All workflows

Delta Policy Gate / Machine JSON State Validation

Machine-native deterministic JSON before/after state change policy evaluation for rule-based CI/CD jobs, inventory event processors, non-AI scheduler pipelines, billing record reconciliation and automated deployments. SHA-256 checksums of caller-supplied JSON, changed JSON pointers, baseline assertions, blocked-field and regression policy checks. Does NOT independently verify origin, external measurements, cryptographic signatures or machine owner consent; purchase only by authorized buyers.

3 credits per call · $0.03 USDC with x402

Sample input

{
  "before": {
    "status": "open",
    "price": 10
  },
  "after": {
    "status": "closed",
    "price": 12
  },
  "policy": {
    "blocked_paths": [
      "/price"
    ],
    "required_changed_paths": [
      "/status"
    ]
  }
}

Worked sample output

{
  "ok": true,
  "mode": "delta_policy_gate",
  "change_ref": null,
  "decision": "hold",
  "findings": [
    {
      "id": "blocked_path_changed",
      "detail": "Blocked JSON pointer changed: /price"
    }
  ],
  "observations": [],
  "before_sha256": "c6a3e41eb38bec743730cdceaa6715ec3f8ea45d2be717b1dcab7b7fbba011e1",
  "after_sha256": "97bcf68fe8fda0941ccb119acdd65f20c536b3154d3b5ffdccd70b6e04e23891",
  "total_changes": 2,
  "changes": [
    {
      "path": "/price",
      "kind": "modified"
    },
    {
      "path": "/status",
      "kind": "modified"
    }
  ],
  "proof": {
    "sha256": "c97b574b56014fd12106c0f70e2a5338781978edd7a8aba11b26ef363ccb6fe2",
    "type": "caller_supplied_json_sha256",
    "external_source_verified": false,
    "digitally_signed": false,
    "notarized": false
  },
  "limitations": [
    "The service cannot establish who supplied the JSON, its external source, or the truth of the measurements.",
    "SHA-256 is a checksum, not a notarized third-party attestation.",
    "No systems are modified, actions executed, wallets billed by this algorithm or outside accounts accessed."
  ]
}

Worked example using published sample data only. Own-data execution is paid.

Connect in curl

Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.

curl 'https://bounty-engineer-x402-api.onrender.com/v1/prepaid/delta-policy-gate' \
  -H "Authorization: Bearer $BOUNTY_API_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: workflow-request-001' \
  -H 'X-Max-Credits: 3' \
  --data '{"before":{"status":"open","price":10},"after":{"status":"closed","price":12},"policy":{"blocked_paths":["/price"],"required_changed_paths":["/status"]}}'

Connect in n8n

Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.

Use an HTTP POST to https://bounty-engineer-x402-api.onrender.com/v1/prepaid/delta-policy-gate. Send JSON and these headers; store the Bearer token as a private credential.

{
  "method": "POST",
  "headers": {
    "Authorization": "Bearer YOUR_PRIVATE_API_KEY",
    "Content-Type": "application/json",
    "Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
    "X-Max-Credits": "3"
  },
  "body": {
    "before": {
      "status": "open",
      "price": 10
    },
    "after": {
      "status": "closed",
      "price": 12
    },
    "policy": {
      "blocked_paths": [
        "/price"
      ],
      "required_changed_paths": [
        "/status"
      ]
    }
  }
}

Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe