Server definition
- Hash
- sha256:351b3d6c22d11df76eef544c656ce87f41e4e9bda2ac686e83c1b5c1c9b2db86
- What it is
- What a remote MCP server returned when asked what it offers: 6 tools
The blob, as servednamed by its sha256
{
"instructions": "Call check_agent_purchase before an autonomous HTTP payment and check_reversibility before a real-world commitment. ExitProof prefers stablecoin machine-payment rails, never invents an exit right, and challenges paid operations only after specialist preflight succeeds.",
"tools": [
{
"description": "Build a bounded cancellation/refund action pack from an existing actionable Exit Manifest. Pass manifest_id and access_token together as the credential pair returned by create_exit_manifest or settlement recovery; use get_exit_manifest for retrieval only, or check_reversibility then create_exit_manifest when no manifest exists. This $1.00 MPP operation prefers Tempo stablecoin when available, retains Stripe card/link as a compatible fallback, and can charge but never contacts the merchant, executes a cancellation, files a chargeback, or guarantees success. Invalid or mismatched credentials and non-actionable manifests are rejected before payment; an identical settled retry with the same payment credential avoids a second settlement, while generatedAt and deadlineStatus can reflect the current time.",
"inputSchema": {
"additionalProperties": false,
"description": "Credentials for one previously created Exit Manifest. Both values are required together and are returned by create_exit_manifest or settlement recovery.",
"properties": {
"access_token": {
"description": "Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it.",
"pattern": "^xp_[A-Za-z0-9_-]{20,}$",
"type": "string"
},
"manifest_id": {
"description": "Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters.",
"pattern": "^xm_[a-f0-9]{32}$",
"type": "string"
}
},
"required": [
"manifest_id",
"access_token"
],
"type": "object"
},
"name": "build_exit_pack",
"outputSchema": {
"additionalProperties": true,
"description": "Bounded action pack derived from an actionable Exit Manifest.",
"properties": {
"actionability": {
"additionalProperties": true,
"description": "Why the stored manifest is actionable and which exit route is established.",
"type": "object"
},
"assessment": {
"description": "Reversibility assessment preserved by the manifest.",
"type": "string"
},
"currency": {
"description": "Currency associated with recorded monetary values.",
"type": "string"
},
"deadlineStatus": {
"description": "Current status of the recorded exit deadline at generation time.",
"enum": [
"open",
"passed",
"not_established"
],
"type": "string"
},
"evidenceChecklist": {
"description": "Evidence to retain while pursuing the exit.",
"items": {
"type": "string"
},
"type": "array"
},
"exitRoute": {
"additionalProperties": true,
"description": "Recorded cancellation/refund route or cited-source route to follow.",
"type": "object"
},
"generatedAt": {
"description": "Timestamp when the action pack was generated.",
"type": "string"
},
"limitations": {
"description": "Boundaries and caveats; ExitProof does not execute the exit or guarantee success.",
"items": {
"type": "string"
},
"type": "array"
},
"manifestId": {
"description": "Manifest used to build this action pack.",
"type": "string"
},
"maximumStatedLossMinor": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"description": "Maximum stated loss in minor currency units when established."
},
"prerequisites": {
"description": "Checks to complete before acting on the exit plan.",
"items": {
"type": "string"
},
"type": "array"
},
"reversibleUntil": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "Recorded exit deadline when established."
},
"schemaVersion": {
"const": "exitproof-exit-pack.v1",
"description": "Exit-pack response schema version."
