Raw schema
{
"type": "object",
"properties": {
"prompt": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"description": "Legacy compatibility input: the original prompt whose response is being verified. Use together with response, not with autonomous action fields."
},
"response": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"description": "Legacy compatibility input: the response to evaluate against prompt. Use together with prompt, not with autonomous action fields."
},
"use_case": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"description": "Stable identifier describing why the exact autonomous action is being proposed. Required together with action for the autonomous_execution contract."
},
"action": {
"type": "object",
"additionalProperties": true,
"description": "The proposed action. For executable pilot authorization use interai-canonical-action/v1 with host-registry tool_id, type, operation, exact arguments, and explicit side-effect semantics.",
"properties": {
"schema": {
"type": "string",
"const": "interai-canonical-action/v1"
},
"tool_id": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"type": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"operation": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"arguments": {
"type": "object"
},
"external_side_effect": {
"type": "boolean"
},
"irreversible": {
"type": "boolean"
},
"destination": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"resource": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
}
}
},
"execution_context": {
"type": "object",
"additionalProperties": false,
"description": "Host-attested execution context bound to a canonical action. InterAI authenticates the account, not the truth of host-provided workspace, actor, run, or environment values.",
"properties": {
"schema": {
"type": "string",
"const": "interai-host-execution-context/v1"
},
"workspace_id": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"environment": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"actor_id": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
},
"run_id": {
"type": "string",
"minLength": 1,
"pattern": "\\S"
}
},
"required": [
"schema",
"workspace_id",
"environment"
]
},
"authorization_ttl_seconds": {
"type": "integer",
"minimum": 1,
"maximum": 300,
"default": 60,
"description": "Lifetime of a single-use execution authorization for a canonical action. Only Bearer-authenticated pilot requests receive executable authorization material."
},
"context": {
"type": "object",
"additionalProperties": true,
"description": "Optional runtime context surrounding the proposed action, such as environment, agent identity, counterparty, user confirmation, or other facts relevant to this decision."
},
"policy": {
"type": "object",
"additionalProperties": false,
"description": "Optional strictly validated caller-scoped restrictions. They may tighten the boundary but cannot weaken host or account policy.",
"properties": {
"blocked_action_types": {
"type": "array",
"maxItems": 100,
"items": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"maxLength": 128
}
},
"allowed_action_types": {
"type": "array",
"maxItems": 100,
"items": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"maxLength": 128
}
},
"allowed_action_types_enforced": {
"type": "boolean"
},
"amount_usd_limit": {
"type": "number",
"minimum": 0
},
"require_human_review_above": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"max_risk_level": {
"type": "string",
"enum": [
"low",
"medium",
"high"
]
},
"require_user_confirmation_for_irreversible": {
"type": "boolean"
},
"require_trust_receipt": {
"type": "boolean"
}
}
},
"external_evidence": {
"type": "array",
"description": "Optional signed or verifiable external assertions. Current Stage 2 evidence is parsed, verified, bound, and recorded as non-authoritative evidence; it does not directly determine the InterAI execution decision or risk score.",
"items": {
"$schema": "http://json-schema.org/draft-07/schema#",
"$id": "external-evidence/v0/rev6",
"title": "external-evidence/v0 (rev6) wire item",
"description": "Closed JSON Schema for one item of the optional top-level external_evidence collection. additionalProperties:false is enforced recursively; required fields are explicit; reference and inline modes are discriminated with oneOf (now actually enforced by conformant Draft-07 validators). rev4 hardening: every uint256 semantics field accepts either a JSON number in 0..9007199254740991 or a canonical decimal-string for larger values (Alejandro 10th-reply targeted correction, completing the 9th-reply integer item); rev3 items are retained: inline_payload closed with a strict profile-specific schema (Insight OracleSafetyCheck v2, 26 fields, required, exact types, additionalProperties:false), signed schemaVersion=2 and evaluationScope=SOURCE_ASSET_ONLY pinned by const. subject_only and order_insensitive binding modes are reserved and NOT accepted on the wire in v0. rev5: the wire shape is unchanged. The bundled self-check validator now evaluates const and enum before any type-specific return, so it agrees with a conformant Draft-07 validator on the pinned schemaVersion=2 and evaluationScope=SOURCE_ASSET_ONLY.",
"type": "object",
"additionalProperties": false,
"required": [
"evidence_id",
"provider",
"assertion",
"validity",
"binding",
"verification"
],
"properties": {
"evidence_id": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$",
"description": "provider canonical digest as claimed by the caller; InterAI recomputes it from the verified signed assertion and a mismatch is NOT_ALLOWED."
},
"provider": {
"type": "object",
"additionalProperties": false,
"required": [
"namespace",
"assertion_version",
"key_id"
],
"properties": {
"namespace": {
"type": "string",
"description": "resolved against the local provider adapter / trust registry"
},
"assertion_version": {
"type": "string",
"description": "must equal the locally configured profile version"
},
"key_id": {
"type": "string",
"description": "must equal the locally pinned key id"
}
}
},
"assertion": {
"type": "object",
"additionalProperties": false,
"required": [
"kind",
"verdict",
"verdict_space"
],
"properties": {
"kind": {
"type": "string",
"enum": [
"assessment",
"observation"
],
"description": "semantics pinned locally per provider profile"
},
"verdict": {
"type": "string",
"description": "provider-native verdict, must equal the signed verdict"
},
"verdict_space": {
"type": "string",
"description": "the scale namespace, pinned locally per provider profile"
},
"observations": {
"type": "object",
"additionalProperties": false,
"required": [
"coverage_status",
"participant_count",
"required_participant_count",
"cross_provider_deviation_bps",
"cross_provider_agreement_bps",
"independence_status",
"max_data_age_seconds"
],
"properties": {
"coverage_status": {
"type": "string"
},
"participant_count": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"required_participant_count": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"cross_provider_deviation_bps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"cross_provider_agreement_bps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"independence_status": {
"type": "string"
},
"max_data_age_seconds": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
}
},
"description": "optional on the wire; if present it must equal the signed projection field by field (compared with structural/JCS equality, not order-sensitive JSON.stringify)"
}
}
},
"validity": {
"type": "object",
"additionalProperties": false,
"required": [
"evaluated_at",
"valid_until"
],
"properties": {
"evaluated_at": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED. must equal signed checkedAt"
},
"valid_until": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED. must equal signed validUntil; expiry is enforced on the signed payload, never this projection"
}
}
},
"binding": {
"type": "object",
"additionalProperties": false,
"required": [
"scope",
"binding_mode",
"action_commitment"
],
"properties": {
"scope": {
"type": "string",
"enum": [
"action"
],
"description": "v0 supports action scope only; subject scope is reserved with subject_only"
},
"binding_mode": {
"type": "string",
"enum": [
"exact_action"
],
"description": "the only supported v0 binding mode. subject_only and order_insensitive are reserved and rejected on the wire."
},
"action_commitment": {
"type": "object",
"additionalProperties": false,
"required": [
"scheme",
"type",
"commitment",
"committed_fields"
],
"properties": {
"scheme": {
"type": "string",
"description": "pinned locally per provider profile (insight.canonical-pre-trade-request/v1)"
},
"type": {
"type": "string",
"description": "pinned locally per provider profile (eip712)"
},
"commitment": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$",
"description": "must equal the signed requestHash"
},
"committed_fields": {
"type": "array",
"items": {
"type": "string"
},
"minItems": 1,
"uniqueItems": true,
"description": "the field list is pinned locally per provider profile"
}
}
}
}
},
"verification": {
"type": "object",
"oneOf": [
{
"type": "object",
"additionalProperties": false,
"required": [
"mode",
"attestation_ref"
],
"properties": {
"mode": {
"const": "reference"
},
"attestation_ref": {
"type": "string",
"description": "resolved through the locally configured adapter / allowlisted origin; a URL in evidence never triggers arbitrary fetching"
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"mode",
"inline_payload",
"inline_signature"
],
"properties": {
"mode": {
"const": "inline"
},
"inline_payload": {
"type": "object",
"additionalProperties": false,
"required": [
"verdict",
"sourceAssetId",
"destinationAssetId",
"subjectChainId",
"action",
"tradeAmountUsd",
"consensusPrice",
"maxDeviationBps",
"manipulationRiskBps",
"participantCount",
"requiredParticipantCount",
"coverageStatus",
"independenceStatus",
"sourceGroupCount",
"crossProviderAgreementBps",
"maxStablecoinDepegBps",
"maxDataAgeSeconds",
"recommendedMaxPositionUsd",
"reasonCodesHash",
"requestHash",
"evaluationScope",
"evaluatedAssetIdsHash",
"providerObservationsHash",
"validUntil",
"checkedAt",
"schemaVersion"
],
"properties": {
"verdict": {
"type": "string"
},
"sourceAssetId": {
"type": "string"
},
"destinationAssetId": {
"type": "string"
},
"subjectChainId": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"action": {
"type": "string"
},
"tradeAmountUsd": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"consensusPrice": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"maxDeviationBps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"manipulationRiskBps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"participantCount": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"requiredParticipantCount": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"coverageStatus": {
"type": "string"
},
"independenceStatus": {
"type": "string"
},
"sourceGroupCount": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"crossProviderAgreementBps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"maxStablecoinDepegBps": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"maxDataAgeSeconds": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"recommendedMaxPositionUsd": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"reasonCodesHash": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$"
},
"requestHash": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$"
},
"evaluationScope": {
"type": "string",
"const": "SOURCE_ASSET_ONLY",
"description": "pinned (Alejandro 9th reply): InterAI must not widen the signed evaluationScope claim"
},
"evaluatedAssetIdsHash": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$"
},
"providerObservationsHash": {
"type": "string",
"pattern": "^0x[0-9a-f]{64}$"
},
"validUntil": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"checkedAt": {
"oneOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "string",
"pattern": "^(0|[1-9][0-9]*)$",
"description": "canonical decimal-string: only for values > 9007199254740991"
}
],
"description": "uint256 semantics: safe integers use JSON number 0..9007199254740991; larger values use canonical decimal-string (no leading zeros, no sign, no exponent, no fraction). Canonical form is enforced: a string whose value fits in the safe range is NOT_ALLOWED."
},
"schemaVersion": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991,
"const": 2,
"description": "pinned (Alejandro 9th reply): only schemaVersion=2 is accepted"
}
},
"description": "profile-specific closed schema for the Insight OracleSafetyCheck v2 (26-field) inline payload: required, exact types, additionalProperties:false, schemaVersion=2 and evaluationScope=SOURCE_ASSET_ONLY pinned by const. A future provider profile pins its own inline schema."
},
"inline_signature": {
"type": "string",
"description": "provider signature over the typed payload"
}
}
}
]
}
}
}
},
"domain": {
"type": "string",
"minLength": 1,
"pattern": "\\S",
"description": "Optional domain label used to provide verification context. It does not replace the exact action, context, or policy inputs."
},
"mode": {
"type": "string",
"enum": [
"fast_heuristic",
"semantic_judge"
],
"description": "Verification mode. Use fast_heuristic for the default low-latency path or semantic_judge when a semantic model judgment is explicitly required."
},
"idempotency_key": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"pattern": "^\\s*[A-Za-z0-9._:-]+\\s*$",
"description": "Stable caller-provided key for retrying the same billed verification without duplicating the economic operation. Reuse it only for the same logical request."
}
},
"description": "Compatibility schema supporting exactly one of two existing contracts: legacy prompt + response, or autonomous use_case + action. Do not mix legacy prompt/response fields with autonomous action fields in the same request.",
"additionalProperties": false,
"oneOf": [
{
"description": "Legacy verification contract. Requires both prompt and response and excludes autonomous action, context, policy, and external evidence fields.",
"required": [
"prompt",
"response"
],
"not": {
"anyOf": [
{
"required": [
"use_case"
]
},
{
"required": [
"action"
]
},
{
"required": [
"execution_context"
]
},
{
"required": [
"authorization_ttl_seconds"
]
},
{
"required": [
"context"
]
},
{
"required": [
"policy"
]
},
{
"required": [
"external_evidence"
]
}
]
}
},
{
"description": "Autonomous execution compatibility contract. Requires use_case and action and excludes legacy prompt/response fields. New integrations should prefer oracle.verify_autonomous_action.",
"required": [
"use_case",
"action"
],
"not": {
"anyOf": [
{
"required": [
"prompt"
]
},
{
"required": [
"response"
]
}
]
}
}
]
}