# Interface contract verification

**Result: 256/256 checks passed; 0 failed.**

Checked shared/tool JSON Schemas, 20 synthetic operation vectors, required fields, REST/MCP mapping equality, local OpenAPI references, error mappings and selected lifecycle/chunk rejections. The OpenAPI mapping was checked structurally against the catalog; no full OpenAPI meta-validator or live protocol suite was run.

No HTTP server, OAuth provider, MCP client, physical command, request store or event replay was executed. The MCP example illustrates pinned 2026-07-28 wire fields; interoperability and I01-I12 remain implementation acceptance obligations.


# Checks

- PASS: 17 unique MCP tools
- PASS: 20 unique REST operations
- PASS: MCP matching protocol metadata
- PASS: MCP structured/text result agreement
- PASS: Stored fixture agrees: interface/0.1.0/examples/mcp-start-exchange.json
- PASS: Stored fixture agrees: interface/0.1.0/examples/operation-vectors.json
- PASS: absent record cannot imply complete evidence
- PASS: administration absent from MCP
- PASS: altered document bytes fail digest
- PASS: artifact_read MCP/REST input parity
- PASS: artifact_read MCP/REST output parity
- PASS: artifact_read OpenAPI mapping
- PASS: artifact_read inputSchema meta-schema
- PASS: artifact_read outputSchema meta-schema
- PASS: artifact_read positive input
- PASS: artifact_read positive output
- PASS: artifact_read rejects principal body injection
- PASS: artifact_read requires artifact_id
- PASS: artifact_read requires length
- PASS: artifact_read requires offset
- PASS: bench_get MCP/REST input parity
- PASS: bench_get MCP/REST output parity
- PASS: bench_get OpenAPI mapping
- PASS: bench_get inputSchema meta-schema
- PASS: bench_get outputSchema meta-schema
- PASS: bench_get positive input
- PASS: bench_get positive output
- PASS: bench_get rejects principal body injection
- PASS: bench_get requires bench_id
- PASS: bench_list MCP/REST input parity
- PASS: bench_list MCP/REST output parity
- PASS: bench_list OpenAPI mapping
- PASS: bench_list inputSchema meta-schema
- PASS: bench_list outputSchema meta-schema
- PASS: bench_list positive input
- PASS: bench_list positive output
- PASS: bench_list rejects principal body injection
- PASS: bench_list requires cursor
- PASS: bench_list requires limit
- PASS: change_apply OpenAPI mapping
- PASS: change_apply positive input
- PASS: change_apply positive output
- PASS: change_apply rejects principal body injection
- PASS: change_apply requires approval_ref
- PASS: change_apply requires change_id
- PASS: change_apply requires expected_generation
- PASS: change_apply requires request_id
- PASS: change_get OpenAPI mapping
- PASS: change_get positive input
- PASS: change_get positive output
- PASS: change_get rejects principal body injection
- PASS: change_get requires change_id
- PASS: change_submit OpenAPI mapping
- PASS: change_submit positive input
- PASS: change_submit positive output
- PASS: change_submit rejects principal body injection
- PASS: change_submit requires bench_id
- PASS: change_submit requires expected_generation
- PASS: change_submit requires kind
- PASS: change_submit requires reason
- PASS: change_submit requires request_id
- PASS: change_submit requires target_ref
- PASS: device_get MCP/REST input parity
- PASS: device_get MCP/REST output parity
- PASS: device_get OpenAPI mapping
- PASS: device_get inputSchema meta-schema
- PASS: device_get outputSchema meta-schema
- PASS: device_get positive input
- PASS: device_get positive output
- PASS: device_get rejects principal body injection
- PASS: device_get requires bench_id
- PASS: device_get requires device_id
- PASS: device_list MCP/REST input parity
- PASS: device_list MCP/REST output parity
- PASS: device_list OpenAPI mapping