},
"sources": {
"description": "Recorded source references supporting the action pack.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"steps": {
"description": "Ordered bounded next steps for pursuing cancellation or refund.",
"items": {
"type": "string"
},
"type": "array"
},
"suggestedRequest": {
"description": "Suggested message the user or agent can adapt when requesting cancellation/refund.",
"type": "string"
},
"unresolvedLossExposure": {
"description": "True when the recorded evidence does not establish a complete maximum loss.",
"type": "boolean"
}
},
"required": [
"schemaVersion",
"manifestId",
"generatedAt",
"assessment",
"actionability",
"exitRoute",
"prerequisites",
"deadlineStatus",
"steps",
"suggestedRequest",
"evidenceChecklist",
"sources",
"limitations"
],
"type": "object"
}
},
{
"description": "Inspect one autonomous HTTP purchase before the calling agent pays it. This $0.01 machine-payment operation validates a real 402 challenge, compares advertised price/protocol/network/asset/payment destination when supplied, checks x402 v2 exact resource binding when available, and surfaces retry or settled-delivery recovery signals. ExitProof never forwards payment credentials and never sends a live POST, PUT, PATCH, or DELETE probe; for those methods the caller supplies an already-observed 402 challenge. Conflicting, malformed, inaccessible, non-402, or unsafe targets are rejected before ExitProof issues its own payment challenge. Use check_reversibility instead for cancellation/refund terms on a real-world commitment, create_exit_manifest to preserve an eligible exit path, and build_exit_pack when an exit is actually needed. A successful check is not a recommendation, merchant-identity guarantee, delivery guarantee, legal opinion, or authorization to spend.",
"inputSchema": {
"additionalProperties": false,
"description": "Pre-payment safety check for one autonomous HTTP purchase. ExitProof either performs a credential-free GET/HEAD probe or analyzes a 402 challenge already observed by the caller. It never forwards payment credentials or sends state-changing probe requests.",
"properties": {
"advertised": {
"additionalProperties": false,
"description": "Optional payment facts advertised by discovery metadata. ExitProof compares these to the observed 402 challenge and rejects material conflicts before its own payment challenge.",
"properties": {
"asset": {
"description": "Advertised asset symbol or address.",
"maxLength": 120,
"type": "string"
},
"currency": {
"description": "Advertised currency or asset code.",
"type": "string"
},
"network": {
"description": "Advertised payment network, for example eip155:8453.",
"maxLength": 120,
"type": "string"
},
"pay_to": {
"description": "Advertised payment destination.",
"maxLength": 200,
"type": "string"
},
"price_cents": {
"description": "Advertised price in whole USD cents.",
"minimum": 1,
"type": "integer"
},
"protocol": {
"description": "Advertised machine-payment protocol.",
"enum": [
"x402",
"mpp"
],
"type": "string"
}
},
"type": "object"
},
"live_probe": {
"description": "Whether ExitProof may make one anonymous, credential-free request to target_url. Defaults true for GET/HEAD and false for state-changing methods.",
"type": "boolean"
},
"observed_response": {
"additionalProperties": false,
"description": "A 402 response already observed by the calling agent. Required when live_probe is false. Supply payment challenge headers only, never a payment credential.",
"properties": {
"http_status": {
"const": 402,
"description": "HTTP 402 status from the target.",
"type": "integer"
},
"observed_at": {
"description": "RFC 3339 timestamp with explicit timezone for when the caller observed this response.",
"format": "date-time",
"type": "string"
},
"payment_required": {
"description": "PAYMENT-REQUIRED response header for x402 v2, when present.",
"maxLength": 32768,
"type": "string"
},
"www_authenticate": {
"description": "WWW-Authenticate response header containing an MPP Payment challenge, when present.",
"maxLength": 32768,
"type": "string"
}
},
"required": [
"http_status"
],
"type": "object"
},
"operation": {
"description": "Optional caller label for the target operation. This is descriptive only and is included in the check digest.",
"maxLength": 160,
"type": "string"
},
"request_method": {
"default": "GET",
"description": "HTTP method of the contemplated purchase. Live probing is allowed only for GET or HEAD. For state-changing methods supply observed_response instead.",
"enum": [
"GET",
"HEAD",
"POST",
"PUT",
"PATCH",
"DELETE"
],
"type": "string"
},
"retry_contract": {
"additionalProperties": false,
"description": "Optional retry, settled-delivery recovery, and refund/reversal facts advertised by the target. These remain caller-supplied unless independently verified elsewhere.",
"properties": {
"idempotent_retry": {
"description": "Whether the target advertises safe idempotent retry semantics.",
"type": "boolean"
},
"refund_or_reversal_url": {
"description": "Public HTTPS refund, reversal, or recovery documentation URL, when published.",
"format": "uri",
"type": "string"
},
"settled_delivery_recovery": {
"description": "Whether the target advertises recovery after settlement if delivery fails without requiring a second payment.",
"type": "boolean"
},
"source_url": {
"description": "Public HTTPS source supporting the retry/recovery claims.",
"format": "uri",
"type": "string"
}
},
"type": "object"
},
"target_url": {
"description": "Public HTTPS endpoint the agent is considering paying. Credentials, localhost, private-address literals, and non-HTTPS URLs are rejected.",
"format": "uri",
"type": "string"
}
},
"required": [
"target_url"
],
"type": "object"
},
"name": "check_agent_purchase",
"outputSchema": {
"additionalProperties": true,
"description": "Point-in-time pre-payment safety result. eligible_to_attempt means the observed payment requirements are internally consistent and a positive retry/recovery signal was supplied; review_required means no contradiction was found but one or more safety facts remain unknown.",
"properties": {
"advertised": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"description": "Normalized caller-supplied advertised terms used for consistency checks."
