{
  "id": "lockfile-inventory",
  "name": "Lockfile Inventory",
  "description": "Extract npm package-lock v2/v3 packages by sorted location, retaining versions, resolved sources, integrity/license strings and dev/optional/devOptional/link/install-script flags. No package installation, graph resolution or hash verification. Workspace names require a declared name; node_modules names can be inferred from location.",
  "category": "supply-chain",
  "priceUsd": "0.005",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.005",
    "sixDecimalTokenBaseUnits": "5000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "inventory npm lockfile",
    "extract package-lock dependencies",
    "inspect lockfile integrity metadata"
  ],
  "whenToUse": [
    "Read package locations and declared metadata without installing anything",
    "Retain nested copies and workspace links as separate locations"
  ],
  "whenNotToUse": [
    "npm v1, Yarn, pnpm, Poetry or Cargo lockfiles",
    "Transitive dependency graph resolution, artifact retrieval or installation verification"
  ],
  "capabilities": [
    "npm package-lock v2/v3 packages table",
    "Explicit root toggle; sorted location rows; false for omitted boolean flags",
    "Links reported without following targets; legacy dependencies table ignored"
  ],
  "related": [
    "dependency-risk-flags",
    "sbom-inventory"
  ],
  "limits": {
    "inputBytes": 100000,
    "jsonNodes": 12000,
    "jsonDepth": 24,
    "outputBytes": 300000,
    "packageLocationsIncludingRoot": 500,
    "locationCharacters": 1024
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_JSON",
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "UNSAFE_KEY",
    "OUTPUT_LIMIT",
    "INVALID_DOCUMENT",
    "UNSUPPORTED_LOCKFILE"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "lockfile-inventory",
      "operation.category": "supply-chain",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 300000,
      "limit.jsonDepth": 24,
      "limit.jsonNodes": 12000
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/lockfile-inventory.md",
  "serviceContract": "/reference/services/lockfile-inventory.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/lockfile-inventory",
    "mpp": "/v1/mpp/lockfile-inventory"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "document": {
        "type": "object",
        "propertyNames": {
          "type": "string"
        },
        "additionalProperties": {},
        "description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
      },
      "includeRoot": {
        "default": false,
        "type": "boolean"
      }
    },
    "required": [
      "document"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "lockfile-inventory",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "lockfileVersion": {
            "anyOf": [
              {
                "type": "number",
                "const": 2
              },
              {
                "type": "number",
                "const": 3
              }
            ]
          },
          "packageCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 500
          },
          "packages": {
            "maxItems": 500,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "location": {
                  "type": "string",
                  "maxLength": 1024
                },
                "name": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "resolved": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "integrity": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "license": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "dev": {
                  "type": "boolean"
                },
                "optional": {
                  "type": "boolean"
                },
                "devOptional": {
                  "type": "boolean"
                },
                "link": {
                  "type": "boolean"
                },
                "inBundle": {
                  "type": "boolean"
                },
                "hasInstallScript": {
                  "type": "boolean"
                }
              },
              "required": [
                "location",
                "name",
                "version",
                "resolved",
                "integrity",
                "license",
                "dev",
                "optional",
                "devOptional",
                "link",
                "inBundle",
                "hasInstallScript"
              ],
              "additionalProperties": false
            }
          },
          "scope": {
            "type": "string",
            "const": "npm package-lock v2/v3 packages table only; legacy dependencies ignored; absent boolean flags are false; link targets are not followed and hashes are not verified."
          }
        },
        "required": [
          "lockfileVersion",
          "packageCount",
          "packages",
          "scope"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "document": {
      "name": "edge-worker",
      "lockfileVersion": 3,
      "packages": {
        "": {
          "name": "edge-worker",
          "version": "1.0.0"
        },
        "node_modules/worker-kit": {
          "version": "1.2.0",
          "resolved": "https://registry.example/worker-kit-1.2.0.tgz",
          "license": "MIT",
          "dev": true
        }
      }
    },
    "includeRoot": false
  },
  "exampleResponse": {
    "operation": "lockfile-inventory",
    "version": "0.29.0",
    "result": {
      "lockfileVersion": 3,
      "packageCount": 1,
      "packages": [
        {
          "location": "node_modules/worker-kit",
          "name": "worker-kit",
          "version": "1.2.0",
          "resolved": "https://registry.example/worker-kit-1.2.0.tgz",
          "integrity": null,
          "license": "MIT",
          "dev": true,
          "optional": false,
          "devOptional": false,
          "link": false,
          "inBundle": false,
          "hasInstallScript": false
        }
      ],
      "scope": "npm package-lock v2/v3 packages table only; legacy dependencies ignored; absent boolean flags are false; link targets are not followed and hashes are not verified."
    },
    "provenance": {
      "inputSha256": "44372e18b4f1fb63575b3659833ee08607dc747c5e42deb3df735da0985fee80",
      "outputSha256": "b0104ed8c8a474575b7c231e15b166b1022bb87eb42a3f8e18782794e5e86b31",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/lockfile-inventory.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
