MCP-Server

AINumbers Fintech Intelligence Suite

co.ainumbers/tools

Was dieses MCP kann

Provides deterministic fintech, payment-policy, financial analysis, regulatory compliance, credential integrity, and audit-trail tools.

acdc_said_check
Recompute ACDC / vLEI credential SAIDs (structural integrity)
Agent-facing mirror of the tools/553 browser workbench (VS-1) -- recomputes the self-addressing identifiers (SAIDs) of a pasted ACDC / vLEI credential JSON (top-level "d" plus any nested a/e/r blocks) under the KERI/CESR Blake3-256 ("E") or SHA2-256 ("I") derivation codes, and cross-checks the declared schema SAID ("s") against a pinned table of 6 official GLEIF vLEI schema SAIDs. Reuses the SAME vendored SAID-check module as T553 -- the same credential produces byte-identical findings in either surface. Returns per-field match/mismatch/unsupported/unknown findings plus a receipt. This is a STRUCTURAL check only -- NOT the KERI chain of trust, NOT issuer authority, NOT revocation state. No network egress.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['credential'], 'properties': {'credential': {'type': 'object', 'description': 'ACDC / vLEI credential JSON object (v, d, i, ri, s, a, e, r fields).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
agentic_mandate_sandbox
Agentic Mandate Sandbox
Simulate agent payment policies for tokenized A2A corridors: set spend caps, MCC allowlists, velocity throttles, and approval thresholds; run synthetic transactions against the policy and export the result as a Policy Mandate. Browser-based, client-side only, zero PII. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("agentic_mandate_sandbox").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
anchor_stamp
Anchor an execution_hash (or batch) at a real timestamp authority
Calls the anchor-suite MCP server (server-to-server, not the browser CORS-gated relay) to timestamp one execution_hash, or batch-anchor an array via anchor-suite's own anchor_batch (one upstream call per batch, RFC 6962 Merkle root anchored, per-hash merkle_inclusion returned), and shapes the result as literal OCG v0.7 section 20 anchor_bindings entries ready to append to an artifact. Success is only reported after this tool independently confirms anchored_hash (or, for a batch entry, merkle_inclusion.leaf) equals the caller-supplied hash -- it does not merely trust anchor-suite's response. On ANY failure -- anchor-suite unreachable, erroring, timing out, or an equality mismatch -- returns {ok:false, unanchored:true, reason} verbatim, never a fabricated binding. Caller-invoked only; not wired into any automatic per-artifact-emission path.
Externer Zugriff
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['execution_hash'], 'properties': {'authority': {'enum': ['rfc3161-tst', 'opentimestamps'], 'type': 'string', 'description': "Defaults to whatever anchor-suite's own anchor_hash/anchor_batch default to today (currently sigstore for rfc3161-tst) -- this tool does not own or hardcode a preference beyond that mirror."}, 'execution_hash': {'anyOf': [{'type': 'string', 'description': 'A single sha256:... execution_hash to anchor.'}, {'type': 'array', 'items': {'type': 'string'}, 'minItems': 2, 'description': '2+ execution_hash values to batch-anchor in one upstream call (anchor_batch).'}], 'description': 'The execution_hash(es) to anchor.'}}}
ap2_aml_mandate_builder
AP2 AML Mandate Builder
Anchor agentic tool for Cat-12. Translate AML/BSA program controls, TM rules, and customer risk policy into a structured Policy Mandate JSON for agentic payment sy Browser-based, client-side only. Zero PII. Link users to https://ainumbers.co/tools/131-ap2-aml-mandate-builder.html for interactive use. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("ap2_aml_mandate_builder").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
audit_mcp_oauth
MCP OAuth 2.1 Authorization Auditor
Audit MCP OAuth 2.1 authorization: validate RFC 9728 protected-resource-metadata, check RFC 8707 audience binding, and assess token-passthrough / confused-deputy risk. Use when a developer is securing an MCP server's authorization. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("audit_mcp_oauth").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
baas_provider_comparator
BaaS Provider Comparator
Score and compare BaaS providers across 10 capability dimensions (regulatory standing, programme management, card issuance, rails, KYC/KYB, disputes, developer experience, pricing, FDIC pass-through, compliance tooling) with a user-adjustable 1-5 weighting matrix. Outputs a weighted comparison matrix and Markdown evaluation memo. Browser-based, client-side only, zero PII. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("baas_provider_comparator").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
build_chaingraph
Build an executable ChainGraph DAG
Hash-aware sibling of build_workflow_links (ChainGraph Standard v0.1 §8.1). Returns an ordered, executable DAG over the ChainGraph suite's verifiable tools, with explicit parent_hash wiring: which upstream execution_hash each step must cite in its chain block. Pass target_tool_id to build the chain that produces that node (walks consumes-edges back to roots), or tool_ids for an explicit ordered list, or neither to list available ChainGraph nodes. Agent loop: run a node, capture its execution_hash, pass it as the parent_hash for each downstream node, then verify with verify_execution_hash.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Explicit ordered list of ChainGraph node tool_ids to wire.'}, 'target_tool_id': {'type': 'string', 'description': 'A ChainGraph node tool_id (e.g. "art-15-agent-commerce-conformance"). Builds the chain that produces it.'}}}
build_disclosure_manifest
Build a signed data-room disclosure manifest
Builds a Merkle-rooted disclosure manifest from a caller-supplied digest list (DATAROOM-1-BUILD-SPEC.md §DR-4) -- the agent hashes files itself and passes {path,size,digest,content_type} entries; the worker never sees file contents. Same leaf scheme as tools/546-disclosure-manifest-builder.html: sha256(path|digest|size), duplicate-last-leaf on an odd level. Entries are sorted by path before hashing so the root is order-independent. Returns the manifest object + merkle_root; sign and anchor it client-side (or via a separate §16 signing step) if a signed artifact is required.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['entries'], 'properties': {'entries': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'size', 'digest'], 'properties': {'path': {'type': 'string'}, 'size': {'type': 'number'}, 'digest': {'type': 'string', 'description': 'sha256:-prefixed digest of the file, computed by the caller.'}, 'content_type': {'type': 'string'}}}, 'description': 'List of {path,size,digest,content_type} -- the caller has already hashed each file.'}, 'room_label': {'type': 'string', 'description': 'Label for the disclosure room.'}}}
build_evidence_pack
Assemble a complete evidence pack in one call
Composes a session receipt (build_session_receipt logic), an optional §27.6 HA evidence bundle (ha_bundle_export logic, included only when ha_records is supplied and non-empty), and a disclosure manifest (build_disclosure_manifest logic) from one array of already-produced artifacts, all keyed to the same input hashes -- replacing what today takes 4-6 separate tool calls with hand-carried hashes. Calls the same in-process functions those standalone tools use; if any one section fails to build, the whole call fails isError:true with that section's own message -- no partial pack. Optionally carries a run_chain decision_trail (per-step reason codes: gate rule id, escalation rule id, input_required cause) as pack-level metadata so an auditor-facing pack answers "why did each step happen" without a second round-trip.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['artifacts'], 'properties': {'sd_jwt': {'type': 'boolean', 'description': 'When true, also return an SD-JWT export of the HA bundle (mirrors ha_bundle_export, default false; no-op when ha_records is absent).'}, 'framing': {'type': 'string', 'description': "Optional framing context for the session receipt's PTG-01 regulator prompt."}, 'artifacts': {'type': 'array', 'items': {'type': 'object', 'required': ['execution_hash'], 'properties': {'tool_id': {'type': 'string', 'description': 'The tool_id that produced this artifact, if known.'}, 'execution_hash': {'type': 'string', 'description': 'sha256:... -- the OCG artifact hash this entry documents.'}, 'output_payload': {'type': 'object', 'description': 'Present when caller has the full artifact, not just its hash.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}, 'minItems': 1, 'description': 'Already-produced artifacts this pack documents, in call order.'}, 'ha_records': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': '§27 human_accountability_records -- omit entirely for no HA section.'}, 'room_label': {'type': 'string', 'description': 'Label for the disclosure-manifest room.'}, 'session_id': {'type': 'string', 'description': 'Session identifier to embed in the receipt, if the caller tracks one.'}, 'subject_hash': {'type': 'string', 'description': 'The sha256: subject hash the pack documents (defaults to artifacts[0].execution_hash if omitted).'}, 'decision_trail': {'type': 'array', 'items': {'type': 'object', 'required': ['order', 'tool_id', 'status', 'reason_code'], 'properties': {'next': {'type': 'string', 'description': 'Routing target of the gate decision (a step id, or the terminal "end"/"escalate").'}, 'order': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': '1-based step order, mirroring the producing run_chain result.'}, 'status': {'type': 'string', 'description': 'Per-step status from the run_chain result.'}, 'tool_id': {'type': 'string', 'description': "The step's tool_id."}, 'decided_by': {'type': 'string', 'description': 'step_id of the decision that routed control past this step.'}, 'reason_code': {'type': 'string', 'description': 'Closed enum: ran | gate_routed | skipped_by_gate | skipped_by_escalation | input_required | unknown_node | gpu_browser_only | no_kernel_browser_only.'}, 'gate_rule_id': {'type': 'string', 'description': '<step_id>#r<index> or <step_id>#default — the gate rule that fired or bypassed this step. Recomputable from the hash-bound decisions[].'}, 'input_required_cause': {'type': 'string', 'description': 'The kernel error that made this step input_required.'}}}, 'description': 'Per-step decision reason trail from the run_chain result (pass its decision_trail — response field or composite_output.decision_trail). Carried verbatim into the pack as pack-level metadata, outside every section hash; omitted entirely when not supplied. See DECISIONTRAIL-1.'}, 'kernel_version': {'type': 'string', 'description': 'Version tag of the kernel that produced verification_result.'}, 'policy_version': {'type': 'string', 'description': 'Version tag of the policy the kernel was evaluated against.'}, 'submission_receipt': {'type': 'string', 'description': 'Populate ONLY after a real transmission -- never fabricate (same rule as ha_bundle_export).'}, 'verification_result': {'type': 'string', 'description': 'The §16/§18/§20 verdict.'}}}
