Verify a narrow capability token for action, resource prefix, expiry, and nonce before sandbox access.
Required APIdef verify_capability(token, action, resource, now, used_nonces):
return {'allowed': ..., 'reason': ...}BehaviorThink through the mechanism first if you want the extra reasoning step. It never blocks the editor.
verify_capability({'action': 'read', 'prefix': '/docs/', 'expires': 10, 'nonce': 'n1'}, 'read', '/docs/a.txt', 3, [])a capability grants only its declared authority
verify_capability({'action': 'read', 'prefix': '/docs/', 'expires': 10, 'nonce': 'n1'}, 'read', '/secrets/a', 3, [])['reason']path boundaries are enforced by the token
2 hidden edge tests run after the visible contract passes.
Run Tests to see the contract verdicts here.