{"access_pass":{"duration_seconds":86400,"scope":"decision_feed_v1","storage":"Only a hash of the independently random bearer secret, its expiry, and settlement binding are stored in the payer's Durable Object. The raw pass is not stored server-side or in analytics."},"agent_identity":{"purpose":"Optionally expose Cloudflare-verified agent provenance without turning caller-supplied identity headers into trust evidence.","retained":false,"trusted_only_when":"Cloudflare Bot Management sets request.cf.botManagement.verifiedBot to true.","untrusted_headers":["Signature-Agent","Forwarded"]},"authenticated_test_classification":"X-AgentWork-Traffic-Class is honored only with a separately provisioned X-AgentWork-Test-Key; the test secret is never stored or exported.","caller_attribution":{"not_stored":["raw IP address","full user-agent string","referral path or query","request URL"],"retained_days":90,"stored":["stable HMAC caller pseudonym","optional HMAC client ID","optional client name and version","user-agent family","referral and origin hostnames","country","ASN","Cloudflare colo","route","status","event type","timestamp"]},"catalog_measurement":{"default":"Ordinary public browser traffic counts as outside. Authenticated operator and test traffic plus Cloudflare bot evidence are excluded.","not_stored":["raw IP address","full URL or path or query","full user-agent string","target URL or target query","cookies","browser fingerprint"],"retained_days":30,"session_window_minutes":30,"stored":["UTC day","HMAC session pseudonym","coarse user-agent family","referral hostname","country","traffic class","configuration version","destination class","opaque action ID"],"third_party_code":false,"traffic_classes":["outside","operator","test","bot"]},"execution_requests":{"access":"The raw request token is returned once and must be supplied in X-AgentWork-Request-Token or the MCP status tool while the temporary request record exists. The active working ciphertext is erased when work becomes terminal; the separately encrypted privacy-safe archive and complete participant and swarm lifecycle remain available only through authenticated operator tracking endpoints. Participant history is not exposed through MCP.","not_stored":["raw reusable password","raw bearer token","raw API key","wallet secret","payment credential","raw IP address","raw request token"],"payment":"Routing is free during the current pilot. A future paid execution offer must disclose price and require explicit selection and authority before any charge or procurement.","purpose":"Accept responsibility for a blocked outcome, get it to an executor, and report acceptance evidence or an honest failure.","retention":"The validated privacy-safe ask, execution lifecycle, result, assignments, attempts, adjudication, and requester outcomes are retained permanently. Temporary request-token hashes, caller fingerprint hashes, idempotency hashes, and rate rows are deleted after 180 days.","secure_input":"Reusable secrets are redacted before permanent storage. The request retains only the secret class and a requirement for a later ephemeral authorized continuation.","stored":["permanent AES-256-GCM encrypted sanitized request","authorized private or public context inside the encrypted brief","authority","deadline","maximum authorized budget","route preference","capability-backed offers","selection","attempts","verification","bounded result and evidence","opt-in participant lifecycle","HMAC daily fingerprint for at most 180 days","hash of the request token for at most 180 days"]},"future_agent_purchasing":{"caveat":"The migration creates an evidence seam only. No runtime route currently writes purchase intents, signs payments, or moves funds.","enabled":false,"endpoint":"/v1/buyer-capabilities","never_store":["wallet private key","wallet signing secret","raw delivered private content"],"storage_if_activated":["bounded purchase intent","recipient hash","provider receipt digest","settlement state","delivery digest"]},"optional_headers":["X-AgentWork-Client-Id","X-AgentWork-Client-Name","X-AgentWork-Client-Version","X-AgentWork-Traffic-Class"],"optional_product_analytics":{"enabled_only_when_configured":true,"exported":["vendor-specific HMAC caller and payer pseudonyms","route template","status and lifecycle outcome","coarse latency and result-count buckets","validated filter dimensions","optional client name and version","country","coarsened referral domain","feedback category","fixed-price revenue","explicit test/canary classification"],"never_exported":["raw IP address","full user-agent string","raw search phrase","wallet address","transaction hash","payment header, signature, or proof","access-pass token","exact opportunity ID tied to a caller","feedback text","request URL","credentials or secrets"],"person_profiles":false,"processor":"PostHog US or EU Cloud","retention_requirement_days":90},"owner_confirmed_escalations":{"analytics":"Agent-reported, qualified, owner-verified, offer-ready, funded, provider-accepted, and owner-accepted counts remain separate. Authenticated self-test, canary, provider, and verifier traffic is excluded from organic demand.","authority":"Owner confirmation is not payment. Provider procurement still requires the displayed procure_execution scope, an offer, and later funding evidence. Discovery, availability, callability, funding, delivery, technical verification, and owner acceptance are separate states.","not_stored":["raw credential","private URL","personal data","unsafe account-access material","raw owner-confirmation token","agent-claimed authority as owner authority","fabricated payment or provider success"],"purpose":"Qualify an agent-reported unfinished job, ask the actual owner to verify the specification and bounded authority, and form an offer only from an exact-fit current capability with known cost and availability.","retention":"The privacy-safe escalation contract, owner-confirmed scope, commercial-offer evidence, and append-only state transitions are retained with the canonical request. Expired and used confirmation-token hashes remain for replay prevention; raw owner tokens are never stored.","stored":["privacy-safe expected artifact","hashes or origins of public attempted-artifact references","owner feedback without personal data, secrets, or URLs","attempt count and elapsed effort","acceptance gates and material constraints","displayed maximum budget and authority","hashed one-time owner token and expiry","owner-confirmed bounded scope","supplier cost, risk allowance, margin, deadline, terms, and evidence tier","separate lifecycle evidence"]},"paid_attribution":{"not_stored":["payment header","payment proof","raw access pass"],"retained_days":365,"stored":["public payer wallet","public settlement transaction","route","amount","caller and client pseudonyms","optional client name and version","country","timestamp"]},"procurement_requests":{"access":"The raw request token is returned once and must be supplied in X-AgentWork-Request-Token to read private status. It is never accepted in a URL.","not_stored":["raw IP address","raw request token","name","email address","phone number","street address","URL","credential","payment method"],"payment":"No payment is collected at submission. 29 USD becomes due only after three currently available quotes satisfy the predeclared acceptance test.","purpose":"Preserve the parked corporate-catering experiment and private status access for any existing requests. It is not the current AgentWork front door.","retained_days":180,"stored":["request type","city and state","needed-by date","budget","headcount","requirements","acceptance test","price acceptance","request state","result JSON","HMAC daily fingerprint","hash of the request token"]},"public_growth_stats":{"endpoint":"/v1/stats","primary_metric_is_a_proxy":true,"purpose":"Expose aggregate qualified-use, funnel, health, and supply-expansion evidence without caller, payer, transaction, or session identifiers."},"purpose":"Measure outside usage, repeat callers, acquisition sources, agent integrations, and paid conversion.","routing_requests":{"access":"The raw request token is returned once and must be supplied in X-AgentWork-Request-Token to read private status or report an outcome. It is never accepted in a URL.","not_stored":["submitted goal","submitted blocker","submitted constraints","submitted acceptance test","raw IP address","raw request token","name","email address","phone number","street address","URL","credential","payment method"],"payment":"No payment is requested or collected during the discovery pilot.","purpose":"Find where a blocked agent outcome can be completed reliably and return one private evidence-backed execution route or an honest no-route result.","retained_days":180,"stored":["terminal input placeholders","optional deadline and budget","frequency","request state","private route result","requester-reported outcome evidence","HMAC daily fingerprint","hash of the request token"]},"service":"AgentWork API"}