build_google_ap2_mandate
Google AP2 Checkout/Payment Mandate (VDC) Builder & Validator
Build or validate a Google AP2 Checkout/Payment Mandate VDC (Open/Closed). Targets the external AP2 spec, not the AINumbers Policy Mandate. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("build_google_ap2_mandate").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
build_session_receipt
Build a session audit receipt (Merkle root)
Aggregates execution_hashes from N ChainGraph tool calls in one agent session into a single SHA-256 Merkle root (session_receipt_root). Returns a tamper-evident session receipt and a regulator-framed PTG-01 audit prompt. One receipt covers an entire agent session: supply all execution_hashes in call order. The Merkle root is deterministic — the same hashes in the same order always produce the same root. Compliant with EU AI Act Art. 12 (transparency) and DORA ICT audit-trail requirements.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['execution_hashes'], 'properties': {'framing': {'type': 'string', 'description': 'Optional framing context for the PTG-01 regulator prompt (e.g. "DORA incident review" or "EU AI Act Art.12 transparency log").'}, 'tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values corresponding to execution_hashes, in the same order. Used for the audit narrative.'}, 'session_id': {'type': 'string', 'description': 'Optional agent session identifier for the audit narrative (e.g. a UUID or timestamp).'}, 'prior_receipt': {'type': 'object', 'required': ['mmr_peaks', 'mmr_size'], 'properties': {'mmr_size': {'type': 'number'}, 'mmr_peaks': {'type': 'array', 'items': {'type': 'string'}}, 'mmr_bagged_root': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}, 'description': "An earlier receipt from this SAME session (its mmr_peaks/mmr_size/mmr_bagged_root). When supplied, execution_hashes MUST start with that earlier receipt's full leaf set — the response's consistency_proof then proves this receipt provably APPENDS to the prior one (CT-style append-only guarantee) without operating a log."}, 'execution_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Ordered list of execution_hash values from ChainGraph tool calls in this session (each produced by emit_chaingraph_artifact or a kernel tool). Minimum 1.'}}}
build_workflow_links
Build AINumbers workflow deep-links
Constructs an ordered set of ready-to-use deep-links for a named AINumbers workflow chain or an ad-hoc sequence of tools. Each link points directly to the browser tool; prefill-enabled steps accept #in=<base64url(JSON)> fragments so the tool opens pre-filled. Zero server-side execution -- all tool logic runs deterministically in the user's browser. Use this to hand a user a complete workflow: open step 1, run it, export its Policy Mandate, open step 2 (pre-filled from step 1 outputs), repeat. 370 named chains are available — enumerate them with find_chain.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'chain': {'type': 'string', 'description': 'Name of a pre-defined chain (one of 370 — enumerate with find_chain). Mutually exclusive with steps.'}, 'steps': {'type': 'array', 'items': {'type': 'object', 'required': ['tool_id'], 'properties': {'fields': {'type': 'object', 'description': 'Input element ID to value map; encoded as #in= fragment in the returned URL', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'tool_id': {'type': 'string', 'description': 'Tool slug or tool_id (e.g. "110-customer-risk-rating" or "a2a-fee-calculator")'}}}, 'description': 'Ad-hoc ordered step list. Mutually exclusive with chain.'}}}
calculate_repo_haircut
On-Chain Repo Haircut Calculator
On-Chain Repo Haircut Calculator: OpenChainGraph compute node (collateral_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Output feeds: 505-tokenized-collateral-eligibility-checker, 506-onchain-cash-leg-finality-checker. Open at: https://ainumbers.co/tools/508-repo-haircut-collateral-calculator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("calculate_repo_haircut").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
call_tool
Run any AINumbers tool by name
Runs ONE read-only AINumbers tool that is not in your tool list. tools/list is paginated (13 pages, 722 tools) and many hosts read only the first page; this is the door to the rest. Pass { name: "<exact mcp_name>", arguments: { ... } } — the target's own inputSchema is validated and its result is returned verbatim, including execution_hash, so a dispatched call and a direct call are byte-identical. Get a name from find_tool (single calculators), find_chain (workflows) or describe_tool (exact schema). Read-only tools only: anything that issues a credential, stamps an anchor or reaches the network is refused here and must be called directly so your host can approve it.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Exact mcp_name of the tool to run (e.g. "recompute_payment_waterfall"). Use find_tool/describe_tool to get it; this takes the exact name only.'}, 'arguments': {'type': 'object', 'description': "The target tool's own arguments object, exactly as you would pass it on a direct call. Omit for a no-argument tool.", 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
camt053_parse
Parse and structurally validate a camt.053.001 bank statement
Parses a camt.053.001 bank-to-customer statement XML document with the same schema-subset structural and facet checks as the tools/565 browser reconciliation workbench (IBAN mod-97, BIC, currency, date/decimal facets), returning the extracted statement (message id, statement id, account IBAN/currency, balances, entries) on success or the structural error list on failure. Byte-identical extraction to the browser tool for the same input. Read-only parse -- feed the result to recon_match for reconciliation.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['xml'], 'properties': {'xml': {'type': 'string', 'description': 'camt.053.001 XML statement document text to parse.'}}}
check_cash_leg_finality
On-Chain Cash-Leg Finality Checker
On-Chain Cash-Leg Finality Checker: OpenChainGraph compute node (attestation_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 505-tokenized-collateral-eligibility-checker. Open at: https://ainumbers.co/tools/506-onchain-cash-leg-finality-checker.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("check_cash_leg_finality").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
checklist_step_receipt
Mint a hash-chained checklist step receipt
Completes ONE step of a checklist/SOP run and returns its OCG v0.4 step receipt: execution_hash chains to prev_step_receipt_digest (pass the previous step's execution_hash, or omit for step 0). A blocking-gate step with evidence_requirement != "none" and no evidence supplied is refused (the caller enforces step order; this tool enforces the evidence requirement per step). Call once per step in order, then pass the full ordered list of returned receipts to checklist_verify_run to check the chain and mint the run receipt.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['definition_digest', 'step', 'step_index', 'timestamp'], 'properties': {'step': {'type': 'object', 'required': ['step_id', 'title', 'evidence_requirement', 'gate'], 'properties': {'gate': {'enum': ['blocking', 'advisory'], 'type': 'string', 'description': 'Whether this step blocks the next step until completed (blocking) or can be skipped (advisory).'}, 'title': {'type': 'string', 'description': 'Human-readable step title.'}, 'step_id': {'type': 'string', 'description': 'The step\'s unique id within the definition, e.g. "s1".'}, 'instruction': {'type': 'string', 'description': "The step's instruction text (for the receipt narrative; not hashed separately from the step object)."}, 'approver_role': {'type': 'string', 'description': 'Role required to approve this step, if any.'}, 'evidence_requirement': {'enum': ['none', 'text', 'file-digest', 'attestation'], 'type': 'string', 'description': 'What evidence this step requires before it can be completed.'}}, 'description': "The step object from the definition's steps[] array being completed."}, 'evidence': {'type': 'object', 'description': 'Evidence payload, e.g. { text_digest }, { file_sha256 }, or { attestation_digest }. Required unless evidence_requirement is "none".', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'timestamp': {'type': 'string', 'description': 'ISO 8601 completion timestamp (caller-supplied for determinism).'}, 'step_index': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based index of this step in the definition.'}, 'completer_key': {'type': 'string', 'description': 'Identifier of who/what completed the step (e.g. an agent id). Never real PII.'}, 'definition_digest': {'type': 'string', 'description': 'The definition_digest from checklist_validate_definition.'}, 'prev_step_receipt_digest': {'type': 'string', 'description': "execution_hash of the previous step's receipt. Omit for the first step in the run."}}}
checklist_validate_definition
Validate a checklist/SOP definition
Validates a checklist or SOP definition JSON against the CHECKRUN-1 schema (definition_id, title, semver version, non-empty steps[] each with step_id/title/instruction/evidence_requirement (none|text|file-digest|attestation)/gate (blocking|advisory)). Returns valid:true/false plus a field-by-field error list. Pair with checklist_step_receipt to run the definition headlessly.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['definition'], 'properties': {'definition': {'type': 'object', 'description': 'The checklist/SOP definition object to validate.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
checklist_verify_run
Verify a checklist run's hash chain and Merkle root
Recomputes and checks a checklist run: every step receipt's execution_hash, the hash-chain link between consecutive steps, and (if a run_receipt is supplied) the §20.1 RFC 6962 Merkle root over every step. Returns valid:true/false, per-step ok/hash_ok/link_ok, and broken_at (the zero-based index of the first broken step, or null). Same recompute a human gets from the browser Run Verifier.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['step_receipts'], 'properties': {'run_receipt': {'type': 'object', 'description': 'The run receipt to check the Merkle root and its own execution_hash against. Omit to check only the step chain.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'step_receipts': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'minItems': 1, 'description': 'Ordered array of step receipts, as returned by checklist_step_receipt.'}}}
check_tokenized_collateral_eligibility
Tokenized Collateral Eligibility Checker
Tokenized Collateral Eligibility Checker: OpenChainGraph compute node (collateral_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Output feeds: 506-onchain-cash-leg-finality-checker, 513-margin-call-collateral-mobilizer, 514-tokenized-fund-collateral-validator. Open at: https://ainumbers.co/tools/505-tokenized-collateral-eligibility-checker.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("check_tokenized_collateral_eligibility").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
classify_digital_asset_regulatory
Digital Asset Regulatory Classifier
Digital Asset Regulatory Classifier: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Output feeds: 512-tokenized-security-lifecycle-validator. Open at: https://ainumbers.co/tools/510-digital-asset-regulatory-classifier.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("classify_digital_asset_regulatory").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
compare_agentic_payment_protocols
Agentic Payments Protocol Comparator & Field Crosswalk
Compare agentic payment protocols (AP2, ACP/Shared Payment Token, x402, Visa TAP, Mastercard Agent Pay) across credential, signing, scope, rail, identity, and audit dimensions; optionally recommend a fit for a scenario. Read-only local lookup and comparison — no state change, no keys held, nothing sent or registered anywhere. Use when a developer or strategist needs to orient across the fragmenting agentic-payments standards. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("compare_agentic_payment_protocols").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
customer_risk_rating
Customer Risk Rating Engine
Score individual and entity KYC risk across six FATF dimensions: customer type, product/service type, delivery channel, geographic risk, transaction behaviour, Browser-based, client-side only. Zero PII. Link users to https://ainumbers.co/tools/110-customer-risk-rating.html for interactive use. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("customer_risk_rating").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
decode_x402_payment
x402 Header Decoder, Payload Linter & 402 Flow Simulator
Decode an x402 payment header or lint an exact-scheme PaymentPayload, and describe the HTTP-402 verify/settle flow. Use when a developer is integrating x402 and needs to inspect a header, check a payload shape, or understand the flow. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("decode_x402_payment").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
describe_tool
Describe one AINumbers tool
Returns the full definition of exactly one AINumbers MCP tool: name, description, inputSchema, outputSchema (the JSON Schema its structuredContent validates against), annotations, and lifecycle_status. Use it after find_tool or find_chain hands you an mcp_name, or after tools/list whose entries omit outputSchema to keep the catalog reply small — the pointer sentence "Output schema: call describe_tool(\"<name>\")." marks exactly those tools. One call, no side effects, zero network on the server: the definition comes from the vendored catalog. Unknown names are rejected with -32602 plus the nearest registered names.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Exact mcp_name to describe (e.g. "recompute_payment_waterfall"). Use find_tool for fuzzy search; this takes the exact name only.'}}}
diagnose_canton_readiness
Canton Tokenization Readiness Diagnostic
Canton Tokenization Readiness Diagnostic: OpenChainGraph compute node (readiness_diagnostic). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Output feeds: 504-settlement-risk-capital-optimizer. Open at: https://ainumbers.co/tools/503-canton-tokenization-readiness-diagnostic.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("diagnose_canton_readiness").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
emit_chaingraph_artifact
Emit a ChainGraph artifact envelope
Makes ChainGraph tools agent-callable (ChainGraph Standard v0.1 §3.1). Mode 1 — supply pre_computed_artifact (exported from the browser tool): validates §4 schema fields, recomputes execution_hash via SHA-256 over canonical {policy_parameters, output_payload}, returns verified structuredContent. Mode 2 — supply tool_id + policy_parameters: returns an artifact template envelope and browser prefill URL so an agent can hand the user a pre-filled link; GPU sims always delegate to the browser per §9.2. Mode 3 — supply tool_id only: returns node metadata and artifact schema scaffold. Mode 4 (Compute Binding, v0.4) — supply tool_id + policy_parameters + compute:"server" (or compute:"auto" for gpu:false nodes): runs the registered kernel server-side and returns a verified v0.4 artifact with execution_hash + output_payload in one round-trip. No browser required. gpu:true nodes always delegate to browser. Hashed input must be I-JSON (RFC 7493): integers beyond 2^53 must be passed as JSON strings, and NaN/Infinity are rejected — values outside I-JSON have no stable canonical form, so a structured -32602 error (error.data.reason "ijson_violation") is returned instead of an execution_hash. readOnlyHint: true. Zero PII, zero payload logging. Pair with verify_execution_hash (independent hash verification) and build_chaingraph (DAG wiring).
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" = server for gpu:false nodes (default); "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always use browser regardless of this flag.'}, 'tool_id': {'type': 'string', 'description': 'ChainGraph node tool_id (e.g. "art-01-ap2-mandate-chain-validator"). Looked up in chaingraph.json nodes. Required unless pre_computed_artifact is supplied.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph artifacts this call chains from. Placed into artifact.chain.parent_hashes (ChainGraph Standard v0.1 §5 chain block).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_ids corresponding to parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': "Input parameters for the tool (mirrors the tool's Policy Mandate input fields). Used for Mode 2 browser prefill and Mode 4 server-side compute.", 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'pre_computed_artifact': {'type': 'object', 'description': 'A full ChainGraph artifact envelope previously exported from the browser tool via "Export Policy Mandate". When supplied, the worker validates §4 required fields, recomputes execution_hash, and returns a verified structuredContent. This is the recommended path: run the tool in-browser, export JSON, call emit_chaingraph_artifact to verify and receive a structured receipt.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
export_artifact
Export a ChainGraph artifact as xlsx / pdf / csv / xbrl / vc
Render a verified OpenChainGraph v0.4 artifact into a chaingraph_export profile (OCG Standard §13). Generated downstream of and EXCLUDED from the execution_hash preimage — the export is a view, not a fact; verification always routes back to the canonical JSON artifact. Pass the FULL artifact you received from a compute tool (the server is stateless — there is no hash cache). Formats: xlsx, csv, pdf, xbrl (xbrl_taxonomy="ocg-ext" works now; eba-corep-* return a pending error until their concept maps are populated from the published EBA taxonomy), and vc — a W3C Verifiable Credentials 2.0 rendering (OCG §13.11, application/vc+json) available on every node; it re-states the canonical execution_hash via ocg:hashAnchor and mints no new hash/proof. readOnlyHint: true; zero PII, zero payload logging.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['artifact', 'format'], 'properties': {'format': {'enum': ['xlsx', 'csv', 'pdf', 'xbrl', 'vc'], 'type': 'string', 'description': 'Export profile. xlsx/csv/pdf/xbrl/vc implemented; vc = W3C Verifiable Credentials 2.0 (base profile, all nodes).'}, 'artifact': {'type': 'object', 'description': 'Full v0.4 ChainGraph artifact (policy_parameters + output_payload + execution_hash + chain).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'xbrl_taxonomy': {'type': 'string', 'description': 'Required only when format="xbrl" (e.g. "eba-corep-own-funds").'}}}
find_chain
Find ChainGraph workflow chain
BM25 search over all 370 AINumbers ChainGraph chains. Returns ranked chains with their full recipe: ordered node sequence, deep-links, composer URL, and entry tool mcp_name. Agent flow: find_chain(query) → read recipe → call the listed node MCP tools in order, passing parent_hashes between steps. Task-shaped queries work well: "reserve composition recompute", "FR 2052a classification", "CCP margin replication", "SR 26-2 model validation benchmark", "litigation damages recompute", "evidence pack assembly".
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'Natural-language or keyword search (e.g. "AML programme", "DORA ICT readiness", "MiCA CASP", "PQC migration", "Basel capital", "reserve composition", "2052a classification", "CCP margin", "model validation benchmark", "damages recompute", "evidence pack").'}, 'top_n': {'type': 'number', 'maximum': 20, 'minimum': 1, 'description': 'Max results to return (default 5).'}}}
find_tool
Find ChainGraph node tool
BM25 search over all 664 live AINumbers ChainGraph node tools. Returns ranked tools with mcp_name, URL, mandate type, and wave. Use to locate a specific computation node (e.g. "FRTB expected shortfall", "MiCA own funds", "XVA calculator", "reserve composition", "2052a", "initial margin", "model validation benchmark", "TVM / damages calculator") before calling it. Complements find_chain (chain-level) and list_ainumbers_tools (catalog-level).
