MCPサーバー

ExitProof

com.davisvillelabs/exitproof

このMCPでできること

Evaluates purchase reversibility, preserves exit evidence, and inspects payment challenges before autonomous purchases.

build_exit_pack
Build exit pack
Build a bounded cancellation/refund action pack from an existing actionable Exit Manifest. Pass manifest_id and access_token together as the credential pair returned by create_exit_manifest or settlement recovery; use get_exit_manifest for retrieval only, or check_reversibility then create_exit_manifest when no manifest exists. This $1.00 MPP operation prefers Tempo stablecoin when available, retains Stripe card/link as a compatible fallback, and can charge but never contacts the merchant, executes a cancellation, files a chargeback, or guarantees success. Invalid or mismatched credentials and non-actionable manifests are rejected before payment; an identical settled retry with the same payment credential avoids a second settlement, while generatedAt and deadlineStatus can reflect the current time.
外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['manifest_id', 'access_token'], 'properties': {'manifest_id': {'type': 'string', 'pattern': '^xm_[a-f0-9]{32}$', 'description': 'Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters.'}, 'access_token': {'type': 'string', 'pattern': '^xp_[A-Za-z0-9_-]{20,}$', 'description': 'Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it.'}}, 'description': 'Credentials for one previously created Exit Manifest. Both values are required together and are returned by create_exit_manifest or settlement recovery.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['schemaVersion', 'manifestId', 'generatedAt', 'assessment', 'actionability', 'exitRoute', 'prerequisites', 'deadlineStatus', 'steps', 'suggestedRequest', 'evidenceChecklist', 'sources', 'limitations'], 'properties': {'steps': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Ordered bounded next steps for pursuing cancellation or refund.'}, 'sources': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Recorded source references supporting the action pack.'}, 'currency': {'type': 'string', 'description': 'Currency associated with recorded monetary values.'}, 'exitRoute': {'type': 'object', 'description': 'Recorded cancellation/refund route or cited-source route to follow.', 'additionalProperties': True}, 'assessment': {'type': 'string', 'description': 'Reversibility assessment preserved by the manifest.'}, 'manifestId': {'type': 'string', 'description': 'Manifest used to build this action pack.'}, 'generatedAt': {'type': 'string', 'description': 'Timestamp when the action pack was generated.'}, 'limitations': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Boundaries and caveats; ExitProof does not execute the exit or guarantee success.'}, 'actionability': {'type': 'object', 'description': 'Why the stored manifest is actionable and which exit route is established.', 'additionalProperties': True}, 'prerequisites': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Checks to complete before acting on the exit plan.'}, 'schemaVersion': {'const': 'exitproof-exit-pack.v1', 'description': 'Exit-pack response schema version.'}, 'deadlineStatus': {'enum': ['open', 'passed', 'not_established'], 'type': 'string', 'description': 'Current status of the recorded exit deadline at generation time.'}, 'reversibleUntil': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'description': 'Recorded exit deadline when established.'}, 'suggestedRequest': {'type': 'string', 'description': 'Suggested message the user or agent can adapt when requesting cancellation/refund.'}, 'evidenceChecklist': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Evidence to retain while pursuing the exit.'}, 'maximumStatedLossMinor': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'description': 'Maximum stated loss in minor currency units when established.'}, 'unresolvedLossExposure': {'type': 'boolean', 'description': 'True when the recorded evidence does not establish a complete maximum loss.'}}, 'description': 'Bounded action pack derived from an actionable Exit Manifest.', 'additionalProperties': True}
check_agent_purchase
Check agent purchase
Inspect one autonomous HTTP purchase before the calling agent pays it. This $0.01 machine-payment operation validates a real 402 challenge, compares advertised price/protocol/network/asset/payment destination when supplied, checks x402 v2 exact resource binding when available, and surfaces retry or settled-delivery recovery signals. ExitProof never forwards payment credentials and never sends a live POST, PUT, PATCH, or DELETE probe; for those methods the caller supplies an already-observed 402 challenge. Conflicting, malformed, inaccessible, non-402, or unsafe targets are rejected before ExitProof issues its own payment challenge. Use check_reversibility instead for cancellation/refund terms on a real-world commitment, create_exit_manifest to preserve an eligible exit path, and build_exit_pack when an exit is actually needed. A successful check is not a recommendation, merchant-identity guarantee, delivery guarantee, legal opinion, or authorization to spend.
