{"uid":"cap_CGGXeqnygYm6-UzNrC0ye","slug":"assurance-attest-d09d63f1","name":"Assurance Attest","description":"Signed receipt for one agent action. Post an x402 payment intent or MCP tool call (optional policy + settlement outcome) and get a canonical HMAC-signed record: binding hash, verdict, findings, and a free public verify URL third parties can check without trusting your agent's logs. Loop it after every payment or tool call to build a tamper-evident audit trail. Canonicalization hermes-stable-json-v1; org history and probes available on Assurance plans.","url":"https://hermesplant.com/api/agent-services/assurance/attest","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"intent":{"type":"object","description":"x402: resourceUrl+method (+scheme/network/asset/amountUnits/payTo). mcp: serverId+toolName (+toolArguments or toolArgumentsHash)."},"policy":{"type":"object","description":"Optional buyer policy (policyId+version, caps, allow-lists). Omit for a binding-only attestation under the permissive policy."},"outcome":{"type":"object","description":"Optional settlement outcome: outcome fulfilled|failed|rejected, settlementId, responseStatus, evidenceHashes[]."},"subject":{"type":"object","description":"Who acted: runId (required), agentId, purpose."},"protocol":{"type":"string","description":"\"x402\" or \"mcp\"."}}},"responseSchema":{"type":"json","example":{"record":{"kind":"agent-action-attestation","outcome":{"outcome":"fulfilled","settlementId":"0xsettle"},"verdict":"allow","protocol":"x402","attestedAt":"2026-07-12T00:00:00.000Z","bindingHash":"<sha256>","attestationId":"att_<uuid>"},"status":"attested","verify":{"url":"https://hermesplant.com/api/agent-services/assurance/verify","method":"POST"},"service":"assurance","integrity":{"keyId":"assurance-primary","signature":"<hmac>","recordHash":"<sha256>","canonicalization":"hermes-stable-json-v1","signatureAlgorithm":"HMAC-SHA-256"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_tN07WFK7kOBn0D-LkCxrV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Creates a signed, machine-readable attestation record for consequential agent actions (x402 payments, MCP tool calls) with policy verdict and tamper-evident integrity proof.","exampleAgentPrompt":"Before my agent finalizes this x402 payment to https://api.example.com/data for run run-abc123 with purpose 'fetch market data', create a signed attestation record so I have tamper-evident proof it was reviewed and allowed.","exampleUseCases":[{"title":"Audit trail for agent x402 payment","prompt":"My agent just processed an x402 payment to https://vendor.com/api/report — run ID is run-7f2a, agent ID is agent-finance-01, purpose is 'purchase analytics report'. Create a signed attestation for this with the settlement ID 0xabc999 and mark the outcome as fulfilled so I have a verifiable receipt."},{"title":"Safety gate log for MCP tool execution","prompt":"Before my agent calls the 'run_shell' tool on MCP server prod-infra-01 for run ID run-deploy-882, I need an attestation record that captures the tool name, arguments hash, and a policy verdict — use the mcp protocol and subject it to our default policy so we have an audit trail."},{"title":"Evidence record for rejected infrastructure action","prompt":"My agent tried to execute a database migration but it was rejected by policy during run run-sql-441, agent ID agent-db-ops, purpose 'schema migration'. Attest this with outcome rejected and protocol x402 so compliance has a machine-readable record of the blocked action."}],"resultDescription":"Returns a JSON object containing: an attestationId (att_<uuid>), a verdict (allow/deny), bindingHash, attestedAt timestamp, protocol, and optionally the settlement outcome. The integrity block includes an HMAC-SHA-256 signature, recordHash, keyId, and canonicalization method so the record can be independently verified via the /verify endpoint.","failureModes":["Missing required fields (runId, protocol, intent) returns a 400 validation error","Invalid protocol value (not 'x402' or 'mcp') causes schema rejection","Malformed intent object missing required subfields (resourceUrl for x402, serverId+toolName for mcp) returns an error","Payment failure or USDC balance insufficient results in x402 payment required response","Signature verification failure on the returned record indicates a server-side integrity issue","Duplicate runId attestations may be rejected or flagged depending on policy configuration"],"whenToPreferThis":"Use this endpoint when you need a cryptographically signed, machine-readable audit record for a specific consequential agent action — particularly x402 micropayments or MCP tool invocations — and require tamper-evident evidence suitable for compliance review or downstream verification. Prefer this over generic logging when policy verdict (allow/deny), HMAC integrity proofs, and a verifiable receipt with a settlementId are required. Choose the Quick Gate sibling if you only need a pre-action safety check without creating a persistent attestation record.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:34:08.974Z","isFirstParty":false}