},
"assessment": {
"description": "Bounded pre-payment status. This is not a recommendation to buy.",
"enum": [
"eligible_to_attempt",
"review_required"
],
"type": "string"
},
"availablePaymentOffers": {
"description": "All parseable x402 or MPP offers found in the observed response.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"checkDigest": {
"description": "SHA-256 digest of the normalized target, payment facts, recovery facts, and evidence provenance.",
"pattern": "^[a-f0-9]{64}$",
"type": "string"
},
"checkedAt": {
"description": "Time the check result was produced.",
"format": "date-time",
"type": "string"
},
"checks": {
"description": "Individual safety checks. Conflicts reject before payment and therefore never appear as a paid result.",
"items": {
"additionalProperties": false,
"properties": {
"detail": {
"type": "string"
},
"id": {
"type": "string"
},
"status": {
"enum": [
"pass",
"unknown"
]
}
},
"required": [
"id",
"status",
"detail"
],
"type": "object"
},
"type": "array"
},
"evidence": {
"description": "Evidence provenance, including whether the 402 challenge was independently observed by ExitProof.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"limitations": {
"description": "Boundaries on what the paid result establishes.",
"items": {
"type": "string"
},
"type": "array"
},
"nextStep": {
"additionalProperties": true,
"description": "Machine-readable status and bounded instruction for the calling agent.",
"type": "object"
},
"observedPayment": {
"additionalProperties": true,
"description": "Selected machine-payment offer normalized from the observed 402 challenge.",
"type": "object"
},
"receiptEnvelope": {
"$ref": "https://davisvillelabs.com/agents/davisville-receipt-envelope.v1.schema.json",
"description": "Additive Davisville Receipt Envelope v1. The native ExitProof purchase-check result remains authoritative."
},
"reversibility": {
"additionalProperties": true,
"description": "Published retry, settled-delivery recovery, and reversal metadata supplied for this target.",
"type": "object"
},
"schemaVersion": {
"const": "exitproof-agent-purchase-check.v1",
"description": "Agent purchase check schema version."
},
"target": {
"additionalProperties": true,
"description": "Normalized target endpoint and contemplated method.",
"type": "object"
}
},
"required": [
"schemaVersion",
"checkedAt",
"assessment",
"target",
"observedPayment",
"availablePaymentOffers",
"checks",
"reversibility",
"evidence",
"limitations",
"nextStep",
"checkDigest",
"receiptEnvelope"
],
"type": "object"
}
},
{
"description": "Evaluate one commitment’s cancellation/refund reversibility from transaction-specific checkout terms plus maintained policy evidence, without charging or creating durable state. Use before a purchase, booking, subscription, rental, service, ticket, digital purchase, or deposit when exit deadlines or loss matter; use list_supported_policies only for maintained-overlay coverage, and create_exit_manifest only after paidExitManifestAvailable=true. Do not use for purchase desirability, legal advice, chargeback decisions, or executing a cancellation. Supply checkout_terms whenever available because they control the transaction-specific assessment; expected_commitment_at moves deadline evaluation forward when the commitment is future-dated, and missing or conflicting evidence can return assessment=unknown rather than inventing an exit right.",
"inputSchema": {
"additionalProperties": false,
"description": "One contemplated or existing commitment to evaluate. merchant, commitment_type, and amount are required. Transaction-specific checkout_terms are the strongest input when available; maintained policy evidence can add context but never overrides conflicting transaction-specific terms.",
"properties": {
"amount": {
"description": "Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation.",
"minimum": 0,
"type": "number"
},
"checkout_terms": {
"additionalProperties": false,
"description": "Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while maintained policy evidence remains contextual.",
"properties": {
"auto_renews": {
"description": "Whether the supplied transaction terms explicitly state that the commitment renews automatically.",
"type": "boolean"
},
"cancellable": {
"description": "Whether the supplied transaction terms explicitly state that the commitment can be canceled.",
"type": "boolean"
},
"cancellation_deadline": {
"description": "RFC 3339 timestamp with explicit timezone for the stated cancellation deadline, even when cancellation may involve a loss.",
"format": "date-time",
"type": "string"
},
"cancellation_method": {
