VM02 // ALLOWANCE EXPOSURE PREFLIGHT

MACHINE 002

Allowance Exposure Preflight

Live 0.01 USDC BASE / x402 / USDC

Give the machine one owner, one ERC-20 token, and one spender on Base. It reads the direct allowance and the owner’s current balance at one block and returns normalized exposure plus deterministic large-approval evidence. It does not connect a wallet, sign, simulate, or tell you to revoke.

PURPOSE

Plain-English job

Agents often need a factual snapshot of how much of one token one owner has already approved to one spender, compared with the owner’s current balance. This machine does that read at a single Base block. It is not a wallet-wide scanner, not Permit2, and not a safety score.

WHEN TO CALL

Job-shaped selection

Call when you need a same-block Base allowance-versus-balance snapshot for one owner, one ERC-20 token, and one spender. Not a wallet-wide scanner, Permit2 reader, other-chain checker, simulator, or revoke advisor. Sibling first-party machines are listed on GET /v1/catalog.

INPUT

Exact JSON object

Required fields only. Additional properties are rejected before payment.

{
  "owner": "0x0000000000000000000000000000000000000001",
  "token": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
  "spender": "0x0000000000000000000000000000000000000002"
}

The example is the OpenAPI/Bazaar contract example used in tests.

OUTPUT

Factual structured JSON

Status is OK or HOLD. Key fields include allowance, balance, min(allowance, balance) exposure, max_uint256_approval, effectively_unlimited, same-block evidence, and limitations.

{
  "status": "OK",
  "machine": "VM02",
  "methodology_version": "allowance-exposure-0.1.0",
  "network": "eip155:8453",
  "allowance_covers_current_balance": true,
  "max_uint256_approval": false,
  "effectively_unlimited": false
}
LIMITATIONS

Known bounds

SECURITY BOUNDARIES // PUBLIC

What is safe to say publicly

Public machine payTo (contract field, not a manual-pay destination): 0xdb7b2b54f80479826222749a2ea73a8acc306e1e

CONTRACT

Verified live routes

Live public API origin:

POST https://api.agentmercantile.com/v1/allowance-exposure

GET https://api.agentmercantile.com/openapi.json

Unsigned POST of the example body returns HTTP 402 with x402 v2 exact 10,000 atomic Base USDC. This page does not run that call in the browser and does not start a payment. Public contact: contact@agentmercantile.com.