外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['target_url'], 'properties': {'operation': {'type': 'string', 'maxLength': 160, 'description': 'Optional caller label for the target operation. This is descriptive only and is included in the check digest.'}, 'advertised': {'type': 'object', 'properties': {'asset': {'type': 'string', 'maxLength': 120, 'description': 'Advertised asset symbol or address.'}, 'pay_to': {'type': 'string', 'maxLength': 200, 'description': 'Advertised payment destination.'}, 'network': {'type': 'string', 'maxLength': 120, 'description': 'Advertised payment network, for example eip155:8453.'}, 'currency': {'type': 'string', 'description': 'Advertised currency or asset code.'}, 'protocol': {'enum': ['x402', 'mpp'], 'type': 'string', 'description': 'Advertised machine-payment protocol.'}, 'price_cents': {'type': 'integer', 'minimum': 1, 'description': 'Advertised price in whole USD cents.'}}, 'description': 'Optional payment facts advertised by discovery metadata. ExitProof compares these to the observed 402 challenge and rejects material conflicts before its own payment challenge.', 'additionalProperties': False}, 'live_probe': {'type': 'boolean', 'description': 'Whether ExitProof may make one anonymous, credential-free request to target_url. Defaults true for GET/HEAD and false for state-changing methods.'}, 'target_url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTPS endpoint the agent is considering paying. Credentials, localhost, private-address literals, and non-HTTPS URLs are rejected.'}, 'request_method': {'enum': ['GET', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string', 'default': 'GET', 'description': 'HTTP method of the contemplated purchase. Live probing is allowed only for GET or HEAD. For state-changing methods supply observed_response instead.'}, 'retry_contract': {'type': 'object', 'properties': {'source_url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTPS source supporting the retry/recovery claims.'}, 'idempotent_retry': {'type': 'boolean', 'description': 'Whether the target advertises safe idempotent retry semantics.'}, 'refund_or_reversal_url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTPS refund, reversal, or recovery documentation URL, when published.'}, 'settled_delivery_recovery': {'type': 'boolean', 'description': 'Whether the target advertises recovery after settlement if delivery fails without requiring a second payment.'}}, 'description': 'Optional retry, settled-delivery recovery, and refund/reversal facts advertised by the target. These remain caller-supplied unless independently verified elsewhere.', 'additionalProperties': False}, 'observed_response': {'type': 'object', 'required': ['http_status'], 'properties': {'http_status': {'type': 'integer', 'const': 402, 'description': 'HTTP 402 status from the target.'}, 'observed_at': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for when the caller observed this response.'}, 'payment_required': {'type': 'string', 'maxLength': 32768, 'description': 'PAYMENT-REQUIRED response header for x402 v2, when present.'}, 'www_authenticate': {'type': 'string', 'maxLength': 32768, 'description': 'WWW-Authenticate response header containing an MPP Payment challenge, when present.'}}, 'description': 'A 402 response already observed by the calling agent. Required when live_probe is false. Supply payment challenge headers only, never a payment credential.', 'additionalProperties': False}}, 'description': 'Pre-payment safety check for one autonomous HTTP purchase. ExitProof either performs a credential-free GET/HEAD probe or analyzes a 402 challenge already observed by the caller. It never forwards payment credentials or sends state-changing probe requests.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['schemaVersion', 'checkedAt', 'assessment', 'target', 'observedPayment', 'availablePaymentOffers', 'checks', 'reversibility', 'evidence', 'limitations', 'nextStep', 'checkDigest', 'receiptEnvelope'], 'properties': {'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'status', 'detail'], 'properties': {'id': {'type': 'string'}, 'detail': {'type': 'string'}, 'status': {'enum': ['pass', 'unknown']}}, 'additionalProperties': False}, 'description': 'Individual safety checks. Conflicts reject before payment and therefore never appear as a paid result.'