{"uid":"cap_Yk_dlJFzYJNBu9yXXVpXo","slug":"intentfence-policy-pack-authorization-8598216f","name":"IntentFence Policy Pack Authorization","description":"Fail-closed, action-bound authorization for AI agents with five-minute ES256 receipts, MCP risk scanning, and x402 payment safety.","url":"https://agentpass-protocol.rmalka06.chatgpt.site/api/policy-packs","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"runtime":{"enum":["cloudflare-agents","coinbase-agentkit","mcp-gateway","openai-agents-js"],"type":"string"},"project_name":{"type":"string","maxLength":120,"minLength":1,"description":"A public-safe project label. Do not include credentials or secrets."},"authorization":{"type":"object","required":["subject","action","policy"],"properties":{"action":{"type":"object","required":["type","resource","protocol"],"properties":{"type":{"type":"string","maxLength":120,"minLength":1},"method":{"type":"string","maxLength":20,"minLength":1},"protocol":{"enum":["mcp","http","a2a","payment","other"],"type":"string"},"resource":{"type":"string","maxLength":1000,"minLength":1},"payload_sha256":{"type":"string","pattern":"^[0-9a-f]{64}$"}},"additionalProperties":false},"policy":{"type":"object","required":["allowed_action_types","allowed_resources"],"properties":{"max_cost":{"type":"object","required":["amount","currency"],"properties":{"amount":{"type":"number","minimum":0},"currency":{"type":"string","maxLength":12,"minLength":1}},"additionalProperties":false},"allowed_resources":{"type":"array","items":{"type":"string"},"maxItems":50,"minItems":1,"uniqueItems":true},"allowed_action_types":{"type":"array","items":{"type":"string"},"maxItems":50,"minItems":1,"uniqueItems":true},"max_data_retention_hours":{"type":"number","minimum":0},"require_human_approval_for":{"type":"array","items":{"type":"string"},"maxItems":50,"uniqueItems":true}},"additionalProperties":false},"context":{"type":"object","properties":{"currency":{"type":"string","maxLength":12,"minLength":1},"quoted_cost":{"type":"number","minimum":0},"data_retention_hours":{"type":"number","minimum":0}},"additionalProperties":false},"subject":{"type":"string","maxLength":200,"minLength":1},"approval":{"type":"object","required":["approved_by","approved_at","expires_at","action_digest","proof_id"],"properties":{"proof_id":{"type":"string","maxLength":200,"minLength":1},"expires_at":{"type":"string","format":"date-time"},"approved_at":{"type":"string","format":"date-time"},"approved_by":{"type":"string","maxLength":200,"minLength":1},"action_digest":{"type":"string","pattern":"^[0-9a-f]{64}$"}},"additionalProperties":false}},"additionalProperties":false}}},"responseSchema":{"type":"json","example":{"runtime":"cloudflare-agents","decision":{"status":"safe_to_proceed","receipt":{"signed":true,"assurance":"action-bound-policy-authorization"}},"integration":{"filename":"intentfence-cloudflare-agents.ts","language":"typescript"},"intentfence":"policy-pack-1.0","verification_tier":"production-policy-pack+x402-settled"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_eMUmpX3KEqZzHD1oyAPMT","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Issues fail-closed, action-bound ES256 authorization receipts for AI agent actions after MCP risk scanning and x402 payment settlement","exampleAgentPrompt":"Before you proceed with that file deletion action, run it through IntentFence to get a signed policy-pack authorization receipt — I want a fail-closed check that confirms it's safe to proceed before you actually execute anything.","exampleUseCases":[{"title":"Gate irreversible financial agent action","prompt":"Before my agent submits that $500 wire transfer, have IntentFence scan it against the policy pack and give me a signed ES256 receipt confirming it's authorized — don't let the action execute unless you get a safe_to_proceed decision."},{"title":"MCP risk scan before tool call","prompt":"My agent is about to invoke a shell command tool via MCP — run it through IntentFence first and only continue if you get a valid action-bound authorization receipt back with a safe status."},{"title":"Enforce agent policy in Cloudflare Workers","prompt":"I need to add fail-closed authorization to my Cloudflare agent — use IntentFence to get the policy-pack integration TypeScript file and a signed receipt before any sensitive action runs."}],"resultDescription":"A JSON object containing a safety decision (e.g. 'safe_to_proceed'), a signed ES256 action-bound receipt, the runtime environment (e.g. 'cloudflare-agents'), a TypeScript integration file, the IntentFence policy-pack version, and a verification tier confirming x402 payment settlement.","failureModes":["Action deemed unsafe — decision status returns a non-safe value and receipt is not issued","x402 payment not settled — authorization blocked due to payment failure","ES256 signing failure — receipt cannot be generated","Policy pack not found or misconfigured — returns error with no decision","MCP risk scan timeout — action gating fails closed by default","Malformed action payload — request rejected before scanning"],"whenToPreferThis":"Use this endpoint when an AI agent is about to execute a potentially dangerous, irreversible, or high-stakes action and you need a cryptographically signed, action-bound authorization receipt before proceeding. Prefer IntentFence over generic guardrails when you need MCP risk scanning, fail-closed behavior, x402 payment-verified authorization, and a short-lived ES256 receipt tied to the specific action.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:36:08.754Z","isFirstParty":false}