{
  "api_contract": "sourcey.catalog-api/v1",
  "release_id": "sha256:5f55a0147eca9a82d821b7cfb73339dd8059c146b9acbb6ed66c9e3d40a8e1b0",
  "artifact_sha256": "sha256:ec393385ec4e7be15a393d925f0df78d54a12787f2995a84fad1b570583dac06",
  "data": {
    "revision_contract": "sourcey.agent-readiness-revision/v1alpha1",
    "agent_readiness_profile_id": "arp_01kzf0m4xn2p7wd9g3a5rt8zq6",
    "entity_id": "ent_01kyh8fpe5dk9hex187x4g03fn",
    "scope": {
      "product": {
        "key": "vercel-rest-api",
        "name": "Vercel REST API"
      },
      "funnel": {
        "key": "deployment-operations",
        "name": "Deployment operations"
      }
    },
    "catalog_binding": {
      "base_release_id": "sha256:8986cb1640fd748dd005e5c94c7b02d3f44a3d39ff6b72573091bd81af84c61e",
      "entity_revision_digest": "sha256:2ca7db4f429b3bb813bb1ac6d59c8cb5213e3c16a9096dfaa1455909f7b73e13"
    },
    "declaration_revision_digest": "sha256:d71be82b4542d1caf53b6eef94b6c4237601920f428cc37485c128276b6db97c",
    "declaration": {
      "declaration_id": "declaration_vercel_api_deployment_operations",
      "provenance": {
        "repository": "sourcey/agent-ready-services",
        "commit": "ca383f7867c18d91567fcb8326be55f7411d9554",
        "path": "entities/ve/vercel.yaml",
        "git_blob_oid": "860880f6043e6b93357a098b2df91c7ba0e3c157",
        "blob_digest": "sha256:5a34c8c678d9d4d273f7ab003404b4e313d5bda811dbb2f10d4ab1f199bbeddd"
      },
      "status": "community_declared"
    },
    "lifecycle": "active",
    "effective_from": "2026-09-06T08:47:58Z",
    "signals": [
      {
        "stage": "evaluate",
        "signal_code": "eligibility_decidability",
        "selector_group_id": "eligibility_decidability-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:51:21.755Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "service-terms"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:f69b36b3d3059bf70c97bfaf012229445f9c1a6545ab53d87704814a6a051437",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
              "sha256:3ce5ff491b6fc70427ba9faab35d6f9781aa9e5b59c495c60022e29f82a10e68",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:e518cd78c5a7164b9237499ee0f2830b4ab24f63d14bfac708f4c20a548d8d2e"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "service-terms"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
                "start_byte": 9300,
                "end_byte": 10094,
                "value_digest": "sha256:89b7c06c13317b210660c52084b8f79c96ead3a733cba57d8dc9cc21ad1c1f96"
              },
              {
                "artifact_digest": "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
                "start_byte": 6905,
                "end_byte": 7704,
                "value_digest": "sha256:5ec198c6f5a80582fdd3b3c6dde5fe6d88820f2ee80d1559ee869d083e07486e"
              }
            ]
          }
        ],
        "note": "Vercel's Terms of Service state explicit eligibility conditions, requiring users to be at least 16 years of age, have electronic devices controlled by them, and possess legal authority to bind a company or legal entity when entering into the agreement on its behalf."
      },
      {
        "stage": "evaluate",
        "signal_code": "pricing_decidability",
        "selector_group_id": "pricing_decidability-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:04.903Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "pricing"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0d4954350adf1117bcd27487982ca67671c2a50e559f38abe7a731c287d94465",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0b17540be2d8745404dc414b361847489896f43682b585b967f0460ee3ee3b83",
              "sha256:1a5f7f2b6c44919f599b90029ca25da3bf1f902e3ef6dc67ed77a3aa4068ddda",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:75f419e59aa755d822f64e9de36288834eb306a50d7dc1d3d7ba400f98d1c360"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "pricing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1a5f7f2b6c44919f599b90029ca25da3bf1f902e3ef6dc67ed77a3aa4068ddda",
                "start_byte": 7041,
                "end_byte": 7844,
                "value_digest": "sha256:ec7fdf1cd27cb0572efc28bf68debcec5b98a55d3ec24b611faf5b1e2f1ce16e"
              },
              {
                "artifact_digest": "sha256:1a5f7f2b6c44919f599b90029ca25da3bf1f902e3ef6dc67ed77a3aa4068ddda",
                "start_byte": 7845,
                "end_byte": 8643,
                "value_digest": "sha256:1e4d1675c04e0c987c29b29afc79d77c992b6391f5968139bb3b5843cdf0de14"
              }
            ]
          }
        ],
        "note": "Vercel discloses its pricing tiers, including a $0/month Hobby plan and a $20/month Pro plan (which includes $20 of usage credit). Prices are stated in USD and exclude applicable taxes calculated based on billing address."
      },
      {
        "stage": "evaluate",
        "signal_code": "service_discovery",
        "selector_group_id": "service_discovery-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "api-reference"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:943a5cf193acb7bee0816e1a05a3af1f15024c9f02f2e25c3b3fefb309fe68c6",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:582d332defc5accb90ffa27aae7274e35c4873202e616f65c1f8a0880f6ffb44",
              "sha256:8b816e086332fb2ea249b7f60ab8f17f09520d4ab8f93df7ae1d14eaa5a834e8",
              "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
                "start_byte": 174172,
                "end_byte": 174968,
                "value_digest": "sha256:54277203aaf932da696c226383d0e3f5e0bc2758dbba64a2c469f8e23e9990c9"
              }
            ]
          }
        ],
        "note": "The Vercel REST API is publicly discoverable and hosted at the stable base entrypoint URL https://api.vercel.com."
      },
      {
        "stage": "evaluate",
        "signal_code": "structured_evaluation_discovery",
        "selector_group_id": "structured_evaluation_discovery-primary",
        "value": "partial",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "api-reference"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:943a5cf193acb7bee0816e1a05a3af1f15024c9f02f2e25c3b3fefb309fe68c6",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:582d332defc5accb90ffa27aae7274e35c4873202e616f65c1f8a0880f6ffb44",
              "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
              "sha256:c82fef36554f19acc4aac8d86a021f82efbe93c44b27b33e12be2732e39cd770"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
                "start_byte": 230792,
                "end_byte": 231599,
                "value_digest": "sha256:d004e41feb57627762f0035cdc1b7c5057b3184e02faa7f2b5b355aa107382a8"
              }
            ]
          }
        ],
        "note": "Vercel changelog text notes automatic REST API documentation with OpenAPI, but the retained text does not provide a verified schema artifact for the complete evaluation surface."
      },
      {
        "stage": "evaluate",
        "signal_code": "terms_access",
        "selector_group_id": "terms_access-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:51:21.755Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "service-terms"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:f69b36b3d3059bf70c97bfaf012229445f9c1a6545ab53d87704814a6a051437",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:063240f7aff97740036dc381946de1cbf098c31d15f6d1c7100a1a9b463e0906",
              "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:e518cd78c5a7164b9237499ee0f2830b4ab24f63d14bfac708f4c20a548d8d2e"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "service-terms"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
                "start_byte": 6112,
                "end_byte": 6904,
                "value_digest": "sha256:3959dcda0ad9cf80831fd1e7ab6e92ffd896372f1c9f3b907e04e7ceb2124cd3"
              },
              {
                "artifact_digest": "sha256:3471a196b755b2d3b03be2a846f6efb5b9aa0336770fff3cc43ee031ff23cb35",
                "start_byte": 6905,
                "end_byte": 7704,
                "value_digest": "sha256:5ec198c6f5a80582fdd3b3c6dde5fe6d88820f2ee80d1559ee869d083e07486e"
              }
            ]
          }
        ],
        "note": "Vercel's Terms of Service are stable, readable, retrievable online, and materially complete, covering age eligibility, license terms, payment terms, and service API conditions."
      },
      {
        "stage": "evaluate",
        "signal_code": "verified_web_agent_access",
        "selector_group_id": "verified_web_agent_access-primary",
        "value": "unknown",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "api-reference"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [],
        "note": "Standard metadata directives appear, but retained admissible evidence does not establish an explicit web-agent or robot access policy for the assessed API documentation surface."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_control_operability",
        "selector_group_id": "access_control_operability-primary",
        "value": "unknown",
        "observed_at": "2026-09-06T08:51:55.665Z",
        "tested_surfaces": [
          {
            "node_kind": "endpoint",
            "node_id": "registration"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [],
        "note": "The signup page displays social login options and email entry, but does not provide complete evidence of deterministic validation, navigation, and handoffs."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_entrypoint_stability",
        "selector_group_id": "access_entrypoint_stability-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:51:55.665Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "account-signup"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "direct_observation",
            "captures": [
              {
                "retained_capture_digest": "sha256:31f8664c96fec256393ae837717f39881cfd022de3d0202e5b772125cb142606",
                "capture_rung": "headless"
              }
            ],
            "artifact_digests": [
              "sha256:2dce0273fc6f95c86e47e109fccdf6dc258277ced3d16ab78e13d3a5834adeca",
              "sha256:49684cb94dbe588f6d5b4bbdb8eefda71d6027ce5d0efba0bf4843a46da642f8",
              "sha256:4aa2f5cf40e9ac2786833494d98bc96c94c440f1f32c5ec581b10889a0f047ba",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:8c685cb462711eaac432606206da4fe07a5f8ee9c6d8b6e4f982a1b7273968a0",
              "sha256:9f30c3cf3cce9c087d1e7868716c5371c4f70ca3a9410e47433fc1d4020f1fa3"
            ],
            "locators": [
              {
                "artifact_digest": "sha256:8c685cb462711eaac432606206da4fe07a5f8ee9c6d8b6e4f982a1b7273968a0",
                "start_byte": 667,
                "end_byte": 1040,
                "value_digest": "sha256:bd50309f70a7ceb311148b279cd1daba0ef584608c7525e666b98a3088f9ca1f"
              }
            ]
          }
        ],
        "note": "Vercel's signup page provides a canonical entrypoint to begin account registration via OAuth providers and email."
      },
      {
        "stage": "sign_up",
        "signal_code": "captcha_compatible_access",
        "selector_group_id": "captcha_compatible_access-primary",
        "value": "unknown",
        "observed_at": "2026-09-06T08:51:55.665Z",
        "tested_surfaces": [
          {
            "node_kind": "endpoint",
            "node_id": "registration"
          },
          {
            "node_kind": "resource",
            "node_id": "account-signup"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [],
        "note": "The signup page captures do not contain an explicit declaration or verified-agent alternative regarding CAPTCHA boundaries across the signup flow."
      },
      {
        "stage": "sign_up",
        "signal_code": "delegated_identity_access",
        "selector_group_id": "delegated_identity_access-primary",
        "value": "partial",
        "observed_at": "2026-09-06T08:51:15.476Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:e925eaf59fc3d2a898f2bf0046a765d9ee6e3f9e2e08485c2013a4b974dc09dd",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2ba251dfef3c1714fdc127c472bc92bb31f7449462918e87a317ce793cf96cd6",
              "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
              "sha256:40b42ed6ee65d7936e06ff94e339d7e60124d9a6d476a433559f75798c24948a",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
                "start_byte": 16282,
                "end_byte": 17060,
                "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:08d5837c6603b7c98bab69d13a185acf7d977b138c3deac4b8712a7770e39afb",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:8c6d04da457fa40f8b17d5b5de3f077b3ec7447334e53ec6706a1aa1d913e382",
              "sha256:9d50687a2b20b5e73630367bc84f5891d2d72433d32bb9dd9d8069242f28b0f9",
              "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
              "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "access-tokens"
            },
            "locators": [
              {
                "artifact_digest": "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
                "start_byte": 8645,
                "end_byte": 9440,
                "value_digest": "sha256:f7731ef118770e55d0b5a5db53b005d800994bf85ab341a4e85b18d78a41a350"
              }
            ]
          }
        ],
        "note": "Vercel Access Tokens can be created in account settings or via Vercel CLI (`vercel tokens add`) and scoped to specific teams or projects, but initial creation relies on manual dashboard UI interaction or copying the secret."
      },
      {
        "stage": "sign_up",
        "signal_code": "phone_verification_compatible",
        "selector_group_id": "phone_verification_compatible-primary",
        "value": "unknown",
        "observed_at": "2026-09-06T08:51:55.665Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "account-signup"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [],
        "note": "The initial signup screen does not state whether phone verification is required, absent, or explicitly resumable."
      },
      {
        "stage": "pay",
        "signal_code": "checkout_operability",
        "selector_group_id": "checkout_operability-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:17.442Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0ea09515653dde0d4d5c7fd1f454f3c01f41c74b1649eb2c55671a6fc75a1563",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
              "sha256:43ddb574ecfa7d548d2c476cc408b312990a2141ef5138ca3840ddf0a257cf3c",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:922fa838e4d6f8ecd2d1baad9017d8351c58e9174e85a08812d8ebb34cc60519"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
            },
            "locators": [
              {
                "artifact_digest": "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
                "start_byte": 8673,
                "end_byte": 8844,
                "value_digest": "sha256:87a1f6e097131707a6a48557cf49c11a81ac5fa725c1c71e26bc0ddc287093f5"
              },
              {
                "artifact_digest": "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
                "start_byte": 9479,
                "end_byte": 9562,
                "value_digest": "sha256:af0ae012e2e7a535c346cb5da467c6503296bddaaa3ac3c470d3bc187624e242"
              }
            ]
          }
        ],
        "note": "POST /v1/billing/buy lets an agent construct a credit purchase with a bearer token and returns a checkoutSessionId and checkoutSessionUrl, so approval can be handed to a person at the URL and the session resumed by id."
      },
      {
        "stage": "pay",
        "signal_code": "commitment_disclosure",
        "selector_group_id": "commitment_disclosure-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:52:01.429Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:3dee279471ea892efb5561a0e7dc30d5580c0ef23b0cef968a8a4e818c212681",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:8542e156bf713ba3196c6460ed3c4c1520d526bf52ed8834cf9765ffdd008849",
              "sha256:c65b1f80062582eb9cca4c92d73354ba15e267d57260617caa7c7ddf091c51a9",
              "sha256:c81fc84ae8264ec1ea032ecdecc2d41dbcf1a476c0be450e9b60bc634e56ff69"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "billing-checkout"
            },
            "locators": [
              {
                "artifact_digest": "sha256:c81fc84ae8264ec1ea032ecdecc2d41dbcf1a476c0be450e9b60bc634e56ff69",
                "start_byte": 14128,
                "end_byte": 14926,
                "value_digest": "sha256:25caa0694bfd1c783dc17335c55e9ed3edae2b902bc5a745b796687fdc34a8cd"
              }
            ]
          }
        ],
        "note": "The evidence discloses payment timing at the start of each billing cycle, card payment methods, and USD currency charging conditions."
      },
      {
        "stage": "pay",
        "signal_code": "payment_authorization",
        "selector_group_id": "payment_authorization-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:17.442Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0ea09515653dde0d4d5c7fd1f454f3c01f41c74b1649eb2c55671a6fc75a1563",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:243283b0b40c8fc3be74283806ffa353c101f9de54b8218d24cf738fcc9c3189",
              "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
              "sha256:43ddb574ecfa7d548d2c476cc408b312990a2141ef5138ca3840ddf0a257cf3c",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
            },
            "locators": [
              {
                "artifact_digest": "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
                "start_byte": 448,
                "end_byte": 528,
                "value_digest": "sha256:704efe39331be67f2cc8b0491532ece6ee039e08baa382ec18587bddb29b4ce6"
              },
              {
                "artifact_digest": "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
                "start_byte": 8673,
                "end_byte": 8844,
                "value_digest": "sha256:87a1f6e097131707a6a48557cf49c11a81ac5fa725c1c71e26bc0ddc287093f5"
              }
            ]
          }
        ],
        "note": "Credit purchases through POST /v1/billing/buy charge the payment method on file immediately and are limited to Owner, Member, Developer, Security and Billing roles, so payment is authorized within the scoped authority of the token holder."
      },
      {
        "stage": "pay",
        "signal_code": "self_service_purchase",
        "selector_group_id": "self_service_purchase-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:17.442Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0ea09515653dde0d4d5c7fd1f454f3c01f41c74b1649eb2c55671a6fc75a1563",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
              "sha256:43ddb574ecfa7d548d2c476cc408b312990a2141ef5138ca3840ddf0a257cf3c",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:94c96deb63b0f080b1db7bc341063c5ceeae45a2c0f0b2831c170afdd85b61f3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-74d9faecf8e412bdc34272487dd9c3b5ccc64ea4c6ef4f0027ebbd1f3651c877"
            },
            "locators": [
              {
                "artifact_digest": "sha256:2629a8bf094a36d42fbfa58a8785a471b6eef8329759ce7e72bc5becbf7a2eed",
                "start_byte": 8673,
                "end_byte": 8844,
                "value_digest": "sha256:87a1f6e097131707a6a48557cf49c11a81ac5fa725c1c71e26bc0ddc287093f5"
              }
            ]
          }
        ],
        "note": "Vercel documents programmatic credit purchase through POST /v1/billing/buy against the payment method on file, charged immediately, alongside the self-service Pro plan upgrade; no vendor review stands in the path."
      },
      {
        "stage": "provision",
        "signal_code": "access_material_delivery",
        "selector_group_id": "access_material_delivery-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:51:01.223Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:e925eaf59fc3d2a898f2bf0046a765d9ee6e3f9e2e08485c2013a4b974dc09dd",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2ba251dfef3c1714fdc127c472bc92bb31f7449462918e87a317ce793cf96cd6",
              "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:e451296d53c4fc5f067d2946826432ecf26555368e9499f777d7c9f258185321"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
                "start_byte": 17061,
                "end_byte": 17848,
                "value_digest": "sha256:c02b6465738b1b6f3faf890bce294a494ec613f041da4d12e046c86ed16c9b4c"
              }
            ]
          }
        ],
        "note": "Vercel provides an agent-usable CLI command (`vercel tokens add \"<name>\"`) that creates personal access tokens and prints the plaintext value directly to stdout for immediate capture in CI environments or scripts."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_completion",
        "selector_group_id": "provisioning_completion-primary",
        "value": "partial",
        "observed_at": "2026-09-06T08:50:02.374Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "deployment-operations"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ff76b7bcbe9d9a363626f4a7e7c4dfc2b2cc07c1ed471ad1276efcaa5d41bc82",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
              "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff",
              "sha256:7e68e1af1dd83d21689efffadd66411fcbaa4e1b56e31e42151e4e9780383e45",
              "sha256:cf40369b56a310b643b01700d10a9ff53442364fe26808e50cce585c38baad60"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "deployment-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
                "start_byte": 16867,
                "end_byte": 17667,
                "value_digest": "sha256:d7cbb3d4969a9d3120d0268f69ef7f45f56e25d76deb8ba5f3e44731be1d48be"
              },
              {
                "artifact_digest": "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
                "start_byte": 17668,
                "end_byte": 18464,
                "value_digest": "sha256:2a4b7004ec8dbaa58974e085fa2179ea2cc387db5174dc8a300a62d3595f6431"
              }
            ]
          }
        ],
        "note": "Vercel REST API's deployment creation returns a deployment object with a `readyState` field and indicates callers can poll `readyState` to track progress through states such as QUEUED, INITIALIZING, BUILDING, READY, or ERROR. However, current evidence leaves explicit reconciliation procedures and specific documented time bounds unresolved."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_operability",
        "selector_group_id": "provisioning_operability-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:02.374Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "deployment-operations"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ff76b7bcbe9d9a363626f4a7e7c4dfc2b2cc07c1ed471ad1276efcaa5d41bc82",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
              "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff",
              "sha256:cf40369b56a310b643b01700d10a9ff53442364fe26808e50cce585c38baad60",
              "sha256:e177178197999a6e909f5efed27d9d73cb14413c42d50582fcbfe80730871f7f"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "deployment-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
                "start_byte": 10586,
                "end_byte": 11375,
                "value_digest": "sha256:88d4855d46f21137730fe499f3f355dccbcaba36f51ed3a7f2e8503c0567b52a"
              }
            ]
          }
        ],
        "note": "Deployments can be initiated programmatically via direct HTTP POST requests to `https://api.vercel.com/v13/deployments` using a bearer access token."
      },
      {
        "stage": "operate",
        "signal_code": "agent_protocol_interface",
        "selector_group_id": "agent_protocol_interface-primary",
        "value": "unknown",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "deployment-api"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [],
        "note": "The retained excerpts describe REST or RPC interfaces, SDKs and CLIs for Vercel REST API; they contain no first-party statement that an agent-native protocol interface is absent, and several navigation excerpts mention MCP resources without establishing coverage of the assessed targets."
      },
      {
        "stage": "operate",
        "signal_code": "credential_lifecycle",
        "selector_group_id": "credential_lifecycle-primary",
        "value": "partial",
        "observed_at": "2026-09-06T08:51:15.476Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:e925eaf59fc3d2a898f2bf0046a765d9ee6e3f9e2e08485c2013a4b974dc09dd",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2ba251dfef3c1714fdc127c472bc92bb31f7449462918e87a317ce793cf96cd6",
              "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
              "sha256:40b42ed6ee65d7936e06ff94e339d7e60124d9a6d476a433559f75798c24948a",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
                "start_byte": 16282,
                "end_byte": 17060,
                "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:08d5837c6603b7c98bab69d13a185acf7d977b138c3deac4b8712a7770e39afb",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:8c6d04da457fa40f8b17d5b5de3f077b3ec7447334e53ec6706a1aa1d913e382",
              "sha256:9d50687a2b20b5e73630367bc84f5891d2d72433d32bb9dd9d8069242f28b0f9",
              "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
              "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "access-tokens"
            },
            "locators": [
              {
                "artifact_digest": "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
                "start_byte": 8645,
                "end_byte": 9440,
                "value_digest": "sha256:f7731ef118770e55d0b5a5db53b005d800994bf85ab341a4e85b18d78a41a350"
              }
            ]
          }
        ],
        "note": "Vercel access tokens can be created, listed, and revoked via the Vercel CLI (vercel tokens add, list, rm) or account settings with project scoping. However, explicit recovery mechanisms following compromise are not fully detailed in the retained evidence."
      },
      {
        "stage": "operate",
        "signal_code": "failure_contract",
        "selector_group_id": "failure_contract-primary",
        "value": "partial",
        "observed_at": "2026-09-06T08:50:32.100Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "api-errors"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:643ca8ab3cc8c61183c4d36783d5bd866fc3f88617b681a85e14e0a06aedbe34",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:14d1d9c1b347190be66cc1b03c2c6037743751d939512544ac4f4643c1ac8a84",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:71a90a377ccd0094d64e76bed4442d130b2e603b5ce57139b10d5c4d81dda243",
              "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
                "start_byte": 7871,
                "end_byte": 8579,
                "value_digest": "sha256:9499095de33134270ce727ddcc46583aa483f3dcb608971a997174e89683b05d"
              },
              {
                "artifact_digest": "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
                "start_byte": 8580,
                "end_byte": 9377,
                "value_digest": "sha256:872f7f5c5ce144424ee6316888391eda9bfa285dd144f1f44efd8bc1678979c4"
              }
            ]
          }
        ],
        "note": "The REST API documentation describes general error codes (such as forbidden, rate_limited with reset timestamps, bad_request, internal_server_error, and not_found), but complete safe handling semantics like explicit idempotency and reconciliation are not fully detailed."
      },
      {
        "stage": "operate",
        "signal_code": "operation_authentication",
        "selector_group_id": "operation_authentication-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:51:15.476Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "access-tokens"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:08d5837c6603b7c98bab69d13a185acf7d977b138c3deac4b8712a7770e39afb",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:9d50687a2b20b5e73630367bc84f5891d2d72433d32bb9dd9d8069242f28b0f9",
              "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
              "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311",
              "sha256:fbecd01b9111d36493f10ebbae4a5123b79c68525a6f221230a73deba084bb73"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "access-tokens"
            },
            "locators": [
              {
                "artifact_digest": "sha256:c1744356e775864edddb37551dc0e6cedf967922d396d5b8b65373f115a9222f",
                "start_byte": 9441,
                "end_byte": 10216,
                "value_digest": "sha256:6b0e30c4180ee754ee68d49ecc9c33a8c3d63880ca64e65504c40818c2d6d102"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:e925eaf59fc3d2a898f2bf0046a765d9ee6e3f9e2e08485c2013a4b974dc09dd",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2ba251dfef3c1714fdc127c472bc92bb31f7449462918e87a317ce793cf96cd6",
              "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
              "sha256:40b42ed6ee65d7936e06ff94e339d7e60124d9a6d476a433559f75798c24948a",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
            },
            "locators": [
              {
                "artifact_digest": "sha256:3225abe2ae9714c4b3c422145acd308ccd5284bd1bb158ce6c99b5393b4e506d",
                "start_byte": 16282,
                "end_byte": 17060,
                "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
              }
            ]
          }
        ],
        "note": "Requests to the Vercel REST API are authenticated using scoped Vercel Access Tokens passed via the Authorization header as a Bearer token."
      },
      {
        "stage": "operate",
        "signal_code": "operation_contract",
        "selector_group_id": "operation_contract-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "deployment-api"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ff76b7bcbe9d9a363626f4a7e7c4dfc2b2cc07c1ed471ad1276efcaa5d41bc82",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
              "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff",
              "sha256:cf40369b56a310b643b01700d10a9ff53442364fe26808e50cce585c38baad60",
              "sha256:f7789f71ca9d59d592f69434bca250a8d5336562c544325e8d464562b3a97fac"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "deployment-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
                "start_byte": 16867,
                "end_byte": 17667,
                "value_digest": "sha256:d7cbb3d4969a9d3120d0268f69ef7f45f56e25d76deb8ba5f3e44731be1d48be"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:943a5cf193acb7bee0816e1a05a3af1f15024c9f02f2e25c3b3fefb309fe68c6",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:582d332defc5accb90ffa27aae7274e35c4873202e616f65c1f8a0880f6ffb44",
              "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
              "sha256:f52d034f0f5852e9561a768cb693e84d8bd16bfd51782603623e2b98ec320b9f"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
                "start_byte": 182933,
                "end_byte": 183754,
                "value_digest": "sha256:784f6a8157ce018cdce12b341840ff35975fd625e57d4f63b130cbe4074c9ac9"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:643ca8ab3cc8c61183c4d36783d5bd866fc3f88617b681a85e14e0a06aedbe34",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:14d1d9c1b347190be66cc1b03c2c6037743751d939512544ac4f4643c1ac8a84",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
              "sha256:c454378782cb5dcf1fe291750ea8ba1696a7ae3415a1e820121ee2f71c1d21f9"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
                "start_byte": 8580,
                "end_byte": 9377,
                "value_digest": "sha256:872f7f5c5ce144424ee6316888391eda9bfa285dd144f1f44efd8bc1678979c4"
              }
            ]
          }
        ],
        "note": "Vercel defines explicit REST endpoints, parameters, request and response structures, status codes, and error formats across deployment and management operations."
      },
      {
        "stage": "operate",
        "signal_code": "target_interface_access",
        "selector_group_id": "target_interface_access-primary",
        "value": "yes",
        "observed_at": "2026-09-06T08:50:37.612Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "deployment-api"
          }
        ],
        "assessment_method": {
          "name": "public-semantic-assessment",
          "version": "2026-09-06",
          "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:943a5cf193acb7bee0816e1a05a3af1f15024c9f02f2e25c3b3fefb309fe68c6",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:582d332defc5accb90ffa27aae7274e35c4873202e616f65c1f8a0880f6ffb44",
              "sha256:8b816e086332fb2ea249b7f60ab8f17f09520d4ab8f93df7ae1d14eaa5a834e8",
              "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a316c4a4848a12b71d0c43b54ccf116f7a58acd85c76cdfb1200791a14285b3d",
                "start_byte": 174172,
                "end_byte": 174968,
                "value_digest": "sha256:54277203aaf932da696c226383d0e3f5e0bc2758dbba64a2c469f8e23e9990c9"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ff76b7bcbe9d9a363626f4a7e7c4dfc2b2cc07c1ed471ad1276efcaa5d41bc82",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
              "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff",
              "sha256:cf40369b56a310b643b01700d10a9ff53442364fe26808e50cce585c38baad60",
              "sha256:e177178197999a6e909f5efed27d9d73cb14413c42d50582fcbfe80730871f7f"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "deployment-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0968540d0673a758709776dcdcc2313471943ae4587b2f885fdd894082ec5f31",
                "start_byte": 10586,
                "end_byte": 11375,
                "value_digest": "sha256:88d4855d46f21137730fe499f3f355dccbcaba36f51ed3a7f2e8503c0567b52a"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:643ca8ab3cc8c61183c4d36783d5bd866fc3f88617b681a85e14e0a06aedbe34",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:14d1d9c1b347190be66cc1b03c2c6037743751d939512544ac4f4643c1ac8a84",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
              "sha256:c0dbbfb70c5ba41d6a25323606f1288b89590106c7891f948a714a3690194a27"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:75bb6df98983fffac6f5e4ae8a5f42ce8b9c322578c63dd933dc1603be441674",
                "start_byte": 7077,
                "end_byte": 7870,
                "value_digest": "sha256:aa4ccb63fdb63a761afb4c42fd7fcdb3552298d1f6a09df17c5ffce6efc356a6"
              }
            ]
          }
        ],
        "note": "Essential service operations across Vercel REST API errors, reference overview, and deployment management endpoints are documented and accessible via standard HTTP REST requests."
      }
    ],
    "revision_digest": "sha256:7c59a04f00102d531d6008028c0c551ded5cd1d5d0a9fb3f37d7d3172a5f1d7b"
  }
}