}, 'target': {'type': 'object', 'description': 'Normalized target endpoint and contemplated method.', 'additionalProperties': True}, 'evidence': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Evidence provenance, including whether the 402 challenge was independently observed by ExitProof.'}, 'nextStep': {'type': 'object', 'description': 'Machine-readable status and bounded instruction for the calling agent.', 'additionalProperties': True}, 'checkedAt': {'type': 'string', 'format': 'date-time', 'description': 'Time the check result was produced.'}, 'advertised': {'anyOf': [{'type': 'object', 'additionalProperties': True}, {'type': 'null'}], 'description': 'Normalized caller-supplied advertised terms used for consistency checks.'}, 'assessment': {'enum': ['eligible_to_attempt', 'review_required'], 'type': 'string', 'description': 'Bounded pre-payment status. This is not a recommendation to buy.'}, 'checkDigest': {'type': 'string', 'pattern': '^[a-f0-9]{64}$', 'description': 'SHA-256 digest of the normalized target, payment facts, recovery facts, and evidence provenance.'}, 'limitations': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Boundaries on what the paid result establishes.'}, 'reversibility': {'type': 'object', 'description': 'Published retry, settled-delivery recovery, and reversal metadata supplied for this target.', 'additionalProperties': True}, 'schemaVersion': {'const': 'exitproof-agent-purchase-check.v1', 'description': 'Agent purchase check schema version.'}, 'observedPayment': {'type': 'object', 'description': 'Selected machine-payment offer normalized from the observed 402 challenge.', 'additionalProperties': True}, 'receiptEnvelope': {'$ref': 'https://davisvillelabs.com/agents/davisville-receipt-envelope.v1.schema.json', 'description': 'Additive Davisville Receipt Envelope v1. The native ExitProof purchase-check result remains authoritative.'}, 'availablePaymentOffers': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'All parseable x402 or MPP offers found in the observed response.'}}, 'description': 'Point-in-time pre-payment safety result. eligible_to_attempt means the observed payment requirements are internally consistent and a positive retry/recovery signal was supplied; review_required means no contradiction was found but one or more safety facts remain unknown.', 'additionalProperties': True}
check_reversibility
Check reversibility
Evaluate one commitment’s cancellation/refund reversibility from transaction-specific checkout terms plus maintained policy evidence, without charging or creating durable state. Use before a purchase, booking, subscription, rental, service, ticket, digital purchase, or deposit when exit deadlines or loss matter; use list_supported_policies only for maintained-overlay coverage, and create_exit_manifest only after paidExitManifestAvailable=true. Do not use for purchase desirability, legal advice, chargeback decisions, or executing a cancellation. Supply checkout_terms whenever available because they control the transaction-specific assessment; expected_commitment_at moves deadline evaluation forward when the commitment is future-dated, and missing or conflicting evidence can return assessment=unknown rather than inventing an exit right.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['merchant', 'commitment_type', 'amount'], 'properties': {'amount': {'type': 'number', 'minimum': 0, 'description': 'Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation.'}, 'region': {'type': 'string', 'maxLength': 80, 'description': 'Optional state, province, or region label when the commitment or merchant terms are region-specific.'}, 'country': {'type': 'string', 'pattern': '^[A-Za-z]{2}$', 'maxLength': 2, 'minLength': 2, 'description': 'Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters.'}, 'currency': {'type': 'string', 'default': 'USD', 'pattern': '^[A-Za-z]{3}$', 'maxLength': 3, 'minLength': 3, 'description': 'Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD.'}, 'merchant': {'type': 'string', 'maxLength': 160, 'minLength': 1, 'description': 'Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets.'}, 'event_type': {'enum': ['initial', 'renewal', 'purchase', 'reservation', 'deposit', 'other'], 'type': 'string', 'default': 'initial', 'description': 'Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment.'}, 'checkout_terms': {'type': 'object', 'properties': {'refundable': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the committed amount is refundable.'}, 'source_url': {'type': 'string', 'maxLength': 500, 'description': 'HTTP(S) source URL for the supplied transaction terms. ExitProof removes credentials, query parameters, and fragments before storing the URL.'}, 'auto_renews': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the commitment renews automatically.'}, 'cancellable': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the commitment can be canceled.'}, 'observed_at': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for when the caller observed these checkout terms.'}, 'charge_timing': {'type': 'string', 'maxLength': 160, 'description': 'When the merchant states the charge will occur, such as immediately, at check-in, or 24 hours before renewal.'}, 'renewal_interval': {'type': 'string', 'maxLength': 80, 'description': 'Human-readable renewal interval from the supplied terms, such as monthly or annually. Use only when auto-renewal terms are stated.'}, 'cancellation_method': {'type': 'string', 'maxLength': 240, 'description': 'Recorded method or path for cancellation/refund, such as an account page, support channel, or merchant instruction. This can make a later exit pack actionable.'}, 'nonrefundable_amount': {'type': 'number', 'minimum': 0, 'description': 'Amount explicitly stated as nonrefundable, in major units of currency.'}, 'cancellation_deadline': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for the stated cancellation deadline, even when cancellation may involve a loss.'}, 'free_cancellation_until': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 deadline with explicit timezone through which the supplied terms state cancellation is free.'}, 'cancellation_penalty_amount': {'type': 'number', 'minimum': 0, 'description': 'Stated cancellation penalty in major units of currency. Mutually exclusive with cancellation_penalty_percent.'}, 'cancellation_penalty_percent': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Stated cancellation penalty as a percentage from 0 to 100. Mutually exclusive with cancellation_penalty_amount.'}}, 'description': 'Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while maintained policy evidence remains contextual.', 'additionalProperties': False}, 'commitment_type': {'enum': ['subscription', 'reservation', 'ticket', 'service', 'software', 'digital_purchase', 'rental', 'deposit', 'other'], 'type': 'string', 'description': 'Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method.'}, 'client_reference': {'type': 'string', 'maxLength': 200, 'description': 'Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here.'}, 'purchase_channel': {'enum': ['direct', 'apple', 'google_play', 'marketplace', 'travel_agency', 'other', 'unknown'], 'type': 'string', 'default': 'unknown', 'description': 'Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself.'}, 'expected_commitment_at': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp.'}}, 'description': 'One contemplated or existing commitment to evaluate. merchant, commitment_type, and amount are required. Transaction-specific checkout_terms are the strongest input when available; maintained policy evidence can add context but never overrides conflicting transaction-specific terms.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['schemaVersion', 'assessment', 'merchant', 'commitmentType', 'amountMinor', 'currency', 'evaluatedAt', 'reason', 'evidence', 'limitations', 'paidExitManifestAvailable', 'paidExitPackAvailable', 'caseDigest'], 'properties': {'reason': {'type': 'string', 'description': 'Concise evidence-grounded explanation of the assessment.'}, 'currency': {'type': 'string', 'description': 'Normalized three-letter currency code.'}, 'evidence': {'type': 'array', 'items': {'type': 'object', 'properties': {'type': {'type': 'string', 'description': 'Evidence type, such as checkout_terms or official_policy.'}, 'authority': {'type': 'string', 'description': 'Authority label for the source.'