TrustBoost PII Sanitizer · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the TrustBoost PII Sanitizer API

14 actions 14 updates documentation extends ../openapi/trustboost-dev-openapi.json
Generated by API Evangelist Written by API Evangelist tooling for TrustBoost PII Sanitizer's API. It is a proposal applied on top of the contract, not a document TrustBoost PII Sanitizer publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

tagsx-observedx-a2a-skillx-aliasesx-agent-cardx-agent-descriptionx-mcp-serverx-mcp-server-card

Targets 12

$.info
$.servers[0]
$.paths['/sanitize'].post
$.paths['/sanitize'].get
$.paths['/sanitize/preview'].post
$.paths['/score/{wallet_address}'].get
$.paths['/verify/{anchor_tx}'].get
$.paths['/budget/{operator_id}'].get
$.paths['/health'].get
$.paths['/mcp'].post
$.paths['/message/send'].post
$

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the TrustBoost PII Sanitizer API
  version: 1.0.0
extends: ../openapi/trustboost-dev-openapi.json
x-generated: '2026-09-19'
x-method: generated
x-source: >-
  Generated from openapi/trustboost-dev-openapi.json plus the probed and searched artifacts in this repo.
  Captures API Evangelist annotations without mutating the provider's contract. Every route and status
  named below was observed live or documented by the provider; nothing is proposed that does not exist.
actions:
- target: $.info
  description: Link the provider's other machine-readable surfaces from the contract.
  update:
    x-agent-card: https://api.trustboost.dev/.well-known/agent-card.json
    x-agent-description: https://api.trustboost.dev/.well-known/agent-description.json
    x-mcp-server: https://api.trustboost.dev/mcp
    x-mcp-server-card: https://api.trustboost.dev/.well-known/mcp-server-card.json
    x-llms-txt: https://api.trustboost.dev/llms.txt
    x-pricing: https://api.trustboost.dev/pricing
    x-privacy-policy: https://github.com/teodorofodocrispin-cmyk/TrustBoost-PII-Sanitizer/blob/main/PRIVACY.md
    x-repository: https://github.com/teodorofodocrispin-cmyk/TrustBoost-PII-Sanitizer
    x-payment:
      protocol: x402 v2
      discovery: https://api.trustboost.dev/.well-known/x402
      challenge_status: 402
      challenge_header: PAYMENT-REQUIRED
      payment_header: PAYMENT-SIGNATURE (X-PAYMENT legacy)
      rails: ['eip155:8453 USDC $0.01/call', 'solana mainnet USDC $0.01/call or 149 USDC per 10,000 via tx_hash']
      preflight: https://api.trustboost.dev/preflight
      policy_hash: https://api.trustboost.dev/policy
- target: $.info
  description: Record the limits documented in prose, since no rate-limit headers are declared.
  update:
    x-rate-limits:
    - {scope: per-ip, resource: 'POST /sanitize/preview', limit: 3, window: 1h}
    - {scope: per-wallet_address, resource: 'POST /sanitize with tx_hash TRIAL', limit: 50, window: lifetime, exhaustion_status: 402}
    - {scope: per-request, resource: 'POST /sanitize text', limit: '10,000 characters', exhaustion_status: 413}
    - {scope: per-request, resource: 'POST /sanitize/preview text', limit: '500 characters'}
- target: $.info
  description: >-
    Routes the provider documents (llms.txt, pricing, README) and serves live but does not declare in this
    contract — recorded so a consumer knows they exist and knows they are unspecified.
  update:
    x-undeclared-routes:
    - {method: POST, path: /redact, alias_of: /sanitize, observed: 'GET 402'}
    - {method: POST, path: /detect, alias_of: /sanitize/preview, observed: 'GET 402'}
    - {method: POST, path: /demo, alias_of: /sanitize/preview, observed: 'GET 405'}
    - {method: POST, path: /sanitize/quick, description: 'pay-per-call only, x402 v2, $0.01 USDC', observed: 'GET 402'}
    - {method: GET, path: '/anchor/{anchor_tx}', alias_of: '/verify/{anchor_tx}', observed: '404 for unknown tx'}
    - {method: GET, path: /preflight, observed: 200}
    - {method: GET, path: /policy, observed: 200}
- target: $.servers[0]
  description: Note that this is the provider's only host; the apex domain does not resolve.
  update:
    x-note: api.trustboost.dev is the sole host (Render behind Cloudflare). trustboost.dev and www.trustboost.dev have no DNS A record.
- target: $.paths['/sanitize'].post
  description: Tag, payment semantics, and the responses documented outside the contract.
  update:
    tags: [Sanitization]
    x-payment-gate: 'tx_hash TRIAL (50/wallet) | Solana bundle tx_hash | x402 PAYMENT-SIGNATURE'
    x-idempotency: none — a retry consumes quota again; bundle tx_hash is single-use (409)
    x-mcp-tool: sanitize_pii
    x-a2a-skill: sanitize_pii
    x-documented-responses-not-declared:
      '409': 'TX_HASH_ALREADY_USED — "Each tx_hash can only be used once." (SKILL.md)'
      '422': 'FastAPI validation error {detail: [{type, loc, msg, input}]}'
- target: $.paths['/sanitize'].get
  description: Tag the x402 discovery operation and record the observed challenge.
  update:
    tags: [Payment]
    x-observed: 'HTTP 402 with PAYMENT-REQUIRED header; body x402Version 2, accepts[] eip155:8453 and solana mainnet, amount 10000 (USDC 6 decimals), maxTimeoutSeconds 300'
- target: $.paths['/sanitize/preview'].post
  update:
    tags: [Sanitization]
    x-free-tier: '3 per IP per hour, 500 characters, no wallet, zero retention'
    x-aliases: [/demo, /detect]
- target: $.paths['/score/{wallet_address}'].get
  update:
    tags: [Trust]
    x-a2a-skill: trustboost_score
    x-observed: 'GET /score/probe 200 {"trust_tier":"NEW","trustboost_score":null,"history":{"total_requests":0}}'
    x-enum-trust_tier: [NEW, ACTIVE, VERIFIED, TRUSTED]
- target: $.paths['/verify/{anchor_tx}'].get
  update:
    tags: [Trust]
    x-a2a-skill: verify_proof
    x-aliases: ['/anchor/{anchor_tx}']
    x-observed: 'GET /verify/probe 404 {"status":"not_found","note":"Only paid sanitizations are anchored on Solana"}'
- target: $.paths['/budget/{operator_id}'].get
  update:
    tags: [Governance]
    x-observed: 'GET /budget/probe 200 {"budget_active":false,"message":"No privacy budget registered for this operator. Unlimited access."}'
- target: $.paths['/health'].get
  update:
    tags: [Operations]
    x-observed: '200 {"status":"ok","version":"2.6.0","service":"TrustBoost-PII-Sanitizer","infrastructure":"FastAPI+Supabase+Render"}'
- target: $.paths['/mcp'].post
  update:
    tags: [Protocols]
    x-mcp: {protocolVersion: '2024-11-05', serverInfo: {name: trustboost, version: 2.6.0}, tools: [sanitize_pii], schema_key: input_schema (non-standard)}
- target: $.paths['/message/send'].post
  update:
    tags: [Protocols]
    x-observed: 'POST with a JSON-RPC 2.0 body → 422 body.message Field required; GET → 405. A REST route, not A2A JSONRPC.'
- target: $
  description: Declare the tags the actions above apply; the provider's contract declares none.
  update:
    tags:
    - {name: Sanitization, description: Redact PII from text}
    - {name: Payment, description: x402 discovery}
    - {name: Trust, description: Proof of Sanitization and TrustBoost Score}
    - {name: Governance, description: Privacy budget}
    - {name: Operations, description: Health}
    - {name: Protocols, description: MCP and A2A ingress routes}