All workflows

Agent Failure-Cost Firewall

Calculate the downstream financial blast radius of a proposed agent action over a dependency graph and block plans that exceed declared exposure or critical-node limits before execution.

2490 credits per call · $24.90 USDC with x402

Sample input

{
  "target_ids": [
    "db"
  ],
  "max_exposure_usd": 1000,
  "nodes": [
    {
      "id": "db",
      "dependencies": [],
      "exposure_usd": 200,
      "criticality": 0.9
    },
    {
      "id": "checkout",
      "dependencies": [
        "db"
      ],
      "exposure_usd": 600,
      "criticality": 1
    },
    {
      "id": "analytics",
      "dependencies": [
        "db"
      ],
      "exposure_usd": 50,
      "criticality": 0.2
    }
  ]
}

Worked sample output

{
  "ok": true,
  "mode": "failure_cost_firewall",
  "decision": "allow",
  "blockers": [],
  "target_ids": [
    "db"
  ],
  "affected_count": 3,
  "affected_nodes": [
    {
      "id": "checkout",
      "dependencies": [
        "db"
      ],
      "exposure_usd": 600,
      "criticality": 1
    },
    {
      "id": "db",
      "dependencies": [],
      "exposure_usd": 200,
      "criticality": 0.9
    },
    {
      "id": "analytics",
      "dependencies": [
        "db"
      ],
      "exposure_usd": 50,
      "criticality": 0.2
    }
  ],
  "gross_exposure_usd": 850,
  "weighted_exposure_usd": 790,
  "critical_nodes": [
    "checkout",
    "db"
  ],
  "report_sha256": "15b65259c5dec8c5c7d229402a0ff9e963013cd1ae5dcdb4e23415218bc89580",
  "limitations": [
    "Blast radius is derived only from the caller-supplied dependency graph and declared exposure values.",
    "It does not execute, cancel or quarantine any remote agent."
  ]
}

Worked example using published sample data only. Own-data execution is paid.

Connect in curl

Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.

curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/failure-cost-firewall' \
  -H "Authorization: Bearer $BOUNTY_API_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: workflow-request-001' \
  -H 'X-Max-Credits: 2490' \
  --data '{"target_ids":["db"],"max_exposure_usd":1000,"nodes":[{"id":"db","dependencies":[],"exposure_usd":200,"criticality":0.9},{"id":"checkout","dependencies":["db"],"exposure_usd":600,"criticality":1},{"id":"analytics","dependencies":["db"],"exposure_usd":50,"criticality":0.2}]}'

Connect in n8n

Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.

Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/failure-cost-firewall. Send JSON and these headers; store the Bearer token as a private credential.

{
  "method": "POST",
  "headers": {
    "Authorization": "Bearer YOUR_PRIVATE_API_KEY",
    "Content-Type": "application/json",
    "Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
    "X-Max-Credits": "2490"
  },
  "body": {
    "target_ids": [
      "db"
    ],
    "max_exposure_usd": 1000,
    "nodes": [
      {
        "id": "db",
        "dependencies": [],
        "exposure_usd": 200,
        "criticality": 0.9
      },
      {
        "id": "checkout",
        "dependencies": [
          "db"
        ],
        "exposure_usd": 600,
        "criticality": 1
      },
      {
        "id": "analytics",
        "dependencies": [
          "db"
        ],
        "exposure_usd": 50,
        "criticality": 0.2
      }
    ]
  }
}

Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe