{
  "id": "http-signature-base-compose",
  "name": "Compose an HTTP request signature base",
  "description": "Compose inert ASCII RFC 9421 request signature-base and Signature-Input artifacts from ordered, supplied non-secret field examples and explicit context. Does not sign, verify, authorize or send requests.",
  "category": "protocol-assurance",
  "priceUsd": "0.006",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.006",
    "sixDecimalTokenBaseUnits": "6000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "compose an HTTP request signature base",
    "extract ordered RFC 9421 request components"
  ],
  "whenToUse": [
    "Build an inert signature-base example from supplied request context and ordered ASCII field lines",
    "Compare raw and binary-wrapped field boundaries before using an external signer"
  ],
  "whenNotToUse": [
    "Signing, verification, keys, credentials, authentication, authorization, payment, or live HTTP requests",
    "Responses, trailers, CONNECT, query-parameter selection, Structured Field parsing, Unicode or obs-text fields",
    "Secret or production request payloads, including secrets in targets, free text or key identifiers"
  ],
  "capabilities": [
    "Ordered field provenance and per-line binary wrapping",
    "Strict bounded schema and complete semantic preflight before execution",
    "Exact ASCII artifacts, byte lengths and SHA-256 artifact hashes"
  ],
  "limits": {
    "inputBytes": 16384,
    "jsonNodes": 1024,
    "depth": 12,
    "outputBytes": 200000,
    "headerLines": 64,
    "headerNameBytes": 64,
    "headerValueBytes": 1024,
    "aggregateHeaderValueBytes": 4096,
    "targetBytes": 1024,
    "authorityBytes": 259,
    "components": 32,
    "parameters": 6,
    "labelBytes": 64,
    "signatureBaseBytes": 8192,
    "signatureInputBytes": 4096
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_UNICODE",
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "OUTPUT_LIMIT",
    "INVALID_REQUEST_CONTEXT",
    "INVALID_FIELD",
    "FORBIDDEN_FIELD",
    "UNSUPPORTED_COMPONENT",
    "DUPLICATE_COMPONENT",
    "MISSING_COMPONENT",
    "AMBIGUOUS_FIELD",
    "INVALID_PARAMETER"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "http-signature-base-compose",
      "operation.category": "protocol-assurance",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 16384,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 200000,
      "limit.jsonDepth": 12,
      "limit.jsonNodes": 1024,
      "integrity.profile": "http-sig-rfc9421-request-ascii-v1",
      "integrity.signs": false,
      "integrity.verifies": false,
      "integrity.authenticity": false,
      "integrity.networkTransmission": false,
      "integrity.hashAlgorithm": "SHA-256",
      "httpSignature.requestOnly": true,
      "httpSignature.explicitContext": true,
      "httpSignature.asciiOnly": true,
      "httpSignature.orderedFieldOccurrences": true,
      "httpSignature.perOccurrenceBinaryWrapping": true,
      "httpSignature.preservePercentEscapes": true,
      "httpSignature.secretDetectionComplete": false,
      "httpSignature.freshnessGuaranteed": false,
      "httpSignature.replayResistance": false,
      "httpSignature.receiverAcceptance": false,
      "httpSignature.maxHeaderLines": 64,
      "httpSignature.maxHeaderValueBytes": 1024,
      "httpSignature.maxAggregateHeaderValueBytes": 4096,
      "httpSignature.maxTargetBytes": 1024,
      "httpSignature.maxComponents": 32,
      "httpSignature.maxBaseBytes": 8192,
      "httpSignature.maxSignatureInputBytes": 4096,
      "input.label.maxLength": 64,
      "input.label.minLength": 1,
      "input.components.maxItems": 32,
      "input.parameters.maxItems": 6,
      "input.parameters.minItems": 1
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/http-signature-base-compose.md",
  "serviceContract": "/reference/services/http-signature-base-compose.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/http-signature-base-compose",
    "mpp": "/v1/mpp/http-signature-base-compose"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "request": {
        "type": "object",
        "properties": {
          "method": {
            "type": "string",
            "minLength": 1,
            "maxLength": 32,
            "pattern": "^[!#$%&'*+.^_`|~0-9A-Za-z-]+$(?![\\s\\S])"
          },
          "scheme": {
            "type": "string",
            "enum": [
              "http",
              "https"
            ]
          },
          "authority": {
            "type": "string",
            "minLength": 1,
            "maxLength": 259,
            "pattern": "^[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?(?::[1-9][0-9]{0,4})?$(?![\\s\\S])"
          },
          "target": {
            "type": "string",
            "minLength": 1,
            "maxLength": 1024,
            "pattern": "^\\/(?:[A-Za-z0-9._~!$&'()*+,;=:@/-]|%[0-9A-Fa-f]{2})*(?:\\?(?:[A-Za-z0-9._~!$&'()*+,;=:@/?-]|%[0-9A-Fa-f]{2})*)?$(?![\\s\\S])"
          },
          "headers": {
            "maxItems": 64,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 64,
                  "pattern": "^[!#$%&'*+.^_`|~0-9A-Za-z-]+$(?![\\s\\S])"
                },
                "value": {
                  "type": "string",
                  "maxLength": 1024,
                  "pattern": "^[\\x09\\x20-\\x7e]*$(?![\\s\\S])"
                }
              },
              "required": [
                "name",
                "value"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "method",
          "scheme",
          "authority",
          "target",
          "headers"
        ],
        "additionalProperties": false
      },
      "label": {
        "type": "string",
        "minLength": 1,
        "maxLength": 64,
        "pattern": "^[a-z*][a-z0-9_.*-]*$(?![\\s\\S])"
      },
      "components": {
        "maxItems": 32,
        "type": "array",
        "items": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "type": {
                  "type": "string",
                  "const": "derived"
                },
                "name": {
                  "type": "string",
                  "enum": [
                    "@method",
                    "@scheme",
                    "@authority",
                    "@target-uri",
                    "@path",
                    "@query"
                  ]
                }
              },
              "required": [
                "type",
                "name"
              ],
              "additionalProperties": false
            },
            {
              "type": "object",
              "properties": {
                "type": {
                  "type": "string",
                  "const": "field"
                },
                "name": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 64,
                  "pattern": "^[!#$%&'*+.^_`|~0-9a-z-]+$(?![\\s\\S])"
                },
                "mode": {
                  "type": "string",
                  "enum": [
                    "raw",
                    "binary"
                  ]
                }
              },
              "required": [
                "type",
                "name",
                "mode"
              ],
              "additionalProperties": false
            }
          ]
        }
      },
      "parameters": {
        "minItems": 1,
        "maxItems": 6,
        "type": "array",
        "items": {
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "enum": [
                    "created",
                    "expires"
                  ]
                },
                "value": {
                  "type": "string",
                  "maxLength": 15,
                  "pattern": "^(?:0|[1-9][0-9]{0,14})$(?![\\s\\S])"
                }
              },
              "required": [
                "name",
                "value"
              ],
              "additionalProperties": false
            },
            {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "enum": [
                    "keyid",
                    "nonce",
                    "tag"
                  ]
                },
                "value": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 256,
                  "pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
                }
              },
              "required": [
                "name",
                "value"
              ],
              "additionalProperties": false
            },
            {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "const": "alg"
                },
                "value": {
                  "type": "string",
                  "enum": [
                    "rsa-pss-sha512",
                    "rsa-v1_5-sha256",
                    "hmac-sha256",
                    "ecdsa-p256-sha256",
                    "ecdsa-p384-sha384",
                    "ed25519"
                  ]
                }
              },
              "required": [
                "name",
                "value"
              ],
              "additionalProperties": false
            }
          ]
        }
      }
    },
    "required": [
      "request",
      "label",
      "components",
      "parameters"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "http-signature-base-compose",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "profile": {
            "type": "string",
            "const": "http-sig-rfc9421-request-ascii-v1"
          },
          "signatureBase": {
            "type": "string",
            "minLength": 1,
            "maxLength": 8192,
            "pattern": "^[\\x09\\x0a\\x20-\\x7e]*$(?![\\s\\S])"
          },
          "byteLength": {
            "type": "integer",
            "minimum": 1,
            "maximum": 8192
          },
          "sha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$(?![\\s\\S])"
          },
          "signatureInput": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string",
                "const": "signature-input"
              },
              "value": {
                "type": "string",
                "minLength": 1,
                "maxLength": 4096,
                "pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
              },
              "byteLength": {
                "type": "integer",
                "minimum": 1,
                "maximum": 4096
              },
              "sha256": {
                "type": "string",
                "pattern": "^[a-f0-9]{64}$(?![\\s\\S])"
              }
            },
            "required": [
              "name",
              "value",
              "byteLength",
              "sha256"
            ],
            "additionalProperties": false
          },
          "components": {
            "maxItems": 32,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "identifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 69,
                  "pattern": "^[\\x20-\\x7e]*$(?![\\s\\S])"
                },
                "value": {
                  "type": "string",
                  "maxLength": 8192,
                  "pattern": "^[\\x09\\x20-\\x7e]*$(?![\\s\\S])"
                },
                "headerIndexes": {
                  "maxItems": 64,
                  "type": "array",
                  "items": {
                    "type": "integer",
                    "minimum": 0,
                    "maximum": 63
                  }
                }
              },
              "required": [
                "identifier",
                "value",
                "headerIndexes"
              ],
              "additionalProperties": false
            }
          }
        },
        "required": [
          "profile",
          "signatureBase",
          "byteLength",
          "sha256",
          "signatureInput",
          "components"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "request": {
      "method": "POST",
      "scheme": "https",
      "authority": "api.example.com",
      "target": "/v1/items?limit=10",
      "headers": [
        {
          "name": "Content-Type",
          "value": "application/json"
        },
        {
          "name": "Cache-Control",
          "value": "max-age=60"
        },
        {
          "name": "cache-control",
          "value": " no-transform "
        }
      ]
    },
    "label": "demo",
    "components": [
      {
        "type": "derived",
        "name": "@method"
      },
      {
        "type": "derived",
        "name": "@authority"
      },
      {
        "type": "derived",
        "name": "@path"
      },
      {
        "type": "derived",
        "name": "@query"
      },
      {
        "type": "field",
        "name": "content-type",
        "mode": "raw"
      },
      {
        "type": "field",
        "name": "cache-control",
        "mode": "raw"
      }
    ],
    "parameters": [
      {
        "name": "created",
        "value": "1700000000"
      },
      {
        "name": "keyid",
        "value": "demo-key"
      }
    ]
  },
  "exampleResponse": {
    "operation": "http-signature-base-compose",
    "version": "0.29.0",
    "result": {
      "profile": "http-sig-rfc9421-request-ascii-v1",
      "signatureBase": "\"@method\": POST\n\"@authority\": api.example.com\n\"@path\": /v1/items\n\"@query\": ?limit=10\n\"content-type\": application/json\n\"cache-control\": max-age=60, no-transform\n\"@signature-params\": (\"@method\" \"@authority\" \"@path\" \"@query\" \"content-type\" \"cache-control\");created=1700000000;keyid=\"demo-key\"",
      "byteLength": 289,
      "sha256": "65400d9ddc9e40a9d916cf84f6fcb158dd7a0eda5ac3aab66d0edfd12b01eb0d",
      "signatureInput": {
        "name": "signature-input",
        "value": "demo=(\"@method\" \"@authority\" \"@path\" \"@query\" \"content-type\" \"cache-control\");created=1700000000;keyid=\"demo-key\"",
        "byteLength": 113,
        "sha256": "5f6fb3f5e0453d1599d8ae03a24e9e6052ff9180b2e0fd4533afe79e35ed5cbd"
      },
      "components": [
        {
          "identifier": "\"@method\"",
          "value": "POST",
          "headerIndexes": []
        },
        {
          "identifier": "\"@authority\"",
          "value": "api.example.com",
          "headerIndexes": []
        },
        {
          "identifier": "\"@path\"",
          "value": "/v1/items",
          "headerIndexes": []
        },
        {
          "identifier": "\"@query\"",
          "value": "?limit=10",
          "headerIndexes": []
        },
        {
          "identifier": "\"content-type\"",
          "value": "application/json",
          "headerIndexes": [
            0
          ]
        },
        {
          "identifier": "\"cache-control\"",
          "value": "max-age=60, no-transform",
          "headerIndexes": [
            1,
            2
          ]
        }
      ]
    },
    "provenance": {
      "inputSha256": "4c566ce40d6d3390f029304d7fea2ae98b0f787afa766c0168a44f5132a73e57",
      "outputSha256": "fb2b84b135aa6b57b8b49279f1c9ce1b410a052b89201d78f4322d82c88b3df3",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/http-signature-base-compose.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
