{
"requested": [
"read",
"deploy"
],
"allowed": [
"read"
]
}
Portable intent card · agent-governance
Tool Permission Audit API for agents
Compare requested agent tools with an explicit least-privilege allowlist. Use it as a bounded preflight or analysis step inside an enterprise agent workflow before data, policy, integration, security, or commercial decisions reach production. Returns deterministic machine-readable JSON for $0.003 USDC via x402 on Base. Execution is first-party, local-only, stateless, memory-only, and has no paid upstream or input retention. Results are advisory; the caller remains responsible for authorization and production controls.
Intent to transaction
One command, attributed.
The source header follows this discovery route through challenge, payment and delivery without exposing the buyer or request body.
npx agentcash@latest fetch https://api.delx.ai/api/v1/x402/tool-permission-audit -m POST -H 'x-delx-source: intent-card-tool-permission-audit-api' --max-amount 0.003 -b '{"requested":["read","deploy"],"allowed":["read"]}'
Example inputPOST /api/v1/x402/tool-permission-audit
Agent discoverydelx/intent-card/v1
{
"intent": "Tool Permission Audit for an agent workflow",
"tool_name": "util_tool_permission_audit",
"price_usdc": "0.003",
"machine_url": "https://commerce.delx.ai/intents/tool-permission-audit-api.json"
}
Portable and inspectable