Tenant-scoped idempotent quantum jobs
Submit, poll, and cancel bounded N/M jobs through a versioned carrier, opaque ownership scope, atomic idempotency, terminal state invariants, and explicit production gates.
A tenant-scoped, idempotent job boundary
NM-RFC-0008 freezes the provider-neutral 0.1 request, ownership, state, retry, and result carrier contract. The API remains preview until a durable production provider and real operational evidence exist.
NM-RFC-0008preview0.1.0-previewOwnership before lookup
Poll and cancel require the same opaque server-derived client scope as submission. Another scope receives not found, and a missing scope is unauthorized.
tenant scope + job id → job | 404One key, one request
Idempotency-Key is mandatory. The tenant, key, and canonical SHA-256 request fingerprint reserve one job atomically; conflicting reuse returns 409.
tenant + key + SHA-256(request)Closed-world input
Actual UTF-8 body size, known fields, source, target, shots, and metadata are bounded before provider access. Unknown extensions and control characters are rejected.
unknown fields → NM-JOB-TYPE-001Terminal states stay terminal
Only documented transitions are accepted. Cancellation cannot be overwritten by stale completion; deterministic N/M failures are never retried.
queued → running → terminalSubmission example
curl -X POST /api/nm/jobs \
-H "content-type: application/json" \
-H "idempotency-key: experiment-2026-0001" \
--data '{"source":"module bell; fn main() { let q = qreg[1]; H(q[0]); return q; }","shots":1024}'Versioned public carrier
{
"format": "nm-quantum-job",
"version": "0.1",
"contractVersion": "0.1.0-preview",
"status": "queued",
"attempts": 0,
"maxAttempts": 2
}Stable diagnostic families
Open JSON SchemaNM-JOB-PARSE-001NM-JOB-TYPE-001NM-JOB-VERSION-001NM-JOB-LIMIT-001NM-JOB-STATE-001NM-JOB-IDEMPOTENCY-001NM-JOB-TENANT-001NM-JOB-PROVIDER-001Promotion evidence
Operational reports are aggregate-only and retain no source, metadata, job id, tenant, client token, IP, or idempotency key.
Durable-store conformance
The public 0.1 harness verifies atomic reservation, tenant isolation, schedule claims, rollback, restart persistence, expired-lease recovery, and isolated cleanup. The memory adapter intentionally cannot pass the production-ready result.
Hardware preview-readiness evidence
The separate fail-closed 0.1 reader binds one production deployment and exact candidate to an account-grade provider decision, a durable store, retained real-QPU provenance, a rollback drill, 14-day operations, byte-verified artifacts, and authorized reviews. This mechanism does not select a provider and does not promote hardwareExecution by itself.
0.1npm run report:nm:hardware-execution-readiness -- --input <evidence.json> --artifact-root <retained-directory> --checkStill open before stable
A real durable store/provider must pass the conformance harness; account-grade tenant isolation, a live rollback drill, remote-browser evidence, and at least 14 days / 100 real submissions remain required.