{
  "id": "sbom-inventory",
  "name": "SBOM Inventory",
  "description": "Extract names, versions, PURLs, declared licenses and hashes from CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3. Includes nested CycloneDX components and metadata.component; excludes services, external BOMs, relationships and unconsumed fields. No full document, license, PURL or hash validation.",
  "category": "supply-chain",
  "priceUsd": "0.005",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.005",
    "sixDecimalTokenBaseUnits": "5000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "extract SBOM inventory",
    "extract component names, versions and licenses from a software bill of materials",
    "read CycloneDX components",
    "read SPDX packages"
  ],
  "whenToUse": [
    "Build a small auditable component inventory from caller-supplied SBOM JSON",
    "Retain source JSON pointers and distinguish declared/concluded license fields"
  ],
  "whenNotToUse": [
    "Full SBOM conformance checks, dependency resolution or vulnerability scanning",
    "XML/tag-value inputs, external document traversal or artifact verification"
  ],
  "capabilities": [
    "CycloneDX 1.5 and 1.6 JSON, SPDX 2.3 JSON",
    "Nested components, metadata root, normalized license/hash lists and source pointers",
    "Unknown fields ignored; consumed fields strictly type-checked"
  ],
  "related": [
    "sbom-diff",
    "package-url-inspect",
    "spdx-expression-analyze"
  ],
  "limits": {
    "inputBytes": 100000,
    "jsonNodes": 12000,
    "jsonDepth": 24,
    "outputBytes": 300000,
    "components": 500,
    "licensesPerComponent": 16,
    "hashesPerComponent": 16,
    "spdxExternalRefsPerPackage": 64
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_JSON",
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "UNSAFE_KEY",
    "OUTPUT_LIMIT",
    "INVALID_DOCUMENT",
    "UNSUPPORTED_SBOM",
    "AMBIGUOUS_COMPONENT"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "sbom-inventory",
      "operation.category": "supply-chain",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 300000,
      "limit.jsonDepth": 24,
      "limit.jsonNodes": 12000
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/sbom-inventory.md",
  "serviceContract": "/reference/services/sbom-inventory.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/sbom-inventory",
    "mpp": "/v1/mpp/sbom-inventory"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "document": {
        "type": "object",
        "propertyNames": {
          "type": "string"
        },
        "additionalProperties": {},
        "description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
      }
    },
    "required": [
      "document"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "sbom-inventory",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "format": {
            "type": "string",
            "enum": [
              "CycloneDX",
              "SPDX"
            ]
          },
          "specVersion": {
            "type": "string",
            "enum": [
              "1.5",
              "1.6",
              "2.3"
            ]
          },
          "componentCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 500
          },
          "components": {
            "maxItems": 500,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "sourcePointer": {
                  "type": "string",
                  "maxLength": 4096
                },
                "reference": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "name": {
                  "type": "string",
                  "maxLength": 2048
                },
                "group": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "version": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "purl": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 4096
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "type": {
                  "anyOf": [
                    {
                      "type": "string",
                      "maxLength": 2048
                    },
                    {
                      "type": "null"
                    }
                  ]
                },
                "licenses": {
                  "maxItems": 16,
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "kind": {
                        "type": "string",
                        "enum": [
                          "id",
                          "name",
                          "expression",
                          "declared",
                          "concluded"
                        ]
                      },
                      "value": {
                        "type": "string",
                        "maxLength": 2048
                      }
                    },
                    "required": [
                      "kind",
                      "value"
                    ],
                    "additionalProperties": false
                  }
                },
                "hashes": {
                  "maxItems": 16,
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "algorithm": {
                        "type": "string",
                        "maxLength": 100
                      },
                      "value": {
                        "type": "string",
                        "maxLength": 2048
                      }
                    },
                    "required": [
                      "algorithm",
                      "value"
                    ],
                    "additionalProperties": false
                  }
                }
              },
              "required": [
                "sourcePointer",
                "reference",
                "name",
                "group",
                "version",
                "purl",
                "type",
                "licenses",
                "hashes"
              ],
              "additionalProperties": false
            }
          },
          "scope": {
            "type": "string",
            "const": "Extracted fields only; not full SBOM validation, dependency resolution, vulnerability scanning, or license compliance advice."
          }
        },
        "required": [
          "format",
          "specVersion",
          "componentCount",
          "components",
          "scope"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "document": {
      "bomFormat": "CycloneDX",
      "specVersion": "1.6",
      "components": [
        {
          "type": "library",
          "name": "worker-kit",
          "version": "1.2.0",
          "purl": "pkg:npm/worker-kit@1.2.0",
          "licenses": [
            {
              "license": {
                "id": "MIT"
              }
            }
          ]
        }
      ]
    }
  },
  "exampleResponse": {
    "operation": "sbom-inventory",
    "version": "0.29.0",
    "result": {
      "format": "CycloneDX",
      "specVersion": "1.6",
      "componentCount": 1,
      "components": [
        {
          "sourcePointer": "/components/0",
          "reference": null,
          "name": "worker-kit",
          "group": null,
          "version": "1.2.0",
          "purl": "pkg:npm/worker-kit@1.2.0",
          "type": "library",
          "licenses": [
            {
              "kind": "id",
              "value": "MIT"
            }
          ],
          "hashes": []
        }
      ],
      "scope": "Extracted fields only; not full SBOM validation, dependency resolution, vulnerability scanning, or license compliance advice."
    },
    "provenance": {
      "inputSha256": "80931d8b46b2cd7402b3eb7dedc67a8372ac5684a142e1ebfa31493d5b89c3fc",
      "outputSha256": "7e9c092e6244e94d15ec23a34c2caa1ee002055ee1038c47c42ec09cd231c2b7",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/sbom-inventory.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
