{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
    "entity_slug": "cloudflare",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4x62a9z5fqb4kvp1hme",
      "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
      "scope": {
        "product": {
          "key": "cloudflare-developer-platform",
          "name": "Cloudflare Developer Platform"
        },
        "funnel": {
          "key": "api-resource-management",
          "name": "API resource management"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:cddeb11506db30b6ffb13fcff407b1931f123a1eb2cc8edf5ca023ba03c71100"
      },
      "declaration_revision_digest": "sha256:fbf85e0aea60781614317b6de681b432139b970c7f589452085a3a183310807b",
      "declaration": {
        "declaration_id": "declaration_cloudflare_api_resource_management",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/cl/cloudflare.yaml",
          "git_blob_oid": "4499cb0c38945f75501557dd38021a37d46c2f87",
          "blob_digest": "sha256:55def0b3b8a18e6566c98d0ba1f514659988fd9dad49d001a7125194470f8948"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Upload and manage Cloudflare Worker scripts through the API",
            "interface_ids": [
              "resource-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "cloudflare",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "api-errors",
            "uri": "https://developers.cloudflare.com/fundamentals/api/troubleshooting/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "api-limits",
            "uri": "https://developers.cloudflare.com/fundamentals/api/reference/limits/",
            "roles": [
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "api-reference",
            "uri": "https://developers.cloudflare.com/api/typescript/resources/workers/subresources/scripts/methods/update",
            "roles": [
              "discovery",
              "documentation",
              "operations",
              "provisioning"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "api-tokens",
            "uri": "https://developers.cloudflare.com/fundamentals/api/get-started/create-token/",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://developers.cloudflare.com/billing/get-started/create-billing-profile/",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "dashboard-signup",
            "uri": "https://dash.cloudflare.com/sign-up",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "plans",
            "uri": "https://www.cloudflare.com/plans/",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-6b1ec9edf6e5bc9be8277ad21ed6b287369ef3921b9c2e9d3e880f4b575bf7c9",
            "uri": "https://developers.cloudflare.com/billing",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-ad6794a9ae3bd4ff2735c8265a155b678454af08c375d85510b9b8fa1fe2753c",
            "uri": "https://developers.cloudflare.com/fundamentals/setup/account/login",
            "roles": [
              "access",
              "documentation"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342",
            "uri": "https://developers.cloudflare.com/workers/versions-and-deployments/index.md",
            "roles": [
              "documentation",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://www.cloudflare.com/terms/",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://developers.cloudflare.com/support/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "cloudflare-api",
            "uri": "https://api.cloudflare.com/client/v4",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "endpoint_id": "registration",
            "uri": "https://dash.cloudflare.com/sign-up",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "api-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [],
            "resource_ids": [
              "api-tokens"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          },
          {
            "interface_id": "resource-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "cloudflare-api"
            ],
            "resource_ids": [
              "api-errors",
              "api-limits",
              "api-reference"
            ],
            "operated_by_participant_id": "cloudflare",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "errors-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "reference-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "relation-describes-225c96c782ab756fb616d37d053e0fd7f9b4f86e55f67726f3184979e08c37a3",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "dashboard-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "separate-eligibility-resource",
            "role": "eligibility",
            "rationale": "Applicable access conditions are published within the service terms; no separate eligibility resource is declared."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:a698fc22baea686a28ff862dd451eb76d2419bf12bb09a3f696acdc44c7b2741",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "C+",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "evaluate",
        "stage_label": "Evaluate",
        "public_state": "limited",
        "finding": {
          "signal_code": "eligibility_decidability",
          "condition": "Can an agent decide every material eligibility condition before commitment?",
          "finding": "Only some material eligibility conditions are decidable before commitment.",
          "context": "The Self-Serve Subscription Agreement explicitly establishes that if an individual enters into the agreement on behalf of a company, organization, or another legal entity, they represent to Cloudflare that they have the authority to bind such entity."
        }
      },
      "limitations": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "The Self-Serve Subscription Agreement explicitly establishes that if an individual enters into the agreement on behalf of a company, organization, or another legal entity, they represent to Cloudflare that they have the authority to bind such entity."
          },
          "remediation": {
            "signal_code": "eligibility_decidability",
            "code": "improve.evaluate.eligibility_decidability",
            "instruction": "State every material eligibility condition and required input explicitly."
          }
        },
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "pricing_decidability",
            "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
            "finding": "The pricing model is visible but omits a material variable or condition.",
            "context": "Cloudflare provides explicit pricing plans including Free ($0/month) and paid plans in USD, and notes that Workers compute is free to try, but complete usage-based variables or rate conditions for Workers are omitted in the capture."
          },
          "remediation": {
            "signal_code": "pricing_decidability",
            "code": "improve.evaluate.pricing_decidability",
            "instruction": "Publish readable complete pricing or explicit no-charge status and conditions."
          }
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Cloudflare provides API tokens with customizable permissions, resource access, and client IP filtering, but token secrets are generated in the dashboard and shown only once, requiring manual copying."
          },
          "remediation": {
            "signal_code": "delegated_identity_access",
            "code": "improve.sign_up.delegated_identity_access",
            "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Cloudflare API tokens generate a secret upon creation in the dashboard. The secret is only displayed once to the user to copy, requiring manual transfer."
          },
          "remediation": {
            "signal_code": "access_material_delivery",
            "code": "improve.provision.access_material_delivery",
            "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "provisioning_completion",
            "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
            "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
            "context": "Workers versions and deployments expose immutable version identity and active deployment state, but the retained evidence does not fully establish bounded failure reconciliation."
          },
          "remediation": {
            "signal_code": "provisioning_completion",
            "code": "improve.provision.provisioning_completion",
            "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "operation_contract",
            "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
            "finding": "The operation contract omits a material operation, field, or effect.",
            "context": "Cloudflare documentation defines REST endpoint paths, request bodies, query costs, rate limits, and verification responses across Worker script upload, troubleshooting, and rate limit references. However, complete input/output schema definitions and effect semantics for all targets are not fully captured."
          },
          "remediation": {
            "signal_code": "operation_contract",
            "code": "improve.operate.operation_contract",
            "instruction": "Document stable inputs, outputs, effects, and target coverage for essential operations."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Cloudflare documents API token troubleshooting and verification responses including status codes and error messages, but does not fully establish safe retry, idempotency, cancellation, or reconciliation semantics."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Cloudflare API documentation describes token creation, setting permissions, TTL, client IP filtering, editing existing tokens, and rolling tokens. It leaves full programmatic recovery and compromise handling details unevidenced in this excerpt."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "The Self-Serve Subscription Agreement explicitly establishes that if an individual enters into the agreement on behalf of a company, organization, or another legal entity, they represent to Cloudflare that they have the authority to bind such entity."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "The pricing model is visible but omits a material variable or condition.",
              "context": "Cloudflare provides explicit pricing plans including Free ($0/month) and paid plans in USD, and notes that Workers compute is free to try, but complete usage-based variables or rate conditions for Workers are omitted in the capture."
            },
            {
              "signal_code": "service_discovery",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "context": "The exact service and stable API entrypoints are discoverable via the Cloudflare API reference, which lists specific methods and endpoints such as Upload Worker Module under Account & User Management."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "Applicable commitment terms are retrievable and readable through the Self-Serve Subscription Agreement, which explicitly specifies that the authoritative English version at www.cloudflare.com/terms governs the use of Cloudflare Services."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.317Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:23e8f81c7c4d1f2030b09cf86a3f1b922de3746d2843c71026e8a73e42d55871",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2854ac9685b840e9ad804ef9377d6f473fed7fae6ac7bf51ba3f7ff18738c6ad",
                    "sha256:45025f32a295a35c501b67a7ceb032aaee921e5336f919b05a5ebcbd20102853",
                    "sha256:53a81488eef5ad279c22e80ecc4cfc63ea6be4d1353b51fa5b2f9ca9c9b0f832",
                    "sha256:df46fcd8b4d2bdb37f1e856b5d3157cc7bd0e4c76e3700a1b167cca5115e2af2"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2854ac9685b840e9ad804ef9377d6f473fed7fae6ac7bf51ba3f7ff18738c6ad",
                      "start_byte": 17778,
                      "end_byte": 18606,
                      "value_digest": "sha256:3372c950e10cdb73cae578274376fb2186b5f55951d9f36b6917e13e398c3eb2"
                    }
                  ]
                }
              ],
              "note": "The Self-Serve Subscription Agreement explicitly establishes that if an individual enters into the agreement on behalf of a company, organization, or another legal entity, they represent to Cloudflare that they have the authority to bind such entity.",
              "remediation": {
                "signal_code": "eligibility_decidability",
                "code": "improve.evaluate.eligibility_decidability",
                "instruction": "State every material eligibility condition and required input explicitly."
              }
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "The pricing model is visible but omits a material variable or condition.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:16.207Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "plans"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8b3b90434e29ec626779436e6682d9772902cfc26439b52dc1077079d391a4c1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:51df2590101b4fba742f26427885173d642eaab2de6c7e31ff573bf35a071ec9",
                    "sha256:906db4e9293dd7034f6cd8e1e69ac363977bcb387a6700b53ad39070f7b4ae30",
                    "sha256:b897602b3ac0cd558752087abdcab82a127d4557eaf155ed8733c73778828435",
                    "sha256:e7f14098012d3cefcaf2278aadeb86ff0fe141a469375fe19b42c0d15b6d87f4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "plans"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b897602b3ac0cd558752087abdcab82a127d4557eaf155ed8733c73778828435",
                      "start_byte": 9233,
                      "end_byte": 10023,
                      "value_digest": "sha256:823193ff715baf5da9ce1ed17e092ae6eb1d56962b3909469eff6a3a1148e3a0"
                    }
                  ]
                }
              ],
              "note": "Cloudflare provides explicit pricing plans including Free ($0/month) and paid plans in USD, and notes that Workers compute is free to try, but complete usage-based variables or rate conditions for Workers are omitted in the capture.",
              "remediation": {
                "signal_code": "pricing_decidability",
                "code": "improve.evaluate.pricing_decidability",
                "instruction": "Publish readable complete pricing or explicit no-charge status and conditions."
              }
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:04.846Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-reference"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:72c95d07377e4176471827585e15324e91d495abaf1ad57085d4e2717d028699",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1463d5332989fbad37f4f2f1cdd973ade83a7e310cc325074ea5c060020bce14",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:ad43b099c64fec7ea3c1a30cf2b5fe54e459513e3837e8fa614995e616fac780",
                    "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20",
                      "start_byte": 387941,
                      "end_byte": 388735,
                      "value_digest": "sha256:72795bfe5f36326ddc104e359a5f0a5b5dcde1cf8c4d1f5188221fddb7ea4777"
                    }
                  ]
                }
              ],
              "note": "The exact service and stable API entrypoints are discoverable via the Cloudflare API reference, which lists specific methods and endpoints such as Upload Worker Module under Account & User Management."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.317Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:23e8f81c7c4d1f2030b09cf86a3f1b922de3746d2843c71026e8a73e42d55871",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2854ac9685b840e9ad804ef9377d6f473fed7fae6ac7bf51ba3f7ff18738c6ad",
                    "sha256:293a326de607aabff56a73c0da161a17bb5c593e074cda8575d538c1bd691eee",
                    "sha256:45025f32a295a35c501b67a7ceb032aaee921e5336f919b05a5ebcbd20102853",
                    "sha256:53a81488eef5ad279c22e80ecc4cfc63ea6be4d1353b51fa5b2f9ca9c9b0f832"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2854ac9685b840e9ad804ef9377d6f473fed7fae6ac7bf51ba3f7ff18738c6ad",
                      "start_byte": 18607,
                      "end_byte": 19410,
                      "value_digest": "sha256:64ab803d661fc83933d694e82f6fbc3029f548cc8957d91af0547701ee7add77"
                    },
                    {
                      "artifact_digest": "sha256:2854ac9685b840e9ad804ef9377d6f473fed7fae6ac7bf51ba3f7ff18738c6ad",
                      "start_byte": 49075,
                      "end_byte": 49875,
                      "value_digest": "sha256:9324a652aff410c2535ebee29e8cee8180b39a47afc83e802b07441cba541550"
                    }
                  ]
                }
              ],
              "note": "Applicable commitment terms are retrievable and readable through the Self-Serve Subscription Agreement, which explicitly specifies that the authoritative English version at www.cloudflare.com/terms governs the use of Cloudflare Services."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "eligibility_decidability",
              "code": "improve.evaluate.eligibility_decidability",
              "instruction": "State every material eligibility condition and required input explicitly."
            },
            {
              "signal_code": "pricing_decidability",
              "code": "improve.evaluate.pricing_decidability",
              "instruction": "Publish readable complete pricing or explicit no-charge status and conditions."
            }
          ]
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Cloudflare provides API tokens with customizable permissions, resource access, and client IP filtering, but token secrets are generated in the dashboard and shown only once, requiring manual copying."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured endpoint for sign-up returned a security verification page (Ray ID: a2e1a4323cfaf753) preventing direct observation or explicit documentation of sign-up form controls."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The current public capture encountered an access-control response, but one observation cannot establish whether CAPTCHA is a durable agent barrier."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence does not establish whether phone verification is required, absent, or resumable for account setup."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "context": "Cloudflare Fundamentals documentation provides a stable canonical route to access the Cloudflare dashboard and sign in using email/password, SSO, or social login options."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:12.248Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured endpoint for sign-up returned a security verification page (Ray ID: a2e1a4323cfaf753) preventing direct observation or explicit documentation of sign-up form controls."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:06.695Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ad6794a9ae3bd4ff2735c8265a155b678454af08c375d85510b9b8fa1fe2753c"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bbad0af8264a1d75187bc66183ad9a55504e9fe35636d0db9b9e0dd9443d013e",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:5824a99e258a115614543cda3d6657e55071eea2d1f0483bd5be6acb20c2f1d2",
                    "sha256:651dd5bfb6b603f3f44a51f74bb56fbd5e39ea0a0e23e7686ccc4928003cf4e4",
                    "sha256:99432c4172c56f9c94abd9326f2ef97802c0a66313ef7c9bf45f12965439491c",
                    "sha256:ad26e8505136af73c1c4b058106f177865752b6cdc48ac1bbb8a9b0089fac2aa",
                    "sha256:e0859621877c909a4e17777290cb7b15c9ea9c84a0f2cb6515081dabbad72bf8",
                    "sha256:eb7903da8110848b7c54f83c7882dba14dfbc05fd274717027f53eb30ba27742"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:651dd5bfb6b603f3f44a51f74bb56fbd5e39ea0a0e23e7686ccc4928003cf4e4",
                      "start_byte": 17988,
                      "end_byte": 18802,
                      "value_digest": "sha256:ebedfcb28b2358f0de5b4f19dee30f456ff4e5c191914d1341f49f83c16378a5"
                    },
                    {
                      "artifact_digest": "sha256:651dd5bfb6b603f3f44a51f74bb56fbd5e39ea0a0e23e7686ccc4928003cf4e4",
                      "start_byte": 0,
                      "end_byte": 801,
                      "value_digest": "sha256:159bcdd90e5312af00deb74d7816ae27193ce6dcb6552cefb93fab59e974bf83"
                    }
                  ]
                }
              ],
              "note": "Cloudflare Fundamentals documentation provides a stable canonical route to access the Cloudflare dashboard and sign in using email/password, SSO, or social login options."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:06.695Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ad6794a9ae3bd4ff2735c8265a155b678454af08c375d85510b9b8fa1fe2753c"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The current public capture encountered an access-control response, but one observation cannot establish whether CAPTCHA is a durable agent barrier."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:11.478Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:6f4b0eae4ea601b699b9dbbac241f8aea1b1e3c1c344d81f027b54ffe4e332e2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:33579efe341ac65295029f3117d515d458a8748c5b7cd412587861ffe00f7331",
                    "sha256:7a294831bb8c00a8ae5e3ec91e175438942cb08c0375e417f6600a2704370a22",
                    "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                    "sha256:f0c5186fd18d943e738b2300f8f94cfc245728a51d200fd41cf859ec4d847dd6"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 17686,
                      "end_byte": 18505,
                      "value_digest": "sha256:7e5766559b224dbee2b4f101536e5f72fc8135ce664815c7ae225ee6435cecdd"
                    },
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 19307,
                      "end_byte": 20105,
                      "value_digest": "sha256:4ecffc4238770a3554f78225294f8b662ce3cd181b98a7a4950626ad553faf2a"
                    }
                  ]
                }
              ],
              "note": "Cloudflare provides API tokens with customizable permissions, resource access, and client IP filtering, but token secrets are generated in the dashboard and shown only once, requiring manual copying.",
              "remediation": {
                "signal_code": "delegated_identity_access",
                "code": "improve.sign_up.delegated_identity_access",
                "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
              }
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:12.248Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ad6794a9ae3bd4ff2735c8265a155b678454af08c375d85510b9b8fa1fe2753c"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained evidence does not establish whether phone verification is required, absent, or resumable for account setup."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "delegated_identity_access",
              "code": "improve.sign_up.delegated_identity_access",
              "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
            }
          ]
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Cloudflare explicitly discloses commercial commitments for its plans and products, including Free ($0/month), Pro ($20/mo billed annually or $25/mo billed monthly), Business ($200/mo billed annually or $250/mo billed monthly), and usage-based rates such as Workers at $0.30 per million requests and $0.02 per million CPU ms."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Documentation describes adding a primary payment method in the dashboard, but does not document an end-to-end flow for an agent to deterministically construct checkout, hand off approval safely, and resume."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Documentation details adding card or wallet payment details and completing 3D Secure authentication, but current evidence does not document a scoped delegation rail or explicit human-authorization mechanism with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "Cloudflare documents direct self-service paths to change domain plans, upgrade subscriptions, and manage paid add-on services directly through the Cloudflare dashboard without requiring sales intervention."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:23.948Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-6b1ec9edf6e5bc9be8277ad21ed6b287369ef3921b9c2e9d3e880f4b575bf7c9"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "Documentation describes adding a primary payment method in the dashboard, but does not document an end-to-end flow for an agent to deterministically construct checkout, hand off approval safely, and resume."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:16.207Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "plans"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8b3b90434e29ec626779436e6682d9772902cfc26439b52dc1077079d391a4c1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:8c5e6f785007ce92ec4f1900f0dd98f998a66882e92354f4c49c741faff765bc",
                    "sha256:906db4e9293dd7034f6cd8e1e69ac363977bcb387a6700b53ad39070f7b4ae30",
                    "sha256:b897602b3ac0cd558752087abdcab82a127d4557eaf155ed8733c73778828435",
                    "sha256:e7f14098012d3cefcaf2278aadeb86ff0fe141a469375fe19b42c0d15b6d87f4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "plans"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b897602b3ac0cd558752087abdcab82a127d4557eaf155ed8733c73778828435",
                      "start_byte": 9233,
                      "end_byte": 10023,
                      "value_digest": "sha256:823193ff715baf5da9ce1ed17e092ae6eb1d56962b3909469eff6a3a1148e3a0"
                    },
                    {
                      "artifact_digest": "sha256:b897602b3ac0cd558752087abdcab82a127d4557eaf155ed8733c73778828435",
                      "start_byte": 12406,
                      "end_byte": 13199,
                      "value_digest": "sha256:90e3e6ec6b4a61bd628fe4de348cd3172ff410b3093f0fa0a0561bec1c03b6e6"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly discloses commercial commitments for its plans and products, including Free ($0/month), Pro ($20/mo billed annually or $25/mo billed monthly), Business ($200/mo billed annually or $250/mo billed monthly), and usage-based rates such as Workers at $0.30 per million requests and $0.02 per million CPU ms."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:23.948Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-6b1ec9edf6e5bc9be8277ad21ed6b287369ef3921b9c2e9d3e880f4b575bf7c9"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "Documentation details adding card or wallet payment details and completing 3D Secure authentication, but current evidence does not document a scoped delegation rail or explicit human-authorization mechanism with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:24.044Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-6b1ec9edf6e5bc9be8277ad21ed6b287369ef3921b9c2e9d3e880f4b575bf7c9"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:19980be2b16d819c09332847aa1be9aab66db6af931122b129a819d104841df8",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:328b3aaf9570939c5d7df10d2ea8a936f1aba84b254914d1a7b99699dd96f6b0",
                    "sha256:9f5ef0873b5ffada2447a771d3882afa24f89e7b3d5eb6d703d6bb6accde22dc",
                    "sha256:ad473b51e0a4c3be7a5ba7691c72e9639188b060b95a10114058f4c0d82c4c8a",
                    "sha256:c0e6b82d901dce70e79fd93a18aa3288fecbffca45ec34c50b8a8fa694f36740"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-6b1ec9edf6e5bc9be8277ad21ed6b287369ef3921b9c2e9d3e880f4b575bf7c9"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ad473b51e0a4c3be7a5ba7691c72e9639188b060b95a10114058f4c0d82c4c8a",
                      "start_byte": 8727,
                      "end_byte": 9516,
                      "value_digest": "sha256:b88b10ee85cbb1327a94b693e6d200bd58457053f70fc3b9bfb683a6df1d3679"
                    }
                  ]
                }
              ],
              "note": "Cloudflare documents direct self-service paths to change domain plans, upgrade subscriptions, and manage paid add-on services directly through the Cloudflare dashboard without requiring sales intervention."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Cloudflare API tokens generate a secret upon creation in the dashboard. The secret is only displayed once to the user to copy, requiring manual transfer."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "context": "Workers versions and deployments expose immutable version identity and active deployment state, but the retained evidence does not fully establish bounded failure reconciliation."
            },
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "Provisioning can be triggered via 'wrangler deploy', which automatically creates a new Worker version and deploys it directly."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:11.478Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:6f4b0eae4ea601b699b9dbbac241f8aea1b1e3c1c344d81f027b54ffe4e332e2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2f2ab2027da4245ad96406e18236f8b1cd51347d4ef9b21fd68b52f51c044937",
                    "sha256:7a294831bb8c00a8ae5e3ec91e175438942cb08c0375e417f6600a2704370a22",
                    "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                    "sha256:f0c5186fd18d943e738b2300f8f94cfc245728a51d200fd41cf859ec4d847dd6"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 19307,
                      "end_byte": 20105,
                      "value_digest": "sha256:4ecffc4238770a3554f78225294f8b662ce3cd181b98a7a4950626ad553faf2a"
                    }
                  ]
                }
              ],
              "note": "Cloudflare API tokens generate a secret upon creation in the dashboard. The secret is only displayed once to the user to copy, requiring manual transfer.",
              "remediation": {
                "signal_code": "access_material_delivery",
                "code": "improve.provision.access_material_delivery",
                "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
              }
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:27.665Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f1cdc552d4ab30d97f407085a4c8e888be264d295429ec301b2579b72c644032",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:217c635cb4f15bded7604762a09cdb77069ce1603326042eca4a4e041583a9c4",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a573c4fe4f76b2e5c168fc5b6d7e56d6539306f16905263feecf3c22734b70d",
                    "sha256:afa33886b7d9e553bd9b7cbe3ef0b8507ef9c6da7f3f664d0cedf2ef2b5edcfe"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:afa33886b7d9e553bd9b7cbe3ef0b8507ef9c6da7f3f664d0cedf2ef2b5edcfe",
                      "start_byte": 651,
                      "end_byte": 815,
                      "value_digest": "sha256:e96b3b0d0a0e1e7fe1c956292f518f0fc44b4994ce836988dd15dc3e828a7940"
                    }
                  ]
                }
              ],
              "note": "Workers versions and deployments expose immutable version identity and active deployment state, but the retained evidence does not fully establish bounded failure reconciliation.",
              "remediation": {
                "signal_code": "provisioning_completion",
                "code": "improve.provision.provisioning_completion",
                "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
              }
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:27.665Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-reference"
                },
                {
                  "node_kind": "resource",
                  "node_id": "api-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f1cdc552d4ab30d97f407085a4c8e888be264d295429ec301b2579b72c644032",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:217c635cb4f15bded7604762a09cdb77069ce1603326042eca4a4e041583a9c4",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a5565709e76ecd6f6267be1a123190d09ce09a08f1fdc7bd5db9270047f1e9d0",
                    "sha256:afa33886b7d9e553bd9b7cbe3ef0b8507ef9c6da7f3f664d0cedf2ef2b5edcfe"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-bc8b49ed87d1f5f8ab2920f8fb566580b21dbc2818786704c4b560b7b364b342"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:afa33886b7d9e553bd9b7cbe3ef0b8507ef9c6da7f3f664d0cedf2ef2b5edcfe",
                      "start_byte": 2389,
                      "end_byte": 2645,
                      "value_digest": "sha256:ea7de6531b0b07062767ab7a1e99b64bae0343ce47c31d4fd928cca60ac38b36"
                    }
                  ]
                }
              ],
              "note": "Provisioning can be triggered via 'wrangler deploy', which automatically creates a new Worker version and deploys it directly."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "access_material_delivery",
              "code": "improve.provision.access_material_delivery",
              "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
            },
            {
              "signal_code": "provisioning_completion",
              "code": "improve.provision.provisioning_completion",
              "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "operation_contract",
            "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
            "finding": "The operation contract omits a material operation, field, or effect.",
            "context": "Cloudflare documentation defines REST endpoint paths, request bodies, query costs, rate limits, and verification responses across Worker script upload, troubleshooting, and rate limit references. However, complete input/output schema definitions and effect semantics for all targets are not fully captured."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "failure_contract",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "context": "Cloudflare documents API token troubleshooting and verification responses including status codes and error messages, but does not fully establish safe retry, idempotency, cancellation, or reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "Cloudflare API documentation describes token creation, setting permissions, TTL, client IP filtering, editing existing tokens, and rolling tokens. It leaves full programmatic recovery and compromise handling details unevidenced in this excerpt."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Cloudflare resources are accessible through documented, usable interfaces including REST API endpoints, TypeScript/SDK clients, and Wrangler CLI tools."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "Cloudflare supports request-time authentication using scoped API tokens via the Authorization Bearer header, allowing granular access controls across Account, User, or Zone resources."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:11.478Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:6f4b0eae4ea601b699b9dbbac241f8aea1b1e3c1c344d81f027b54ffe4e332e2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7a294831bb8c00a8ae5e3ec91e175438942cb08c0375e417f6600a2704370a22",
                    "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                    "sha256:dc98c23af9cc614b541ace08c32845d58b787ba1fe4eb9096abc5491c1bd86ac",
                    "sha256:f0c5186fd18d943e738b2300f8f94cfc245728a51d200fd41cf859ec4d847dd6"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 18506,
                      "end_byte": 19306,
                      "value_digest": "sha256:b0287a5a5b57a48cd218e9bab79eb4ea4777500dc52496bcd4ced0a1c2eaf36a"
                    },
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 19307,
                      "end_byte": 20105,
                      "value_digest": "sha256:4ecffc4238770a3554f78225294f8b662ce3cd181b98a7a4950626ad553faf2a"
                    }
                  ]
                }
              ],
              "note": "Cloudflare API documentation describes token creation, setting permissions, TTL, client IP filtering, editing existing tokens, and rolling tokens. It leaves full programmatic recovery and compromise handling details unevidenced in this excerpt.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:40.676Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-errors"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f5898f4657e57faa820dd065ea7295f2374e53bc6f433f2a63af9535ca2b1e71",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                    "sha256:43ac27e871991e80559288a06dc28b0cdd6d6c52c1bc9bce67e083a191ef8bb6",
                    "sha256:a881b0ad0b2d2a7c160105f928ca67cca4ee75938f3aa992ec27c769a32bc022",
                    "sha256:e22b46c8cc1f92104fe319a192cf5ce80bff96c48bafaa8306cb56f1f2b872a1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                      "start_byte": 17281,
                      "end_byte": 18051,
                      "value_digest": "sha256:552717ec9913484495442e186a95333ea432ce202f88f2f0ed9e89fc16da6205"
                    },
                    {
                      "artifact_digest": "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                      "start_byte": 18052,
                      "end_byte": 18854,
                      "value_digest": "sha256:79caa354cbaf9de20985abcb080461ac989af965c65e510cc188050ef2a29575"
                    }
                  ]
                }
              ],
              "note": "Cloudflare documents API token troubleshooting and verification responses including status codes and error messages, but does not fully establish safe retry, idempotency, cancellation, or reconciliation semantics.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:11.478Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:6f4b0eae4ea601b699b9dbbac241f8aea1b1e3c1c344d81f027b54ffe4e332e2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7a294831bb8c00a8ae5e3ec91e175438942cb08c0375e417f6600a2704370a22",
                    "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                    "sha256:d5a4e11c75335ecffb85d8d38ec750dca59baa1b1a2cdb0861b7b7aceb9e8994",
                    "sha256:f0c5186fd18d943e738b2300f8f94cfc245728a51d200fd41cf859ec4d847dd6"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 19307,
                      "end_byte": 20105,
                      "value_digest": "sha256:4ecffc4238770a3554f78225294f8b662ce3cd181b98a7a4950626ad553faf2a"
                    },
                    {
                      "artifact_digest": "sha256:c77d739f2b3819df6fcc6851b98113ef026016dab4899e669b18f521779ac18d",
                      "start_byte": 20106,
                      "end_byte": 20906,
                      "value_digest": "sha256:926fcacd1b797b8f11bb49207ecb2733fb6d4676ac5415329b0df8b212e1657c"
                    }
                  ]
                }
              ],
              "note": "Cloudflare supports request-time authentication using scoped API tokens via the Authorization Bearer header, allowing granular access controls across Account, User, or Zone resources."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "The operation contract omits a material operation, field, or effect.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:40.676Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "resource-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f5898f4657e57faa820dd065ea7295f2374e53bc6f433f2a63af9535ca2b1e71",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                    "sha256:25cbbc2a178d1a0d6c0362a2b115e2bff95a93a1f4f353fda4bdcc787552322e",
                    "sha256:43ac27e871991e80559288a06dc28b0cdd6d6c52c1bc9bce67e083a191ef8bb6",
                    "sha256:e22b46c8cc1f92104fe319a192cf5ce80bff96c48bafaa8306cb56f1f2b872a1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                      "start_byte": 18855,
                      "end_byte": 19645,
                      "value_digest": "sha256:21f696168801b25141233f9c7d0ff4655177c955f5b29a4f2d5701be78bd69cc"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:719614b199a25778f9dc95f612aab738f883567786aa877fec90e59371fb51a1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0ade5248eae9f53c834f30d4ac0d770f06e359f7669dd05c2fc7cf3bbfc0dad6",
                    "sha256:364e8ec99899e660ea3b90ee0ef65e4017bb3f14433538520e93086c89b9a357",
                    "sha256:8cc450c52208703179b6df4670bb7afc113524a9183b4456da03470daa4c08f7",
                    "sha256:e811f43c4222e0b74a05ff217fb8cad9be94f2e34b31096bf2bec249c9bfbeea"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e811f43c4222e0b74a05ff217fb8cad9be94f2e34b31096bf2bec249c9bfbeea",
                      "start_byte": 18443,
                      "end_byte": 19211,
                      "value_digest": "sha256:8bc0943c88427fdee9821a82a3be833c91189ac2af13ec190efbc40b1fe34510"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:72c95d07377e4176471827585e15324e91d495abaf1ad57085d4e2717d028699",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1463d5332989fbad37f4f2f1cdd973ade83a7e310cc325074ea5c060020bce14",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20",
                    "sha256:dc406e53ce6e30ed8eefc5fb9238ced437d6693b7efc74bf8c1ba2d14c9a3322"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20",
                      "start_byte": 480514,
                      "end_byte": 481298,
                      "value_digest": "sha256:e13e7b2bbcf4f4926b6936f8451a838bcec868358c62c90c26898063eed01532"
                    }
                  ]
                }
              ],
              "note": "Cloudflare documentation defines REST endpoint paths, request bodies, query costs, rate limits, and verification responses across Worker script upload, troubleshooting, and rate limit references. However, complete input/output schema definitions and effect semantics for all targets are not fully captured.",
              "remediation": {
                "signal_code": "operation_contract",
                "code": "improve.operate.operation_contract",
                "instruction": "Document stable inputs, outputs, effects, and target coverage for essential operations."
              }
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:40.676Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "resource-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:72c95d07377e4176471827585e15324e91d495abaf1ad57085d4e2717d028699",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1463d5332989fbad37f4f2f1cdd973ade83a7e310cc325074ea5c060020bce14",
                    "sha256:332e462a18c8b7e3c17713e56dfa9c112497c9c5c2a80f382dfdfdf288e9bf54",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c8626c0348a5edf08fcb6ebf642d4337a3fd913109dffe795de31966398e9a20",
                      "start_byte": 472910,
                      "end_byte": 473706,
                      "value_digest": "sha256:0ae28f90f675f13faf0dcbd2a3582a83ab59d93b35dd14134e8de9f58635c1eb"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f5898f4657e57faa820dd065ea7295f2374e53bc6f433f2a63af9535ca2b1e71",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                    "sha256:23d1cd0883270f081fee0a6a6b61e51b5e71b6630c134643c35a9d86c9397ea9",
                    "sha256:43ac27e871991e80559288a06dc28b0cdd6d6c52c1bc9bce67e083a191ef8bb6",
                    "sha256:e22b46c8cc1f92104fe319a192cf5ce80bff96c48bafaa8306cb56f1f2b872a1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:06dadb6ec2ca4f3c5875eaea10cb9abb905e9eca955e66e5d7202274bc3eed44",
                      "start_byte": 18052,
                      "end_byte": 18854,
                      "value_digest": "sha256:79caa354cbaf9de20985abcb080461ac989af965c65e510cc188050ef2a29575"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:719614b199a25778f9dc95f612aab738f883567786aa877fec90e59371fb51a1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0ade5248eae9f53c834f30d4ac0d770f06e359f7669dd05c2fc7cf3bbfc0dad6",
                    "sha256:364e8ec99899e660ea3b90ee0ef65e4017bb3f14433538520e93086c89b9a357",
                    "sha256:8cc450c52208703179b6df4670bb7afc113524a9183b4456da03470daa4c08f7",
                    "sha256:e811f43c4222e0b74a05ff217fb8cad9be94f2e34b31096bf2bec249c9bfbeea"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e811f43c4222e0b74a05ff217fb8cad9be94f2e34b31096bf2bec249c9bfbeea",
                      "start_byte": 18443,
                      "end_byte": 19211,
                      "value_digest": "sha256:8bc0943c88427fdee9821a82a3be833c91189ac2af13ec190efbc40b1fe34510"
                    }
                  ]
                }
              ],
              "note": "Cloudflare resources are accessible through documented, usable interfaces including REST API endpoints, TypeScript/SDK clients, and Wrangler CLI tools."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "operation_contract",
              "code": "improve.operate.operation_contract",
              "instruction": "Document stable inputs, outputs, effects, and target coverage for essential operations."
            },
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:06.695Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:143fb3a5ae1a4fc6155f5c8e16ecd410704f40023aee090f6ff9e26614a2ab9f",
          "sha256:26c635d1fa14ac17e237eb5c720cd41b3900f487e24ae0efb1e2b8596fa81663",
          "sha256:26e92f74138d4f7bd5b392e0fc0dec74419e68442c76a8441d5f9563373c2b28",
          "sha256:42fc51b69bb1516f9c1899bc76ca50a25d3803f88afb68824a185eddd9e30916",
          "sha256:44d664620c6030435950a8175bee888ef185f2802719295e79ea6b0f59616f66",
          "sha256:49561955d241a06c114508ccfbc6dd42a222457b76e0c8540437fbcd767b324e",
          "sha256:4eae2465dc6e9ed4002b20d5d3690eac5bfbd8855d38674158554653095e0440",
          "sha256:511b497f89d6b76727df507669f46f0dfb9851dd76c7046c3b6b0fa992e9ca32",
          "sha256:6e1ebf22f659279fb7fb14e59b8113416d895294118e563ef72e23371cdd0f5f",
          "sha256:79b5109197b482520206d4a19b8d960b9dd6d78b4cea93431e214a5107a106ad",
          "sha256:806984bfedcf9e6653a2f69ec8cc0954fbf77124fc1953c99f4d10ce2013c0a3",
          "sha256:82fe319355050e606972005b067a4d55b36974d291d4af35011c00eb2bc19f17",
          "sha256:86826820be1da07e69aa100bce6b5c90aa9232ec3a9b654e9d7f796ec9711e9d",
          "sha256:8fdc400682c3edbac992f82715747bc7df0f54f6b6ef2d819eba2c06962090e7",
          "sha256:903731941428f4d4568cb2dc0bf43c116c3817f482353c4c6d9aadeed476bbcf",
          "sha256:9b05de4610d566929b9fe55f388855f7fc5b33e3f43e1791c20a6116b2d4f830",
          "sha256:9f9408763b831df52b01d7aa5fd5d1624dcca310d9d29f042f6be90c803a1b5e",
          "sha256:a06fa75c2bec45b6eb352d91b0dfee97904b55b525cdc83be7eedbaa20cee12e",
          "sha256:a7ad97cd0c84a1e9a60c99f4a59483f79ee68fe2110f392dbbcc7997a3986216",
          "sha256:aadb42c64817d7306d0e5db738708904947fd4e15f1e93a38fc65dbbfcdaf260",
          "sha256:b49a4b4fa485ffebfb7e5bbc4ea4ac0babc6cef003b1e7b9e819896dcaf28b37",
          "sha256:be6e8967400b1441f9a352582f4c29b82b267185b2b2458ae5e12bcfa5dc6197",
          "sha256:bee844d18d88f0e45bb2bee833897e66584d8f452a85614c26ee63afc07935f4",
          "sha256:c005c4e4793c47ee1b8c24060ec757caa3046914f28f41245d776f3ad5032f84",
          "sha256:c42a0bd8384f8bc610f9bfc7dbdf1170877cee9e1a82ba3c300060160d51e264",
          "sha256:e35bb5aa0d66bc8fe74fc7058437c2ef30cae47a9f2466e04a6ce73ed1756ac8",
          "sha256:e7a0f8c05943ee8dd190415b75764d69d6d1a5bd4de90790400d4c915706835e"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:511b497f89d6b76727df507669f46f0dfb9851dd76c7046c3b6b0fa992e9ca32"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.317Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:9b05de4610d566929b9fe55f388855f7fc5b33e3f43e1791c20a6116b2d4f830"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:16.207Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:c005c4e4793c47ee1b8c24060ec757caa3046914f28f41245d776f3ad5032f84"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:04.846Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:e35bb5aa0d66bc8fe74fc7058437c2ef30cae47a9f2466e04a6ce73ed1756ac8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.317Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:26e92f74138d4f7bd5b392e0fc0dec74419e68442c76a8441d5f9563373c2b28"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:12.248Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:49561955d241a06c114508ccfbc6dd42a222457b76e0c8540437fbcd767b324e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:06.695Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:143fb3a5ae1a4fc6155f5c8e16ecd410704f40023aee090f6ff9e26614a2ab9f",
              "sha256:44d664620c6030435950a8175bee888ef185f2802719295e79ea6b0f59616f66",
              "sha256:c42a0bd8384f8bc610f9bfc7dbdf1170877cee9e1a82ba3c300060160d51e264"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:06.695Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:be6e8967400b1441f9a352582f4c29b82b267185b2b2458ae5e12bcfa5dc6197"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:11.478Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:4eae2465dc6e9ed4002b20d5d3690eac5bfbd8855d38674158554653095e0440"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:12.248Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:b49a4b4fa485ffebfb7e5bbc4ea4ac0babc6cef003b1e7b9e819896dcaf28b37"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:23.948Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:a7ad97cd0c84a1e9a60c99f4a59483f79ee68fe2110f392dbbcc7997a3986216"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:16.207Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:82fe319355050e606972005b067a4d55b36974d291d4af35011c00eb2bc19f17"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:23.948Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:42fc51b69bb1516f9c1899bc76ca50a25d3803f88afb68824a185eddd9e30916"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:24.044Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:bee844d18d88f0e45bb2bee833897e66584d8f452a85614c26ee63afc07935f4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:11.478Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:26c635d1fa14ac17e237eb5c720cd41b3900f487e24ae0efb1e2b8596fa81663"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:27.665Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:86826820be1da07e69aa100bce6b5c90aa9232ec3a9b654e9d7f796ec9711e9d"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:27.665Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:aadb42c64817d7306d0e5db738708904947fd4e15f1e93a38fc65dbbfcdaf260"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:11.478Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:e7a0f8c05943ee8dd190415b75764d69d6d1a5bd4de90790400d4c915706835e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:40.676Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:79b5109197b482520206d4a19b8d960b9dd6d78b4cea93431e214a5107a106ad"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:11.478Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:8fdc400682c3edbac992f82715747bc7df0f54f6b6ef2d819eba2c06962090e7",
              "sha256:9f9408763b831df52b01d7aa5fd5d1624dcca310d9d29f042f6be90c803a1b5e",
              "sha256:a06fa75c2bec45b6eb352d91b0dfee97904b55b525cdc83be7eedbaa20cee12e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:40.676Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:6e1ebf22f659279fb7fb14e59b8113416d895294118e563ef72e23371cdd0f5f",
              "sha256:806984bfedcf9e6653a2f69ec8cc0954fbf77124fc1953c99f4d10ce2013c0a3",
              "sha256:903731941428f4d4568cb2dc0bf43c116c3817f482353c4c6d9aadeed476bbcf"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:40.676Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/cloudflare/agent-readiness/cloudflare-developer-platform/api-resource-management",
      "projection_digest": "sha256:0ef3bbb86ac19881479a6e8dd6a4b50cd7dd8b05bcbab6b33b5aef97432839ac"
    }
  }
}
