{"uid":"cap_WlFZ5Xw4rQfoyBZ5ToMmN","slug":"delegated-credential-guard-726ed5a6","name":"Delegated Credential Guard","description":"Enforce delegated credential scope, requester and expiry without receiving raw credentials","url":"https://phion.systems/v1/paid/trust/delegated-credential-guard?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input","output"],"properties":{"input":{"type":"object","required":["body"],"properties":{"body":{"type":"object","additionalProperties":true}}},"output":{"type":"object","required":["example"],"properties":{"example":{"type":"object","additionalProperties":true}}}}},"responseSchema":{"type":"json"},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_23U3s4N-RGUAr4k335Wh7","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Enforces delegated credential scope, requester identity, and expiry constraints without ever receiving or exposing the underlying raw credentials","exampleAgentPrompt":"Before letting the sub-agent proceed, check that the delegated credential it's using is still within its permitted scope, the requester is the authorized agent, and it hasn't passed the expiry time — without looking at the raw credential itself.","exampleUseCases":[{"title":"Sub-agent credential scope enforcement","prompt":"My orchestrator agent has delegated a credential to a sub-agent for read-only data access expiring at midnight tonight — can you verify the sub-agent's request is within that scope and the delegation hasn't expired before it proceeds?"},{"title":"Multi-agent pipeline authorization check","prompt":"Before the next stage of my pipeline runs, validate that the delegated credential being passed from agent A to agent B is still scoped to the 'billing:read' permission and that agent B is the authorized requester."},{"title":"Preventing credential overstep in agentic workflows","prompt":"I want to make sure no agent in my workflow is using a delegated credential beyond what it was granted — check this credential's scope, confirm the requesting agent identity matches, and flag if it's expired."}],"resultDescription":"Returns a structured enforcement verdict indicating whether the delegated credential is valid (scope compliant, requester authorized, not expired), along with specific failure reasons for any violated constraint — all without the raw credential being transmitted or stored.","failureModes":["Credential scope exceeded — returns rejection with out-of-scope detail","Credential expiry breached — returns rejection with expiry timestamp","Requester identity mismatch — returns rejection identifying the authorized vs actual requester","Malformed or missing delegation metadata — returns validation error","Policy not evaluable due to incomplete input — returns error indicating missing fields"],"whenToPreferThis":"Choose this endpoint when you need to enforce delegated credential constraints in a zero-trust, privacy-preserving way — particularly in multi-agent workflows where sub-agents receive delegated tokens and you must verify scope, identity, and expiry without ever passing raw secrets to a third party. Prefer it over standard auth checks when the credential is delegated (not direct) and auditability without credential exposure is a requirement.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T06:44:04.217Z","isFirstParty":false,"canonicalSlug":"delegated-credential-guard-726ed5a6"}