generated: '2026-09-19' method: searched source: https://travel.agenthaven.dev/ derived_from: - a2a/agenthaven-dev-agent-card.json (skills[].security, securitySchemes.bearer) - mcp/agenthaven-dev-mcp-tools.json (tool descriptions, const constraints, evidence/audit fields) - https://travel.agenthaven.dev/health (guests policy, mandate_issuers, verifiers) - https://provedby.dev/contracts/guest-buyer.md (mandate jti, TTL, revocation) description: >- x-agentic-access execution contracts for the two operations Agent Bench exposes. derive-agentic-access.py was not run — there is no OpenAPI — and this file is NOT a heuristic classification: the provider publishes real agent-access guidance (who may call what, under whose authority, with what cap, for how long, audited where), and every field below cites the surface it was read from. Only the action-class / consequence labels are ours, applied from the Curity vocabulary to what the provider states. Reviewed per deployment; audience is left null. summary: operations: 2 by_action_class: {connected: 1, acting: 1} by_consequence: {read: 1, physical: 1} human_in_the_loop_required: 1 note: >- The one acting operation moves money in name only — Stripe test mode — so its real-world consequence today is nil; it is classified as physical because the contract is written for a purchase (payment intent, EUR amounts, mandates with spending caps) and a production deployment of the same contract would be one. operations: - operation: search_flights protocol: [MCP tools/call, A2A message/send action search_flights] x-agentic-access: action-class: connected consequence: read subject: optional audience: null authentication: none — "search_flights and tools/list are open" (card securitySchemes.bearer description) token: {required: false} quota: shared anonymous budget 40/day, 120/month; authorised searches exempt (docs; /health counters) escalation: {human-in-the-loop: none} audit: required — one quote.created ledger entry per option returned, with facts.actor null for anonymous calls (ledger reading guide) purpose-binding: correlation_id (optional UUID v4) and exercise (optional test-vector label) travel into the ledger provider_statements: - 'agent card skills[0]: "No authorization needed."' - 'ledger reading guide: "facts.actor null with no facts.authorization_id means the search was anonymous (allowed since 2026-09-14): nobody vouched for the caller, and any authorization that covers the quote may check it out."' - operation: create_checkout protocol: [MCP tools/call, A2A message/send action create_checkout] x-agentic-access: action-class: acting consequence: physical subject: required audience: null authentication: 'http bearer JWT; skill security [{bearer: [commerce:purchase]}]' token: forms: [request envelope (typ request+jwt) signed by the agent's own attested key + third-party mandate (typ mandate+jwt), operator-issued JWT (iss agent-bench-demo-issuer, aud agent-bench, scope commerce:purchase), guest self-issued mandate under a DNSSEC-published key] proof-of-possession: 'yes for form (1) and guests — the mandate is "bound to the quote and to that key" and the envelope is signed per call' max-ttl: 'guest mandates at most 600 s (health guests.mandate_max_seconds); quote valid 10 minutes; operator-token lifetime not published' single-use: 'mandate jti "never reused: the mandate buys once" — replay refused as mandate_consumed' spending-cap: 'carried in the token/mandate — "a spending cap, a currency and a deadline set by the buyer''s human; a request above the cap is refused, and the refusal is written to the ledger"; guests capped at 1000.00 EUR per purchase' revocation: 'live check of the mandate at its issuer (guest-buyer contract §5; refusal mandate_revoked observed)' escalation: human-in-the-loop: required basis: 'the authority to spend comes from a mandate whose cap, currency and deadline are "set by the buyer''s human"; the merchant does not issue self-service tokens ("issued by this merchant''s operator on request")' triggers: [above-cap, expired-mandate, consumed-mandate, revoked-mandate, unknown-signer, quote-hash-mismatch] audit: required — payment_intent.created and checkout.completed (or request.refused) ledger entries, hash-chained and ES256-signed; receipt_jws returned to the caller; correlation_id joins the chain reversibility: none — no cancel/refund/void operation (see conventions/agenthaven-dev-conventions.yml) dry-run: none — the exercise label "changes nothing about how the call is checked" provider_statements: - 'agent card skills[1]: "Needs the bearer authorization described in securitySchemes.bearer."' - 'docs step 2: "The token carries a spending cap, a currency and a deadline set by the buyer''s human; a request above the cap is refused, and the refusal is written to the ledger."' - 'tools/list create_checkout: "Turns the quote into a payment intent and stops there: no ticket is issued. … Test mode: no real card, no real money."' verification_for_agents: responder_identity: 'every output carries evidence {merchant_id const demo-travel-seller, merchant_domain const travel.agenthaven.dev, agent_card_sha256, signer {spiffe_id, kid, key_url}}; the card digest is pinned in the DNSSEC-signed SVCB record and the signer key in /.well-known/spiffe-bundle.json' third_party_verifiers: [https://provedby.dev]