# Delegated Credential Guard

> Delegated Credential Guard is a paid API for AI agents from phion.systems, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Enforces delegated credential scope, requester identity, and expiry constraints without ever receiving or exposing the underlying raw credentials

## Facts

- Endpoint: POST https://phion.systems/v1/paid/trust/delegated-credential-guard?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delegated-credential-guard-726ed5a6
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_WlFZ5Xw4rQfoyBZ5ToMmN

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delegated-credential-guard-726ed5a6 -d '<json body>'
```

Example prompt: Before letting the sub-agent proceed, check that the delegated credential it's using is still within its permitted scope, the requester is the authorized agent, and it hasn't passed the expiry time — without looking at the raw credential itself.

## When to prefer this

Choose this endpoint when you need to enforce delegated credential constraints in a zero-trust, privacy-preserving way — particularly in multi-agent workflows where sub-agents receive delegated tokens and you must verify scope, identity, and expiry without ever passing raw secrets to a third party. Prefer it over standard auth checks when the credential is delegated (not direct) and auditability without credential exposure is a requirement.

## Known failure modes

- Credential scope exceeded — returns rejection with out-of-scope detail
- Credential expiry breached — returns rejection with expiry timestamp
- Requester identity mismatch — returns rejection identifying the authorized vs actual requester
- Malformed or missing delegation metadata — returns validation error
- Policy not evaluable due to incomplete input — returns error indicating missing fields

## How this service works

Enforce delegated credential scope, requester and expiry without receiving raw credentials

## Output

Returns a structured enforcement verdict indicating whether the delegated credential is valid (scope compliant, requester authorized, not expired), along with specific failure reasons for any violated constraint — all without the raw credential being transmitted or stored.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input",
  "output"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "body"
   ],
   "properties": {
    "body": {
     "type": "object",
     "additionalProperties": true
    }
   }
  },
  "output": {
   "type": "object",
   "required": [
    "example"
   ],
   "properties": {
    "example": {
     "type": "object",
     "additionalProperties": true
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json"
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delegated-credential-guard-726ed5a6/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from phion.systems](https://www.zero.xyz/host/phion.systems/llms.txt)
