HYBRID-CHAINDEVELOPERS
DOCUMENTATIONv2
PATCH

Deterministic execution

Update package

/api/v2/execution/packages/{package_uuid}
AUTHENTICATIONBearer token · execution:writeAUTHORITATIVE OWNERexecution-serviceCONTRACT AUTHORITYCapability registry · plannedSTATUSPlanned · not executable
PLANNING CONTRACT · NOT CALLABLE

This page describes intended capability and integration boundaries so people and agents can prepare safely. Do not send this request or register it as an executable tool. Wait until the capability registry marks it implemented-contract, then re-fetch the deployed OpenAPI document and build the request from that machine contract.

PURPOSE + BUSINESS CONTEXT

Planned capability: update an editable execution package draft.

WHEN THIS CALL IS USEFUL

Do not call or register this operation as an executable agent tool yet. Use this page to plan the future package workflow; enable it only after the status becomes implemented-contract and the exact operation appears in deployed OpenAPI.

OUTCOME · Planned · Revise and reconcile

What changes

None today: this route is not executable. Its intended behavior is: when promoted, creates a new DRAFT revision and invalidates validation derived from prior source, manifest, runtime, capability, or resource commitments. Published versions remain immutable.

WHY IT MATTERS

  • Lets people and agents prepare for package without falsely presenting roadmap scope as a live capability.
  • Gives people and agents a contract-backed way to advance package.
  • Makes package and execution lineage reproducible by exposing the commitments an agent needs to validate before trusting a result.

ISOLATION + AUTHORITY

Package, build, deployment, invocation, node, input, output, and receipt authorities remain distinct. No execution operation may change frozen trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, or traffic controls, and no result grants external-domain authority. This planning record grants no runtime authority, and only deployed OpenAPI can define an executable public contract.

BEFORE YOU CALL

  • First confirm that this operation is marked implemented-contract and exists in the currently deployed OpenAPI document; until then, no production request is valid.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Authenticate at the documented boundary: bearer+scope.
  • Treat the proposed package_uuid (path), expected_version (body), change_summary (body), step_up_token (body) as planning input only; re-generate the request from deployed OpenAPI before making a call.
  • Use one Idempotency-Key only for retries of the same byte-equivalent logical mutation.
  • Resolve the exact artifact, schema, runtime, node, resource, and policy commitments relevant to this stage.

WHAT TO DO NEXT

  • Keep this operation disabled in clients, agents, SDKs, and workflow automation while it remains planned-contract.
  • Use the stated owner, lifecycle, authority boundary, and provisional package profile to prepare requirements and conformance tests without sending a request.
  • Monitor the capability registry for implemented-contract, then re-fetch deployed OpenAPI and validate its exact security, parameters, schemas, responses, and agent metadata before enabling the integration.

AGENT GUIDANCE

  • Never call this planned contract, include it in an executable tool registry, or infer runtime availability from this readable page.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Use package only for the purpose and lifecycle stage described by this operation; do not treat it as authority for an adjacent action.
  • Treat the proposed package_uuid (path), expected_version (body), change_summary (body), step_up_token (body) as planning input only; re-generate the request from deployed OpenAPI before making a call.
  • Keep draft, validation, publication, deployment, activation, invocation admission, execution completion, external effect, receipt, and finality as separate stages.
  • After a timeout or conflict, read authoritative state before deciding whether an equivalent retry is safe.
  • When implementation lands, discard generated requests based on this planning record and rebuild them from the deployed OpenAPI operation.
MACHINE CONTRACT

This operation is a non-executable planning contract. Its capability-registry record defines the intended owner, parameters, responses, and integration boundary until an implemented Rust OpenAPI operation replaces it.

EXTENDED INTEGRATION GUIDANCE

Readable request and response reference

Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.

PARAMETERS

Headers, path, query, and body

NAMELOCATIONPRESENCETYPE / RULES / PURPOSE
AuthorizationheaderRequired

Bearer tokenCredential containing execution:write authority.EXAMPLEBearer hc_live_…

Idempotency-KeyheaderRequired

ASCII string · 1–128Caller-generated stable key reused for retries of the same logical mutation.EXAMPLEpatch-api-v2-execution-packages-package-uuid-request-001

package_uuidpathRequired

identifierCanonical package uuid.EXAMPLEpackage-uuid-01

expected_versionbodyRequired

integer · ≥1Current editable DRAFT version for optimistic concurrency.EXAMPLE2

namebodyOptional

string · 2–120Replacement private package name.EXAMPLEInvoice evidence classifier

descriptionbodyOptional

string · max 1000Replacement non-secret purpose and semantics.EXAMPLEAdds a bounded unknown-category result.

runtime_profile_idbodyOptional

approved immutable runtime profile identifierReplacement build and sandbox profile; changing it invalidates prior validation.EXAMPLEwasm-wasi-deterministic-v1

source_bundle_referencebodyOptional

opaque owner-scoped artifact referenceReplacement immutable source artifact.EXAMPLEartifact_01K5…

source_bundle_sha256bodyOptional

lowercase SHA-256 digestDigest of the replacement canonical archive.EXAMPLE9e6c…64hex

manifestbodyOptional

closed package manifest objectReplacement manifest; any change invalidates prior validation.EXAMPLE[object Object]

declared_capabilitiesbodyOptional

allowlisted capability identifier[] · uniqueReplacement capability request.EXAMPLEdeterministic:compute

resource_policybodyOptional

bounded resource objectReplacement execution ceilings.EXAMPLE[object Object]

change_summarybodyRequired

string · 8–500Attributed revision rationale retained with before/after commitments.EXAMPLEClarify output schema and lock dependencies.

step_up_tokenbodyRequired

purpose-bound tokenFresh EXECUTION_PACKAGE_UPDATE authorization bound to the current version and replacement commitment.EXAMPLEhcsu_…

REQUEST

JSON body example

{
  "expected_version": 2,
  "name": "Invoice evidence classifier",
  "description": "Adds a bounded unknown-category result.",
  "runtime_profile_id": "wasm-wasi-deterministic-v1",
  "source_bundle_reference": "artifact_01K5…",
  "source_bundle_sha256": "9e6c…64hex",
  "manifest": {
    "entrypoint": "classify",
    "input_schema_sha256": "a1b2…",
    "output_schema_sha256": "d5e6…",
    "dependency_lock_sha256": "f7a8…"
  },
  "declared_capabilities": [
    "deterministic:compute"
  ],
  "resource_policy": {
    "cpu_millis": 500,
    "memory_mib": 128,
    "wall_time_ms": 5000,
    "output_bytes": 65536,
    "log_bytes": 16384
  },
  "change_summary": "Clarify output schema and lock dependencies.",
  "step_up_token": "hcsu_…"
}

RESPONSES

Status and payload examples

200Editable DRAFT revised with a new version and commitments; any prior validation is invalidated and no published version changes.Not executable · JSON RESPONSE+
{
  "result": "See the operation's authoritative OpenAPI response schema."
}
INTEGRATION DECISION
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
400A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
401The bearer credential is missing, expired, or invalid.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The bearer credential is missing, expired, or invalid."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
403The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
404The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
409The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
422Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.
503Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from isolated execution plans, simulations, approvals, runs, artifacts, logs, and immutable receipts through an implemented operation.
ESCALATE WHEN
Escalate when execution may have started but no terminal receipt exists, or when inputs, artifacts, isolation, and output commitments disagree.

OPERATIONAL NOTES

Security and lifecycle guarantees

  • The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.
  • Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.
DOCUMENTATION STATUS

This planned contract now defines its public parameters, authorization boundary, replay behavior, responses, and authoritative owner. It remains non-executable until its owner adapter and conformance tests are promoted into the Rust gateway.

Return to the V2 directory