}, 'sourceUrl': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'description': 'Source URL when one is available.'}, 'observedAt': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'description': 'When the evidence was observed, when available.'}, 'evidenceOrigin': {'type': 'string', 'description': 'Origin classification, such as caller_supplied or maintained_policy.'}, 'independentlyVerified': {'type': 'boolean', 'description': 'Whether ExitProof independently verified this evidence item.'}}, 'description': 'One evidence item used by ExitProof.', 'additionalProperties': True}, 'description': 'Evidence items supporting or limiting the assessment.'}, 'merchant': {'type': 'string', 'description': 'Normalized merchant or platform name.'}, 'assessment': {'enum': ['fully_reversible', 'conditionally_reversible', 'low_reversibility', 'effectively_irreversible', 'unknown'], 'type': 'string', 'description': 'Evidence-bounded reversibility classification. unknown means current evidence is insufficient or conflicting.'}, 'caseDigest': {'type': 'string', 'description': 'Stable digest of the normalized commitment inputs used for this assessment.'}, 'amountMinor': {'type': 'integer', 'minimum': 0, 'description': 'Commitment amount in minor currency units.'}, 'evaluatedAt': {'type': 'string', 'description': 'Timestamp at which the commitment was evaluated.'}, 'limitations': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Important limits on what the assessment proves.'}, 'evidenceBasis': {'type': 'string', 'description': 'Whether the assessment is based on checkout terms, maintained policy, both, or insufficient evidence.'}, 'evidenceState': {'type': 'string', 'description': 'Current evidence state, such as established, incomplete, conflicting, expired, or missing.'}, 'schemaVersion': {'const': 'exitproof-reversibility.v1', 'description': 'ExitProof reversibility result schema version.'}, 'commitmentType': {'type': 'string', 'description': 'Normalized commitment type.'}, 'decisionSupport': {'type': 'object', 'description': 'Decision-support summary that does not decide whether the user should make the commitment.', 'additionalProperties': True}, 'reversibleUntil': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'description': 'Recorded exit deadline when established, otherwise null.'}, 'evidenceConflict': {'type': 'boolean', 'description': 'True when evidence conflicts and cannot safely support a confident paid result.'}, 'exitPackEligibility': {'type': 'object', 'description': 'Reasoned actionability status for a future exit pack.', 'additionalProperties': True}, 'paidExitPackAvailable': {'type': 'boolean', 'description': 'Whether the current evidence appears actionable enough for a later exit pack after a manifest exists.'}, 'currentExitEstablished': {'anyOf': [{'type': 'boolean'}, {'type': 'null'}], 'description': 'Whether current evidence establishes an exit route.'}, 'maximumStatedLossMinor': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'description': 'Maximum stated loss in minor currency units when safely established, otherwise null.'}, 'paidExitManifestAvailable': {'type': 'boolean', 'description': 'Whether current evidence passes the preflight required before create_exit_manifest can be challenged for payment.'}}, 'description': 'Bounded reversibility assessment with evidence, loss/deadline information, limitations, and paid-operation eligibility flags.', 'additionalProperties': True}
create_exit_manifest
Create Exit Manifest
Persist a privacy-minimized Exit Manifest for an eligible commitment, then return its manifest_id and secret access_token. Use only after check_reversibility says paidExitManifestAvailable=true; pass the exact commitment facts to preserve, with transaction-specific checkout_terms controlling the assessment when supplied. Use check_reversibility for evaluation only, or get_exit_manifest when a manifest already exists. This state-changing $0.25 stablecoin MPP operation checks eligibility before any payment challenge; a fresh authorization creates durable state, while an identical settled retry with the same payment credential recovers the same manifest without a second settlement. The plaintext access token is returned to the caller but stored only as a SHA-256 hash.
外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['merchant', 'commitment_type', 'amount'], 'properties': {'amount': {'type': 'number', 'minimum': 0, 'description': 'Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation.'}, 'region': {'type': 'string', 'maxLength': 80, 'description': 'Optional state, province, or region label when the commitment or merchant terms are region-specific.'}, 'country': {'type': 'string', 'pattern': '^[A-Za-z]{2}$', 'maxLength': 2, 'minLength': 2, 'description': 'Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters.'}, 'currency': {'type': 'string', 'default': 'USD', 'pattern': '^[A-Za-z]{3}$', 'maxLength': 3, 'minLength': 3, 'description': 'Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD.'}, 'merchant': {'type': 'string', 'maxLength': 160, 'minLength': 1, 'description': 'Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets.'}, 'event_type': {'enum': ['initial', 'renewal', 'purchase', 'reservation', 'deposit', 'other'], 'type': 'string', 'default': 'initial', 'description': 'Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment.'}, 'checkout_terms': {'type': 'object', 'properties': {'refundable': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the committed amount is refundable.'}, 'source_url': {'type': 'string', 'maxLength': 500, 'description': 'HTTP(S) source URL for the supplied transaction terms. ExitProof removes credentials, query parameters, and fragments before storing the URL.'}, 'auto_renews': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the commitment renews automatically.'}, 'cancellable': {'type': 'boolean', 'description': 'Whether the supplied transaction terms explicitly state that the commitment can be canceled.'}, 'observed_at': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for when the caller observed these checkout terms.'}, 'charge_timing': {'type': 'string', 'maxLength': 160, 'description': 'When the merchant states the charge will occur, such as immediately, at check-in, or 24 hours before renewal.'}, 'renewal_interval': {'type': 'string', 'maxLength': 80, 'description': 'Human-readable renewal interval from the supplied terms, such as monthly or annually. Use only when auto-renewal terms are stated.'}, 'cancellation_method': {'type': 'string', 'maxLength': 240, 'description': 'Recorded method or path for cancellation/refund, such as an account page, support channel, or merchant instruction. This can make a later exit pack actionable.'}, 'nonrefundable_amount': {'type': 'number', 'minimum': 0, 'description': 'Amount explicitly stated as nonrefundable, in major units of currency.'}, 'cancellation_deadline': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for the stated cancellation deadline, even when cancellation may involve a loss.'}, 'free_cancellation_until': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 deadline with explicit timezone through which the supplied terms state cancellation is free.'}, 'cancellation_penalty_amount': {'type': 'number', 'minimum': 0, 'description': 'Stated cancellation penalty in major units of currency. Mutually exclusive with cancellation_penalty_percent.'}, 'cancellation_penalty_percent': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Stated cancellation penalty as a percentage from 0 to 100. Mutually exclusive with cancellation_penalty_amount.'}}, 'description': 'Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while maintained policy evidence remains contextual.', 'additionalProperties': False}, 'commitment_type': {'enum': ['subscription', 'reservation', 'ticket', 'service', 'software', 'digital_purchase', 'rental', 'deposit', 'other'], 'type': 'string', 'description': 'Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method.'}, 'client_reference': {'type': 'string', 'maxLength': 200, 'description': 'Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here.'}, 'purchase_channel': {'enum': ['direct', 'apple', 'google_play', 'marketplace', 'travel_agency', 'other', 'unknown'], 'type': 'string', 'default': 'unknown', 'description': 'Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself.'}, 'expected_commitment_at': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp.'}}, 'description': 'One contemplated or existing commitment to evaluate. merchant, commitment_type, and amount are required. Transaction-specific checkout_terms are the strongest input when available; maintained policy evidence can add context but never overrides conflicting transaction-specific terms.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['manifestId', 'createdAt', 'expiresAt', 'assessment', 'accessToken', 'accessTokenReturnedOnce', 'privacyNote'], 'properties': {'createdAt': {'type': 'string', 'description': 'Manifest creation timestamp.'}, 'expiresAt': {'type': 'string', 'description': 'Manifest expiration timestamp.'}, 'assessment': {'type': 'string', 'description': 'Reversibility assessment preserved in the manifest.'}, 'manifestId': {'type': 'string', 'description': 'Unguessable identifier for the stored Exit Manifest.'}, 'accessToken': {'type': 'string', 'description': 'Secret bearer token required with manifestId for later retrieval or exit-pack creation. ExitProof does not store this token in plaintext.'}, 'privacyNote': {'type': 'string', 'description': 'How ExitProof protects and may recover the access token.'}, 'paidExitPackAvailable': {'type': 'boolean', 'description': 'Whether the stored manifest is eligible for an exit-pack preflight at creation time.'}, 'accessTokenReturnedOnce': {'type': 'boolean', 'description': 'Whether this response is the first normal return of the access token.'}, 'accessTokenReissuedForSettlementRecovery': {'type': 'boolean', 'description': 'True only when deterministic settlement recovery re-derived the access token after a settled delivery failure.'}}, 'description': 'Durable privacy-minimized Exit Manifest plus the bearer access token returned to the caller.', 'additionalProperties': True}
get_exit_manifest
Get Exit Manifest
Retrieve one previously created Exit Manifest without charging or changing stored state. Pass manifest_id and access_token together: the ID selects the record and the secret token authorizes access to that same record, so neither value is sufficient alone. Use this for preserved evidence and terms; use build_exit_pack for an actionable cancellation/refund plan, or create_exit_manifest when no manifest exists. This free, repeatable read does not refresh, re-evaluate, or extend evidence; missing, expired, or mismatched credentials fail without modifying the manifest.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['manifest_id', 'access_token'], 'properties': {'manifest_id': {'type': 'string', 'pattern': '^xm_[a-f0-9]{32}$', 'description': 'Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters.'}, 'access_token': {'type': 'string', 'pattern': '^xp_[A-Za-z0-9_-]{20,}$', 'description': 'Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it.'}}, 'description': 'Credentials for one previously created Exit Manifest. Both values are required together and are returned by create_exit_manifest or settlement recovery.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['schemaVersion', 'manifest'], 'properties': {'manifest': {'type': 'object', 'description': 'Stored Exit Manifest. This read does not refresh or reinterpret the original evidence.', 'additionalProperties': True}, 'schemaVersion': {'const': 'exitproof-manifest-read.v1', 'description': 'Manifest-read response schema version.'}}, 'description': 'Authenticated read of one previously stored Exit Manifest.', 'additionalProperties': False}
list_supported_policies
List supported policies
List the maintained merchant policy overlays and snapshot version/date ExitProof can add to transaction-specific evidence. Use this only to inspect maintained coverage; use check_reversibility to evaluate an actual commitment, including an unlisted merchant when transaction-specific checkout_terms are available. An absent merchant means no maintained overlay, not that no cancellation, refund, contractual, or legal right exists. This is a free read-only snapshot: it creates no durable state, issues no payment challenge, and does not fetch or verify a merchant’s live policy at call time.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'properties': {}, 'description': 'No parameters. This tool lists the current maintained policy-overlay catalog.', 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['schemaVersion', 'policySnapshot', 'important', 'merchants'], 'properties': {'important': {'type': 'string', 'description': 'Coverage caveat explaining that transaction-specific checkout terms can be used for any merchant.'}, 'merchants': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'displayName', 'aliases', 'ruleIds'], 'properties': {'id': {'type': 'string', 'description': 'Stable maintained-policy merchant identifier.'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Names that map to this merchant policy overlay.'}, 'ruleIds': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Maintained rule identifiers available for this merchant.'}, 'displayName': {'type': 'string', 'description': 'Human-readable merchant name.'}}, 'additionalProperties': False}, 'description': 'Merchants with maintained policy overlays.'}, 'schemaVersion': {'const': 'exitproof-supported-policies.v1', 'description': 'Supported-policy response schema version.'}, 'policySnapshot': {'type': 'object', 'description': 'Version and verification date for the maintained policy snapshot.', 'additionalProperties': True}}, 'description': 'Maintained merchant-policy overlay catalog. This is coverage metadata, not a statement that unlisted merchants cannot be evaluated.', 'additionalProperties': False}
変更
check_agent_purchase
2026年9月29日2:50
変更
build_exit_pack
2026年9月27日2:42
変更
create_exit_manifest
2026年9月27日2:42
追加
check_agent_purchase
2026年9月27日2:42
追加
list_supported_policies
2026年9月23日2:40
追加
build_exit_pack
2026年9月23日2:40
追加
get_exit_manifest
2026年9月23日2:40
追加
create_exit_manifest
2026年9月23日2:40
追加
check_reversibility
2026年9月23日2:40