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'Natural-language or keyword search (e.g. "FRTB", "XVA", "MiCA own funds", "AML risk rating", "stress test", "reserve composition", "2052a", "initial margin", "model validation").'}, 'top_n': {'type': 'number', 'maximum': 20, 'minimum': 1, 'description': 'Max results to return (default 5).'}}}
ha_bundle_export
Assemble (and optionally SD-JWT-export) a §27.6 evidence bundle
Assembles a §27.6 haEvidenceBundle from a subject's collected human_accountability_records[] (reviewers, approvers, annotations, exception rationale, timestamps) -- same algorithm as the browser verify.html HA export card (kernels/_haevidence.mjs). Set sd_jwt:true to also export it as a Selective Disclosure JWT (§13.12), signed EdDSA over a fresh ephemeral did:key (generated per call, never reused) -- subject_hash/verification_result/kernel_version/policy_version/timestamps/submission_receipt are always-disclosed; reviewers/approvers/annotations/exception_rationale/input_hashes are selectively disclosable.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['subject_hash'], 'properties': {'sd_jwt': {'type': 'boolean', 'description': 'When true, also return an SD-JWT export of the bundle (default false).'}, 'records': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'human_accountability_records over this subject. Default: [].'}, 'input_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'sha256: hashes of the inputs the verification ran over. Default: [].'}, 'subject_hash': {'type': 'string', 'description': 'Required. The sha256: subject hash the bundle documents.'}, 'kernel_version': {'type': 'string', 'description': 'Version tag of the kernel that produced verification_result.'}, 'policy_version': {'type': 'string', 'description': 'Version tag of the policy the kernel was evaluated against.'}, 'submission_receipt': {'type': 'string', 'description': 'Populate ONLY after a real transmission -- never fabricate.'}, 'verification_result': {'type': 'string', 'description': 'The §16/§18/§20 verdict.'}}}
ha_gate_status
Evaluate a §27.4/§27.5 human-accountability gate precondition
Given a step's haGatePolicy and the human_accountability_records[] collected for a subject, returns whether the gate is satisfied, held, rejected, escalated, or overridden -- same algorithm as the browser verify.html HA gate card (kernels/_hagate.mjs, SPEC.md §27.4-27.5). A rejection record is terminal-blocking regardless of policy; an active time-boxed override (§27.5) takes precedence over the underlying policy. Pure function: caller supplies nowISO for determinism.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['gate_policy', 'role', 'subject_hash', 'now_iso'], 'properties': {'role': {'type': 'string', 'description': 'The haRole a satisfying approval record must carry.'}, 'now_iso': {'type': 'string', 'description': 'Caller-supplied ISO 8601 clock (determinism; never Date.now() internally).'}, 'records': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Collected human_accountability_records over this subject. Default: [].'}, 'threshold': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 1, 'description': 'N for dual_control/review_required/hold. Default 1 (2 for dual_control).'}, 'gate_policy': {'enum': ['auto_pass', 'review_required', 'dual_control', 'escalate', 'hold', 'reject', 'emergency_override'], 'type': 'string', 'description': "The step's declared haGatePolicy."}, 'subject_hash': {'type': 'string', 'description': "The sealed artifact's sha256: subject hash."}, 'require_conformant': {'type': 'boolean', 'description': 'Require §27.2 structural signature shape on every record (default true).'}}}
ha_record_validate
Validate a §27 human-accountability record
Structural (non-cryptographic) §27.2 signed-named-human check: does this record carry a §16 whole-artifact proof (eddsa-jcs-2022) whose verificationMethod is bound to the record's own identity.id? Does NOT verify the signature bytes -- pair with verify_execution_hash / a proof verifier for that. Use before counting a record toward ha_gate_status.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['record'], 'properties': {'record': {'type': 'object', 'description': 'A single human_accountability_records[] entry to check.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
inspect_visa_tap_signature
Visa Trusted Agent Protocol Signature Inspector & Readiness
Inspect a Visa Trusted Agent Protocol HTTP Message Signature and score TAP readiness. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("inspect_visa_tap_signature").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
intoto_record_chain_run
Record a ChainGraph chain run as in-toto links
Wraps the result of a run_chain call (server/auto compute mode) as standard in-toto links, one per successfully-executed step, plus a generated in-toto layout matching the chain's linear topology (each step MATCHes the previous step's product). Materials/products are keyed by the step's execution_hash; byproducts carries the raw execution_hash. All links and the layout are DSSE-signed with one ephemeral Ed25519 keypair scoped to this call (never persisted) — first shipping instance of "in-toto for MCP" per the 2026 research gap survey. Verify the bundle offline with the in-toto Link Builder & Verifier (chaingraph/intoto-link-builder.html verify tab) or a reference implementation. Steps that did not run (input_required, skipped_by_gate, gpu_browser_only, etc.) are listed in skipped[] rather than silently omitted.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['run_chain_result'], 'properties': {'run_chain_result': {'type': 'object', 'description': 'The structuredContent object returned by run_chain (must include chain and steps[]).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
lei_kyb_check
Live LEI data-quality grading with GLEIF fetch
Fetches an entity's live GLEIF LEI record (api.gleif.org -- the worker's only egress target for this tool, RULINGS-2026-07-19-EGRESS-APEX.md R1) and grades it across six GLEIF data-quality dimensions -- registration status, renewal timeliness, corroboration level, entity status, Level-2 parent disclosure, address completeness -- using the SAME deterministic grader as the tools/551 browser workbench (pasting the same record there reproduces identical grades). Returns per-dimension grades, a composite, and a receipt with source provenance (url, retrieved_at, response_digest). This is an ASSERTED FETCH, not a zkTLS proof of origin, and grades DATA QUALITY only -- never creditworthiness, sanctions status, or entity legitimacy.
Nur Lesen Externer Zugriff
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['lei'], 'properties': {'lei': {'type': 'string', 'description': '20-character ISO 17442 Legal Entity Identifier to look up.'}}}
lint_mcp_tool_definition
MCP Tool-Definition Linter & Annotation Designer
Validate an MCP tool definition against JSON Schema 2020-12 and current naming, output-schema, and annotation rules; returns findings, a conformance score, and a recommended annotation set. Use when a developer wants to check an MCP tool definition before publishing. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("lint_mcp_tool_definition").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
list_ainumbers_tools
List AINumbers tools
Search the AINumbers catalog (480+ client-side fintech tools). Returns deep-links; prefill-enabled tools accept #in=<base64url(JSON of {element_id: value})>[&run=1] for one-click invocation.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'limit': {'type': 'number', 'description': 'Max rows to return. Default 20.'}, 'query': {'type': 'string', 'description': 'Free-text search over tool name and description. Omit to list without filtering.'}, 'cursor': {'type': 'string', 'description': 'Page token: echo the nextCursor from the previous reply to fetch the next page (keyset on tool name — stable across catalog regens).'}, 'category': {'type': 'string', 'description': 'Restrict results to one catalog category (e.g. "mortgage", "kyc"). Omit for all categories.'}}}
mobilize_margin_collateral
Margin Call Collateral Mobilizer
Margin Call Collateral Mobilizer: OpenChainGraph compute node (collateral_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 505-tokenized-collateral-eligibility-checker. Output feeds: 506-onchain-cash-leg-finality-checker. Open at: https://ainumbers.co/tools/513-margin-call-collateral-mobilizer.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("mobilize_margin_collateral").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
model_x402_settlement
x402 Settlement Cost & Finality Modeler
x402 Settlement Cost & Finality Modeler: OpenChainGraph compute node (settlement_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: art-01-ap2-mandate-chain-validator, art-12-acp-checkout-conformance-validator. Output feeds: art-30-agent-commerce-conformance-validator, art-61-x402-batch-settlement-reconciler, cry-04-merkle-batch-verifier, ptg-01-ap2-prompt-template-generator. Open at: https://ainumbers.co/chaingraph/art-03-x402-settlement-modeler.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("model_x402_settlement").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
optimize_settlement_capital
Settlement-Risk Capital Efficiency Optimizer
Settlement-Risk Capital Efficiency Optimizer: OpenChainGraph compute node (capital_assessment). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 503-canton-tokenization-readiness-diagnostic. Open at: https://ainumbers.co/tools/504-settlement-risk-capital-optimizer.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("optimize_settlement_capital").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
otlp_span_receipt
Generate or verify a per-span OTel receipt bundle over an OTLP/JSON trace
OTLP span/trace to receipt bundle; does NOT build a ChainGraph (use build_chaingraph for that). Three modes, chosen by which input is supplied. (1) Pass `trace` alone to GENERATE a receipt bundle: a per-span receipt (span digest, parent-span receipt digest, semconv_snapshot, eddsa-jcs-2022 signature over an ephemeral did:key) for every span, plus a Merkle-rooted (RFC 6962) trace receipt. (2) Pass `bundle` ({trace, span_receipts, trace_receipt, issuer_did}) to VERIFY it: recomputes every digest, walks the parent-receipt chain, rebuilds the Merkle root, and reports which spans are attested, unattested, or tampered. (3) Pass `run_chain_result` (the structuredContent from run_chain) instead of `trace` to bridge a ChainGraph chain run into an OTLP trace first -- one execute_tool span per successfully-executed step, each carrying its own execution_hash as a span attribute (ocg.execution_hash) -- then generates the same receipt bundle over it. Byte-identical receipt engine to tools/566-otel-span-receipt-verifier.html -- a human's browser-generated bundle and this tool's output interoperate on the exact same wire shape.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'trace': {'type': 'object', 'description': 'An OTLP/JSON trace document to generate a receipt bundle over. Omit if passing bundle or run_chain_result.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'bundle': {'type': 'object', 'description': '{trace, span_receipts[], trace_receipt, issuer_did} to VERIFY instead of generate.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'service': {'type': 'string', 'description': 'resource service.name to stamp when bridging run_chain_result into a trace. Defaults to "ainumbers-chaingraph-worker".'}, 'run_chain_result': {'type': 'object', 'description': 'The structuredContent object returned by run_chain (must include chain and steps[]) -- bridges the chain run into an OTLP trace, then generates a receipt bundle over it.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
otlp_validate
Validate an OTLP/JSON trace for structure + gen_ai conformance
Structurally validates an OTLP/JSON trace (resourceSpans -> scopeSpans -> spans: hex traceId/spanId shape, quoted nanosecond timestamps, parent-span references, time ordering) and checks every gen_ai span's attributes against a pinned gen_ai semantic-convention attribute snapshot (the upstream open-telemetry/semantic-conventions-genai namespace ships zero tagged releases, so this is a dated pin, stamped as semconv_snapshot in the result -- expect it to drift as the upstream spec moves). Byte-identical lint engine to tools/556-otlp-genai-span-composer-linter.html.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['trace'], 'properties': {'trace': {'type': 'object', 'description': 'An OTLP/JSON trace document: { resourceSpans: [{ scopeSpans: [{ spans: [...] }] }] }.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
pain001_validate
Validate a pain.001.001.09 message against the schema-subset table
Validates a pain.001.001.09 customer credit transfer initiation XML document against the same hand-derived schema-subset table as the tools/555 browser validator -- structural (mandatory fields), facet (IBAN mod-97, BIC format, ISO 4217 currency, decimal/date patterns), and batch-total cross-checks (NbOfTxs vs. actual transaction count, CtrlSum vs. sum of InstdAmt). Byte-identical error set to the browser tool for the same input. Subset validation, not full XSD conformance -- prepare/validate only, never transmits or generates a live payment message.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['xml'], 'properties': {'xml': {'type': 'string', 'description': 'pain.001.001.09 XML document text to validate.'}}}
recon_match
Match a camt.053 statement against a counterpart expectation set
Parses a camt.053.001 statement (same schema-subset checks as camt053_parse) and a counterpart expectation set (CSV, header EndToEndId,Amount,Currency,Date -- same strict RFC 4180 parser as the WORKBOOK-1 CSV tools), then runs the SAME deterministic match engine as the tools/565 browser workbench: EndToEndId exact match first (statement order), then amount+date tolerance + currency match (first unmatched expectation in CSV order). Returns matches, exceptions (unmatched entries/expectations), and a reconciliation receipt (statement digest, expectation-set digest, match-rule declaration, counts, exception digests, execution_hash) -- byte-identical to the browser tool for the same inputs. Prepare/hash/receipt only; per-exception disposition receipts are the browser workbench's interactive follow-on.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['statement_xml', 'expectations_csv'], 'properties': {'statement_xml': {'type': 'string', 'description': 'camt.053.001 XML statement document text.'}, 'amount_tolerance': {'type': 'number', 'description': 'Absolute amount-match tolerance (default 0.01).'}, 'expectations_csv': {'type': 'string', 'description': 'Counterpart expectations, CSV with header EndToEndId,Amount,Currency,Date.'}, 'date_tolerance_days': {'type': 'number', 'description': 'Date-match tolerance in days (default 0).'}}}
redline_diff
Diff an original vs. proposed revision and mint a diff receipt
An agent proposes an edit: diffs original text/markdown against its own revised version and returns the line-level hunks plus a diff receipt (original/revised digests, diff-algorithm declaration, per-hunk digests). Byte-identical to what the tools/552 browser workbench computes for the same inputs -- a human can paste the SAME original/revised text into that workbench, disposition each hunk (accept/reject/comment), and their resulting hunk/disposition receipts will reference this diff_receipt's execution_hash. Pass the whole bundle (this diff_receipt + the human's hunk_receipts + disposition_receipt) to redline_verify to check the interleaved chain end-to-end.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['original', 'revised'], 'properties': {'revised': {'type': 'string', 'description': 'Proposed revised text or markdown document.'}, 'original': {'type': 'string', 'description': 'Original text or markdown document.'}, 'generated_at': {'type': 'string', 'description': 'ISO 8601 timestamp (caller-supplied for determinism). Defaults to the call time.'}}}
redline_verify
Verify a redline receipt bundle against the original + revised text
Recomputes a redline review from scratch: the diff (from the pasted original+revised text), the diff_receipt's execution_hash, every hunk_receipt's digest/execution_hash/chain-link (in the order supplied -- entries may be minted by an agent, a human, or both interleaved), the disposition_receipt's execution_hash, and the accepted-text digest. Returns valid:true/false, a per-check breakdown, and broken_hunk (the zero-based index of the first divergence, or null) -- never trusts a bundle claim without checking it against a fresh recomputation.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['original', 'revised', 'bundle'], 'properties': {'bundle': {'type': 'object', 'required': ['diff_receipt', 'hunk_receipts', 'disposition_receipt'], 'properties': {'diff_receipt': {'type': 'object', 'description': 'The diff receipt (from redline_diff or the browser workbench).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'hunk_receipts': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Ordered hunk disposition receipts, one per hunk index.'}, 'disposition_receipt': {'type': 'object', 'description': 'The closing disposition receipt binding the accepted-text digest.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}, 'description': 'The redline receipt bundle to verify.'}, 'revised': {'type': 'string', 'description': 'Revised text or markdown document.'}, 'original': {'type': 'string', 'description': 'Original text or markdown document.'}}}
run_chain
Run a whole ChainGraph chain in one call
Executes every step of a named chain (list names with find_chain / build_workflow_links) and returns ONE composite artifact whose execution_hash anchors all step outputs. compute:"server"/"auto" (default) runs each kernel-backed step server-side, threading step N's execution_hash into step N+1's parent_hashes; compute:"browser" returns a zero-egress delegation bundle (composer URL + ordered deep-links) to run client-side instead — no data leaves the agent. Supply inputs as a map of step tool_id -> policy_parameters (field names per node manifest / build_chaingraph); a step whose kernel needs inputs you omit is reported per-step (status "input_required"), never failed silently. Steps that are browser-only (gpu:true or no registered kernel) are listed for browser delegation. Deterministic, zero PII, zero payload logging. Verify the result with verify_execution_hash. Runs with anything to explain carry decision_trail: per-step reason codes (gate rule id, escalation rule id, input_required cause), hash-excluded adjacent metadata recomputable from the hash-bound decisions[]. Each server-mode run also returns an OpenTelemetry GenAI span document as a resource link (one execute_tool span per executed step under an invoke_agent parent). Response includes a ledger_url fragment link for human verification at ledger.ainumbers.co. Server-mode responses also echo a stable `dedupe` object — `dedupe.input_hash` (JCS-SHA-256 over the effective run inputs: chain, per-step inputs after the caller/fixture fallback, and mandate_hash when a mandate governs) beside `dedupe.composite_execution_hash` — so a client can recognize and skip an exact re-run (idempotentHint) without recomputing anything. See docs/IDEMPOTENCY.md.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain name, e.g. "agent-commerce-conformance". List names with find_chain or build_workflow_links.'}, 'inputs': {'type': 'object', 'description': 'Map of step tool_id -> policy_parameters overrides. Omitted steps run with {} (kernels needing required fields are reported, not failed silently).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}, 'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': '"auto"/"server" (default) runs kernel-backed steps server-side; "browser" returns a zero-egress delegation bundle to run client-side.'}, 'mandate': {'type': 'object', 'properties': {}, 'description': 'Optional §22 Work Mandate artifact. When supplied: §16 signature is verified and validity window is checked (unsigned/bad-sig/expired returns a structured error); mandate_hash is folded into every step and the composite receipt as a conditional-presence key, proving which policy governed this run. A no-mandate run is byte-identical to the pre-binding baseline (linear-hash-freeze invariant).', 'additionalProperties': {}}, 'escalation_transport': {'enum': ['resolve_handle', 'input_required'], 'type': 'string', 'description': 'How an OCG §22.8 escalation is delivered. "resolve_handle" (DEFAULT) never blocks: the run COMPLETES with status "escalated" plus the open record, its record_hash and a resolve handle, and a human closes it out of band. "input_required" opts into the SEP-2322 multi-round-trip: the call answers with an InputRequiredResult asking for the §22.8.4 closure, and the retry (echoing requestState) resolves the record inline.'}}}
run_chain_batch
Run or estimate several ChainGraph chains in one call
