Delegated Agent Scope Gate — Authority Policy Preflight
Fail-closed, read-only match of an agent action against caller-supplied tool, origin, recipient, network, expiry and spend permissions. Returns policy decision and SHA-256 audit hashes. NOT a signature or owner identity verifier; externally authenticated authorization is still mandatory.
3 credits per call · $0.025 USDC with x402
Sample input
{
"mandate": {
"agent_id": "researcher-1",
"allowed_tools": [
"web_extract"
],
"allowed_origins": [
"https://example.com"
],
"issued_at": "2026-10-01T00:00:00Z",
"expires_at": "2027-10-01T00:00:00Z",
"max_spend_usd": 1,
"max_action_usd": 0.1
},
"action": {
"agent_id": "researcher-1",
"tool": "web_extract",
"destination_url": "https://example.com/page",
"amount_usd": 0.03,
"evaluated_at": "2026-10-10T00:00:00Z"
}
}Worked sample output
{
"ok": true,
"mode": "delegated-agent-scope-gate",
"policy_match": true,
"recommendation": "policy_only_allow_if_separately_authenticated",
"reasons": [],
"checked_at": "2026-10-10T00:00:00Z",
"mandate_policy_sha256": "91611c0ba58b043c06ef00e6c44b0d20d1dd5546030e212bed2b80fa32e9d67b",
"action_sha256": "5954033fd2485a94598df95ff3eae01f4fb1cded549f8560a89b00629e65737c",
"cryptographic_signature_verified": false,
"owner_identity_verified": false,
"authoritative_authorization": false,
"subsequent_payment_executed": false,
"warning": "Caller-declared rules alone do not prove a valid delegation. An authenticated owner mandate, signature or trusted identity provider must be verified independently before execution."
}Worked example using published sample data only. Own-data execution is paid.
Connect in curl
Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.
curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/delegated-agent-scope-gate' \
-H "Authorization: Bearer $BOUNTY_API_KEY" \
-H 'Content-Type: application/json' \
-H 'Idempotency-Key: workflow-request-001' \
-H 'X-Max-Credits: 3' \
--data '{"mandate":{"agent_id":"researcher-1","allowed_tools":["web_extract"],"allowed_origins":["https://example.com"],"issued_at":"2026-10-01T00:00:00Z","expires_at":"2027-10-01T00:00:00Z","max_spend_usd":1,"max_action_usd":0.1},"action":{"agent_id":"researcher-1","tool":"web_extract","destination_url":"https://example.com/page","amount_usd":0.03,"evaluated_at":"2026-10-10T00:00:00Z"}}'Connect in n8n
Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.
Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/delegated-agent-scope-gate. Send JSON and these headers; store the Bearer token as a private credential.
{
"method": "POST",
"headers": {
"Authorization": "Bearer YOUR_PRIVATE_API_KEY",
"Content-Type": "application/json",
"Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
"X-Max-Credits": "3"
},
"body": {
"mandate": {
"agent_id": "researcher-1",
"allowed_tools": [
"web_extract"
],
"allowed_origins": [
"https://example.com"
],
"issued_at": "2026-10-01T00:00:00Z",
"expires_at": "2027-10-01T00:00:00Z",
"max_spend_usd": 1,
"max_action_usd": 0.1
},
"action": {
"agent_id": "researcher-1",
"tool": "web_extract",
"destination_url": "https://example.com/page",
"amount_usd": 0.03,
"evaluated_at": "2026-10-10T00:00:00Z"
}
}
}Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe