",
  "description": "Compare a supplied text-file manifest with supplied UTF-8 contents: byte sizes, SHA-256 digests, missing/extra/duplicate paths and bounded portable-path collisions. Does not read a filesystem, decode archives, trust an unsigned manifest or verify publisher identity.",
  "category": "workflow-assurance",
  "priceUsd": "0.01",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.01",
    "sixDecimalTokenBaseUnits": "10000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "Verify an agent artifact handoff against expected file hashes and sizes",
    "Detect missing files, duplicate paths and portable filename collisions"
  ],
  "whenToUse": [
    "Verify an agent artifact handoff against expected file hashes and sizes",
    "Detect missing files, duplicate paths and portable filename collisions"
  ],
  "whenNotToUse": [
    "Signature verification, malware detection or archive extraction",
    "Reading remote or local files, binary contents, or complete cross-platform filename validation"
  ],
  "capabilities": [
    "UTF-8 SHA-256 and byte-length comparison per entry",
    "Portable subset rejects traversal, controls, reserved names; NFC/ASCII-case collision signals"
  ],
  "related": [
    "content-digest",
    "evidence-quote-check"
  ],
  "limits": {
    "inputBytes": 100000,
    "outputBytes": 400000,
    "jsonNodes": 8000,
    "depth": 20,
    "findings": 200,
    "quoteSearchCharacters": 4000000,
    "quoteOccurrenceEvaluations": 200000,
    "manifestEntries": 100,
    "files": 100,
    "pathCharacters": 512
  },
  "errorCodes": [
    "INPUT_LIMIT",
    "OUTPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "UNSAFE_KEY",
    "DUPLICATE_ID",
    "EDGE_LIMIT",
    "EVALUATION_LIMIT",
    "INVALID_UNICODE",
    "INVALID_RETRY_AFTER",
    "INVALID_RETRY_INPUT"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "artifact-manifest-check",
      "operation.category": "workflow-assurance",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 400000,
      "limit.jsonDepth": 20,
      "limit.jsonNodes": 8000,
      "input.manifest.maxItems": 100,
      "input.files.maxItems": 100
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/artifact-manifest-check.md",
  "serviceContract": "/reference/services/artifact-manifest-check.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/artifact-manifest-check",
    "mpp": "/v1/mpp/artifact-manifest-check"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "manifest": {
        "maxItems": 100,
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "path": {
              "type": "string",
              "minLength": 1,
              "maxLength": 512
            },
            "sizeBytes": {
              "type": "integer",
              "minimum": 0,
              "maximum": 100000
            },
            "sha256": {
              "type": "string",
              "pattern": "^[a-fA-F0-9]{64}$"
            }
          },
          "required": [
            "path",
            "sizeBytes",
            "sha256"
          ],
          "additionalProperties": false
        }
      },
      "files": {
        "maxItems": 100,
        "type": "array",
        "items": {
          "type": "object",
          "properties": {
            "path": {
              "type": "string",
              "minLength": 1,
              "maxLength": 512
            },
            "text": {
              "type": "string",
              "maxLength": 90000
            }
          },
          "required": [
            "path",
            "text"
          ],
          "additionalProperties": false
        }
      },
      "allowExtraFiles": {
        "default": false,
        "type": "boolean"
      }
    },
    "required": [
      "manifest",
      "files"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "artifact-manifest-check",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "profile": {
            "type": "string",
            "const": "supplied-text-manifest-v1"
          },
          "passesChecks": {
            "type": "boolean"
          },
          "verifiedCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "extraPaths": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "entries": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "path": {
                  "type": "string"
                },
                "status": {
                  "type": "string",
                  "enum": [
                    "verified",
                    "missing",
                    "ambiguous",
                    "mismatch",
                    "invalid_path"
                  ]
                },
                "expectedBytes": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                },
                "actualBytes": {
                  "anyOf": [
                    {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 9007199254740991
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "expectedSha256": {
                  "type": "string"
                },
                "actualSha256": {
                  "type": [
                    "string",
                    "null"
                  ]
                }
              },
              "required": [
                "path",
                "status",
                "expectedBytes",
                "actualBytes",
                "expectedSha256",
                "actualSha256"
              ],
              "additionalProperties": false
            }
          },
          "findings": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "severity": {
                  "type": "string",
                  "enum": [
                    "error",
                    "warning"
                  ]
                },
                "path": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                }
              },
              "required": [
                "code",
                "severity",
                "path",
                "message"
              ],
              "additionalProperties": false
            }
          },
          "findingCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "errorCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "truncated": {
            "type": "boolean"
          }
        },
        "required": [
          "profile",
          "passesChecks",
          "verifiedCount",
          "extraPaths",
          "entries",
          "findings",
          "findingCount",
          "errorCount",
          "truncated"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "manifest": [
      {
        "path": "output.txt",
        "sizeBytes": 5,
        "sha256": "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824"
      }
    ],
    "files": [
      {
        "path": "output.txt",
        "text": "hello"
      }
    ]
  },
  "exampleResponse": {
    "operation": "artifact-manifest-check",
    "version": "0.29.0",
    "result": {
      "profile": "supplied-text-manifest-v1",
      "passesChecks": true,
      "verifiedCount": 1,
      "extraPaths": [],
      "entries": [
        {
          "path": "output.txt",
          "status": "verified",
          "expectedBytes": 5,
          "actualBytes": 5,
          "expectedSha256": "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824",
          "actualSha256": "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824"
        }
      ],
      "findings": [],
      "findingCount": 0,
      "errorCount": 0,
      "truncated": false
    },
    "provenance": {
      "inputSha256": "6c419edcbce9b5dcecf7cbc7a8529adb101c74f45956a8021ad1d79a30ad154d",
      "outputSha256": "cc6ef62785c4ab397fb42be4f1381cf8eb76fbc602deb58c6e21f87dd9c2297d",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/artifact-manifest-check.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