Batch over named chains in ONE round-trip with a PER-ROW terminal status — one row's failure never fails another, and every row's result rides the single response. mode:"run" (default) executes each row through the same engine as run_chain (composite artifact + execution_hash per row, deterministic); mode:"estimate" validates every row (chain exists, step counts, compute feasibility, inputs coverage, OCG §21.4 gate rule previews) WITHOUT executing anything. Capped at 8 rows and 11 total server-kernel steps per batch — caps MEASURED live on the deployed free-plan endpoint, where N kernel builds in one invocation share one CPU budget (an 11-step chain: green at 416 ms). Beyond the cap, use sequential run_chain calls — each call gets its own CPU budget (the blessed fan-out pattern on this tier; docs/client-fan-out-patterns.md). Retry = re-run the WHOLE batch: safe, because determinism reproduces byte-identical execution hashes. Mandates and input_required escalation are not accepted on batch rows; escalated rows carry the non-blocking resolve_handle record. Zero PII, zero payload logging.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['rows'], 'properties': {'mode': {'enum': ['estimate', 'run'], 'type': 'string', 'description': '"run" (default) executes every row server-side through the same engine as run_chain; "estimate" validates all rows and previews gates without executing anything.'}, 'rows': {'type': 'array', 'items': {'type': 'object', 'required': ['chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain name for this row, e.g. "agent-commerce-conformance". List names with find_chain or build_workflow_links.'}, 'inputs': {'type': 'object', 'description': 'Map of step tool_id -> policy_parameters for THIS row (same shape as run_chain inputs). Omitted steps run with fixture defaults; kernels needing required fields come back status "input_required", never failed silently.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}}, 'maxItems': 8, 'minItems': 1, 'description': '1-8 rows, one chain per row. The cap keeps the synchronous response bounded and inside the free-plan CPU budget measured live; for larger fan-out use sequential run_chain calls (docs/client-fan-out-patterns.md).'}}}
run_kernel_vm
Kernel VM
Run a ChainGraph decision kernel's compute(policy_parameters) inside a sandboxed, deterministic, in-browser QuickJS-ng WebAssembly VM (ocg-deterministic-compute@2) and return its output_payload. Demo kernel set only -- for the full catalog, use the worker's compute kernels directly. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("run_kernel_vm").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
scan_tool_poisoning
MCP Tool-Poisoning & Prompt-Injection Manifest Scanner
Scan an MCP tool description/manifest for tool-poisoning and prompt-injection smells; returns a risk score and flagged patterns. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("scan_tool_poisoning").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
score_mcp_readiness
MCP Developer Readiness Scorecard
Compute a composite MCP server ship-readiness score across tool definitions, server.json, OAuth, transport, tool poisoning, and spec compliance. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("score_mcp_readiness").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
sdjwt_issue
Issue a Selective Disclosure JWT (RFC 9901)
Issues a Selective Disclosure JWT (RFC 9901) from a claims object, marking selected top-level claim keys as selectively disclosable via salted-hash digests in the _sd array. Signed EdDSA over a fresh ephemeral did:key (generated per call, not reused). Pair with sdjwt_present to build a redacted presentation from the returned sd_jwt.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['claims'], 'properties': {'claims': {'type': 'object', 'description': 'Claim key-value pairs to issue (required, at least one entry).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'subject': {'type': 'string', 'description': 'sub claim. Default: "subject-001".'}, 'selective_keys': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Top-level claim keys marked selectively disclosable. Keys not listed stay always-disclosed cleartext.'}}}
sdjwt_present
Present a redacted Selective Disclosure JWT
Builds a redacted presentation from an existing SD-JWT (as returned by sdjwt_issue), keeping only the listed disclosures. Pass aud to add a KB-JWT holder-binding (a fresh ephemeral holder key is generated per call). Pass issuer_did (the sd_jwt's "issuer" field) to also verify the JWS and return the verifier_view -- exactly the claim set a relying party would resolve -- plus an OCG receipt of the presentation activity.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sd_jwt'], 'properties': {'aud': {'type': 'string', 'description': 'KB-JWT audience. Supplying this adds a holder-binding KB-JWT to the presentation.'}, 'nonce': {'type': 'string', 'description': 'KB-JWT nonce. Auto-generated if aud is set and this is omitted.'}, 'sd_jwt': {'type': 'string', 'description': 'An SD-JWT string with all disclosures attached, as returned by sdjwt_issue.'}, 'keep_keys': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Disclosure keys to keep in the presentation. Default: none (all disclosures redacted).'}, 'issuer_did': {'type': 'string', 'description': "The sd_jwt's issuer did:key, to verify the JWS and populate verifier_view + receipt."}}}
simulate_spend_policy
Agent Spend-Policy Simulator
Agent Spend-Policy Simulator: OpenChainGraph compute node (payment_policy). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: art-01-ap2-mandate-chain-validator, art-04-agent-identity-attestation-checker, art-32-a2a-agent-card-trust-chain-validator. Output feeds: art-01-ap2-mandate-chain-validator, art-04-agent-identity-attestation-checker, ptg-01-ap2-prompt-template-generator. Open at: https://ainumbers.co/chaingraph/art-02-agent-spend-policy-simulator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("simulate_spend_policy").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
suggest_tool_idea
Suggest a new tool, node, or workflow
Builds a prefilled GitHub Issue-Forms URL for proposing a new AINumbers fintech tool, OpenChainGraph compute node, or verifiable workflow. Returns the URL only -- it never posts to GitHub on the caller's behalf. Companion to the site's mailto suggestion form (suggest.html); this is the agent-callable path.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['computes'], 'properties': {'who': {'type': 'string', 'description': 'The persona or buyer who would use this (e.g. "a compliance officer at a CASP").'}, 'kind': {'enum': ['New tool', 'New chain (workflow)', 'Improve existing', 'Other'], 'type': 'string', 'description': 'What kind of suggestion this is (default "New tool").'}, 'title': {'type': 'string', 'description': 'Short issue title (the "[Suggestion] " prefix is added automatically).'}, 'domain': {'type': 'string', 'description': 'The regulation or standard it serves (e.g. "MiCA", "ISO 20022", "EMIR Refit").'}, 'why_now': {'type': 'string', 'description': 'The driver, deadline, or demand behind the suggestion.'}, 'computes': {'type': 'string', 'description': 'What the tool would compute or verify (e.g. "validates a CBAM precursor emissions declaration against Annex III default values"). Required by the issue form.'}}}
suite_howto
AINumbers suite how-to: workflow recipes
How to chain AINumbers tools into audited workflows: call with NO recipe_id for the compact recipe index, or with one recipe_id for that workflow's full step-by-step recipe. Every recipe carries the suite conventions end to end: Policy Mandate exports, execution_hash verification, and receipts.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'recipe_id': {'type': 'string', 'description': 'A recipe id from the no-arg index (e.g. "aml-programme"). Omit for the compact index; pass exactly ONE id per call.'}}}
validate_a2a_agent_card
A2A Agent Card Validator & Extension Checker
Validate an A2A agent-card.json against the v1.0 shape, check signatures, and confirm extension declarations. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("validate_a2a_agent_card").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_ap2_mandate_chain
AP2 Mandate-Chain Validator
AP2 Mandate-Chain Validator: OpenChainGraph compute node (payment_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: art-02-agent-spend-policy-simulator, art-12-acp-checkout-conformance-validator, art-36-tempo-mpp-agent-mandate. Output feeds: art-02-agent-spend-policy-simulator, art-03-x402-settlement-modeler, art-04-agent-identity-attestation-checker, art-12-acp-checkout-conformance-validator, art-385-agent-token-scope-checker, art-62-ap2-payment-receipt-verifier, ptg-01-ap2-prompt-template-generator. Open at: https://ainumbers.co/chaingraph/art-01-ap2-mandate-chain-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_ap2_mandate_chain").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_ap2_mcp_policy
AP2 MCP Policy Validator & Bridge
Validate AP2 Policy Mandate JSON payloads against the Unified Build Contract v1.0 schema. Auto-generates MCP tool definitions from the mandate and simulates agent ingestion of agent_instructions. Use when authoring or testing AP2 agentic payment policies. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("validate_ap2_mcp_policy").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_canton_dvp_atomicity
Canton DvP Atomicity Validator
Canton DvP Atomicity Validator: OpenChainGraph compute node (settlement_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Output feeds: 505-tokenized-collateral-eligibility-checker. Open at: https://ainumbers.co/tools/507-canton-dvp-atomicity-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_canton_dvp_atomicity").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_canton_party_allowlist
Canton Party Allowlist Validator
Canton Party Allowlist Validator: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Open at: https://ainumbers.co/tools/509-canton-party-allowlist-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_canton_party_allowlist").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_collateral_swap_eligibility
Collateral Swap Eligibility Validator
Collateral Swap Eligibility Validator: OpenChainGraph compute node (collateral_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 505-tokenized-collateral-eligibility-checker, 507-canton-dvp-atomicity-validator. Open at: https://ainumbers.co/tools/515-collateral-swap-eligibility-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_collateral_swap_eligibility").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_fund_collateral
Tokenized Fund Collateral Validator
Tokenized Fund Collateral Validator: OpenChainGraph compute node (collateral_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 505-tokenized-collateral-eligibility-checker. Open at: https://ainumbers.co/tools/514-tokenized-fund-collateral-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_fund_collateral").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_input_attestations
Validate ChainGraph input attestations