"description": "Recorded method or path for cancellation/refund, such as an account page, support channel, or merchant instruction. This can make a later exit pack actionable.",
"maxLength": 240,
"type": "string"
},
"cancellation_penalty_amount": {
"description": "Stated cancellation penalty in major units of currency. Mutually exclusive with cancellation_penalty_percent.",
"minimum": 0,
"type": "number"
},
"cancellation_penalty_percent": {
"description": "Stated cancellation penalty as a percentage from 0 to 100. Mutually exclusive with cancellation_penalty_amount.",
"maximum": 100,
"minimum": 0,
"type": "number"
},
"charge_timing": {
"description": "When the merchant states the charge will occur, such as immediately, at check-in, or 24 hours before renewal.",
"maxLength": 160,
"type": "string"
},
"free_cancellation_until": {
"description": "RFC 3339 deadline with explicit timezone through which the supplied terms state cancellation is free.",
"format": "date-time",
"type": "string"
},
"nonrefundable_amount": {
"description": "Amount explicitly stated as nonrefundable, in major units of currency.",
"minimum": 0,
"type": "number"
},
"observed_at": {
"description": "RFC 3339 timestamp with explicit timezone for when the caller observed these checkout terms.",
"format": "date-time",
"type": "string"
},
"refundable": {
"description": "Whether the supplied transaction terms explicitly state that the committed amount is refundable.",
"type": "boolean"
},
"renewal_interval": {
"description": "Human-readable renewal interval from the supplied terms, such as monthly or annually. Use only when auto-renewal terms are stated.",
"maxLength": 80,
"type": "string"
},
"source_url": {
"description": "HTTP(S) source URL for the supplied transaction terms. ExitProof removes credentials, query parameters, and fragments before storing the URL.",
"maxLength": 500,
"type": "string"
}
},
"type": "object"
},
"client_reference": {
"description": "Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here.",
"maxLength": 200,
"type": "string"
},
"commitment_type": {
"description": "Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method.",
"enum": [
"subscription",
"reservation",
"ticket",
"service",
"software",
"digital_purchase",
"rental",
"deposit",
"other"
],
"type": "string"
},
"country": {
"description": "Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters.",
"maxLength": 2,
"minLength": 2,
"pattern": "^[A-Za-z]{2}$",
"type": "string"
},
"currency": {
"default": "USD",
"description": "Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD.",
"maxLength": 3,
"minLength": 3,
"pattern": "^[A-Za-z]{3}$",
"type": "string"
},
"event_type": {
"default": "initial",
"description": "Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment.",
"enum": [
"initial",
"renewal",
"purchase",
"reservation",
"deposit",
"other"
],
"type": "string"
},
"expected_commitment_at": {
"description": "RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp.",
"format": "date-time",
"type": "string"
},
"merchant": {
"description": "Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets.",
"maxLength": 160,
"minLength": 1,
"type": "string"
},
"purchase_channel": {
"default": "unknown",
"description": "Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself.",
"enum": [
"direct",
"apple",
"google_play",
"marketplace",
"travel_agency",
"other",
"unknown"
],
"type": "string"
},
"region": {
"description": "Optional state, province, or region label when the commitment or merchant terms are region-specific.",
"maxLength": 80,
"type": "string"
}
},
"required": [
"merchant",
"commitment_type",
"amount"
],
"type": "object"
},
"name": "check_reversibility",
"outputSchema": {
"additionalProperties": true,
"description": "Bounded reversibility assessment with evidence, loss/deadline information, limitations, and paid-operation eligibility flags.",
"properties": {
"amountMinor": {
"description": "Commitment amount in minor currency units.",
"minimum": 0,
"type": "integer"
},
"assessment": {
"description": "Evidence-bounded reversibility classification. unknown means current evidence is insufficient or conflicting.",
"enum": [
"fully_reversible",
"conditionally_reversible",
"low_reversibility",
"effectively_irreversible",
"unknown"
],
"type": "string"
},
"caseDigest": {
"description": "Stable digest of the normalized commitment inputs used for this assessment.",
"type": "string"
},
"commitmentType": {
"description": "Normalized commitment type.",
"type": "string"
},
"currency": {
"description": "Normalized three-letter currency code.",
"type": "string"
},
"currentExitEstablished": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"description": "Whether current evidence establishes an exit route."
