{"api":"v1","generated_at":"2026-09-15T22:53:09.383Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/sqlpermit-schemasure-com-v1-guard-sql-a26ee4","pinned_page":"https://tollindex.com/e/sqlpermit-schemasure-com-v1-guard-sql-a26ee4/at/2026-09-15T21-20Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T21:20:12.737Z","snapshot_stamp":"2026-09-15T21-20Z","endpoint":{"slug":"sqlpermit-schemasure-com-v1-guard-sql-a26ee4","canonical_url":"https://sqlpermit.schemasure.com/v1/guard/sql","resource":"https://sqlpermit.schemasure.com/v1/guard/sql","http_method":"POST","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"Decide whether an agent-authored PostgreSQL statement complies with an execution policy, using PostgreSQL's own parser rather than pattern matching. Detects statement stacking, data-modifying CTEs, COPY PROGRAM, privilege changes, and dangerous functions that read as ordinary SELECTs. Returns reason codes and an optional short-lived signed permit bound to the exact normalized statement. Never connects to your database.","service_name":"SQLPermit","declared_category":null,"declared_tags":["sql","postgresql","policy","guard","read-only"],"route_template":null,"registry_updated":"2026-09-15T07:39:58.785Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"guard sql","category":"compute","first_observed_by_toll":"2026-09-10T19:08:24.178Z","last_observed_by_toll":"2026-09-15T21:20:12.737Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-10T19:08:24.178Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"0x9876af0F6D8Ed5155Cd02d1ca56D128601612690","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T21:20:12.737Z","calls_30d":36,"unique_payers_30d":6,"last_called_at":"2026-09-15T07:39:58.538Z"},"validation":{"latest":{"observed_at":"2026-09-15T06:04:29.859Z","state":"pass","failed_checks":[],"endpoint_http_status":402,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":5,"ratio":1},{"days":30,"observed":5,"passed":5,"ratio":1},{"days":90,"observed":5,"passed":5,"ratio":1}],"history_90d":[{"observed_at":"2026-09-15T06:04:29.859Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T05:35:34.327Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T05:29:42.008Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T07:46:36.996Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-11T11:37:37.264Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-11","state_changed":true}]},"seller":{"wallet":"0x9876af0F6D8Ed5155Cd02d1ca56D128601612690","page":"https://tollindex.com/seller/0x9876af0F6D8Ed5155Cd02d1ca56D128601612690","endpoints":6,"hosts":5},"reports":0,"registry_record":{"cdp":[{"tags":["sql","postgresql","policy","guard","read-only"],"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","version":"2"},"payTo":"0x9876af0F6D8Ed5155Cd02d1ca56D128601612690","amount":"10000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":60}],"quality":{"lastCalledAt":"2026-09-15T07:39:58.538Z","l30DaysTotalCalls":36,"l30DaysUniquePayers":6},"resource":"https://sqlpermit.schemasure.com/v1/guard/sql","extensions":{"bazaar":{"info":{"input":{"body":{"sql":"SELECT id, total FROM analytics.orders ORDER BY created_at DESC LIMIT 100","policy":{"max_rows":1000,"read_only":true,"allowed_tables":["analytics.orders"],"allowed_schemas":["analytics"],"allowed_functions":["count","sum","avg"],"allow_multi_statement":false},"dialect":"postgresql","audience":"executor:acme-prod-01","issue_permit":true,"target_pg_major":18},"type":"http","method":"POST","bodyType":"json"},"output":{"type":"json","example":{"ok":true,"result":{"permit":"eyJhbGciOiJFZDI1NTE5Iiwia2lkIjoi…","grammar":"pg18/libpg-query@18.1.4","findings":[],"stmt_hash":"sha256:0f4c1d8e2b7a9c5d3e6f8a1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d","permit_kid":"uGzLTTwi4LTsOiBLgwf2wMU7ILTecj18Y_71Y37bVD8","obligations":{"max_rows":1000,"require_read_only_tx":true,"statement_timeout_ms":30000},"policy_hash":"sha256:2b7a9c5d3e6f8a1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d0f4c1d8e","classification":"read_only","normalized_sql":"SELECT id, total FROM analytics.orders ORDER BY created_at DESC LIMIT 100","statement_count":1,"statement_types":["SelectStmt"],"target_pg_major":18,"stmt_fingerprint":"a1b2c3d4e5f60718","permit_expires_at":"2026-08-03T12:00:45.000Z","referenced_tables":["analytics.orders"],"referenced_schemas":["analytics"],"referenced_functions":[]},"verdict":"pass","evidence":[],"warnings":["stmt_fingerprint is ADVISORY and must not be used for authorization: libpg-query fingerprints discard literal constants, so two statements differing only in a value share one fingerprint. stmt_hash is the binding value."],"confidence":1,"risk_codes":[],"request_hash":"sha256:1c2d0f4c1d8e2b7a9c5d3e6f8a1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b","data_versions":{"parser":"libpg-query@18.1.4","grammar":"pg18/libpg-query@18.1.4","pg_parse_version":"180004"},"policy_version":"sqlpermit-policy-1.0.0"}}},"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","required":["dialect","target_pg_major","sql"],"properties":{"sql":{"type":"string","maxLength":100000,"minLength":1},"policy":{"type":"object","properties":{"max_rows":{"type":"integer","minimum":1,"description":"Row ceiling. Becomes a permit obligation the executor enforces."},"read_only":{"type":"boolean","description":"Reject anything that can change data or schema, including writes reached through a CTE."