Information
- OpenAPI version:
3.1.0
Private, encrypted storage for any JSON records, with verifiable crypto-erasure.
Every call runs over TLS 1.3. Machines authenticate with 7-day client certificates issued by the
server’s client CA (mutual TLS). People authenticate with passkeys and send the session token as a
bearer token; sensitive actions require a passkey assertion made within the last five minutes
(ADR-0010). Errors are RFC 9457 problem details with a code member. Idempotency-Key is honoured
on session creation, exports and deletions. Browser requests must carry an allowed Origin.
Paths use segments (/commit, /approve) where architecture section 8 sketched colon verbs.
Two-person rule: a person is controlled by whoever requested their invite and whoever issued its
code, a machine by whoever requested it and whoever issued its bootstrap code, and control follows
these links through the whole chain. An approval is never decided by its requester, by anyone who controls the requester,
by anyone the requester controls, or by anyone who shares a controller with the requester; both
sides are worked out when the decision is made. Approved actions run once: the server claims an
approval before it executes it. Revoking an identity or disabling a person cancels their open
requests and any approval they decided that is still in its cool-off, and disabling a person voids
the unredeemed codes they issued last. One principal may have at most limits.pending_approvals
requests (50 by default) waiting for a decision; a request past that answers 429 too_many_pending.
Every route has a time budget; a request that runs out of it before its change is stored answers
503 timeout, and a stored change is always answered.
Deployments have a role (ADR-0012), reported by /v1/meta. A cell serves one customer and every
path below except the platform tag. The platform serves the platform tag, sign-in, people,
approvals, the audit events and its own /v1/status; it has no data plane, so ingest, reads,
deletions, keys, machine identities and the custodian audit paths answer 404 there. Platform roles
are admin, approver, auditor and operator for staff, and owner for a founder, who holds only
org:read.
Client certificate issued by the server’s client CA
Security scheme type: mutualTLS
Session token from a passkey sign-in
Security scheme type: http