},
"decisionSupport": {
"additionalProperties": true,
"description": "Decision-support summary that does not decide whether the user should make the commitment.",
"type": "object"
},
"evaluatedAt": {
"description": "Timestamp at which the commitment was evaluated.",
"type": "string"
},
"evidence": {
"description": "Evidence items supporting or limiting the assessment.",
"items": {
"additionalProperties": true,
"description": "One evidence item used by ExitProof.",
"properties": {
"authority": {
"description": "Authority label for the source.",
"type": "string"
},
"evidenceOrigin": {
"description": "Origin classification, such as caller_supplied or maintained_policy.",
"type": "string"
},
"independentlyVerified": {
"description": "Whether ExitProof independently verified this evidence item.",
"type": "boolean"
},
"observedAt": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "When the evidence was observed, when available."
},
"sourceUrl": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "Source URL when one is available."
},
"type": {
"description": "Evidence type, such as checkout_terms or official_policy.",
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"evidenceBasis": {
"description": "Whether the assessment is based on checkout terms, maintained policy, both, or insufficient evidence.",
"type": "string"
},
"evidenceConflict": {
"description": "True when evidence conflicts and cannot safely support a confident paid result.",
"type": "boolean"
},
"evidenceState": {
"description": "Current evidence state, such as established, incomplete, conflicting, expired, or missing.",
"type": "string"
},
"exitPackEligibility": {
"additionalProperties": true,
"description": "Reasoned actionability status for a future exit pack.",
"type": "object"
},
"limitations": {
"description": "Important limits on what the assessment proves.",
"items": {
"type": "string"
},
"type": "array"
},
"maximumStatedLossMinor": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"description": "Maximum stated loss in minor currency units when safely established, otherwise null."
},
"merchant": {
"description": "Normalized merchant or platform name.",
"type": "string"
},
"paidExitManifestAvailable": {
"description": "Whether current evidence passes the preflight required before create_exit_manifest can be challenged for payment.",
"type": "boolean"
},
"paidExitPackAvailable": {
"description": "Whether the current evidence appears actionable enough for a later exit pack after a manifest exists.",
"type": "boolean"
},
"reason": {
"description": "Concise evidence-grounded explanation of the assessment.",
"type": "string"
},
"reversibleUntil": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "Recorded exit deadline when established, otherwise null."
},
"schemaVersion": {
"const": "exitproof-reversibility.v1",
"description": "ExitProof reversibility result schema version."
}
},
"required": [
"schemaVersion",
"assessment",
"merchant",
"commitmentType",
"amountMinor",
"currency",
"evaluatedAt",
"reason",
"evidence",
"limitations",
"paidExitManifestAvailable",
"paidExitPackAvailable",
"caseDigest"
],
"type": "object"
}
},
{
"description": "Persist a privacy-minimized Exit Manifest for an eligible commitment, then return its manifest_id and secret access_token. Use only after check_reversibility says paidExitManifestAvailable=true; pass the exact commitment facts to preserve, with transaction-specific checkout_terms controlling the assessment when supplied. Use check_reversibility for evaluation only, or get_exit_manifest when a manifest already exists. This state-changing $0.25 stablecoin MPP operation checks eligibility before any payment challenge; a fresh authorization creates durable state, while an identical settled retry with the same payment credential recovers the same manifest without a second settlement. The plaintext access token is returned to the caller but stored only as a SHA-256 hash.",
"inputSchema": {
"additionalProperties": false,
"description": "One contemplated or existing commitment to evaluate. merchant, commitment_type, and amount are required. Transaction-specific checkout_terms are the strongest input when available; maintained policy evidence can add context but never overrides conflicting transaction-specific terms.",
"properties": {
"amount": {
"description": "Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation.",
"minimum": 0,
"type": "number"
},
"checkout_terms": {
"additionalProperties": false,
"description": "Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while maintained policy evidence remains contextual.",
"properties": {
"auto_renews": {
"description": "Whether the supplied transaction terms explicitly state that the commitment renews automatically.",
"type": "boolean"
},
"cancellable": {