- PASS: device_list inputSchema meta-schema
- PASS: device_list outputSchema meta-schema
- PASS: device_list positive input
- PASS: device_list positive output
- PASS: device_list rejects principal body injection
- PASS: device_list requires bench_id
- PASS: device_list requires cursor
- PASS: device_list requires limit
- PASS: document exact bytes digest
- PASS: document parsed and original bytes agree
- PASS: document_get MCP/REST input parity
- PASS: document_get MCP/REST output parity
- PASS: document_get OpenAPI mapping
- PASS: document_get inputSchema meta-schema
- PASS: document_get outputSchema meta-schema
- PASS: document_get positive input
- PASS: document_get positive output
- PASS: document_get rejects principal body injection
- PASS: document_get requires sha256
- PASS: error conflict OpenAPI status
- PASS: error conflict structure
- PASS: error cursor_expired OpenAPI status
- PASS: error cursor_expired structure
- PASS: error event_gap OpenAPI status
- PASS: error event_gap structure
- PASS: error forbidden OpenAPI status
- PASS: error forbidden structure
- PASS: error gone OpenAPI status
- PASS: error gone structure
- PASS: error internal_error OpenAPI status
- PASS: error internal_error structure
- PASS: error invalid_request OpenAPI status
- PASS: error invalid_request structure
- PASS: error not_found OpenAPI status
- PASS: error not_found structure
- PASS: error not_ready OpenAPI status
- PASS: error not_ready structure
- PASS: error payload_too_large OpenAPI status
- PASS: error payload_too_large structure
- PASS: error policy_denied OpenAPI status
- PASS: error policy_denied structure
- PASS: error rate_limited OpenAPI status
- PASS: error rate_limited structure
- PASS: error unauthenticated OpenAPI status
- PASS: error unauthenticated structure
- PASS: error unavailable OpenAPI status
- PASS: error unavailable structure
- PASS: events_get MCP/REST input parity
- PASS: events_get MCP/REST output parity
- PASS: events_get OpenAPI mapping
- PASS: events_get inputSchema meta-schema
- PASS: events_get outputSchema meta-schema
- PASS: events_get positive input
- PASS: events_get positive output
- PASS: events_get rejects principal body injection
- PASS: events_get requires after
- PASS: events_get requires bench_id
- PASS: events_get requires limit
- PASS: evidence_get MCP/REST input parity
- PASS: evidence_get MCP/REST output parity
- PASS: evidence_get OpenAPI mapping
- PASS: evidence_get inputSchema meta-schema
- PASS: evidence_get outputSchema meta-schema
- PASS: evidence_get positive input
- PASS: evidence_get positive output
- PASS: evidence_get rejects principal body injection
- PASS: evidence_get requires evidence_id
- PASS: gateway_info MCP/REST input parity
- PASS: gateway_info MCP/REST output parity
- PASS: gateway_info OpenAPI mapping
- PASS: gateway_info inputSchema meta-schema
- PASS: gateway_info outputSchema meta-schema
- PASS: gateway_info positive input
- PASS: gateway_info positive output
- PASS: gateway_info rejects principal body injection
- PASS: lease_create MCP/REST input parity
- PASS: lease_create MCP/REST output parity
- PASS: lease_create OpenAPI mapping
- PASS: lease_create inputSchema meta-schema
- PASS: lease_create outputSchema meta-schema
- PASS: lease_create positive input
- PASS: lease_create positive output
- PASS: lease_create rejects principal body injection
- PASS: lease_create requires bench_id
- PASS: lease_create requires duration_ms
- PASS: lease_create requires expected_generation
- PASS: lease_create requires request_id
- PASS: lease_release MCP/REST input parity
- PASS: lease_release MCP/REST output parity
- PASS: lease_release OpenAPI mapping
- PASS: lease_release inputSchema meta-schema
- PASS: lease_release outputSchema meta-schema
- PASS: lease_release positive input
- PASS: lease_release positive output
- PASS: lease_release rejects principal body injection
- PASS: lease_release requires lease_id
- PASS: lease_release requires reason
- PASS: lease_release requires request_id
- PASS: lease_renew MCP/REST input parity
- PASS: lease_renew MCP/REST output parity
- PASS: lease_renew OpenAPI mapping
- PASS: lease_renew inputSchema meta-schema
- PASS: lease_renew outputSchema meta-schema
- PASS: lease_renew positive input
- PASS: lease_renew positive output
- PASS: lease_renew rejects principal body injection
- PASS: lease_renew requires duration_ms
- PASS: lease_renew requires lease_id
- PASS: lease_renew requires request_id
- PASS: lease_renew requires sequence
- PASS: local OpenAPI reference interface.schema.json#/\$defs/bench
- PASS: local OpenAPI reference interface.schema.json#/\$defs/change
- PASS: local OpenAPI reference interface.schema.json#/\$defs/device
- PASS: local OpenAPI reference interface.schema.json#/\$defs/event
- PASS: local OpenAPI reference interface.schema.json#/\$defs/failure
- PASS: local OpenAPI reference interface.schema.json#/\$defs/lease
- PASS: local OpenAPI reference interface.schema.json#/\$defs/limits
- PASS: local OpenAPI reference interface.schema.json#/\$defs/run
- PASS: no self-approval Boolean
- PASS: nonterminal cannot claim pass
- PASS: reject invalid chunk length 0
- PASS: reject invalid chunk length 65537
- PASS: reject invalid chunk offset -1
- PASS: reject invalid chunk offset 9007199254740992
- PASS: run_cancel MCP/REST input parity
- PASS: run_cancel MCP/REST output parity
- PASS: run_cancel OpenAPI mapping
- PASS: run_cancel inputSchema meta-schema
- PASS: run_cancel outputSchema meta-schema
- PASS: run_cancel positive input
- PASS: run_cancel positive output
- PASS: run_cancel rejects principal body injection
- PASS: run_cancel requires reason
- PASS: run_cancel requires request_id
- PASS: run_cancel requires run_id
- PASS: run_check MCP/REST input parity
- PASS: run_check MCP/REST output parity
- PASS: run_check OpenAPI mapping
- PASS: run_check inputSchema meta-schema
- PASS: run_check outputSchema meta-schema
- PASS: run_check positive input
- PASS: run_check positive output
- PASS: run_check rejects principal body injection
- PASS: run_check requires bench_id
- PASS: run_check requires binding_ref
- PASS: run_find MCP/REST input parity
- PASS: run_find MCP/REST output parity
- PASS: run_find OpenAPI mapping
- PASS: run_find inputSchema meta-schema
- PASS: run_find outputSchema meta-schema
- PASS: run_find positive input
- PASS: run_find positive output
- PASS: run_find rejects principal body injection
- PASS: run_find requires request_id
- PASS: run_get MCP/REST input parity
- PASS: run_get MCP/REST output parity
- PASS: run_get OpenAPI mapping
- PASS: run_get inputSchema meta-schema
- PASS: run_get outputSchema meta-schema
- PASS: run_get positive input
- PASS: run_get positive output
- PASS: run_get rejects principal body injection
- PASS: run_get requires run_id
- PASS: run_start MCP/REST input parity
- PASS: run_start MCP/REST output parity
- PASS: run_start OpenAPI mapping
- PASS: run_start inputSchema meta-schema
- PASS: run_start outputSchema meta-schema
- PASS: run_start positive input
- PASS: run_start positive output
- PASS: run_start rejects principal body injection
- PASS: run_start requires bench_id
- PASS: run_start requires binding_ref
- PASS: run_start requires expected_generation
- PASS: run_start requires lease_id
- PASS: run_start requires request_id
- PASS: shared Draft 2020-12 schema
- PASS: storage gap can report terminal uncertainty
- PASS: storage gap cannot report pass
- PASS: terminal pass needs verified safety
- PASS: terminal requires outcome and record