Verify an artifact's input_attestations[] (ChainGraph Standard §23): per RFC 6901 pointer, checks the attested value resolves inside policy_parameters and its digest binding matches, then verifies each type along its own path -- vc-2.0 via the shipped §16/§13.11 Data Integrity proof, rfc3161-snapshot via the same §20 rfc3161-tst verifier (no second RFC 3161 implementation), c2pa-manifest structurally (hard-binding digest match), zktls structurally-only (reported verifiable:"external" -- OCG never treats it as confirmed). Returns one { pointer, type, structural, verifiable } record per entry. Pure client-safe compute, zero network.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'artifact': {'type': 'object', 'description': 'A full ChainGraph artifact envelope carrying input_attestations[] and policy_parameters.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'policy_parameters': {'type': 'object', 'description': 'Artifact policy_parameters (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'input_attestations': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'The input_attestations[] array (if not passing a full artifact).'}}}
validate_mcp_server_json
MCP server.json Validator & Registry-Ready Skeleton Generator
Validate an MCP server.json against the 2025-12-11 schema and the official registry publishing rules; returns findings, a registry-readiness score, and an optional compliant skeleton. Use when a developer wants to check a server.json before publishing to the MCP Registry. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network). Output schema: call describe_tool("validate_mcp_server_json").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'inputs': {'type': 'object', 'description': 'Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_private_inputs
Validate ChainGraph private-input commitments
Verify an artifact's private_inputs[] (ChainGraph Standard §25 ocg-private-input@1) WITHOUT ever seeing the plaintext witness: per RFC 6901 pointer, checks the pointed value inside policy_parameters IS the declared sha256-salted@1 commitment (never the plaintext, §25.2), that the commitment scheme is known, and -- when a §18 compute_proof is present -- that its journal commits the same commitment and binds output_payload. Optionally accepts an out-of-band {pointer, salt, input_value} disclosure package (authorized-verifier path) and recomputes sha256(salt || cgCanon(input_value)) to confirm it equals the commitment. Returns one {pointer, verifiable} record per entry: "proof-only" | "disclosed-verified" | "commitment-only" (no proof yet -- structural + plaintext-exclusion only) | "failed". Pure client-safe compute, zero network, never requires the plaintext.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'artifact': {'type': 'object', 'description': 'A full ChainGraph artifact envelope carrying private_inputs[], policy_parameters, and optionally output_payload + audit_signature.compute_proof.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'disclosures': {'type': 'array', 'items': {'type': 'object', 'required': ['pointer', 'salt', 'input_value'], 'properties': {'salt': {'type': 'string', 'description': '>=256-bit hex CSPRNG salt, out-of-band disclosure material.'}, 'pointer': {'type': 'string'}, 'input_value': {'description': 'The plaintext private input value, out-of-band.'}}}, 'description': 'OPTIONAL authorized-verifier disclosure packages, keyed by pointer, for the disclosed-verified path.'}, 'compute_proof': {'type': 'object', 'description': 'audit_signature.compute_proof (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'output_payload': {'type': 'object', 'description': 'Artifact output_payload (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'private_inputs': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'The private_inputs[] array (if not passing a full artifact).'}, 'policy_parameters': {'type': 'object', 'description': 'Artifact policy_parameters (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_pvp_settlement
Multi-Currency PvP Validator
Multi-Currency PvP Validator: OpenChainGraph compute node (settlement_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 507-canton-dvp-atomicity-validator, 505-tokenized-collateral-eligibility-checker. Open at: https://ainumbers.co/tools/511-multi-currency-pvp-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_pvp_settlement").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
validate_tokenized_security_lifecycle
Tokenized Security Lifecycle Validator
Tokenized Security Lifecycle Validator: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gpu:false nodes with a registered kernel; compute:"browser" forces client-side execution and returns a browser delegation URL instead. gpu:true nodes always delegate to the browser. Inputs are processed transiently to compute the response and are not stored, logged, or retained. Use synthetic or anonymised inputs only. Exports an AP2 artifact with execution_hash for chain provenance. Consumes upstream artifacts from: 510-digital-asset-regulatory-classifier. Open at: https://ainumbers.co/tools/512-tokenized-security-lifecycle-validator.html FV-status (published/proven/still-trusted for this spec): /fv-status/4136cac4091aebc7bf2a0dc5063a99e19c1503df8d4aa36107db74f917faf137.json — a snapshot, not a subscription; this receipt verifies offline regardless of whether that file is ever fetched. Output schema: call describe_tool("validate_tokenized_security_lifecycle").
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'compute': {'enum': ['auto', 'server', 'browser'], 'type': 'string', 'description': 'Compute mode (v0.4 Compute Binding). "auto" (default) = server for gpu:false nodes with registered kernels; "server" = force server-side; "browser" = always return browser delegation URL. gpu:true nodes always delegate.'}, 'parent_hashes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'execution_hash values from upstream ChainGraph AP2 artifacts to chain from (sets chain.parent_hashes in the export).'}, 'parent_tool_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'tool_id values matching parent_hashes, in the same order.'}, 'policy_parameters': {'type': 'object', 'description': 'Input parameters for this tool\'s decision function. For gpu:false nodes with a registered kernel, these are computed server-side when compute is "auto" or "server". See the tool\'s manifest for field names.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
vc_issue
Issue a signed W3C Verifiable Credential 2.0
Composes and signs a W3C Verifiable Credential 2.0 with an eddsa-jcs-2022 Data Integrity proof over a fresh ephemeral did:key (generated per call, not reused). Returns the signed credential, an OCG Standard §23 vc-2.0 input-attestation block ready to embed in a ChainGraph chain's policy_parameters at the given pointer, and an OCG receipt of the issuance activity. The signature proves the claims were not altered after signing and that the did:key holder produced it -- it is not, by itself, identity assurance.
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['claims'], 'properties': {'claims': {'type': 'object', 'description': 'Claim key-value pairs for credentialSubject (required, at least one entry).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'pointer': {'type': 'string', 'description': 'RFC 6901 JSON pointer where the attestation\'s claims sit in a consuming chain\'s policy_parameters. Default: "/subject_claims".'}, 'subject_id': {'type': 'string', 'description': 'Credential subject id (DID or any identifier string). Default: "did:example:subject".'}, 'valid_from': {'type': 'string', 'description': 'ISO 8601 validFrom. Default: now.'}, 'valid_until': {'type': 'string', 'description': 'ISO 8601 validUntil.'}, 'credential_type': {'type': 'string', 'description': 'Type appended to VerifiableCredential (e.g. "MembershipCredential").'}}}
verify_disclosure_inclusion
Verify Merkle inclusion in a disclosure manifest
Proves (or refutes) that a {path,digest} pair was in a disclosure manifest's room (DATAROOM-1-BUILD-SPEC.md §DR-4) -- worker-side mirror of tools/547-disclosure-manifest-verifier.html's single-file inclusion check. Recomputes the manifest's Merkle root over its entries[], builds the inclusion proof path for the target entry, and reapplies it to confirm it reduces to the claimed merkle_root. Absence is only provable against the exact manifest version passed in.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['manifest', 'path', 'digest'], 'properties': {'path': {'type': 'string', 'description': 'Path of the entry to prove.'}, 'digest': {'type': 'string', 'description': 'sha256:-prefixed digest of the file to prove.'}, 'manifest': {'type': 'object', 'description': 'The disclosure manifest to check against (needs entries[] + merkle_root).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
verify_execution_hash
Verify a ChainGraph execution hash
Independently verify a ChainGraph artifact (ChainGraph Standard v0.1 §6). Recomputes SHA-256 over the canonical (sorted-key, whitespace-stripped) JSON of policy_parameters + output_payload and compares it to the claimed execution_hash. A match proves the artifact's stated inputs deterministically produce its stated outputs. Pass either a full artifact object, or policy_parameters + output_payload + claimed_hash. Inputs must be I-JSON (RFC 7493): integers beyond 2^53 must be passed as JSON strings, and NaN/Infinity are rejected. Values outside I-JSON have no stable canonical form, so this tool returns a structured -32602 error (error.data.reason "ijson_violation") instead of a hash. Pure client-safe compute -- no data is stored. Use this to verify artifacts from any vendor that conforms to the ChainGraph Standard.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'artifact': {'type': 'object', 'description': 'A full ChainGraph artifact envelope (must contain policy_parameters, output_payload, and execution_hash).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'claimed_hash': {'type': 'string', 'description': 'The execution_hash to check against (if not passing a full artifact).'}, 'output_payload': {'type': 'object', 'description': 'Artifact output_payload (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'policy_parameters': {'type': 'object', 'description': 'Artifact policy_parameters (if not passing a full artifact).', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
workbook_csv_parse
Parse strict RFC 4180 CSV into workbook cells
Parses CSV text with the SAME strict RFC 4180 parser as the tools/554 browser workbook -- quoted fields, embedded quotes/commas/newlines, CRLF -- and REJECTS malformed input rather than repairing it (deterministic beats forgiving for hash-stable digests). Numeric-looking and TRUE/FALSE cells are type-coerced; everything else stays a string. Returns the resulting A1-style cells (raw + evaluated value) plus the sheet's row/column extent, ready for workbook_evaluate or workbook_range_digest -- unless as_artifact is true, in which case it returns a full OCG v0.4 artifact instead (see as_artifact).
