Review permission changes before an agent release
Review permission changes before an agent release. Compare two explicit allow-only sets by tool, action and exact resource; report additions, removals and wildcard additions. Does not resolve IAM inheritance or wildcard containment, or authorize execution.
21000 (raw units)
price
1
calls / 30d
1
unique payers
2026-09-13
updated
Provider
www.mahastrategies.com · discovered, not yet claimed by its owner
Payment (x402 accepts[])
[
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0xec84c1cd6602bbe387bc8e6f0d3c062f2762de28",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "21000",
"maxTimeoutSeconds": 60
}
]Output schema
{
"bazaar": {
"info": {
"input": {
"body": {
"after": [
{
"action": "read",
"resource": "*",
"tool": "files"
}
],
"before": [
{
"action": "read",
"resource": "public/example",
"tool": "files"
}
],
"dataClass": "synthetic"
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"example": {
"amountBaseUnits": "21000",
"boundaries": [
"Public or synthetic inputs only. Caller labels are declarations,…"
],
"inputDigest": "sha256:1f32d39d3ccd205fb32fda243d7fbf9974016d93752fd2c9a3131ff11…",
"offerId": "tool-permission-diff",
"receiptDigest": "sha256:014b323b46aa62cf7e2648d30c831e4ac71dd0be56b81ad9d2e536a1a…",
"result": {
"added": [
{
"action": "read",
"resource": "*",
"tool": "files"
}
],
"effectiveAuthorizationEvaluated": false,
"removed": [
{
"action": "read",
"resource": "public/example",
"tool": "files"
}
],
"wildcardAdditions": [
{
"action": "read",
"resource": "*",
"tool": "files"
}
]
},
"version": "maha-microproducts/0.1"
},
"type": "json"
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"after": {
"maxItems": 50,
"minItems": 0,
"type": "array"
},
"before": {
"maxItems": 50,
"minItems": 0,
"type": "array"
},
"dataClass": {
"enum": [
"public",
"synthetic"
],
"type": "string"
}
},
"required": [
"dataClass",
"before",
"after"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"additionalProperties": false,
"properties": {
"amountBaseUnits": {
"enum": [
"21000"
],
"type": "string"
},
"boundaries": {
"maxItems": 128,
"minItems": 0,
"type": "array"
},
"inputDigest": {
"maxLength": 71,
"type": "string"
},
"offerId": {
"enum": [
"tool-permission-diff"
],
"type": "string"
},
"receiptDigest": {
"maxLength": 71,
"type": "string"
},
"result": {
"type": "object"
},
"version": {
"enum": [
"maha-microproducts/0.1"
],
"type": "string"
}
},
"required": [
"version",
"offerId",
"amountBaseUnits",
"inputDigest",
"result",
"boundaries",
"receiptDigest"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}
},
"declaration-integrity": {
"canonicalResource": "https://www.mahastrategies.com/api/v1/micro/tool-permission-diff",
"declarationDigest": "sha256:9660e04be1ebd4265476d9c57e8d4d1357c284adaec6b78c2a11b4527215de84",
"metadataVersion": "2026-08-10"
},
"maha-offer": {
"amount": "21000",
"asset": "USDC",
"assetDecimals": 6,
"canonicalResource": "https://www.mahastrategies.com/api/v1/micro/tool-permission-diff",
"declarationInline": "compact",
"declarationUrl": "https://www.mahastrategies.com/api/discovery/x402-offers/tool-permission-diff",
"fullSourceTextStored": false,
"maxRequestBytes": 32768,
"method": "POST",
"network": "eip155:8453",
"offerId": "tool-permission-diff",
"payableInProduction": true,
"status": "available",
"verbatimExcerptsRetained": false
}
}Use it
curl
curl "https://www.mahastrategies.com/api/v1/micro/tool-permission-diff" # -> 402 Payment Required, accepts[] lists how to pay # retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://www.mahastrategies.com/api/v1/micro/tool-permission-diff");
if (res.status === 402) {
const { accepts } = await res.json();
// pay one of accepts[] via an x402 client, then retry with the payment header
}Python
import httpx
res = httpx.get("https://www.mahastrategies.com/api/v1/micro/tool-permission-diff")
if res.status_code == 402:
accepts = res.json()["accepts"]
# pay one of accepts[] via an x402 client, then retry with the payment headerMachine-readable
Everything on this page is also available as clean JSON at /resources/1420.json, and this resource appears in /discovery/resources and /discovery/search.