"description": "Whether the supplied transaction terms explicitly state that the commitment can be canceled.",
"type": "boolean"
},
"cancellation_deadline": {
"description": "RFC 3339 timestamp with explicit timezone for the stated cancellation deadline, even when cancellation may involve a loss.",
"format": "date-time",
"type": "string"
},
"cancellation_method": {
"description": "Recorded method or path for cancellation/refund, such as an account page, support channel, or merchant instruction. This can make a later exit pack actionable.",
"maxLength": 240,
"type": "string"
},
"cancellation_penalty_amount": {
"description": "Stated cancellation penalty in major units of currency. Mutually exclusive with cancellation_penalty_percent.",
"minimum": 0,
"type": "number"
},
"cancellation_penalty_percent": {
"description": "Stated cancellation penalty as a percentage from 0 to 100. Mutually exclusive with cancellation_penalty_amount.",
"maximum": 100,
"minimum": 0,
"type": "number"
},
"charge_timing": {
"description": "When the merchant states the charge will occur, such as immediately, at check-in, or 24 hours before renewal.",
"maxLength": 160,
"type": "string"
},
"free_cancellation_until": {
"description": "RFC 3339 deadline with explicit timezone through which the supplied terms state cancellation is free.",
"format": "date-time",
"type": "string"
},
"nonrefundable_amount": {
"description": "Amount explicitly stated as nonrefundable, in major units of currency.",
"minimum": 0,
"type": "number"
},
"observed_at": {
"description": "RFC 3339 timestamp with explicit timezone for when the caller observed these checkout terms.",
"format": "date-time",
"type": "string"
},
"refundable": {
"description": "Whether the supplied transaction terms explicitly state that the committed amount is refundable.",
"type": "boolean"
},
"renewal_interval": {
"description": "Human-readable renewal interval from the supplied terms, such as monthly or annually. Use only when auto-renewal terms are stated.",
"maxLength": 80,
"type": "string"
},
"source_url": {
"description": "HTTP(S) source URL for the supplied transaction terms. ExitProof removes credentials, query parameters, and fragments before storing the URL.",
"maxLength": 500,
"type": "string"
}
},
"type": "object"
},
"client_reference": {
"description": "Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here.",
"maxLength": 200,
"type": "string"
},
"commitment_type": {
"description": "Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method.",
"enum": [
"subscription",
"reservation",
"ticket",
"service",
"software",
"digital_purchase",
"rental",
"deposit",
"other"
],
"type": "string"
},
"country": {
"description": "Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters.",
"maxLength": 2,
"minLength": 2,
"pattern": "^[A-Za-z]{2}$",
"type": "string"
},
"currency": {
"default": "USD",
"description": "Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD.",
"maxLength": 3,
"minLength": 3,
"pattern": "^[A-Za-z]{3}$",
"type": "string"
},
"event_type": {
"default": "initial",
"description": "Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment.",
"enum": [
"initial",
"renewal",
"purchase",
"reservation",
"deposit",
"other"
],
"type": "string"
},
"expected_commitment_at": {
"description": "RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp.",
"format": "date-time",
"type": "string"
},
"merchant": {
"description": "Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets.",
"maxLength": 160,
"minLength": 1,
"type": "string"
},
"purchase_channel": {
"default": "unknown",
"description": "Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself.",
"enum": [
"direct",
"apple",
"google_play",
"marketplace",
"travel_agency",
"other",
"unknown"
],
"type": "string"
},
"region": {
"description": "Optional state, province, or region label when the commitment or merchant terms are region-specific.",
"maxLength": 80,
"type": "string"
}
},
"required": [
"merchant",
"commitment_type",
"amount"
],
"type": "object"
},
"name": "create_exit_manifest",
"outputSchema": {
"additionalProperties": true,
"description": "Durable privacy-minimized Exit Manifest plus the bearer access token returned to the caller.",
"properties": {
"accessToken": {
"description": "Secret bearer token required with manifestId for later retrieval or exit-pack creation. ExitProof does not store this token in plaintext.",
"type": "string"
},
"accessTokenReissuedForSettlementRecovery": {
"description": "True only when deterministic settlement recovery re-derived the access token after a settled delivery failure.",
"type": "boolean"
},
"accessTokenReturnedOnce": {
"description": "Whether this response is the first normal return of the access token.",
"type": "boolean"
},
"assessment": {
"description": "Reversibility assessment preserved in the manifest.",
"type": "string"
},
"createdAt": {
"description": "Manifest creation timestamp.",
"type": "string"
},
"expiresAt": {
"description": "Manifest expiration timestamp.",
"type": "string"
},
"manifestId": {
"description": "Unguessable identifier for the stored Exit Manifest.",
"type": "string"
},
"paidExitPackAvailable": {
"description": "Whether the stored manifest is eligible for an exit-pack preflight at creation time.",
"type": "boolean"
},
"privacyNote": {
"description": "How ExitProof protects and may recover the access token.",
"type": "string"
}
},
"required": [
"manifestId",
"createdAt",
"expiresAt",
"assessment",
"accessToken",
"accessTokenReturnedOnce",
"privacyNote"
],
"type": "object"
}
},
{
"description": "Retrieve one previously created Exit Manifest without charging or changing stored state. Pass manifest_id and access_token together: the ID selects the record and the secret token authorizes access to that same record, so neither value is sufficient alone. Use this for preserved evidence and terms; use build_exit_pack for an actionable cancellation/refund plan, or create_exit_manifest when no manifest exists. This free, repeatable read does not refresh, re-evaluate, or extend evidence; missing, expired, or mismatched credentials fail without modifying the manifest.",
"inputSchema": {
"additionalProperties": false,
"description": "Credentials for one previously created Exit Manifest. Both values are required together and are returned by create_exit_manifest or settlement recovery.",
"properties": {
"access_token": {
"description": "Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it.",
"pattern": "^xp_[A-Za-z0-9_-]{20,}$",
"type": "string"
},
"manifest_id": {
"description": "Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters.",
"pattern": "^xm_[a-f0-9]{32}$",
"type": "string"
}
},
"required": [
"manifest_id",
"access_token"
],
"type": "object"
},
"name": "get_exit_manifest",
"outputSchema": {
"additionalProperties": false,
"description": "Authenticated read of one previously stored Exit Manifest.",
"properties": {
"manifest": {
"additionalProperties": true,
"description": "Stored Exit Manifest. This read does not refresh or reinterpret the original evidence.",
"type": "object"
},
"schemaVersion": {
"const": "exitproof-manifest-read.v1",
"description": "Manifest-read response schema version."
}
},
"required": [
"schemaVersion",
"manifest"
],
"type": "object"
}
},
{
"description": "List the maintained merchant policy overlays and snapshot version/date ExitProof can add to transaction-specific evidence. Use this only to inspect maintained coverage; use check_reversibility to evaluate an actual commitment, including an unlisted merchant when transaction-specific checkout_terms are available. An absent merchant means no maintained overlay, not that no cancellation, refund, contractual, or legal right exists. This is a free read-only snapshot: it creates no durable state, issues no payment challenge, and does not fetch or verify a merchant’s live policy at call time.",
"inputSchema": {
"additionalProperties": false,
"description": "No parameters. This tool lists the current maintained policy-overlay catalog.",
"properties": {},
"type": "object"
},
"name": "list_supported_policies",
"outputSchema": {
"additionalProperties": false,
"description": "Maintained merchant-policy overlay catalog. This is coverage metadata, not a statement that unlisted merchants cannot be evaluated.",
"properties": {
"important": {
"description": "Coverage caveat explaining that transaction-specific checkout terms can be used for any merchant.",
"type": "string"
},
"merchants": {
"description": "Merchants with maintained policy overlays.",
"items": {
"additionalProperties": false,
"properties": {
"aliases": {
"description": "Names that map to this merchant policy overlay.",
"items": {
"type": "string"
},
"type": "array"
},
"displayName": {
"description": "Human-readable merchant name.",
"type": "string"
},
"id": {
"description": "Stable maintained-policy merchant identifier.",
"type": "string"
},
"ruleIds": {
"description": "Maintained rule identifiers available for this merchant.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"id",
"displayName",
"aliases",
"ruleIds"
],
"type": "object"
},
"type": "array"
},
"policySnapshot": {
"additionalProperties": true,
"description": "Version and verification date for the maintained policy snapshot.",
"type": "object"
},
"schemaVersion": {
"const": "exitproof-supported-policies.v1",
"description": "Supported-policy response schema version."
}
},
"required": [
"schemaVersion",
"policySnapshot",
"important",
"merchants"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:351b3d6c22d11df76eef544c656ce87f41e4e9bda2ac686e83c1b5c1c9b2db86 | sha256sum