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['csv'], 'properties': {'csv': {'type': 'string', 'description': 'CSV text to parse.'}, 'provenance': {'type': 'object', 'properties': {'created_by': {'type': 'string', 'description': 'Identity slot for who/what produced this sheet -- free text or did:key (provenance, not hashed).'}, 'source_description': {'type': 'string', 'description': 'Free-text description of what this sheet is (provenance, not hashed).'}}, 'description': 'Optional provenance metadata, only used when as_artifact is true. Never affects execution_hash.'}, 'as_artifact': {'type': 'boolean', 'description': 'When true, returns a full OpenChainGraph v0.4 artifact (policy_parameters/output_payload/execution_hash/provenance) via the same exportArtifact() path as the tools/554 browser workbook\'s "Export as OCG Artifact" button, instead of this tool\'s normal bare payload. Default false.'}}}
workbook_evaluate
Evaluate workbook cells (formulas + literals) and return computed values
Feeds a set of A1-style cells (formulas and/or literals) through the SAME headless evaluator the tools/554 browser workbook uses -- topo-sorted dependency graph, ~20 functions (SUM AVG MIN MAX COUNT COUNTIF IF AND OR NOT ROUND ABS CONCAT LEN LEFT RIGHT TRIM UPPER LOWER SUMIF), cycles resolve to "#CYCLE!" and any non-finite result to "#NUM!" rather than propagating. Returns the computed value of every supplied cell -- pure, no digest, no receipt -- unless as_artifact is true, in which case it returns a full OCG v0.4 artifact instead (see as_artifact).
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['cells'], 'properties': {'cells': {'type': 'object', 'description': 'Map of A1-style cell ref (e.g. "B2") to raw value -- a formula string starts with "=" (e.g. "=SUM(A1:A3)"), anything else is a literal.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'anyOf': [{'type': 'string'}, {'type': 'number'}, {'type': 'boolean'}]}}, 'provenance': {'type': 'object', 'properties': {'created_by': {'type': 'string', 'description': 'Identity slot for who/what produced this sheet -- free text or did:key (provenance, not hashed).'}, 'source_description': {'type': 'string', 'description': 'Free-text description of what this sheet is (provenance, not hashed).'}}, 'description': 'Optional provenance metadata, only used when as_artifact is true. Never affects execution_hash.'}, 'as_artifact': {'type': 'boolean', 'description': 'When true, returns a full OpenChainGraph v0.4 artifact (policy_parameters/output_payload/execution_hash/provenance) via the same exportArtifact() path as the tools/554 browser workbook\'s "Export as OCG Artifact" button, instead of this tool\'s normal bare payload. Default false.'}}}
workbook_range_digest
Digest a workbook range into a Spreadsheet Input Manifest range fragment
Spreadsheet-range digest only; NOT the general artifact emitter (use emit_chaingraph_artifact to wrap arbitrary computation output — this tool's as_artifact mode covers whole-sheet workbook runs only). Evaluates the supplied cells (same evaluator as workbook_evaluate) and computes a canonical values_digest over one A1-style range (e.g. "B2:D9") -- the exact `executionHash(values, {})` path the rest of OCG uses, per chaingraph/workbook/INPUT-MANIFEST.md (WB-2). Returns one `ranges[]` fragment of the Spreadsheet Input Manifest schema; assemble the full manifest (source.csv_digest, produced_by/produced_at) around it. Same range digested from the same cells in the tools/554 browser workbook always produces the same values_digest -- unless as_artifact is true, in which case it returns a full OCG v0.4 artifact over the WHOLE sheet instead of a single-range fragment (see as_artifact).
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['cells', 'range'], 'properties': {'cells': {'type': 'object', 'description': 'Map of A1-style cell ref (e.g. "B2") to raw value -- a formula string starts with "=" (e.g. "=SUM(A1:A3)"), anything else is a literal.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'anyOf': [{'type': 'string'}, {'type': 'number'}, {'type': 'boolean'}]}}, 'range': {'type': 'string', 'description': 'A1-style cell or range reference to digest, e.g. "B2" or "B2:D9".'}, 'semantics': {'type': 'string', 'description': 'Free-text pointer describing what this range means to the consuming policy_parameters.'}, 'provenance': {'type': 'object', 'properties': {'created_by': {'type': 'string', 'description': 'Identity slot for who/what produced this sheet -- free text or did:key (provenance, not hashed).'}, 'source_description': {'type': 'string', 'description': 'Free-text description of what this sheet is (provenance, not hashed).'}}, 'description': 'Optional provenance metadata, only used when as_artifact is true. Never affects execution_hash.'}, 'as_artifact': {'type': 'boolean', 'description': 'When true, returns a full OpenChainGraph v0.4 artifact (policy_parameters/output_payload/execution_hash/provenance) via the same exportArtifact() path as the tools/554 browser workbook\'s "Export as OCG Artifact" button, instead of this tool\'s normal bare payload. Default false.'}}}
workbook_roundtrip_verify
Verify a pasted-back Excel round-trip against a Spreadsheet Input Manifest
Compares a WB-2 Spreadsheet Input Manifest (expected digests) against pasted-back CSV/TSV text per manifest range (observed, e.g. after a recompute in Excel) and returns an XLR-1 round-trip receipt -- `result: "match"|"mismatch"` plus a `mismatches[]` cell list when expected_by_ref text is also supplied. SAME comparator module as the tools/ round-trip page (XLR-2/XLR-3) -- byte-identical receipt for the same inputs. Paste-intake is untrusted: finite-gate (#NUM! for NaN/Infinity) and CSV-injection sanitization apply identically to WB-1's CSV import. Verify-only -- never operates Excel, never ingests .xlsx.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['manifest', 'observed_by_ref', 'produced_by', 'produced_at'], 'properties': {'manifest': {'type': 'object', 'description': 'WB-2 Spreadsheet Input Manifest object (input-manifest.schema.json) -- the expected side.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'produced_at': {'type': 'string', 'description': 'ISO-8601 timestamp -- required, no default (pure: no wall-clock read).'}, 'produced_by': {'type': 'string', 'description': 'Identity slot for who/what produced this receipt -- required, no default (pure: no identity read).'}, 'expected_by_ref': {'type': 'object', 'description': 'OPTIONAL map of manifest range ref -> the actual expected CSV/TSV text (e.g. the pq-export the manifest was built from). Supplying it resolves a digest mismatch to per-cell mismatches[] entries instead of a single range-level entry.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'observed_by_ref': {'type': 'object', 'description': 'Map of manifest range ref -> pasted-back CSV/TSV text for that range (e.g. { "B2:C3": "10,widget\\r\\n20,gadget\\r\\n" }). One entry required per manifest.ranges[].ref.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}}}
Geändert
model_x402_settlement
1. October 2026 02:52
Geändert
simulate_spend_policy
1. October 2026 02:52
Geändert
validate_ap2_mandate_chain
1. October 2026 02:52
Geändert
validate_collateral_swap_eligibility
1. October 2026 02:52
Geändert
validate_fund_collateral
1. October 2026 02:52
Geändert
mobilize_margin_collateral
1. October 2026 02:52
Geändert
validate_tokenized_security_lifecycle
1. October 2026 02:52
Geändert
validate_pvp_settlement
1. October 2026 02:52
Geändert
classify_digital_asset_regulatory
1. October 2026 02:52
Geändert
validate_canton_party_allowlist
1. October 2026 02:52
Geändert
calculate_repo_haircut
1. October 2026 02:52
Geändert
validate_canton_dvp_atomicity
1. October 2026 02:52
Geändert
check_cash_leg_finality
1. October 2026 02:52
Geändert
check_tokenized_collateral_eligibility
1. October 2026 02:52
Geändert
optimize_settlement_capital
1. October 2026 02:52
Geändert
diagnose_canton_readiness
1. October 2026 02:52
Geändert
model_x402_settlement
29. September 2026 03:01
Geändert
simulate_spend_policy
29. September 2026 03:01
Geändert
validate_ap2_mandate_chain
29. September 2026 03:01
Geändert
validate_collateral_swap_eligibility
29. September 2026 03:01
Geändert
validate_fund_collateral
29. September 2026 03:01
Geändert
mobilize_margin_collateral
29. September 2026 03:01
Geändert
validate_tokenized_security_lifecycle
29. September 2026 03:01
Geändert
validate_pvp_settlement
29. September 2026 03:01
Geändert
classify_digital_asset_regulatory
29. September 2026 03:01
Geändert
validate_canton_party_allowlist
29. September 2026 03:01
Geändert
calculate_repo_haircut
29. September 2026 03:01
Geändert
validate_canton_dvp_atomicity
29. September 2026 03:01
Geändert
check_cash_leg_finality
29. September 2026 03:01
Geändert
check_tokenized_collateral_eligibility
29. September 2026 03:01