Carries validated tenant context across HTTP, queues, and background jobs while rejecting missing or conflicting identities.
Prototype evidence fixture—not an independent certification or production safety guarantee.
4 declared features · TypeScript / node
02Test evidence98% / 265 testspassing fixture run · Jul 20, 2026
03Security evidence98/100 security0 critical · 0 high · FixtureScan 1.4
04ProvenanceSigned fixture buildFunctionFoundry demo build service · Jul 18, 2026
05Reference offerCommercial sourceartifact-access · source-access · modification · commercial-use
31a173daefc4…a2ce1d3cf0Contract, fixture evidence, provenance, and offers above refer to manifest version 1.18.0. The digest identifies its seeded demo artifact; it is not an independent certification.
Carries validated tenant context across HTTP, queues, and background jobs while rejecting missing or conflicting identities. The versioned contract documents deterministic behavior, failure modes, configuration, and integration boundaries for production teams.
application/json
Validated application/json request payload
application/json
Typed application/json response with trace metadata
TypeScript / node 20, 22
Next.js · Fastify · BullMQ
node-service · aws-lambda · container
Contract stability: stable · fixture declared
Declared compatible pieces
Compatibility links are declared fixture metadata and have not been independently integration-tested
31.5–88 agent minutes · 0.5–2 review hours
fixture directional · low confidencePrototype estimate only. It is not an empirical benchmark and must not be presented as measured savings.
Fixture evidence scanned 7/19/2026 with FixtureScan 1.4. Benchmarks use 2 vCPU / 2 GB fixture runner.
| Data classes | internal |
|---|---|
| Permissions | read-write temporary-storage: Bounded request processing |
| Security findings | 0 critical · 0 high |
| SBOM | CycloneDX 1.6 fixture · dependency inventory attached |
| Builder | FunctionFoundry demo build service · signed: true |
| Revision | fixture-tenant-context-propagation-guard-v1 |
| Artifact SHA-256 | 31a173daefc40782cc06dc119dcea5e47046f6b65ac34910133950a2ce1d3cf0 |
| Maintenance | active |
| Option | Model | Rights | Restrictions | Price |
|---|---|---|---|---|
| Private evaluation evaluation | evaluation | evaluation | Non-production use only; Results retained for 30 days | $0.05 / evaluation Seller-stated · waived in prototype · $0 charged |
| Developer artifact individual · 1 seats | one-time | artifact-access, commercial-use | No redistribution; One named developer | $29 |
| Commercial source commercial-source · 10 seats | one-time | artifact-access, source-access, modification, commercial-use | No standalone redistribution; One production application | $149 |
Prototype license text is illustrative and has not received legal review.
| Version | Status | Evidence | Artifact |
|---|---|---|---|
| 1.18.0 | active | 98% coverage · scan recorded | 31a173daefc40782… |
{
"schemaVersion": "1.0",
"capabilityId": "00000000-0000-4000-8000-000000000012",
"name": "Tenant Context Propagation Guard",
"slug": "tenant-context-propagation-guard",
"summary": "Carries validated tenant context across HTTP, queues, and background jobs while rejecting missing or conflicting identities.",
"granularity": "module",
"purposes": [
"tenant isolation",
"context propagation",
"background jobs",
"authorization"
],
"features": [
"signed context",
"queue propagation",
"conflict rejection",
"audit hooks"
],
"functionalDescription": "Carries validated tenant context across HTTP, queues, and background jobs while rejecting missing or conflicting identities. The versioned contract documents deterministic behavior, failure modes, configuration, and integration boundaries for production teams.",
"inputs": [
{
"name": "request",
"contentType": "application/json",
"description": "Validated application/json request payload",
"required": true
}
],
"outputs": [
{
"name": "result",
"contentType": "application/json",
"description": "Typed application/json response with trace metadata",
"required": true
}
],
"runtimes": [
{
"language": "TypeScript",
"runtime": "node",
"versions": [
"20",
"22"
]
}
],
"frameworks": [
"Next.js",
"Fastify",
"BullMQ"
],
"deploymentTargets": [
"node-service",
"aws-lambda",
"container"
],
"dependencies": [
{
"name": "zod",
"version": ">=2",
"optional": false
}
],
"permissions": [
{
"resource": "temporary-storage",
"access": "read-write",
"reason": "Bounded request processing"
}
],
"dataClassifications": [
"internal"
],
"complianceClaims": [
"SBOM available",
"Dependency scan recorded"
],
"testEvidence": {
"coveragePercent": 98,
"tests": 265,
"lastRun": "2026-07-20T14:00:00.000Z",
"status": "passing"
},
"securityEvidence": {
"criticalFindings": 0,
"highFindings": 0,
"score": 98,
"scannedAt": "2026-07-19T09:30:00.000Z",
"scanner": "FixtureScan 1.4"
},
"benchmarks": [
{
"name": "p95 latency",
"value": 243,
"unit": "ms",
"environment": "2 vCPU / 2 GB fixture runner"
}
],
"buildBenchmark": {
"basis": "fixture-directional",
"sampleSize": 0,
"referenceTask": "Reimplement the declared tenant-context-propagation-guard contract in a compatible greenfield repository",
"tokenEstimate": {
"low": 40500,
"high": 100500
},
"agentTimeMinutes": {
"low": 31.5,
"high": 88
},
"humanReviewHours": {
"low": 0.5,
"high": 2
},
"observedAt": null,
"methodology": "Directional fixture derived from declared granularity and integration effort; no coding-agent replay was run.",
"confidence": "low",
"disclosure": "Prototype estimate only. It is not an empirical benchmark and must not be presented as measured savings."
},
"integration": {
"estimatedHours": 1.5,
"packageManager": "pnpm",
"configurationNotes": [
"Pin the immutable artifact digest",
"Configure scoped service credentials"
]
},
"composition": {
"composable": true,
"interface": "middleware",
"compatibleWith": [
"multi-tenant-authorization-middleware",
"audit-log-event-pipeline"
],
"requires": [],
"contractStability": "stable",
"evidence": "fixture-declared",
"notes": [
"Compatibility links are declared fixture metadata and have not been independently integration-tested"
]
},
"commercialModels": [
"licensed-artifact",
"source-license"
],
"licenseOptions": [
{
"id": "evaluation",
"name": "Private evaluation",
"scope": "evaluation",
"priceCents": 5,
"unit": "evaluation",
"rights": [
"evaluation"
],
"developerSeats": null,
"restrictions": [
"Non-production use only",
"Results retained for 30 days"
]
},
{
"id": "developer",
"name": "Developer artifact",
"scope": "individual",
"priceCents": 2900,
"unit": "one-time",
"rights": [
"artifact-access",
"commercial-use"
],
"developerSeats": 1,
"restrictions": [
"No redistribution",
"One named developer"
]
},
{
"id": "commercial-source",
"name": "Commercial source",
"scope": "commercial-source",
"priceCents": 14900,
"unit": "one-time",
"rights": [
"artifact-access",
"source-access",
"modification",
"commercial-use"
],
"developerSeats": 10,
"restrictions": [
"No standalone redistribution",
"One production application"
]
}
],
"artifactDigests": [
{
"algorithm": "sha256",
"digest": "31a173daefc40782cc06dc119dcea5e47046f6b65ac34910133950a2ce1d3cf0",
"artifactType": "source"
}
],
"provenance": {
"builder": "FunctionFoundry demo build service",
"sourceRevision": "fixture-tenant-context-propagation-guard-v1",
"builtAt": "2026-07-18T12:00:00.000Z",
"signed": true
},
"maintenanceStatus": "active",
"version": "1.18.0",
"seller": {
"name": "Boundary Logic",
"verified": true,
"reputation": 5
},
"verificationBadges": [
"Security reviewed",
"High coverage",
"Composition declared"
]
}