All workflows

Delegated Agent Scope Gate — Authority Policy Preflight

Fail-closed, read-only match of an agent action against caller-supplied tool, origin, recipient, network, expiry and spend permissions. Returns policy decision and SHA-256 audit hashes. NOT a signature or owner identity verifier; externally authenticated authorization is still mandatory.

3 credits per call · $0.025 USDC with x402

Sample input

{
  "mandate": {
    "agent_id": "researcher-1",
    "allowed_tools": [
      "web_extract"
    ],
    "allowed_origins": [
      "https://example.com"
    ],
    "issued_at": "2026-10-01T00:00:00Z",
    "expires_at": "2027-10-01T00:00:00Z",
    "max_spend_usd": 1,
    "max_action_usd": 0.1
  },
  "action": {
    "agent_id": "researcher-1",
    "tool": "web_extract",
    "destination_url": "https://example.com/page",
    "amount_usd": 0.03,
    "evaluated_at": "2026-10-10T00:00:00Z"
  }
}

Worked sample output

{
  "ok": true,
  "mode": "delegated-agent-scope-gate",
  "policy_match": true,
  "recommendation": "policy_only_allow_if_separately_authenticated",
  "reasons": [],
  "checked_at": "2026-10-10T00:00:00Z",
  "mandate_policy_sha256": "91611c0ba58b043c06ef00e6c44b0d20d1dd5546030e212bed2b80fa32e9d67b",
  "action_sha256": "5954033fd2485a94598df95ff3eae01f4fb1cded549f8560a89b00629e65737c",
  "cryptographic_signature_verified": false,
  "owner_identity_verified": false,
  "authoritative_authorization": false,
  "subsequent_payment_executed": false,
  "warning": "Caller-declared rules alone do not prove a valid delegation. An authenticated owner mandate, signature or trusted identity provider must be verified independently before execution."
}

Worked example using published sample data only. Own-data execution is paid.

Connect in curl

Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.

curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/delegated-agent-scope-gate' \
  -H "Authorization: Bearer $BOUNTY_API_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: workflow-request-001' \
  -H 'X-Max-Credits: 3' \
  --data '{"mandate":{"agent_id":"researcher-1","allowed_tools":["web_extract"],"allowed_origins":["https://example.com"],"issued_at":"2026-10-01T00:00:00Z","expires_at":"2027-10-01T00:00:00Z","max_spend_usd":1,"max_action_usd":0.1},"action":{"agent_id":"researcher-1","tool":"web_extract","destination_url":"https://example.com/page","amount_usd":0.03,"evaluated_at":"2026-10-10T00:00:00Z"}}'

Connect in n8n

Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.

Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/delegated-agent-scope-gate. Send JSON and these headers; store the Bearer token as a private credential.

{
  "method": "POST",
  "headers": {
    "Authorization": "Bearer YOUR_PRIVATE_API_KEY",
    "Content-Type": "application/json",
    "Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
    "X-Max-Credits": "3"
  },
  "body": {
    "mandate": {
      "agent_id": "researcher-1",
      "allowed_tools": [
        "web_extract"
      ],
      "allowed_origins": [
        "https://example.com"
      ],
      "issued_at": "2026-10-01T00:00:00Z",
      "expires_at": "2027-10-01T00:00:00Z",
      "max_spend_usd": 1,
      "max_action_usd": 0.1
    },
    "action": {
      "agent_id": "researcher-1",
      "tool": "web_extract",
      "destination_url": "https://example.com/page",
      "amount_usd": 0.03,
      "evaluated_at": "2026-10-10T00:00:00Z"
    }
  }
}

Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe