UTCP tools jarvis.policy.check

jarvis.policy.check policy:check

Evaluate command policy for an argv vector

Auth

Header: Authorization: Bearer $JARVIS_BEARER_TOKEN

  • Every call requires a Bearer token (JARVIS_BEARER_TOKEN). Missing/wrong → HTTP 403.
  • Optional capability grants: JARVIS_UTCP_CAPABILITIES=policy:check,run:create (empty = full owner grant).
  • Missing capability on invoke → HTTP 403 with reason "capability denied".
  • Audit actor is a token fingerprint (tok_<prefix>_<sha256[0..4]>), never the raw secret.
  • Loopback bind only in v0 (127.0.0.1).

This tool requires capability policy:check. If JARVIS_UTCP_CAPABILITIES is set, include that grant or the provider returns 403.

curl

curl -sS \
  -H "Authorization: Bearer $JARVIS_BEARER_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"tool":"jarvis.policy.check","args":{"argv":["git","status"]}}' \
  http://127.0.0.1:7777/tools/invoke

Python

import json, os, urllib.request

url = "http://127.0.0.1:7777/tools/invoke"
token = os.environ["JARVIS_BEARER_TOKEN"]
payload = {
  "tool": "jarvis.policy.check",
  "args": {
    "argv": [
      "git",
      "status"
    ]
  }
}

req = urllib.request.Request(
    url,
    data=json.dumps(payload).encode(),
    headers={
        "Authorization": f"Bearer {token}",
        "Content-Type": "application/json",
    },
    method="POST",
)
with urllib.request.urlopen(req) as resp:
    print(resp.read().decode())

Example args

{
  "argv": [
    "git",
    "status"
  ]
}

input_schema

{
  "type": "object",
  "required": [
    "argv"
  ],
  "properties": {
    "argv": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  }
}

output_schema

{
  "type": "object",
  "required": [
    "decision"
  ],
  "properties": {
    "decision": {
      "type": "string"
    },
    "reason": {
      "type": "string"
    },
    "matched_rule": {
      "type": "string"
    }
  }
}

← All UTCP tools