{"access_pass":{"duration_seconds":86400,"scope":"decision_feed_v1","storage":"Only a hash of the independently random bearer secret, its expiry, and settlement binding are stored in the payer's Durable Object. The raw pass is not stored server-side or in analytics."},"authenticated_test_classification":"X-AgentWork-Traffic-Class is honored only with a separately provisioned X-AgentWork-Test-Key; the test secret is never stored or exported.","caller_attribution":{"not_stored":["raw IP address","full user-agent string","referral path or query","request URL"],"retained_days":90,"stored":["stable HMAC caller pseudonym","optional HMAC client ID","optional client name and version","user-agent family","referral and origin hostnames","country","ASN","Cloudflare colo","route","status","event type","timestamp"]},"catalog_measurement":{"default":"Ordinary public browser traffic counts as outside. Authenticated operator and test traffic plus Cloudflare bot evidence are excluded.","not_stored":["raw IP address","full URL or path or query","full user-agent string","target URL or target query","cookies","browser fingerprint"],"retained_days":30,"session_window_minutes":30,"stored":["UTC day","HMAC session pseudonym","coarse user-agent family","referral hostname","country","traffic class","configuration version","destination class","opaque action ID"],"third_party_code":false,"traffic_classes":["outside","operator","test","bot"]},"optional_headers":["X-AgentWork-Client-Id","X-AgentWork-Client-Name","X-AgentWork-Client-Version","X-AgentWork-Traffic-Class"],"optional_product_analytics":{"enabled_only_when_configured":true,"exported":["vendor-specific HMAC caller and payer pseudonyms","route template","status and lifecycle outcome","coarse latency and result-count buckets","validated filter dimensions","optional client name and version","country","coarsened referral domain","feedback category","fixed-price revenue","explicit test/canary classification"],"never_exported":["raw IP address","full user-agent string","raw search phrase","wallet address","transaction hash","payment header, signature, or proof","access-pass token","exact opportunity ID tied to a caller","feedback text","request URL","credentials or secrets"],"person_profiles":false,"processor":"PostHog US or EU Cloud","retention_requirement_days":90},"paid_attribution":{"not_stored":["payment header","payment proof","raw access pass"],"retained_days":365,"stored":["public payer wallet","public settlement transaction","route","amount","caller and client pseudonyms","optional client name and version","country","timestamp"]},"purpose":"Measure outside usage, repeat callers, acquisition sources, agent integrations, and paid conversion.","service":"AgentWork API"}