},"allowed_tables":{"type":"array","items":{"type":"string"},"description":"Permitted relations as schema.table, or a bare name to match an unqualified reference."},"allow_returning":{"type":"boolean","description":"Accept RETURNING on a permitted write without a warning."},"allow_row_locks":{"type":"boolean","description":"Accept SELECT ... FOR UPDATE without a warning."},"allowed_schemas":{"type":"array","items":{"type":"string"},"description":"Schemas the statement may reference."},"allowed_functions":{"type":"array","items":{"type":"string"},"description":"Added to the built-in allowlist. Bare name, or schema.function to admit one of your own."},"allowed_languages":{"type":"array","items":{"type":"string"},"description":"Permitted CREATE FUNCTION languages. Defaults to none."},"statement_timeout_ms":{"type":"integer","minimum":1,"description":"Timeout written into the permit obligations. Defaults to 30000."},"allow_multi_statement":{"type":"boolean","description":"Permit more than one statement in the input. Defaults to false."}},"additionalProperties":false},"dialect":{"enum":["postgresql"],"type":"string"},"subject":{"type":"string","description":"Opaque caller label recorded as the permit subject."},"audience":{"type":"string","description":"Identity of the ONE executor the permit is for. Required when issue_permit is true. Wildcards are rejected."},"issue_permit":{"type":"boolean"},"target_pg_major":{"enum":[18],"type":"integer","description":"Required. The PostgreSQL major the statement will run on. Only 18 is supported in v1: a permit issued under one grammar and verified against another is a parser differential."}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["ok","verdict","confidence","risk_codes","evidence","result","policy_version","request_hash","data_versions","warnings"],"properties":{"ok":{"type":"boolean"},"result":{"type":"object","required":["statement_count","statement_types","referenced_schemas","referenced_tables","referenced_functions","classification","findings","normalized_sql","stmt_hash","stmt_fingerprint","policy_hash","grammar","target_pg_major","obligations"],"properties":{"permit":{"type":"string","description":"Compact JWS. Present only when requested and the verdict is not block."},"grammar":{"type":"string"},"findings":{"type":"array","items":{"type":"object","required":["code","severity","detail","disposition"],"properties":{"code":{"type":"string","description":"Stable reason code, e.g. DATA_MODIFYING_CTE."},"data":{"type":"object"},"span":{"type":"object","properties":{"end":{"type":"integer"},"start":{"type":"integer"}}},"detail":{"type":"string"},"source":{"type":"string"},"severity":{"enum":["info","low","medium","high","critical"],"type":"string"},"disposition":{"enum":["block","warn","info"],"type":"string"}}}},"stmt_hash":{"type":"string","description":"BINDING. sha256 of normalized_sql. The executor recomputes this from the statement it is about to run."},"permit_kid":{"type":"string"},"obligations":{"type":"object","required":["max_rows","statement_timeout_ms","require_read_only_tx"],"properties":{"max_rows":{"type":["integer","null"]},"require_read_only_tx":{"type":"boolean"},"statement_timeout_ms":{"type":"integer"}}},"policy_hash":{"type":"string"},"classification":{"enum":["read_only","write","ddl","mixed"],"type":"string"},"normalized_sql":{"type":"string","description":"Deparsed canonical statement. This, not your original text, is what a permit binds."},"statement_count":{"type":"integer"},"statement_types":{"type":"array","items":{"type":"string"}},"target_pg_major":{"type":"integer"},"stmt_fingerprint":{"type":"string","description":"ADVISORY ONLY — never authorize on this. libpg-query fingerprints discard literal constants, so 'WHERE id = 1' and 'WHERE id = 999999' share one fingerprint."},"permit_expires_at":{"type":"string"},"referenced_tables":{"type":"array","items":{"type":"string"}},"referenced_schemas":{"type":"array","items":{"type":"string"}},"referenced_functions":{"type":"array","items":{"type":"string"}}}},"verdict":{"enum":["pass","warn","block"],"type":"string"},"evidence":{"type":"array","items":{"type":"object","required":["code","severity","detail","disposition"],"properties":{"code":{"type":"string","description":"Stable reason code, e.g. DATA_MODIFYING_CTE."},"data":{"type":"object"},"span":{"type":"object","properties":{"end":{"type":"integer"},"start":{"type":"integer"}}},"detail":{"type":"string"},"source":{"type":"string"},"severity":{"enum":["info","low","medium","high","critical"],"type":"string"},"disposition":{"enum":["block","warn","info"],"type":"string"}}}},"warnings":{"type":"array","items":{"type":"string"}},"confidence":{"type":"number"},"risk_codes":{"type":"array","items":{"type":"string"}},"request_hash":{"type":"string"},"data_versions":{"type":"object"},"policy_version":{"type":"string"}}}}}}}}},"description":"Decide whether an agent-authored PostgreSQL statement complies with an execution policy, using PostgreSQL's own parser rather than pattern matching. Detects statement stacking, data-modifying CTEs, COPY PROGRAM, privilege changes, and dangerous functions that read as ordinary SELECTs. Returns reason codes and an optional short-lived signed permit bound to the exact normalized statement. Never connects to your database.","lastUpdated":"2026-09-15T07:39:58.785Z","serviceName":"SQLPermit","x402Version":2}]}}