İçeriğe geç

Overview

Private, encrypted storage for any JSON records, with verifiable crypto-erasure.

Every call runs over TLS 1.3. Machines authenticate with 7-day client certificates issued by the server’s client CA (mutual TLS). People authenticate with passkeys and send the session token as a bearer token; sensitive actions require a passkey assertion made within the last five minutes (ADR-0010). Errors are RFC 9457 problem details with a code member. Idempotency-Key is honoured on session creation, exports and deletions. Browser requests must carry an allowed Origin. Paths use segments (/commit, /approve) where architecture section 8 sketched colon verbs.

Two-person rule: a person is controlled by whoever requested their invite and whoever issued its code, a machine by whoever requested it and whoever issued its bootstrap code, and control follows these links through the whole chain. An approval is never decided by its requester, by anyone who controls the requester, by anyone the requester controls, or by anyone who shares a controller with the requester; both sides are worked out when the decision is made. Approved actions run once: the server claims an approval before it executes it. Revoking an identity or disabling a person cancels their open requests and any approval they decided that is still in its cool-off, and disabling a person voids the unredeemed codes they issued last. One principal may have at most limits.pending_approvals requests (50 by default) waiting for a decision; a request past that answers 429 too_many_pending. Every route has a time budget; a request that runs out of it before its change is stored answers 503 timeout, and a stored change is always answered.

Deployments have a role (ADR-0012), reported by /v1/meta. A cell serves one customer and every path below except the platform tag. The platform serves the platform tag, sign-in, people, approvals, the audit events and its own /v1/status; it has no data plane, so ingest, reads, deletions, keys, machine identities and the custodian audit paths answer 404 there. Platform roles are admin, approver, auditor and operator for staff, and owner for a founder, who holds only org:read.

Information

  • OpenAPI version: 3.1.0

Client certificate issued by the server’s client CA

Security scheme type: mutualTLS

Session token from a passkey sign-in

Security scheme type: http