{
  "id": "spdx-expression-analyze",
  "name": "SPDX Expression Analyze",
  "description": "Parse bounded SPDX-style license expression syntax into a flat indexed AST, unique identifiers/exceptions and fully parenthesized normalization. Supports AND/OR/WITH, +, LicenseRef and DocumentRef; enforces precedence and simple-left WITH. Does not validate current license/exception lists or give compliance advice; NONE/NOASSERTION document markers are rejected.",
  "category": "supply-chain",
  "priceUsd": "0.003",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.003",
    "sixDecimalTokenBaseUnits": "3000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "parse SPDX license expression",
    "inspect license expression AST",
    "normalize SPDX expression syntax"
  ],
  "whenToUse": [
    "Inspect operator precedence and identifier references in a supplied expression",
    "Perform bounded syntax preparation before a separate policy or license-list check"
  ],
  "whenNotToUse": [
    "Proving identifiers are in the current SPDX list",
    "License compatibility, legal advice or boolean expansion of all license choices"
  ],
  "capabilities": [
    "WITH before AND before OR; case-sensitive operators",
    "Flat postorder indexed AST avoids recursive output amplification",
    "ASCII spaces/tabs only; plus attaches directly to a non-reference identifier"
  ],
  "related": [
    "sbom-inventory",
    "dependency-risk-flags"
  ],
  "limits": {
    "inputBytes": 100000,
    "jsonNodes": 12000,
    "jsonDepth": 24,
    "outputBytes": 300000,
    "expressionCharacters": 4096,
    "tokens": 255,
    "astNodes": 255,
    "parenthesisLevels": 16
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_JSON",
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "UNSAFE_KEY",
    "OUTPUT_LIMIT",
    "INVALID_SPDX_EXPRESSION"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "spdx-expression-analyze",
      "operation.category": "supply-chain",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 300000,
      "limit.jsonDepth": 24,
      "limit.jsonNodes": 12000,
      "verification.licenseCompliance": false,
      "input.expression.maxLength": 4096,
      "input.expression.minLength": 1
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/spdx-expression-analyze.md",
  "serviceContract": "/reference/services/spdx-expression-analyze.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/spdx-expression-analyze",
    "mpp": "/v1/mpp/spdx-expression-analyze"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "expression": {
        "type": "string",
        "minLength": 1,
        "maxLength": 4096
      }
    },
    "required": [
      "expression"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "spdx-expression-analyze",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "syntaxValid": {
            "type": "boolean",
            "const": true
          },
          "normalized": {
            "type": "string",
            "maxLength": 8192
          },
          "root": {
            "type": "integer",
            "minimum": 0,
            "maximum": 254
          },
          "nodes": {
            "minItems": 1,
            "maxItems": 255,
            "type": "array",
            "items": {
              "oneOf": [
                {
                  "type": "object",
                  "properties": {
                    "kind": {
                      "type": "string",
                      "const": "license"
                    },
                    "identifier": {
                      "type": "string",
                      "maxLength": 256
                    },
                    "orLater": {
                      "type": "boolean"
                    },
                    "customReference": {
                      "type": "boolean"
                    }
                  },
                  "required": [
                    "kind",
                    "identifier",
                    "orLater",
                    "customReference"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "object",
                  "properties": {
                    "kind": {
                      "type": "string",
                      "const": "with"
                    },
                    "license": {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 254
                    },
                    "exception": {
                      "type": "string",
                      "maxLength": 128
                    }
                  },
                  "required": [
                    "kind",
                    "license",
                    "exception"
                  ],
                  "additionalProperties": false
                },
                {
                  "type": "object",
                  "properties": {
                    "kind": {
                      "type": "string",
                      "enum": [
                        "and",
                        "or"
                      ]
                    },
                    "left": {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 254
                    },
                    "right": {
                      "type": "integer",
                      "minimum": 0,
                      "maximum": 254
                    }
                  },
                  "required": [
                    "kind",
                    "left",
                    "right"
                  ],
                  "additionalProperties": false
                }
              ]
            }
          },
          "licenseIdentifiers": {
            "maxItems": 128,
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 256
            }
          },
          "exceptions": {
            "maxItems": 128,
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 128
            }
          },
          "scope": {
            "type": "string",
            "const": "SPDX 2.3 expression grammar subset with ASCII spaces/tabs, case-sensitive operators, LicenseRef and optional DocumentRef. Identifiers are not checked against a current SPDX list; no legal or compatibility conclusions."
          }
        },
        "required": [
          "syntaxValid",
          "normalized",
          "root",
          "nodes",
          "licenseIdentifiers",
          "exceptions",
          "scope"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "expression": "MIT OR Apache-2.0 AND GPL-2.0-only WITH Classpath-exception-2.0"
  },
  "exampleResponse": {
    "operation": "spdx-expression-analyze",
    "version": "0.29.0",
    "result": {
      "syntaxValid": true,
      "normalized": "(MIT OR (Apache-2.0 AND GPL-2.0-only WITH Classpath-exception-2.0))",
      "root": 5,
      "nodes": [
        {
          "kind": "license",
          "identifier": "MIT",
          "orLater": false,
          "customReference": false
        },
        {
          "kind": "license",
          "identifier": "Apache-2.0",
          "orLater": false,
          "customReference": false
        },
        {
          "kind": "license",
          "identifier": "GPL-2.0-only",
          "orLater": false,
          "customReference": false
        },
        {
          "kind": "with",
          "license": 2,
          "exception": "Classpath-exception-2.0"
        },
        {
          "kind": "and",
          "left": 1,
          "right": 3
        },
        {
          "kind": "or",
          "left": 0,
          "right": 4
        }
      ],
      "licenseIdentifiers": [
        "Apache-2.0",
        "GPL-2.0-only",
        "MIT"
      ],
      "exceptions": [
        "Classpath-exception-2.0"
      ],
      "scope": "SPDX 2.3 expression grammar subset with ASCII spaces/tabs, case-sensitive operators, LicenseRef and optional DocumentRef. Identifiers are not checked against a current SPDX list; no legal or compatibility conclusions."
    },
    "provenance": {
      "inputSha256": "2d769c525513182591de214bb176bf06aed5e0544a40aa706ec0920311cca573",
      "outputSha256": "32c66e480aa54016a4e908e59960671718f6afa5c0f95e16ae75ac708b083cd2",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/spdx-expression-analyze.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
