{"schemaVersion":2,"generatedFrom":{"v1InventoryOperations":238,"systemCatalogGeneratedAt":"2026-08-10T05:16:07.686Z","explorerSourceContracts":253,"serviceSourceContracts":49},"summary":{"v1SourceOperations":238,"canonicalPublicOperations":858,"internalOnlyOperations":14,"implementedContracts":528,"plannedContracts":330,"explorerOperations":200,"serviceExpansionOperations":47,"applicationExpansionOperations":369,"capabilities":108,"applications":45},"applications":[{"name":"Overview","group":"Operate","description":"Account posture and activity","purpose":"Give an authenticated operator a concise, read-oriented view of account posture, recent activity, alerts, and the next actions that matter.","audiences":["account operators","support agents","portfolio assistants"],"businessCases":["daily account review","exception triage","cross-module navigation"],"workflow":["load the authenticated account projection","inspect balances, activity, and alerts","follow a typed link into the owning module"],"prerequisites":["an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action."],"relatedApplications":["Wallets","Notifications","Trust Center"],"order":0,"operationCount":32,"implementedContracts":22,"plannedContracts":10},{"name":"Wallets","group":"Operate","description":"MPC custody and portfolios","purpose":"Prepare, inspect, govern, and reconcile workspace- and network-bound MPC custody wallets, approved destinations, policies, ceremonies, transfers, and asset portfolios without exposing key or credential material.","audiences":["treasury operators","custody integrations","wallet agents"],"businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"workflow":["select the authenticated workspace, network, purpose, and approved custody policy","read the authoritative token-import-network catalog before inspecting or enabling a contract asset","prepare and complete distinct enrollment, attestation, activation, destination-approval, estimate, intent, signing, submission, and reconciliation stages","read current wallet, policy, approved-address, balance, ceremony, transfer, and evidence state before every governed action","reconcile ambiguous responses from authoritative state before retrying an equivalent idempotent request"],"prerequisites":["wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it."],"relatedApplications":["Governance","Funding","AI Wallet Control"],"order":1,"operationCount":136,"implementedContracts":90,"plannedContracts":46},{"name":"AI Wallet Control","group":"Operate","description":"Agent budgets, capabilities and activity","purpose":"Inspect bearer-scoped Signed Workload Identity bindings, versioned wallet policies, native-asset budgets, retained decisions, and execution-readiness evidence, and preview policy admission without creating transaction state.","audiences":["AI platform operators","automation developers","treasury risk teams"],"businessCases":["agent wallet inventory","native-asset budget and policy review","side-effect-free intent evaluation","retained decision and readiness reconciliation"],"workflow":["discover a bearer-scoped workload binding and independently enrolled operational wallet","read current and historical policy commitments, per-asset budgets, retained intents, activity, approvals, and execution mode","evaluate a typed proposal without creating an intent, reservation, event, approval, transaction, signature, or broadcast","re-read governing resources before any separately authorized downstream action"],"prerequisites":["an authenticated workspace principal","ai-wallets:read for projections or the separate ai-wallets:evaluate scope for dry-run evaluation","an existing Signed Workload Identity binding and independently enrolled AI operational wallet"],"agentGuidance":["Workspace, profile, and role come from the bearer and cannot be selected in the request.","Preserve native-asset amounts as exact decimal strings and never aggregate unlike assets or interpret the summary currency as fiat.","POLICY_APPROVED and retained approval records are policy and review evidence, not transaction construction, signing, broadcast, confirmation, or settlement authority.","The intent-evaluations operation is a side-effect-free preview: execution_created, reservation_created, and event_created remain false.","Binding lifecycle, policy replacement, retained intent creation, approval actions, signing, and broadcast remain unavailable until separately enabled in production OpenAPI; fail closed when any policy, budget, identity, workspace, network, or readiness context cannot be verified."],"relatedApplications":["Wallets","Access Control","Automations"],"order":2,"operationCount":28,"implementedContracts":21,"plannedContracts":7},{"name":"Business Network","group":"Operate","description":"Private Context Exchanges and partner-safe agent context","purpose":"Exchange permission-filtered business context between trusted partners and agents through signed, topic-scoped Context Exchanges.","audiences":["partner integration teams","enterprise agents","data governance operators"],"businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"workflow":["discover an admitted exchange and directional topic grant","read or query filtered context","publish, deliver, or respond with signed commitment evidence"],"prerequisites":["a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"],"order":3,"operationCount":31,"implementedContracts":31,"plannedContracts":0},{"name":"Governance","group":"Operate","description":"Authorities, safes and policy","purpose":"Coordinate proposals, authority assignments, MPC ceremonies, policy decisions, and immutable governance evidence.","audiences":["governance participants","treasury controllers","compliance reviewers"],"businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"workflow":["create or discover a proposal","collect eligible decisions and threshold evidence","verify the resulting immutable state before execution"],"prerequisites":["governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers."],"relatedApplications":["Wallets","Contract Studio","Access Control"],"order":4,"operationCount":23,"implementedContracts":19,"plannedContracts":4},{"name":"Funding","group":"Operate","description":"Deposits and settlement","purpose":"Observe owner-scoped deposits and exceptions, prepare wallet funding routes, and coordinate exact-intent settlement lifecycles across consent, custody, collateral, broadcast, finality, and reconciliation boundaries without making the gateway a value owner.","audiences":["treasury teams","payment operations","reconciliation agents"],"businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"workflow":["discover linked instruments, wallet activation, and funding readiness","prepare a non-value-bearing route and observe deposits","create an exact settlement intent and complete its three-phase consent ceremony","observe separate authorization, collateral, signing, broadcast, and finality states","reconcile exceptions, cancellation, and retained evidence"],"prerequisites":["an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed."],"relatedApplications":["Wallets","Payments","Indexer Controller"],"order":5,"operationCount":45,"implementedContracts":39,"plannedContracts":6},{"name":"Payments","group":"Operate","description":"Value movement and requests","purpose":"Create owner-isolated exact-decimal payment requests and AUTHORIZATION_REQUIRED payment intents, reconcile their commitments and control-plane state, and cancel an intent before any separately authorized value-movement workflow begins.","audiences":["payment applications","merchant agents","accounts-payable teams"],"businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"workflow":["resolve the bearer-derived workspace, counterparty workspace, exact amount, currency, optional payment request, and owner-safe source reference","create one idempotent OPEN request or AUTHORIZATION_REQUIRED payment intent","re-read request and payment versions and explicit safety flags before every dependent action","complete customer authorization, compliance, source reservation, signing, rail submission, confirmation, and settlement only through future separately owned operations","cancel only an exact latest AUTHORIZATION_REQUIRED intent and reconcile its linked request"],"prerequisites":["payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI."],"relatedApplications":["Funding","Commerce","Transfer Compliance"],"order":6,"operationCount":14,"implementedContracts":7,"plannedContracts":7},{"name":"Notifications","group":"Operate","description":"Account signals and action routing","purpose":"Bootstrap a cryptographically bound messaging identity and expose an owner-scoped account-signal inbox without making delivery, acknowledgement, or presentation metadata authoritative for business state.","audiences":["account applications","support systems","alerting agents","secure messaging clients"],"businessCases":["device-bound encrypted messaging","security alerts","workflow reminders","owner-scoped attention queues","notification acknowledgement and archival"],"workflow":["generate independent Ed25519 signing and X25519 encryption keys on the device when secure transport is required","register public keys with an exact domain-separated proof of possession","obtain a short-lived session- and device-bound messaging ticket","list all or unread owner-scoped signals","re-read the referenced authoritative resource before acting","mark selected signals read, unread, or archived with an idempotent command"],"prerequisites":["an authenticated Identity session with a stable device identifier for messaging bootstrap","trust:write for device enrollment or trust:read for ticket issuance","profile:read for inbox reads or profile:write for acknowledgement","secure local custody of both messaging private keys"],"agentGuidance":["Never submit, log, persist centrally, or place messaging private keys or tickets in prompts.","Use messages and inbox signals only as prompts to re-read the owning resource; delivery order, an href, and acknowledgement are not the canonical event sequence.","Messaging credentials and inbox state grant no business-domain authority.","The public notification push contract remains deliberately planned: publication requires a separately authenticated, purpose-bound domain-service publisher rather than an end-user bearer."],"relatedApplications":["Overview","Identity & Login","Access Control","Automations"],"order":7,"operationCount":7,"implementedContracts":6,"plannedContracts":1},{"name":"Trading","group":"Operate","description":"Markets and execution","purpose":"Discover markets and read owner-scoped trading projections behind a stable interface while market and matching authority remain independently controlled.","audiences":["trading applications","portfolio systems","market-data agents"],"businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"workflow":["read venue-scoped market rules and availability","prepare a valid owner-scoped request","reconcile accepted commands through orders, trades, positions, and balances"],"prerequisites":["venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"],"order":8,"operationCount":88,"implementedContracts":40,"plannedContracts":48},{"name":"Strategy Pools","group":"Operate","description":"Automated strategy positions","purpose":"Describe and monitor pooled strategy allocations, participation, performance, and lifecycle decisions.","audiences":["strategy operators","portfolio managers","allocation agents"],"businessCases":["strategy discovery","allocation tracking","performance and lifecycle review"],"workflow":["discover an eligible strategy","inspect risk, terms, and current state","track allocations and performance evidence"],"prerequisites":["an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation."],"relatedApplications":["Trading","Liquidity Management","Trust Center"],"order":9,"operationCount":11,"implementedContracts":4,"plannedContracts":7},{"name":"Liquidity Management","group":"Operate","description":"Liquidity pools, strategies and flows","purpose":"Inspect liquidity pools, strategies, positions, and movement evidence used to manage venue liquidity.","audiences":["liquidity operators","market makers","treasury agents"],"businessCases":["pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"workflow":["discover pools and constraints","inspect position and risk projections","track approved flows and resulting evidence"],"prerequisites":["eligible venue and asset pair","liquidity and treasury authority for mutations"],"agentGuidance":["Read projections do not grant market-making or transfer authority.","Use exact decimal strings and reconcile movements from the authoritative ledger."],"relatedApplications":["Trading","Strategy Pools","Wallets"],"order":10,"operationCount":16,"implementedContracts":7,"plannedContracts":9},{"name":"Commerce","group":"Operate","description":"Merchant operating system","purpose":"Onboard workspace merchants, define catalog and checkout policy, create structured invoices, observe rotational-wallet payments, and hand verified evidence into separately owned settlement and fulfillment lifecycles.","audiences":["merchant platforms","commerce operators","checkout agents"],"businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff","Commerce-backed digital-asset delivery"],"workflow":["create a PENDING_REVIEW merchant profile bound to an eligible operational destination","activate merchant capabilities only through a separate reviewed lifecycle","create catalog products and invoices from server-validated line items and totals","observe checkout and payment evidence from Payments and rotational wallets","cancel only unpaid eligible invoices or enter separately owned refund and exception workflows","settle an eligible rotational wallet through its exact owner and verify retained settlement evidence"],"prerequisites":["commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it."],"relatedApplications":["Payments","Funding","Digital Assets"],"order":11,"operationCount":38,"implementedContracts":20,"plannedContracts":18},{"name":"Digital Assets","group":"Operate","description":"Issue and manage assets","purpose":"Discover published tokens and collections through source-backed public projections, verify exact-decimal supply and retained lifecycle evidence, and keep future issuance, trading, redemption, marketplace, payment, and delivery authority in their separate governed lifecycles.","audiences":["asset issuers","marketplaces","portfolio agents"],"businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation","marketplace listing and cancellation","ownership, provenance, and proof verification","Commerce-backed asset delivery reconciliation"],"workflow":["discover public collections and assets through GET /api/v2/asset-collections and GET /api/v2/assets, preserving cursors and exact decimal strings","resolve one canonical asset UUID, then reconcile detail, lifecycle history, retained proofs, and referenced mint evidence without inferring private holdings or authority","select the asset class, governing network, collection, authorities, precision, supply cap, metadata, and compliance policy","create a private canonical collection or asset draft and review its commitment before publication","publish collection and asset identities separately from minting, holdings, listings, payment, or delivery","apply mint, burn, listing, and cancellation commands only against freshly read version, supply, balance, reservation, and authority state","resolve payment and checkout facts from Commerce and reconcile delivery atomically; never accept caller-authored paid assertions"],"prerequisites":["issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"],"order":12,"operationCount":57,"implementedContracts":12,"plannedContracts":45},{"name":"Billing","group":"Operate","description":"Plans, credits and history","purpose":"Expose the authenticated workspace's current credit position, billing period, metered usage, subscription posture, and purchasable product catalog without disclosing processor customer or subscription identifiers.","audiences":["account owners","finance teams","cost-management agents"],"businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"workflow":["read the billing account to establish the active period and credit-pool composition","read usage to compare rated and pending event totals","read products before presenting eligible plans or top-ups","treat invoices, hosted checkout, and portal-session creation as unavailable until those planned contracts enter the live OpenAPI document"],"prerequisites":["a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries."],"relatedApplications":["Billing Operations","Business Network","Admin Console"],"order":13,"operationCount":6,"implementedContracts":3,"plannedContracts":3},{"name":"Prediction Markets","group":"Operate","description":"Prediction discovery, rules and outcome evidence","purpose":"Discover prediction contracts and inspect their rules, lifecycle, performance, and participant-facing state without implying trading availability.","audiences":["prediction applications","research users","market-data agents"],"businessCases":["prediction discovery","contract detail review","performance and outcome monitoring"],"workflow":["list or search prediction contracts","inspect rules, dates, oracle, and lifecycle","monitor performance and authoritative resolution evidence"],"prerequisites":["a supported jurisdiction and market state","explicit eligibility for any future mutation"],"agentGuidance":["Current contracts are planning references and do not enable prediction trading.","Never infer resolution from price or performance; require authoritative outcome evidence."],"relatedApplications":["Trading","Price Feeds","Prediction Market Ops"],"order":14,"operationCount":4,"implementedContracts":0,"plannedContracts":4},{"name":"Barriers","group":"Build","description":"Programmable transaction gates","purpose":"Define and inspect programmable transaction gates that evaluate explicit conditions before a protected operation proceeds.","audiences":["contract developers","risk engineers","policy agents"],"businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"workflow":["define typed inputs and conditions","validate the barrier contract","evaluate and retain the resulting decision evidence"],"prerequisites":["an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"],"order":15,"operationCount":19,"implementedContracts":2,"plannedContracts":17},{"name":"Developers","group":"Build","description":"API access and credentials","purpose":"Manage API access, signing keys, workload identities, webhooks, SDK discovery, and machine integration metadata.","audiences":["application developers","platform engineers","integration agents"],"businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"workflow":["discover the machine contract and required scopes","register least-privilege credentials and signing keys","validate calls, retries, and event handling"],"prerequisites":["an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans."],"relatedApplications":["API Reference","Integration Guides","Access Control"],"order":16,"operationCount":31,"implementedContracts":20,"plannedContracts":11},{"name":"Contract Studio","group":"Build","description":"Contract authority and deploy","purpose":"Create, analyze, freeze, govern, prepare, and verify deterministic smart-contract launch records.","audiences":["contract teams","governance operators","deployment agents"],"businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"workflow":["create and analyze a draft","freeze exact artifacts and authority intent","bind governance and prepare an unsigned deployment transaction"],"prerequisites":["immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"],"order":17,"operationCount":14,"implementedContracts":14,"plannedContracts":0},{"name":"Execution Studio","group":"Build","description":"Deterministic package execution","purpose":"Create, validate, publish, deploy, invoke, trigger, and verify deterministic execution packages under immutable artifact, schema, sandbox, resource, node-attestation, and external-domain authority boundaries.","audiences":["execution package developers","platform and node operators","verification and reproducibility agents","security, policy, and supply-chain reviewers"],"businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers","operator and node attestation review","execution receipt and output verification"],"workflow":["ingest live OpenAPI and discover approved runtime, validation, capability, network, node, and resource profiles","create a private DRAFT from an immutable source artifact, exact digest, closed manifest, declared capabilities, and bounded resource policy","revise only the editable draft and invalidate any validation derived from changed commitments","validate the exact source, manifest, dependencies, schemas, runtime images, capabilities, policy, reproducibility, and sandbox behavior","publish one validated package version immutably at the admitted visibility","prepare an isolated TEST or PRODUCTION deployment whose limits only narrow package and platform policy","validate invocation inputs before executing and obtain fresh owner-issued authority for any external domain effect","create and govern typed triggers separately from deployment and invocation","verify package, build, input, output, runtime, node, resource, signature, and any separate domain receipt commitments together"],"prerequisites":["execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"],"order":18,"operationCount":44,"implementedContracts":28,"plannedContracts":16},{"name":"Automations","group":"Build","description":"Signed callbacks and rules","purpose":"Define, validate, operate, observe, and retire typed event, schedule, and manual automations with signed callback delivery while preserving the independent authority, policy, and evidence boundary of every underlying business action.","audiences":["workflow and integration developers","operations and reliability teams","automation and orchestration agents","security and audit reviewers"],"businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation","automation lifecycle governance"],"workflow":["ingest live OpenAPI and discover server-owned action profiles, trigger schemas, and workspace policy","register an SSRF-safe HTTPS callback endpoint when signed outcome delivery is required and secure its one-time secret","create a DRAFT automation with one typed trigger, approved action profile, secret-free bindings, callback reference, and bounded execution policy","validate configuration and bindings without invoking the domain action","activate or resume only after current trigger, endpoint, workspace, action-profile, and domain-policy checks pass","for manual EXECUTE, obtain a fresh purpose-bound authorization from the owning domain and bind the request to one exact automation version","distinguish run admission, domain outcome, callback attempt, and receiver acknowledgement as separate states","rotate endpoint signing epochs, retry only eligible failed deliveries without re-running the business action, and retire endpoints or automations with retained evidence"],"prerequisites":["automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"],"order":19,"operationCount":13,"implementedContracts":0,"plannedContracts":13},{"name":"Price Feeds","group":"Build","description":"Multi-source market data","purpose":"Discover canonical price feeds, inspect their provider composition and aggregation policy, read the latest signed observation, and replay entitled evidence without exposing workspace ownership or internal delivery identifiers.","audiences":["market-data clients","treasury and valuation systems","risk engines","pricing agents","audit and reconciliation tools"],"businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"workflow":["list feeds and select the canonical instrument plus quote asset","inspect cadence, provider composition, aggregation policy, and failover posture","read the latest snapshot and evaluate health, age_ms, quality_state, and chain_state before use","use an entitled subscription to replay signed observations in sequence order","advance with next_after_sequence and distinguish window_exceeded from a genuinely empty result"],"prerequisites":["a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"],"order":20,"operationCount":14,"implementedContracts":13,"plannedContracts":1},{"name":"Issuer Launchpad","group":"Build","description":"Evidence-backed decentralized listings","purpose":"Prepare an evidence-backed decentralized listing in a private issuer workspace, conduct version-pinned diligence and independent review, publish only signed validator-finalized disclosures, and admit eligible investors into a governed subscription lifecycle before allocation, issuance, market admission, and trading.","audiences":["issuers and capital-formation teams","verified sales agents and distribution partners","diligence reviewers and auditors","prospective investors and research applications","listing and evidence agents","public indexers"],"businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution","contractual investor subscription","crypto funding readiness with bank funding initially disabled","allocation, issuance, market admission, and matching-engine handoff","citation-bearing agent questions over finalized evidence"],"workflow":["bind the authenticated workspace's verified company authority to an issuer and create a private offering workspace","define a proposed security class and freeze a versioned requirement pack without issuing or minting an asset","open a diligence case and attach exact authorized Data Vault versions to each requirement","let an eligible reviewer re-authorize and pin the complete evidence view before recording an attributed decision and optional independent attestation","create a disclosure or correction release, freeze its exact claims and evidence commitments, sign it with derived issuer authority, and submit it for validator finality","freeze subscription terms and enabled funding rails, then register any legally verified sales distribution agreements","share the permanent public deal link; preserve an optional verified referral identifier through account creation without treating it as authority","authenticate the investor, explicitly accept every required acknowledgement, obtain Identity's signed acceptance receipt for the exact current deal, units and rail, and request the subscription","keep requested, eligible, funds-reserved, allocated, paid, issued, market-admitted, and tradeable states distinct; hand an immutable admission package to Core only after every governing gate passes"],"prerequisites":["an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading","Chain Explorer","Governance"],"order":21,"operationCount":42,"implementedContracts":42,"plannedContracts":0},{"name":"Transfer Compliance","group":"Trust & Data","description":"Credentials and travel rules","purpose":"Create and inspect owner-scoped regulated-transfer workflows, commitment-only identity and wallet readiness, VASP counterparty interoperability, signed policy decisions, reviews, and delivery evidence without exposing Travel Rule cleartext or granting settlement authority.","audiences":["compliance teams","VASP and payment integrations","treasury and custody controls","transfer agents","audit and reconciliation agents"],"businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"workflow":["confirm the sixteen public transfer-compliance contracts in deployed OpenAPI and authenticate with the least-privilege compliance scope","inspect credential and IVMS101 readiness without requesting regulated cleartext","register wallet-control evidence, create a consent-bound disclosure manifest, register a VASP candidate when needed, and authorize only the digest of a client-side encrypted envelope","register or select a VASP counterparty, then re-fetch it to validate status, due diligence, protocol, network, jurisdiction, validity, and public keys","create an idempotent transfer intent, prepare required evidence, and submit only credential and proof commitments for screening","record reviewer decisions under compliance:review, retain exact commitments and receipts, and re-fetch state before any separately authorized consequential action"],"prerequisites":["an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"],"order":22,"operationCount":25,"implementedContracts":21,"plannedContracts":4},{"name":"Data Vault","group":"Trust & Data","description":"Protected files and sharing","purpose":"Navigate minimized owner-scoped protected-object metadata today and design future client-encrypted upload, purpose-bound retrieval, controlled sharing, retention, and erasure workflows without making the gateway a storage owner, key custodian, or cleartext proxy.","audiences":["workspace data owners","records and compliance systems","document-processing agents","evidence and disclosure integrations"],"businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"workflow":["ingest live OpenAPI and use the bearer-derived workspace root; never submit a vault selector","list top-level objects, select by stable object identifier, and refresh current minimized detail","navigate directories one bounded level at a time instead of requesting or inferring a recursive tree","when promoted, create a bounded client-encrypted upload session and complete it only after every ordered part, digest, content root, and manifest commitment verifies","when promoted, request a short-lived subject-, purpose-, object-, version-, and audience-bound download ticket after current owner or grant authorization","when promoted, create, inspect, and revoke typed grants separately from invitations and delivery","reconcile retention, legal holds, grants, replicas, and key-destruction evidence before recycle, restore, or erasure","verify private owner state separately from public Explorer anchor and proof projections"],"prerequisites":["vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"],"order":23,"operationCount":25,"implementedContracts":7,"plannedContracts":18},{"name":"Evidence Streams","group":"Trust & Data","description":"Ingest and verify evidence","purpose":"Discover, ingest, monitor, and verify schema-bound ordered evidence while keeping source authentication, structural validity, chain integrity, operational health, and downstream business authority as explicitly separate conclusions.","audiences":["auditors and assurance teams","event producers and processors","verification and monitoring agents","compliance, settlement, governance, and operational systems consuming evidence"],"businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation","commitment handoff into separately authorized business workflows"],"workflow":["ingest live OpenAPI, authenticate to the bearer-derived workspace, and discover stable stream and schema identifiers","load the exact executable schema and verify its canonical commitment before producing or interpreting evidence","reconcile enrolled-source lifecycle, last activity, rejection counts, aggregate health, open alerts, and quarantine posture","when ingestion is promoted, canonicalize, sign, and append one replay-protected event or a bounded explicitly atomic batch","verify payload, previous-chain, chain, and server-signature commitments across enough history to establish continuity","triage alerts and quarantine through separately authorized versioned decisions without changing the underlying evidence","apply any downstream payment, settlement, disclosure, governance, custody, or operational decision only through that domain's own current policy and authority"],"prerequisites":["evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"],"order":24,"operationCount":27,"implementedContracts":11,"plannedContracts":16},{"name":"Trust Center","group":"Trust & Data","description":"Identity and verification","purpose":"Give an authenticated subject a consent-aware, policy-versioned trust workflow: discover requirements, start and monitor verification, inspect minimized attestation and credential commitments, and manage allowlisted self-asserted claims without exposing regulated evidence or collapsing issuer, reviewer, provider, subject, and relying-party authority.","audiences":["identity subjects","consent-aware onboarding applications","trust and verification agents","credential issuers and relying-party integrators"],"businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"workflow":["fetch current verification policy and sanctions-source posture","select the least intrusive applicable policy and disclose checks, evidence classes, freshness, jurisdiction, and retention before consent","start one idempotent subject-owned verification through the canonical trust lifecycle","poll minimized verification state and distinguish capture, check completion, review, and final decision","evaluate credential or attestation lifecycle, validity, issuer proof, assurance, and commitments under the relying-party policy","manage private self-asserted claims separately from verification evidence and issuer-backed credentials"],"prerequisites":["subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"],"order":25,"operationCount":128,"implementedContracts":77,"plannedContracts":51},{"name":"Entropy Lab","group":"Public Network","description":"Public randomness laboratory","purpose":"Expose a machine-discoverable physical-entropy contract, its pinned Ed25519 verification key, and bounded bearer-authorized source-signed samples without misrepresenting samples as keys, beacons, fairness proofs, or downstream authority.","audiences":["cryptographic protocol developers","verification and testing agents","security engineers","researchers"],"businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"workflow":["fetch current limits and endpoint discovery","fetch and pin the current source identity and Ed25519 public key","create a fresh caller nonce and stable logical-request idempotency key","request the minimum bounded source-signed sample","decode and verify length, digest, identities, canonical signature, and record commitment","apply the downstream protocol's domain separation, derivation, health, contributor, and failure model"],"prerequisites":["an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"],"order":26,"operationCount":8,"implementedContracts":3,"plannedContracts":5},{"name":"Chain Explorer","group":"Public Network","description":"Public records and proofs","purpose":"Expose public chain, asset, contract, funding, and evidence projections with links to independently verifiable proofs.","audiences":["public users","wallets and indexers","research agents"],"businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"workflow":["select the canonical resource identifier","read the public projection","follow proof and related-resource links for verification"],"prerequisites":["a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"],"order":27,"operationCount":200,"implementedContracts":195,"plannedContracts":5},{"name":"Developer Portal","group":"Public Network","description":"Build on Hybrid-Chain","purpose":"Publish a stable machine-discovery entry point for executable OpenAPI, the broader readiness registry, official SDK status, authentication profiles, integration guides, Explorer resources, and cross-cutting agent rules.","audiences":["application developers","solution architects","SDK maintainers","coding and tool-registry agents"],"businessCases":["integration onboarding","SDK generation and publication discovery","environment and authentication setup","agent tool registration","release-time contract validation"],"workflow":["read the portal catalog and follow its resource links","fetch live OpenAPI and select only implemented operations","inspect official SDK publication status or generate a client from the linked contract","apply the published authentication, pagination, error, retry, idempotency, signature, and decimal policies","re-fetch OpenAPI before release validation"],"prerequisites":["a target environment and business outcome","an OpenAPI 3.1-compatible toolchain","appropriate credentials and signing support for non-public operations"],"agentGuidance":["Prefer machine catalogs and OpenAPI over website scraping or inferred neighboring paths.","An empty official SDK catalog means no official package is published; generate from the linked OpenAPI instead of inventing package coordinates.","Pin generated clients to an observed OpenAPI digest and retain generator identity, settings, and artifact digest.","Discovery metadata and route presence never bypass runtime scope, tenant, feature, domain, or downstream-readiness policy."],"relatedApplications":["Developers","API Reference","Integration Guides"],"order":28,"operationCount":2,"implementedContracts":2,"plannedContracts":0},{"name":"API Reference","group":"Public Network","description":"Endpoints, schemas and examples","purpose":"Publish the live OpenAPI machine contract for executable gateway operations and a separate capability registry for ownership, application mapping, business context, legacy parity, and honestly labeled plans.","audiences":["API developers","SDK and validator generators","agent tool registries","conformance and release engineers"],"businessCases":["machine contract ingestion","endpoint and schema discovery","implementation-status verification","client generation","release conformance","roadmap and ownership analysis"],"workflow":["download and digest the live OpenAPI document","select operations by operationId or stable registry operation ID","generate parameters, bodies, validators, security handling, and response branches from exact machine schemas","use the capability registry for ownership and planned context only","re-fetch and compare the contract before release"],"prerequisites":["an OpenAPI 3.1-compatible consumer","support for JSON Schema references and Hybrid-Chain OpenAPI extensions","readiness to handle documented authentication, signing, errors, idempotency, reconciliation, and retries"],"agentGuidance":["OpenAPI is authoritative for executable operations; website examples and narrative guidance cannot widen the machine contract.","A capability-registry-only planned-contract is not callable until promoted into live OpenAPI.","Use contract.reference to move from an implemented registry record to its exact OpenAPI JSON Pointer.","Re-fetch before release and fail closed on incompatible schema, security, scope, or signing changes."],"relatedApplications":["Developer Portal","Developers","Integration Guides"],"order":29,"operationCount":2,"implementedContracts":2,"plannedContracts":0},{"name":"Integration Guides","group":"Public Network","description":"Implementation blueprints","purpose":"Publish searchable, version-pinned task blueprints that connect multiple endpoint contracts into safe business workflows without conflating narrative composition with executable authority.","audiences":["solution architects","integration teams","workflow and planning agents","security and operations reviewers"],"businessCases":["workflow implementation","security-profile adoption","cross-module orchestration","failure and reconciliation design","business-case discovery"],"workflow":["search by exact category and bounded content query","select a stable guide slug and retain the returned source digest","resolve every related endpoint against live OpenAPI","exclude planned-only operations or design explicit future-state boundaries","implement controls, retries, verification, reconciliation, and rollback","revalidate all referenced contracts before release"],"prerequisites":["a defined business outcome and acceptance policy","access to every required implemented module and scope","an OpenAPI-aware consumer that can distinguish implemented and planned registry statuses"],"agentGuidance":["Guides explain composition and expected controls; endpoint OpenAPI remains authoritative for every accepted field, response, and security requirement.","relatedEndpoints can include planned contracts; resolve and filter them against live OpenAPI before generating calls.","Treat nextCursor as opaque and keep it bound to the same search filters.","Preserve sourceSha256 to identify the narrative version used by an implementation and validate all referenced operations again before release."],"relatedApplications":["API Reference","Developer Portal","Developers"],"order":30,"operationCount":2,"implementedContracts":2,"plannedContracts":0},{"name":"Admin Console","group":"Administration","description":"Account growth and platform operations","purpose":"Provide a bounded administrative application map while keeping Identity, access, billing, newsroom, risk, review, infrastructure, and other domain controls at their authoritative services.","audiences":["platform and tenant administrators","support and security leads","operations and audit agents"],"businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"workflow":["discover which administrative operations are executable in live OpenAPI","establish the tenant, role, scope, and fresh step-up boundary required by the owning domain","read the narrow domain projection and retain its version and evidence references","perform only an implemented domain-specific governed action","reconcile the returned state and audit evidence instead of treating command acceptance as completion"],"prerequisites":["restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control"],"order":31,"operationCount":31,"implementedContracts":11,"plannedContracts":20},{"name":"Arena Monitor","group":"Administration","description":"Live matches, wagers, evidence and payout assurance","purpose":"Monitor tenant-scoped Arena matches, viewers, markets, wagers, escrow, payout projections, refereeing, and Hybrid evidence from one read-only administrative surface.","audiences":["Arena operations","risk reviewers","support and demonstration operators"],"businessCases":["live match oversight","wager and escrow observation","evidence-feed audit","referee and payout-assurance review"],"workflow":["authenticate through Identity with both administrative scopes","read the live overview at a bounded simulation position","resume the evidence feed using only the returned opaque cursor","follow canonical proof references when production proof publication becomes available"],"prerequisites":["an authenticated tenant administrator","both admin:read and arena:admin:read authority","an available private Arena engine configured at the Gateway"],"agentGuidance":["This surface is observation-only and grants no match, wager, wallet, escrow, payout, settlement, referee, or game-server authority.","Treat D0 simulation data as synthetic and never describe its projected payouts, proofs, or escrow state as real value movement or chain finality.","Never forward the user's bearer to Arena; the Gateway authenticates Identity and narrows the call to a short-lived signed internal capability.","Treat cursors as opaque, tenant-bound values and fail closed on authority mismatch or malformed engine responses."],"relatedApplications":["Evidence Streams","Indexer Controller","Access Control"],"order":32,"operationCount":2,"implementedContracts":2,"plannedContracts":0},{"name":"Identity & Login","group":"Administration","description":"Login methods and federation policy","purpose":"Create and protect tenant-bound accounts, rotating sessions, TOTP authenticators, federation bindings, profile projections, contact changes, account closure, request-signing keys, and signed workload identities through the authoritative Identity service.","audiences":["end-user applications","identity administrators","authentication and recovery agents","workload and agent platform operators"],"businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance","retention-aware account closure","human API signing-key and machine workload-key lifecycle"],"workflow":["resolve tenant brand, login policy, account type, and current legal terms","register and activate an account or complete an explicit federated login transaction","issue a short-lived session or refreshless workload bearer","read principal-derived profile and security projections","obtain a fresh purpose-bound step-up before sensitive changes","perform the exact mutation and immediately reconcile session, token, key, or lifecycle consequences"],"prerequisites":["configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately."],"relatedApplications":["Access Control","Trust Center","Teams & Workspaces"],"order":33,"operationCount":44,"implementedContracts":44,"plannedContracts":0},{"name":"Infrastructure","group":"Administration","description":"Topology health, incidents and maintenance","purpose":"Expose public service identity and testnet-infrastructure evidence together with a restricted, aggregate-only account-readiness overview; keep observation separate from operational control.","audiences":["site reliability teams","platform operators","incident agents","administration analytics agents"],"businessCases":["service health review","testnet infrastructure evidence verification","account growth and readiness trending","incident coordination"],"workflow":["read the public service and infrastructure posture","verify evidence by stable identifier where available","use the restricted overview only for aggregate account trends","route remediation or identity-level investigation through its separately authorized owner"],"prerequisites":["no credential for public status and Explorer evidence","an admin:read bearer for the aggregate administration overview","an exact evidence identifier for historical verification"],"agentGuidance":["Health and readiness projections are observations, not permission to restart, reconfigure, route traffic, or change market state.","Treat status/info as service identity rather than dependency readiness; use the evidence timestamp, commitment, network, and component identity for operational correlation.","The administration overview contains 52 aggregate weekly cohorts and no account rows. Never infer individual account state or request broader identity data from it.","Access audit events remain a planning contract until Identity and other owners publish a unified cursor, retention policy, event taxonomy, and tenant-safe read model."],"relatedApplications":["Admin Console","Indexer Controller","Evidence Streams"],"order":34,"operationCount":7,"implementedContracts":6,"plannedContracts":1},{"name":"Billing Operations","group":"Administration","description":"Revenue, credits and reconciliation","purpose":"Manage administrative revenue, credit, invoice, and reconciliation workflows separately from customer billing views.","audiences":["finance operations","billing administrators","reconciliation agents"],"businessCases":["revenue operations","credit adjustments","billing reconciliation"],"workflow":["select the tenant and billing period","inspect invoices, usage, credits, and exceptions","record a governed adjustment or reconciliation decision"],"prerequisites":["restricted billing administration scope","attributed reason and source evidence for mutations"],"agentGuidance":["Never infer cash settlement from invoice lifecycle alone.","Keep customer-facing and administrative billing identifiers linked but distinct."],"relatedApplications":["Billing","Admin Console","Funding"],"order":35,"operationCount":3,"implementedContracts":0,"plannedContracts":3},{"name":"Newsroom Operations","group":"Administration","description":"Publishing and editorial control","purpose":"Operate the Core-owned editorial ledger through a restricted, typed boundary for private drafts, safe structured content, scheduled or immediate publication, archival, immutable revisions, and public authenticity evidence.","audiences":["editors","communications teams","publishing agents","compliance reviewers","Explorer integrators"],"businessCases":["editorial workflow","governed publication","scheduled release","correction and archival","revision and authenticity verification"],"workflow":["list minimized article summaries with an exact lifecycle filter or search term","create a private draft with a stable slug and structured safe content blocks","review the returned revision and content commitment","apply a version-bound SAVE_DRAFT, SCHEDULE, PUBLISH, or ARCHIVE action with an attributed reason","re-read the article and verify its retained revision and proof chain","use the public Newsroom and Explorer reads only after the ledger reports publication"],"prerequisites":["an authenticated owner context","admin:news:read for collection access","admin:news:write and an Idempotency-Key for mutations","approved editorial content and publication policy","the latest article version before any lifecycle action","an editorial_date for SCHEDULE"],"agentGuidance":["Creation always produces a private DRAFT; supplying editorial_date does not publish or schedule it.","Send only the documented structured body blocks. HTML, scripts, secrets, arbitrary objects, and unknown fields are rejected.","Treat expected_version as an optimistic concurrency boundary. On 409, re-read the article, review the intervening revision, and create a new intent rather than overwriting it.","Reuse the same Idempotency-Key only for a byte-equivalent retry of one logical mutation. A different request under the same key is a conflict.","author_name is a public byline, not authority. The authenticated profile is the actor recorded by the ledger.","Draft, scheduled, archived, or review state is not public publication. Do not announce or syndicate an article until the returned lifecycle is PUBLISHED.","Retain article_uuid, version, revision, content_commitment, previous_commitment, action reason, and proof identifiers for every release or correction.","Never interpret publication as website deployment authority, trading authority, or permission to mutate Explorer evidence."],"relatedApplications":["Admin Console","Chain Explorer","Evidence Streams"],"order":36,"operationCount":3,"implementedContracts":3,"plannedContracts":0},{"name":"Tenant & Brand Manager","group":"Administration","description":"Domains, branding and entitlements","purpose":"Govern tenant configuration revisions, domains, branding, labels, links, and product entitlements.","audiences":["tenant administrators","brand operations","platform configuration agents"],"businessCases":["tenant branding","custom-domain lifecycle","entitlement management"],"workflow":["create an immutable configuration revision","validate and obtain required review","publish or revert the reviewed revision"],"prerequisites":["tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration."],"relatedApplications":["Teams & Workspaces","Access Control","Billing Operations"],"order":37,"operationCount":22,"implementedContracts":12,"plannedContracts":10},{"name":"Teams & Workspaces","group":"Administration","description":"Membership and workspace administration","purpose":"Create and select workspaces, manage bounded invitations, memberships and roles, and administer versioned tenant configuration, domains, entitlements, and publication revisions without crossing tenant or authority boundaries.","audiences":["workspace owners","team administrators","collaboration agents"],"businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"workflow":["create or select an authenticated workspace","invite members with a bounded predefined role and accept through the invitation owner","read the privacy-minimized active roster before changing or revoking membership","review, change, or revoke membership with version and last-owner protections","draft, review, publish, or revert tenant configuration as separate versioned stages","verify domain possession before any separately owned routing or certificate activation"],"prerequisites":["tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"],"order":38,"operationCount":47,"implementedContracts":29,"plannedContracts":18},{"name":"Access Control","group":"Administration","description":"Roles, sessions and account security","purpose":"Administer and verify least-privilege access through explicit authority lifecycles for sessions, authenticators, signing keys, step-up, role assignments, revocations, and audit evidence without accepting generic action objects or credential-bearing compatibility payloads.","audiences":["security administrators","workspace owners","access-review agents","mobile and workload integration agents"],"businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment","access audit review"],"workflow":["ingest live OpenAPI and choose the explicit resource matching the intended security outcome","create, introspect, refresh, or revoke a session without mixing credential lifecycles","list signing keys before registration or revocation and retain the returned key epoch and evidence","obtain a single-use purpose-bound step-up only immediately before an eligible sensitive operation","for restricted administration, read current roles and sessions, apply the least-privilege version-bound change, and verify audit evidence","discard revoked or rotated credentials and re-read canonical posture before continuing"],"prerequisites":["the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"],"order":39,"operationCount":46,"implementedContracts":32,"plannedContracts":14},{"name":"User Intel & Risk","group":"Administration","description":"Identity lifecycle, evidence and intervention","purpose":"Review tenant-scoped identity lifecycle, deterministic risk signals, alerts, session posture, and attributed interventions without exposing secret or regulated source evidence.","audiences":["risk analysts","support investigators","security administrators","review-assistance agents"],"businessCases":["exact-identity risk triage","account-takeover investigation","alert assignment and resolution","lifecycle intervention","non-trading capability suspension","reviewer-rating evidence"],"workflow":["start with an exact managed-identity identifier or aggregate tenant posture","inspect control versions, evidence commitments, alerts, sessions, and prior events","obtain USER_RISK_INTERVENTION step-up and record one reasoned version-bound action","re-read the canonical record and reconcile retained evidence"],"prerequisites":["admin:identity:read for review or admin:identity:write for intervention","eligible tenant administrator role","fresh purpose-bound step-up, RFC 9421 signature, and stable idempotency key for interventions"],"agentGuidance":["Omitting the exact q identifier returns metrics but no user rows; never turn exact search into directory enumeration.","Signals are deterministic review inputs backed by commitments, not inferred protected attributes and not autonomous adverse-decision authority.","Tenant and actor are derived from the bearer session; do not send tenant_uuid or actor_ref.","Use the latest returned version, re-read after a 409, and reuse an idempotency key only for the same logical body.","TRADING capability changes are frozen. These operations never grant matching, market, payment, settlement, publisher, ingress, allowlist, or traffic authority."],"relatedApplications":["Identity Review","Access Control","Trust Center"],"order":40,"operationCount":3,"implementedContracts":3,"plannedContracts":0},{"name":"Identity Review","group":"Administration","description":"Independent KYC review and decision evidence","purpose":"Provide an independent reviewer workflow for pending KYC evidence, approval, rejection, and retained decisions.","audiences":["KYC reviewers","compliance supervisors","review-assistance agents"],"businessCases":["pending KYC review","independent approval or rejection","decision evidence audit"],"workflow":["list eligible pending reviews","inspect minimum necessary evidence and policy","record an attributed decision with reason and version"],"prerequisites":["independent reviewer authority","complete policy-required evidence"],"agentGuidance":["Agents may summarize evidence but must not fabricate or conceal reviewer attribution.","Keep review authority separate from evidence submission."],"relatedApplications":["Trust Center","User Intel & Risk","Transfer Compliance"],"order":41,"operationCount":3,"implementedContracts":0,"plannedContracts":3},{"name":"Indexer Controller","group":"Administration","description":"Chain synchronization, transfers, reconciliation and proof delivery","purpose":"Monitor chain synchronization, indexed deposits, reconciliation incidents, and public proof-delivery posture.","audiences":["indexer operators","funding operations","reconciliation agents"],"businessCases":["chain sync monitoring","deposit indexing","reconciliation and proof delivery"],"workflow":["read aggregate chain and indexer posture","page through owner-scoped deposits with an optional exact lifecycle filter","compare the related reconciliation evidence before triaging a gap","preserve commitments and re-fetch without manufacturing finality"],"prerequisites":["infrastructure or funding operations scope","canonical chain and network identifiers"],"agentGuidance":["Indexing lag is not chain rollback and indexed state is not finality by itself.","Preserve checkpoint, block, confirmation, event, certificate, and proof identifiers.","Use authenticated funding reads for owner operations and public Explorer projections for public verification; never widen an owner query with profile, vault, wallet, or address selectors.","Treat decimal strings as exact values and first-observed valuations as historical evidence rather than current prices.","A resolved reconciliation incident records evidence workflow state and never implies that this read changed a balance."],"relatedApplications":["Infrastructure","Funding","Chain Explorer"],"order":42,"operationCount":5,"implementedContracts":5,"plannedContracts":0},{"name":"Trading & Matching Ops","group":"Administration","description":"Platform-wide matching, market and risk supervision","purpose":"Document platform-wide market and matching supervision while keeping trading authority, traffic, suspension, and engine selection separately governed.","audiences":["market operations","risk supervisors","incident agents"],"businessCases":["market posture review","matching incident triage","risk and reconciliation supervision"],"workflow":["read current market and engine evidence","compare lag, divergence, risk, and reconciliation posture","escalate through a separately approved control workflow"],"prerequisites":["restricted trading-operations scope","separate explicit approval for any authority or traffic change"],"agentGuidance":["Documentation and observational evidence cannot enable ingress, publishing, allowlists, markets, or traffic.","Keep Python authoritative and trading frozen unless a later approval explicitly changes that boundary."],"relatedApplications":["Trading","Infrastructure","Evidence Streams"],"order":43,"operationCount":1,"implementedContracts":1,"plannedContracts":0},{"name":"Prediction Market Ops","group":"Administration","description":"Prediction lifecycle, oracle and resolution supervision","purpose":"Define the future administrative controls for prediction-contract lifecycle, oracle evidence, exposure review, and resolution governance.","audiences":["prediction-market operators","oracle reviewers","risk supervisors"],"businessCases":["prediction lifecycle supervision","oracle and resolution review","exposure and dispute oversight"],"workflow":["inspect the prediction contract and oracle policy","review exposure, evidence, and disputes","record a governed lifecycle or resolution decision"],"prerequisites":["restricted prediction-operations scope","authoritative oracle and review evidence"],"agentGuidance":["These routes are planning contracts and are not executable.","No resolution, suspension, market-status, or traffic change is authorized by documentation alone."],"relatedApplications":["Prediction Markets","Trading & Matching Ops","Governance"],"order":44,"operationCount":5,"implementedContracts":0,"plannedContracts":5}],"capabilities":[{"name":"Authentication","chapter":"Authentication","chapterOrder":0,"operationCount":9},{"name":"Identity · validate","chapter":"Authentication","chapterOrder":0,"operationCount":1},{"name":"Identity sessions and federation","chapter":"Authentication","chapterOrder":0,"operationCount":22},{"name":"Identity · create","chapter":"User Profile Data","chapterOrder":1,"operationCount":1},{"name":"Identity · get","chapter":"User Profile Data","chapterOrder":1,"operationCount":1},{"name":"Identity · transfer credentials","chapter":"User Profile Data","chapterOrder":1,"operationCount":2},{"name":"User Profile Data","chapter":"User Profile Data","chapterOrder":1,"operationCount":17},{"name":"Identity · mobile","chapter":"Session Management","chapterOrder":2,"operationCount":8},{"name":"Session Management","chapter":"Session Management","chapterOrder":2,"operationCount":1},{"name":"Identity · whitelabels","chapter":"Workspace Management","chapterOrder":3,"operationCount":4},{"name":"Teams & workspaces","chapter":"Workspace Management","chapterOrder":3,"operationCount":7},{"name":"Tenant and brand management","chapter":"Workspace Management","chapterOrder":3,"operationCount":18},{"name":"Workspace Management","chapter":"Workspace Management","chapterOrder":3,"operationCount":11},{"name":"AI wallet control","chapter":"Vault / Wallet Functions","chapterOrder":4,"operationCount":19},{"name":"MPC wallet lifecycle","chapter":"Vault / Wallet Functions","chapterOrder":4,"operationCount":21},{"name":"Operational MPC wallets","chapter":"Vault / Wallet Functions","chapterOrder":4,"operationCount":8},{"name":"Vault / Wallet Functions","chapter":"Vault / Wallet Functions","chapterOrder":4,"operationCount":20},{"name":"Payment Functions","chapter":"Payment Functions","chapterOrder":5,"operationCount":6},{"name":"Payments","chapter":"Payment Functions","chapterOrder":5,"operationCount":7},{"name":"Merchant commerce","chapter":"Merchant Functions","chapterOrder":6,"operationCount":13},{"name":"Merchant Functions","chapter":"Merchant Functions","chapterOrder":6,"operationCount":16},{"name":"Decentralized Trading","chapter":"Decentralized Trading","chapterOrder":7,"operationCount":9},{"name":"Markets and execution","chapter":"Decentralized Trading","chapterOrder":7,"operationCount":17},{"name":"Securities Trading","chapter":"Securities Trading","chapterOrder":8,"operationCount":8},{"name":"Virtual Exchange","chapter":"Virtual Exchange","chapterOrder":9,"operationCount":5},{"name":"Digital assets","chapter":"Tokenized Securities","chapterOrder":10,"operationCount":19},{"name":"Issuer Launchpad","chapter":"Tokenized Securities","chapterOrder":10,"operationCount":42},{"name":"Tokenized Securities","chapter":"Tokenized Securities","chapterOrder":10,"operationCount":9},{"name":"Prediction Markets","chapter":"Prediction Markets","chapterOrder":11,"operationCount":4},{"name":"Barrier Product Constructor","chapter":"Barrier Product Constructor","chapterOrder":12,"operationCount":9},{"name":"Programmable barriers","chapter":"Barrier Product Constructor","chapterOrder":12,"operationCount":8},{"name":"NFT Super Store","chapter":"NFT Super Store","chapterOrder":13,"operationCount":25},{"name":"Account overview","chapter":"General Data","chapterOrder":14,"operationCount":2},{"name":"General Data","chapter":"General Data","chapterOrder":14,"operationCount":5},{"name":"Identity · status","chapter":"General Data","chapterOrder":14,"operationCount":1},{"name":"News and verification","chapter":"General Data","chapterOrder":14,"operationCount":3},{"name":"Platform metadata","chapter":"General Data","chapterOrder":14,"operationCount":1},{"name":"Platform status","chapter":"General Data","chapterOrder":14,"operationCount":1},{"name":"Identity · messaging","chapter":"Notifications","chapterOrder":15,"operationCount":1},{"name":"Notifications","chapter":"Notifications","chapterOrder":15,"operationCount":4},{"name":"Referral System","chapter":"Referral System","chapterOrder":16,"operationCount":3},{"name":"Identity · attestations","chapter":"KYC / AML Functions","chapterOrder":17,"operationCount":13},{"name":"Identity · verification","chapter":"KYC / AML Functions","chapterOrder":17,"operationCount":11},{"name":"KYC / AML Functions","chapter":"KYC / AML Functions","chapterOrder":17,"operationCount":5},{"name":"Access control","chapter":"Admin Functions","chapterOrder":18,"operationCount":6},{"name":"Admin Functions","chapter":"Admin Functions","chapterOrder":18,"operationCount":6},{"name":"Administration overview","chapter":"Admin Functions","chapterOrder":18,"operationCount":1},{"name":"Arena administration","chapter":"Admin Functions","chapterOrder":18,"operationCount":2},{"name":"Billing operations","chapter":"Admin Functions","chapterOrder":18,"operationCount":3},{"name":"Identity login policy","chapter":"Admin Functions","chapterOrder":18,"operationCount":4},{"name":"Newsroom operations","chapter":"Admin Functions","chapterOrder":18,"operationCount":3},{"name":"Prediction market operations","chapter":"Admin Functions","chapterOrder":18,"operationCount":5},{"name":"User intelligence and risk","chapter":"Admin Functions","chapterOrder":18,"operationCount":3},{"name":"Public entropy","chapter":"Quantum Entropy","chapterOrder":19,"operationCount":6},{"name":"Quantum Entropy","chapter":"Quantum Entropy","chapterOrder":19,"operationCount":2},{"name":"Protected data vault","chapter":"Quantum Storage","chapterOrder":20,"operationCount":10},{"name":"Quantum Storage","chapter":"Quantum Storage","chapterOrder":20,"operationCount":10},{"name":"Agent-native Context Mesh","chapter":"Data Sync Functions","chapterOrder":21,"operationCount":31},{"name":"DataStreams Functions","chapter":"DataStreams Functions","chapterOrder":22,"operationCount":7},{"name":"Governance","chapter":"Governance","chapterOrder":23,"operationCount":10},{"name":"Funding & settlement","chapter":"Funding & Settlement","chapterOrder":24,"operationCount":11},{"name":"Strategy pools","chapter":"Strategy Pools","chapterOrder":25,"operationCount":7},{"name":"Customer billing","chapter":"Billing","chapterOrder":26,"operationCount":6},{"name":"Developer access","chapter":"Developer Platform","chapterOrder":27,"operationCount":10},{"name":"Developer documentation","chapter":"Developer Platform","chapterOrder":27,"operationCount":2},{"name":"Integration guides","chapter":"Developer Platform","chapterOrder":27,"operationCount":2},{"name":"Smart-contract lifecycle","chapter":"Smart Contracts","chapterOrder":28,"operationCount":11},{"name":"Deterministic execution","chapter":"Execution","chapterOrder":29,"operationCount":16},{"name":"Automations","chapter":"Automations","chapterOrder":30,"operationCount":13},{"name":"Price feeds","chapter":"Price Feeds","chapterOrder":31,"operationCount":11},{"name":"Transfer compliance","chapter":"Transfer Compliance","chapterOrder":32,"operationCount":18},{"name":"Evidence streams","chapter":"Evidence Streams","chapterOrder":33,"operationCount":16},{"name":"Trust & identity","chapter":"Trust Center","chapterOrder":34,"operationCount":9},{"name":"Explorer · ai wallet policies","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · asset collections","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · asset proofs","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · assets","chapter":"Explorer","chapterOrder":35,"operationCount":4},{"name":"Explorer · balances","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · barriers","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · catalog","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · contracts","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · counterparties","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · currencies","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · data vault","chapter":"Explorer","chapterOrder":35,"operationCount":5},{"name":"Explorer · datastreams","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · evidence events","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · evidence streams","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · execution","chapter":"Explorer","chapterOrder":35,"operationCount":9},{"name":"Explorer · funding","chapter":"Explorer","chapterOrder":35,"operationCount":27},{"name":"Explorer · identities","chapter":"Explorer","chapterOrder":35,"operationCount":4},{"name":"Explorer · liquidity pools","chapter":"Explorer","chapterOrder":35,"operationCount":4},{"name":"Explorer · markets","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · mints","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · mpc wallet ceremonies","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · mpc wallets","chapter":"Explorer","chapterOrder":35,"operationCount":46},{"name":"Explorer · orders","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · prices","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · search","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · settlements","chapter":"Explorer","chapterOrder":35,"operationCount":45},{"name":"Explorer · strategies","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · strategy pools","chapter":"Explorer","chapterOrder":35,"operationCount":2},{"name":"Explorer · summary","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · testnet","chapter":"Explorer","chapterOrder":35,"operationCount":5},{"name":"Explorer · trades","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · transactions","chapter":"Explorer","chapterOrder":35,"operationCount":3},{"name":"Explorer · transfers","chapter":"Explorer","chapterOrder":35,"operationCount":4},{"name":"Explorer · vault assets","chapter":"Explorer","chapterOrder":35,"operationCount":1},{"name":"Explorer · vaults","chapter":"Explorer","chapterOrder":35,"operationCount":4}],"operations":[{"id":"post-api-v2-operational-control-domain","method":"POST","path":"/api/v2/operational-control/{domain}","title":"Execute an authenticated operational-control action","description":"Execute an authenticated operational-control action through the canonical Hybrid-Chain V2 interface.","chapter":"Administration","chapterOrder":35,"capability":"Core operational control plane","owners":["core-operational-control"],"applications":[],"authentication":"bearer+scope","exposure":"authenticated","status":"implemented-contract","parity":"service-migration","sourceKinds":["v2-native"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-control~1{domain}/post","scope":"platform:write","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:write authority.","example":"Bearer hc_live_…"},{"name":"domain","location":"path","required":true,"type":"identifier","description":"Canonical domain.","example":"domain-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for execute an authenticated operational-control action. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Execute an authenticated operational-control action through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to execute an authenticated operational-control action.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":[],"prerequisites":["A bearer credential with platform:write authority and the required tenant, workspace, and role context."],"agentGuidance":["Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":[]}},{"id":"post-internal-api-v2-identity-verification-provider-callback","method":"POST","path":"/api/v2/identity/verification/provider/callback","title":"IDENTITY: receive verification provider callback","description":"IDENTITY: receive verification provider callback through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"internal-only","status":"internal-only","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/provider/callback","source":"Identity APIHandler.py · receive_verification_provider_callback"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-internal-api-v2-identity-verification-provider-callback","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["receive verification provider callback"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: receive verification provider callback through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is an Identity-owner integration hook, not a public client operation. Provider event authentication, replay protection, evidence minimization, and session correlation remain internal-only.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-internal-api-v2-identity-verification-sanctions-sync","method":"POST","path":"/api/v2/identity/verification/sanctions/sync","title":"IDENTITY: sync sanctions sources","description":"IDENTITY: sync sanctions sources through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"internal-only","status":"internal-only","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/sanctions/sync","source":"Identity APIHandler.py · sync_sanctions_sources"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-internal-api-v2-identity-verification-sanctions-sync","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["sync sanctions sources"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: sync sanctions sources through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is an Identity-owner maintenance operation, not a public screening API. Sanctions-source refresh and provider credentials remain internal-only; public integrations may read minimized source posture from GET /api/v2/identity/verification/sanctions/sources.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-internal-api-v1-sync-balance-profiles","method":"GET","path":"/api/v1/sync/balance/profiles","title":"SYNC: Get Profile Short-Balances","description":"SYNC: Get Profile Short-Balances through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/balance/profiles","operation":"SYNC: Get Profile Short-Balances"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-balance-profiles","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get Profile Short-Balances through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get profile short-balances before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-ledger-full","method":"GET","path":"/api/v1/sync/ledger/full","title":"SYNC: Get All Ledger Transactions","description":"SYNC: Get All Ledger Transactions through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/ledger/full","operation":"SYNC: Get All Ledger Transactions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-ledger-full","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Ledger Transactions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all ledger transactions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-profiles-full","method":"GET","path":"/api/v1/sync/profiles/full","title":"SYNC: Get All Profiles","description":"SYNC: Get All Profiles through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/profiles/full","operation":"SYNC: Get All Profiles"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-profiles-full","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Profiles through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all profiles before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-profiles-pending-kyc","method":"GET","path":"/api/v1/sync/profiles/pending_kyc","title":"SYNC: Get All Pending KYCs","description":"SYNC: Get All Pending KYCs through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":["Trust Center"],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/profiles/pending_kyc","operation":"SYNC: Get All Pending KYCs"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-profiles-pending-kyc","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Pending KYCs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Pending KYCs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all pending kycs before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-internal-api-v1-sync-profiles-recent","method":"GET","path":"/api/v1/sync/profiles/recent","title":"SYNC: Get Recent Profiles","description":"SYNC: Get Recent Profiles through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/profiles/recent","operation":"SYNC: Get Recent Profiles"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-profiles-recent","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get Recent Profiles through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get recent profiles before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-reconciliation-full","method":"GET","path":"/api/v1/sync/reconciliation/full","title":"SYNC: Get All Full Reconciliation Data","description":"SYNC: Get All Full Reconciliation Data through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":["Funding"],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/reconciliation/full","operation":"SYNC: Get All Full Reconciliation Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-reconciliation-full","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Full Reconciliation Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Full Reconciliation Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all full reconciliation data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-internal-api-v1-sync-stats-general","method":"GET","path":"/api/v1/sync/stats/general","title":"SYNC: Get General Statistics","description":"SYNC: Get General Statistics through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/stats/general","operation":"SYNC: Get General Statistics"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-stats-general","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get General Statistics through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get general statistics before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-swaps-full","method":"GET","path":"/api/v1/sync/swaps/full","title":"SYNC: Get All Swaps","description":"SYNC: Get All Swaps through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/swaps/full","operation":"SYNC: Get All Swaps"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-swaps-full","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Swaps through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all swaps before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-transfers-full","method":"GET","path":"/api/v1/sync/transfers/full","title":"SYNC: Get All Transfers","description":"SYNC: Get All Transfers through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":[],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/transfers/full","operation":"SYNC: Get All Transfers"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-transfers-full","scope":"platform:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":[],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Transfers through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all transfers before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":[],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context."],"agentGuidance":["This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":[]}},{"id":"get-internal-api-v1-sync-vaults-all-pubkeys","method":"GET","path":"/api/v1/sync/vaults/all_pubkeys","title":"SYNC: Get All Hybrid-Vault Public Keys","description":"SYNC: Get All Hybrid-Vault Public Keys through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":["Data Vault"],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/vaults/all_pubkeys","operation":"SYNC: Get All Hybrid-Vault Public Keys"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-vaults-all-pubkeys","scope":"vault:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Hybrid-Vault Public Keys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Hybrid-Vault Public Keys through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all hybrid-vault public keys before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"get-internal-api-v1-sync-vaults-full","method":"GET","path":"/api/v1/sync/vaults/full","title":"SYNC: Get All Hybrid-Vaults","description":"SYNC: Get All Hybrid-Vaults through the canonical Hybrid-Chain V2 interface.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Data Sync Functions","owners":["internal-integration"],"applications":["Data Vault"],"authentication":"bearer","exposure":"internal-only","status":"internal-only","parity":"internal-only","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/sync/vaults/full","operation":"SYNC: Get All Hybrid-Vaults"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-internal-api-v1-sync-vaults-full","scope":"vault:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Hybrid-Vaults"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"SYNC: Get All Hybrid-Vaults through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all hybrid-vaults before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-account-closure-requests","method":"POST","path":"/api/v2/account-closure-requests","title":"AUTH: Close an Account","description":"AUTH: Close an Account through the canonical Hybrid-Chain V2 interface.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/close_account","operation":"AUTH: Close an Account"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1account-closure-requests/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Close an Account"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-account-closure-requests-request-001"},{"name":"current_password","location":"body","required":true,"type":"string","description":"Current account password used as destructive-intent proof.","example":"current-password-01"},{"name":"step_up_token","location":"body","required":false,"type":"hcsu_ token","description":"Fresh ACCOUNT_CLOSURE_REQUEST authorization; required when TOTP is enabled.","example":"step-up-token-01"},{"name":"reason_code","location":"body","required":false,"type":"UNSPECIFIED | NO_LONGER_NEEDED | PRIVACY | COST | OTHER","description":"Structured closure rationale; defaults to UNSPECIFIED.","example":"reason-code-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"AUTH: Close an Account through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to close an account.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-auth-sessions","method":"GET","path":"/api/v2/auth/sessions","title":"AUTH: List sessions","description":"List the authenticated identity's current and historical V2 client sessions.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/auth/seed","operation":"AUTH: Get Seed"},{"method":"GET","path":"/api/v1/auth/seeds","operation":"AUTH: Get Multi-Tenant Seeds"},{"method":"GET","path":"/api/v1/sessions/active","operation":"SESSION: Get Active Sessions"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1sessions/get","scope":"sessions:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List sessions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing sessions:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated identity's current and historical V2 client sessions.","whenToUse":"Use this operation when an integration needs to list sessions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with sessions:read authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-auth-sessions","method":"POST","path":"/api/v2/auth/sessions","title":"AUTH: Create session","description":"Verify existing Hybrid credentials and issue short-lived V2 access plus a rotating refresh credential.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/login","operation":"AUTH: Log a User in"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1sessions/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create session"],"parameters":[{"name":"email","location":"body","required":true,"type":"email address · max 254","description":"Existing Hybrid-Chain account email.","example":"email-01"},{"name":"password","location":"body","required":true,"type":"string · max 512","description":"Account password; never logged or retained.","example":"password-01"},{"name":"two_factor_code","location":"body","required":false,"type":"6-digit TOTP","description":"Required when an authenticator is enabled.","example":"two-factor-code-01"},{"name":"device_id","location":"body","required":true,"type":"safe identifier · 16–128","description":"Stable identifier scoped to this application installation.","example":"device-id-01"},{"name":"device_name","location":"body","required":false,"type":"string · max 160","description":"Human-readable client label.","example":"device-name-01"},{"name":"platform","location":"body","required":true,"type":"ios | android | web | server","description":"Client class used in session inventory.","example":"platform-01"},{"name":"device_public_key_spki","location":"body","required":false,"type":"SPKI string","description":"Optional device public key for phishing-resistant capabilities.","example":"device-public-key-spki-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Verify existing Hybrid credentials and issue short-lived V2 access plus a rotating refresh credential.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create session.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-auth-sessions-session-id-revocations","method":"POST","path":"/api/v2/auth/sessions/{session_id}/revocations","title":"AUTH: Revoke session","description":"Revoke the current session or use fresh step-up authorization to revoke another client session.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/auth/logout","operation":"AUTH: Log a User out"},{"method":"POST","path":"/api/v1/sessions/destroy","operation":"SESSION: Destroy Session"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1sessions~1{session_id}~1revocations/post","scope":"sessions:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing sessions:write authority.","example":"Bearer hc_live_…"},{"name":"session_id","location":"path","required":true,"type":"identifier","description":"Canonical session id.","example":"session-id-01"},{"name":"session_id","location":"body","required":true,"type":"32-character session identifier","description":"Must exactly match the path session_id.","example":"session-id-01"},{"name":"step_up_token","location":"body","required":false,"type":"one-time hcsu_ token","description":"Fresh SESSION_REVOCATION authorization required when revoking another session.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Revoke the current session or use fresh step-up authorization to revoke another client session.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke session.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with sessions:write authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me","method":"POST","path":"/api/v2/me","title":"AUTH: Verify Bearer Token","description":"AUTH: Verify Bearer Token through the canonical Hybrid-Chain V2 interface.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-profile"],"applications":["Overview","Access Control"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/verify","operation":"AUTH: Verify Bearer Token"},{"method":"POST","path":"/api/v1/profile/advanceddata","operation":"PROFILE: Submit Advanced Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-me","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Verify Bearer Token"],"parameters":[],"responses":[{"status":501,"description":"This legacy compatibility marker is not executable; validate a bearer by calling the implemented GET /api/v2/me operation with that bearer.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"AUTH: Verify Bearer Token through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this compatibility marker. To validate and resolve an opaque bearer, send it as Authorization to the implemented GET /api/v2/me operation and handle 200, 401, and 403 normally.","workflowRole":"create-or-command","sideEffects":"No executable POST behavior exists. Bearer validation is an authenticated read and never requires a token in a JSON body.","businessCases":["daily account review","exception triage","cross-module navigation","interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Never place a bearer token in a body, query string, URL, prompt, log, analytics event, or compatibility payload.","The same marker also absorbed a legacy advanced-profile write. Use PATCH /api/v2/me only for its allowlisted fields and the owning domain APIs for bank, compliance, wallet, trading, preference, and other state.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Trust Center","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-authenticator-disablements","method":"POST","path":"/api/v2/me/authenticator-disablements","title":"AUTH: Disable authenticator","description":"Require purpose-bound step-up or a single-use recovery code, disable TOTP, and revoke active sessions.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/reset2fa","operation":"AUTH: Reset 2FA Code"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1authenticator-disablements/post","scope":"security:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Disable authenticator"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-authenticator-disablements-request-001"},{"name":"step_up_token","location":"body","required":false,"type":"one-time hcsu_ token","description":"Fresh AUTHENTICATOR_DISABLE authorization.","example":"step-up-token-01"},{"name":"recovery_code","location":"body","required":false,"type":"single-use recovery code","description":"Alternative to step-up; provide one authorization method.","example":"recovery-code-01"}],"responses":[{"status":200,"description":"Authenticator disabled and every active interactive session revoked.","example":null},{"status":400,"description":"The authorization body is malformed.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"Neither a valid AUTHENTICATOR_DISABLE step-up nor a valid recovery code was supplied.","example":null},{"status":404,"description":"No authenticator is enabled.","example":null},{"status":503,"description":"Identity is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Require purpose-bound step-up or a single-use recovery code, disable TOTP, and revoke active sessions.","whenToUse":"Use from an authenticated recovery or security-settings workflow with either fresh AUTHENTICATOR_DISABLE step-up or one unused recovery code.","workflowRole":"create-or-command","sideEffects":"Disables TOTP and revokes every active interactive session. A recovery code is atomically consumed when used.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Supply one authorization method; never log the step-up token or recovery code.","After success, discard all session credentials and require a new login before continuing account work.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-authenticator-enrollments","method":"POST","path":"/api/v2/me/authenticator-enrollments","title":"AUTH: Begin authenticator enrollment","description":"Create a bounded TOTP enrollment and return the enrollment secret once under no-store.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/auth/new2facode","operation":"AUTH: Generate new 2FA Registration Code"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1authenticator-enrollments/post","scope":"security:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Begin authenticator enrollment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-authenticator-enrollments-request-001"},{"name":"label","location":"body","required":false,"type":"string · max 64","description":"Account-visible authenticator label; defaults to Hybrid-Chain.","example":"label-01"},{"name":"issuer","location":"body","required":false,"type":"string · max 64","description":"TOTP issuer label; defaults to Hybrid-Chain.","example":"issuer-01"}],"responses":[{"status":201,"description":"Ten-minute session-bound TOTP enrollment and single-view secret returned.","example":null},{"status":400,"description":"The optional label or issuer is invalid.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":409,"description":"An authenticator is already enabled.","example":null},{"status":503,"description":"Identity or authenticator encryption is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a bounded TOTP enrollment and return the enrollment secret once under no-store.","whenToUse":"Begin TOTP setup only in a secure authenticated UI ready to render or import the returned secret immediately.","workflowRole":"create-or-command","sideEffects":"Creates a ten-minute pending enrollment bound to the current account session; TOTP is not active until confirmation.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","The Base32 secret and otpauth URI are returned once under no-store. Keep them out of logs, prompts, screenshots, analytics, and shared state.","Do not claim MFA is enabled from this response. Confirm a current code through the returned enrollment identifier.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-authenticator-enrollments-enrollment-id-confirmations","method":"POST","path":"/api/v2/me/authenticator-enrollments/{enrollment_id}/confirmations","title":"AUTH: Confirm authenticator enrollment","description":"Verify a live authenticator code, activate TOTP, and return single-view recovery codes.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/submitfirst2facode","operation":"AUTH: Submit first 2FA Code"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1authenticator-enrollments~1{enrollment_id}~1confirmations/post","scope":"security:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Confirm authenticator enrollment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-authenticator-enrollments-enrollment-id-confirmations-request-001"},{"name":"enrollment_id","location":"path","required":true,"type":"identifier","description":"Canonical enrollment id.","example":"enrollment-id-01"},{"name":"code","location":"body","required":true,"type":"6-digit TOTP","description":"Current code generated from the pending enrollment secret.","example":"code-01"}],"responses":[{"status":200,"description":"Authenticator enabled and ten single-view recovery codes returned.","example":null},{"status":400,"description":"The enrollment identifier or TOTP shape is invalid.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The enrollment is expired, belongs to another session, is already consumed, or the TOTP is invalid.","example":null},{"status":503,"description":"Identity or authenticator encryption is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Verify a live authenticator code, activate TOTP, and return single-view recovery codes.","whenToUse":"Confirm immediately after enrollment with a current six-digit TOTP generated from the returned secret in the same account session.","workflowRole":"create-or-command","sideEffects":"Consumes the pending enrollment, enables TOTP, and returns ten single-use recovery codes once.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Present recovery codes exactly once and require the person to store them outside the active session. They cannot be fetched again.","An expired, cross-session, already consumed, or invalid-code enrollment fails closed; begin a new enrollment rather than reusing the secret.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-registrations","method":"POST","path":"/api/v2/registrations","title":"AUTH: Register account","description":"Create an inactive tenant-bound account with server-side password hashing, versioned terms acceptance, and encrypted activation delivery.","chapter":"Authentication","chapterOrder":0,"capability":"Authentication","owners":["identity-access","identity-service"],"applications":["Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/auth/registration","operation":"AUTH: Register a Private User"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1registrations/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register account"],"parameters":[{"name":"tenant_uuid","location":"body","required":false,"type":"tenant identifier","description":"Tenant or white-label registration boundary; omission selects global.","example":"tenant-uuid-01"},{"name":"account_type","location":"body","required":true,"type":"personal | corporate","description":"Personal requires first_name and last_name; corporate requires company_name.","example":"account-type-01"},{"name":"email","location":"body","required":true,"type":"email address · max 128","description":"Normalized login and activation-delivery address.","example":"email-01"},{"name":"password","location":"body","required":true,"type":"printable string · 12–128","description":"At least three character classes and must not contain the email local part.","example":"password-01"},{"name":"company_name","location":"body","required":false,"type":"string · max 160","description":"Required for corporate accounts and ignored for personal accounts.","example":"company-name-01"},{"name":"first_name","location":"body","required":false,"type":"string · max 100","description":"Required for personal accounts.","example":"first-name-01"},{"name":"middle_name","location":"body","required":false,"type":"string · max 100","description":"Optional personal middle name.","example":"middle-name-01"},{"name":"last_name","location":"body","required":false,"type":"string · max 100","description":"Required for personal accounts.","example":"last-name-01"},{"name":"terms","location":"body","required":true,"type":"object","description":"accepted must be true and version is required; privacy_policy_version is optional.","example":{}}],"responses":[{"status":201,"description":"Inactive account created and 24-hour activation delivery queued.","example":null},{"status":400,"description":"Registration fields, account-type requirements, password policy, or terms acceptance are invalid.","example":null},{"status":403,"description":"Registration is disabled for the selected tenant.","example":null},{"status":409,"description":"An active or trashed account already exists for this email and tenant.","example":null},{"status":503,"description":"Identity or encrypted activation delivery is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Create an inactive tenant-bound account with server-side password hashing, versioned terms acceptance, and encrypted activation delivery.","whenToUse":"Use for first-party personal or corporate account creation after the application has resolved the tenant brand, current legal terms, and the correct account type.","workflowRole":"create-or-command","sideEffects":"Creates an inactive Identity account, password verifier, versioned terms-acceptance record, and encrypted 24-hour activation delivery. It does not create an authenticated session.","businessCases":["personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change","TOTP enrollment, recovery, and disablement","federated login and explicit account linking","profile and verified contact maintenance"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","configured and reachable Identity authority","tenant login or registration policy permitting the selected method","secure password, authenticator, provider, or Ed25519 private-key custody outside Hybrid-Chain","fresh purpose-bound TOTP step-up for protected changes","tenant administration authority and replacement-key proof for workload lifecycle actions"],"agentGuidance":["Never place passwords, activation or reset credentials, authenticator secrets, TOTP codes, recovery codes, OAuth codes, step-up tokens, access or refresh credentials, assertion JWTs, private keys, or provider tokens in URLs, prompts, logs, analytics, caches, or retained traces.","Distinguish account creation, activation, login, step-up, mutation, and session revocation: success in one phase never implies completion of another.","Password reset requests are intentionally enumeration resistant; always present the accepted response without inferring whether an account exists.","TOTP enrollment is pending until confirmation. Recovery codes are returned once, and authenticator disablement or any password change revokes all interactive sessions.","Federation state, authorization codes, PKCE material, refresh credentials, activation/reset credentials, step-up tokens, recovery codes, and assertion jti values are one-use; never replay them after an ambiguous result.","Human sessions rotate refresh credentials and workloads reassert with a new Ed25519 JWT. A workload bearer is bound to client, workspace, network, scope, expiry, and current public key.","Request-signing and workload-key rotation accepts public Ed25519 material and proof of possession only. Private keys never enter Hybrid-Chain; successful workload rotation revokes prior access tokens.","Use stable identifiers and exact snake_case fields from live OpenAPI. Re-read the authoritative resource after consequential changes and purge invalidated local credentials immediately.","Personal accounts require first_name and last_name; corporate accounts require company_name. Do not send unused fields as identity metadata.","Never log the password or activation delivery. A PENDING_ACTIVATION receipt contains correlation identifiers, not the activation token.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-identity-validate","method":"POST","path":"/api/v2/identity/validate","title":"IDENTITY: validate identity","description":"IDENTITY: validate identity through the canonical Hybrid-Chain V2 interface.","chapter":"Authentication","chapterOrder":0,"capability":"Identity · validate","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/validate","source":"Identity APIHandler.py · validate_identity"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-validate","scope":"identity:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["validate identity"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing identity:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Identity compatibility marker; use the explicit implemented V2 authentication or security lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: validate identity through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot validate credentials, issue or rotate tokens, create or revoke a session, change authenticators, register or revoke a signing key, mint step-up authority, or change account security state.","businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment"],"prerequisites":["A bearer credential with identity:compatibility authority and the required tenant, workspace, and role context.","the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen.","Use implemented GET /api/v2/me with the bearer in the Authorization header. Never place an access token or credential in a validation request body.","Do not translate the legacy body field-for-field or submit access tokens, refresh credentials, passwords, authenticator codes, recovery codes, signing keys, step-up tokens, session selectors, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact implemented canonical operation. Authentication, refresh, revocation, signing-key, step-up, and authenticator lifecycles remain separate authority boundaries.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-account-closure-requests-request-uuid","method":"GET","path":"/api/v2/account-closure-requests/{request_uuid}","title":"PROFILE: Get account closure request","description":"Return the authenticated subject's authoritative account-closure lifecycle state.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1account-closure-requests~1{request_uuid}/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get account closure request"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"request_uuid","location":"path","required":true,"type":"identifier","description":"Canonical request uuid.","example":"request-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated subject's authoritative account-closure lifecycle state.","whenToUse":"Use this operation when an integration needs to get account closure request before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-account-closure-requests-request-uuid-cancellations","method":"POST","path":"/api/v2/account-closure-requests/{request_uuid}/cancellations","title":"PROFILE: Cancel account closure request","description":"Cancel an eligible closure request after fresh authenticator verification when required.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1account-closure-requests~1{request_uuid}~1cancellations/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel account closure request"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-account-closure-requests-request-uuid-cancellations-request-001"},{"name":"request_uuid","location":"path","required":true,"type":"identifier","description":"Canonical request uuid.","example":"request-uuid-01"},{"name":"step_up_token","location":"body","required":false,"type":"hcsu_ token","description":"Fresh ACCOUNT_CLOSURE_REQUEST authorization; required when TOTP is enabled.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an eligible closure request after fresh authenticator verification when required.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel account closure request.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-admin-identity-login-policy","method":"GET","path":"/api/v2/admin/identity/login-policy","title":"AUTH: Get login policy","description":"Read provider readiness and tenant login-method policy with administrator authority.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1login-policy/get","scope":"admin:identity:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get login policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Read provider readiness and tenant login-method policy with administrator authority.","whenToUse":"Use this operation when an integration needs to get login policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"put-api-v2-admin-identity-login-policy","method":"PUT","path":"/api/v2/admin/identity/login-policy","title":"AUTH: Update login policy","description":"Publish tenant login-method policy with administrator authority and purpose-bound step-up authorization.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1login-policy/put","scope":"admin:identity:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update login policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"body","required":true,"type":"tenant identifier","description":"Tenant policy boundary.","example":"tenant-uuid-01"},{"name":"policy","location":"body","required":true,"type":"login policy object","description":"Password, passkey, provider, linking, and recovery booleans; lockout configurations are rejected.","example":{}},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh LOGIN_POLICY_UPDATE authorization.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Publish tenant login-method policy with administrator authority and purpose-bound step-up authorization.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update login policy.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-auth-federation-provider-authorizations","method":"POST","path":"/api/v2/auth/federation/{provider}/authorizations","title":"AUTH: Begin federated authorization","description":"Create a one-time server-owned OAuth authorization-code and PKCE transaction for Google, Apple, or GitHub.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"split-secure-replacement","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/auth/federate","operation":"AUTH: Generate Web-Federation Token"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1federation~1{provider}~1authorizations/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Begin federated authorization"],"parameters":[{"name":"provider","location":"path","required":true,"type":"identifier","description":"Canonical provider.","example":"provider-01"},{"name":"tenant_uuid","location":"body","required":false,"type":"tenant identifier","description":"Tenant login-policy boundary; defaults to global.","example":"tenant-uuid-01"},{"name":"mode","location":"body","required":true,"type":"login | link","description":"Begin sign-in or explicit existing-account linking.","example":"mode-01"},{"name":"redirect_uri","location":"body","required":true,"type":"exact registered HTTPS URI","description":"Must match Identity and provider registration.","example":"redirect-uri-01"},{"name":"return_to","location":"body","required":false,"type":"local absolute path","description":"Post-login navigation target; external URLs are rejected.","example":"return-to-01"},{"name":"step_up_token","location":"body","required":false,"type":"one-time hcsu_ token","description":"Required for link mode with purpose FEDERATED_IDENTITY_LINK.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Create a one-time server-owned OAuth authorization-code and PKCE transaction for Google, Apple, or GitHub.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to begin federated authorization.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-auth-federation-provider-exchanges","method":"POST","path":"/api/v2/auth/federation/{provider}/exchanges","title":"AUTH: Exchange federated authorization","description":"Verify and consume a provider authorization response once, then issue a Hybrid session or complete an explicit account link.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trading","Trust Center","Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"split-secure-replacement","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/auth/federate","operation":"AUTH: Generate Web-Federation Token"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1federation~1{provider}~1exchanges/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Exchange federated authorization"],"parameters":[{"name":"provider","location":"path","required":true,"type":"identifier","description":"Canonical provider.","example":"provider-01"},{"name":"transaction_id","location":"body","required":true,"type":"32-character identifier","description":"Authorization transaction from the begin endpoint.","example":"transaction-id-01"},{"name":"state","location":"body","required":true,"type":"one-time hcfed_ value","description":"Exact state returned at authorization start.","example":"state-01"},{"name":"code","location":"body","required":true,"type":"provider authorization code","description":"Short-lived provider code.","example":"code-01"},{"name":"redirect_uri","location":"body","required":true,"type":"exact registered HTTPS URI","description":"Must equal the URI bound at transaction creation.","example":"redirect-uri-01"},{"name":"device_id","location":"body","required":true,"type":"safe identifier · 16–128","description":"Stable application-scoped client identifier.","example":"device-id-01"},{"name":"device_name","location":"body","required":false,"type":"string · max 160","description":"Human-readable session label.","example":"device-name-01"},{"name":"platform","location":"body","required":true,"type":"ios | android | web | server","description":"Client class.","example":"platform-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Verify and consume a provider authorization response once, then issue a Hybrid session or complete an explicit account link.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to exchange federated authorization.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Transfer Compliance","Identity Review","Teams & Workspaces"]}},{"id":"post-api-v2-auth-session-refreshes","method":"POST","path":"/api/v2/auth/session-refreshes","title":"AUTH: Refresh session","description":"Rotate a single-use refresh credential and issue the next V2 credential pair.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1session-refreshes/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Refresh session"],"parameters":[{"name":"refresh_token","location":"body","required":true,"type":"single-use hcmr_ credential","description":"Current refresh credential, invalid after one successful rotation.","example":"refresh-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Rotate a single-use refresh credential and issue the next V2 credential pair.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to refresh session.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-auth-workload-token-exchanges","method":"POST","path":"/api/v2/auth/workload-token-exchanges","title":"AUTH: Exchange workload assertion","description":"Verify a one-time Ed25519 private-key JWT assertion and issue a refreshless, network-bound scoped workload bearer with a 15-minute default and network-specific lifetime cap.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trading","Trust Center","Identity & Login","Access Control"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1auth~1workload-token-exchanges/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Exchange workload assertion"],"parameters":[{"name":"grant_type","location":"body","required":true,"type":"client_credentials","description":"OAuth client-credentials grant.","example":"grant-type-01"},{"name":"client_assertion_type","location":"body","required":true,"type":"urn:ietf:params:oauth:client-assertion-type:jwt-bearer","description":"Private-key JWT assertion type.","example":"client-assertion-type-01"},{"name":"client_assertion","location":"body","required":true,"type":"compact EdDSA JWT","description":"Single-use assertion signed by the registered Ed25519 workload key.","example":"client-assertion-01"},{"name":"scope","location":"body","required":false,"type":"space-delimited scopes","description":"Optional requested subset; omission requests the client's allowed scopes.","example":"scope-01"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Explicit network context; it must match a network_id carried by the signed assertion.","example":"network-id-01"},{"name":"expires_in","location":"body","required":false,"type":"integer · 60–14400","description":"Requested token lifetime. Defaults to 900 seconds and is capped by workload and network policy.","example":1}],"responses":[{"status":200,"description":"Refreshless, network-bound scoped workload access token.","example":null},{"status":400,"description":"The grant or assertion shape is unsupported.","example":null},{"status":401,"description":"The assertion is invalid, expired, replayed, network-mismatched, or requests unauthorized scopes.","example":null},{"status":503,"description":"Identity workload authentication is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The private key never leaves the workload. Hybrid-Chain stores only the registered public Ed25519 key and issues no client secret or refresh token.","The signed assertion and request must carry the same network_id. The resulting bearer cannot cross workspace or network boundaries.","The default bearer lifetime is 900 seconds. Maximum lifetimes are 3600 seconds on Mainnet, 7200 on Testnet, and 14400 on Devnet; the workload reasserts with a new single-use JWT after expiry."]},"businessContext":{"purpose":"Verify a one-time Ed25519 private-key JWT assertion and issue a refreshless, network-bound scoped workload bearer with a 15-minute default and network-specific lifetime cap.","whenToUse":"Use when an enrolled machine or agent needs a short-lived refreshless bearer for an explicit scope subset and network.","workflowRole":"create-or-command","sideEffects":"Atomically consumes the assertion jti and issues an opaque workspace- and network-bound bearer. No refresh token or client secret is issued.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Sign a fresh EdDSA assertion for every exchange. iss and sub must equal client_id; audience, jti, iat, exp, network_id, and optional token_ttl_seconds are security inputs.","Use the returned renewal_mode=REASSERT contract and create a new single-use assertion after expiry. Never retry the same assertion after an ambiguous response.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Transfer Compliance","Identity Review","Teams & Workspaces"]}},{"id":"get-api-v2-me-contact","method":"GET","path":"/api/v2/me/contact","title":"PROFILE: Get contact projection","description":"Return the authenticated subject's email and phone verification projection.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1contact/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get contact projection"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated subject's email and phone verification projection.","whenToUse":"Use this operation when an integration needs to get contact projection before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-contact-email-change-requests","method":"POST","path":"/api/v2/me/contact/email-change-requests","title":"PROFILE: Request email change","description":"Authenticate a proposed email replacement and deliver a 15-minute one-time token to the new address.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1contact~1email-change-requests/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request email change"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-contact-email-change-requests-request-001"},{"name":"new_email","location":"body","required":true,"type":"email address","description":"Proposed replacement address; the token is delivered here.","example":"new-email-01"},{"name":"current_password","location":"body","required":true,"type":"string","description":"Current account password as reauthentication proof.","example":"current-password-01"},{"name":"step_up_token","location":"body","required":false,"type":"hcsu_ token","description":"Fresh EMAIL_CHANGE authorization; required when TOTP is enabled.","example":"step-up-token-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Authenticate a proposed email replacement and deliver a 15-minute one-time token to the new address.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request email change.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-contact-email-change-requests-confirm","method":"POST","path":"/api/v2/me/contact/email-change-requests/confirm","title":"PROFILE: Confirm email change","description":"Consume the one-time email token, atomically replace the address, and revoke active sessions.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1contact~1email-change-requests~1confirm/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Confirm email change"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-contact-email-change-requests-confirm-request-001"},{"name":"token","location":"body","required":true,"type":"one-time hcat_ token","description":"15-minute verification credential delivered to the proposed contact.","example":"token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Consume the one-time email token, atomically replace the address, and revoke active sessions.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to confirm email change.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-contact-phone-change-requests","method":"POST","path":"/api/v2/me/contact/phone-change-requests","title":"PROFILE: Request phone change","description":"Authenticate a proposed E.164 phone replacement and deliver a 15-minute one-time SMS token.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1contact~1phone-change-requests/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request phone change"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-contact-phone-change-requests-request-001"},{"name":"new_phone","location":"body","required":true,"type":"E.164 phone number","description":"Proposed replacement number; the token is delivered here by SMS.","example":"new-phone-01"},{"name":"current_password","location":"body","required":true,"type":"string","description":"Current account password as reauthentication proof.","example":"current-password-01"},{"name":"step_up_token","location":"body","required":false,"type":"hcsu_ token","description":"Fresh PHONE_CHANGE authorization; required when TOTP is enabled.","example":"step-up-token-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Authenticate a proposed E.164 phone replacement and deliver a 15-minute one-time SMS token.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request phone change.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-me-contact-phone-change-requests-confirm","method":"POST","path":"/api/v2/me/contact/phone-change-requests/confirm","title":"PROFILE: Confirm phone change","description":"Consume the one-time SMS token, atomically replace the phone, and revoke active sessions.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1contact~1phone-change-requests~1confirm/post","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Confirm phone change"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-contact-phone-change-requests-confirm-request-001"},{"name":"token","location":"body","required":true,"type":"one-time hcat_ token","description":"15-minute verification credential delivered to the proposed contact.","example":"token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Consume the one-time SMS token, atomically replace the phone, and revoke active sessions.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to confirm phone change.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-preferences","method":"GET","path":"/api/v2/me/preferences","title":"PROFILE: Get preferences","description":"Return locale, timezone, language, base currency, theme, developer experience, Business Network mode, and workspace ordering preferences.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1preferences/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get preferences"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return locale, timezone, language, base currency, theme, developer experience, Business Network mode, and workspace ordering preferences.","whenToUse":"Use this operation when an integration needs to get preferences before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"put-api-v2-me-preferences","method":"PUT","path":"/api/v2/me/preferences","title":"PROFILE: Update preferences","description":"Update the complete submitted account preference subset through a signed mutation.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1preferences/put","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update preferences"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-preferences-request-001"},{"name":"locale","location":"body","required":false,"type":"BCP 47 locale · max 24","description":"Formatting locale.","example":"locale-01"},{"name":"timezone","location":"body","required":false,"type":"IANA timezone · max 64","description":"Display timezone.","example":"timezone-01"},{"name":"language","location":"body","required":false,"type":"language code · max 16","description":"Preferred language.","example":"language-01"},{"name":"base_currency","location":"body","required":false,"type":"currency code · 2–12","description":"Preferred reporting currency.","example":"base-currency-01"},{"name":"theme","location":"body","required":false,"type":"dark | light","description":"Color theme.","example":"theme-01"},{"name":"developer_mode","location":"body","required":false,"type":"boolean","description":"Whether developer-only Devnet and Testnet experiences are enabled.","example":true},{"name":"business_network_mode","location":"body","required":false,"type":"guided | advanced","description":"Selected Business Network experience.","example":"business-network-mode-01"},{"name":"workspace_order","location":"body","required":false,"type":"array of workspace UUIDs · max 100","description":"Authenticated user's preferred ordering of authorized workspaces.","example":"workspace-order-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update the complete submitted account preference subset through a signed mutation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update preferences.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-privacy","method":"GET","path":"/api/v2/me/privacy","title":"PROFILE: Get privacy settings","description":"Return visibility controls without embedding the full user record.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1privacy/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get privacy settings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return visibility controls without embedding the full user record.","whenToUse":"Use this operation when an integration needs to get privacy settings before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"put-api-v2-me-privacy","method":"PUT","path":"/api/v2/me/privacy","title":"PROFILE: Update privacy settings","description":"Update visibility controls through a signed mutation.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1privacy/put","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update privacy settings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-privacy-request-001"},{"name":"hide_crypto","location":"body","required":false,"type":"boolean","description":"Hide crypto positions in account presentation.","example":true},{"name":"hide_fiat","location":"body","required":false,"type":"boolean","description":"Hide fiat positions in account presentation.","example":true},{"name":"hide_nfts","location":"body","required":false,"type":"boolean","description":"Hide NFT positions in account presentation.","example":true},{"name":"hide_custodian_details","location":"body","required":false,"type":"boolean","description":"Hide custodian details in account presentation.","example":true}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update visibility controls through a signed mutation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update privacy settings.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-profile","method":"GET","path":"/api/v2/me/profile","title":"PROFILE: Get core profile","description":"Return identity, account type, display name, and names without contact, preference, privacy, or verification data.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1profile/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get core profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return identity, account type, display name, and names without contact, preference, privacy, or verification data.","whenToUse":"Use this operation when an integration needs to get core profile before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"patch-api-v2-me-profile","method":"PATCH","path":"/api/v2/me/profile","title":"PROFILE: Update core profile","description":"Update only the authenticated subject's personal or company names through a signed mutation.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1profile/patch","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update core profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-me-profile-request-001"},{"name":"company_name","location":"body","required":false,"type":"string · max 160","description":"Corporate display name.","example":"company-name-01"},{"name":"first_name","location":"body","required":false,"type":"string · max 100","description":"Given name.","example":"first-name-01"},{"name":"middle_name","location":"body","required":false,"type":"string · max 100","description":"Middle name.","example":"middle-name-01"},{"name":"last_name","location":"body","required":false,"type":"string · max 100","description":"Family name.","example":"last-name-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update only the authenticated subject's personal or company names through a signed mutation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update core profile.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-verification-summary","method":"GET","path":"/api/v2/me/verification-summary","title":"PROFILE: Get verification summary","description":"Return current assurance, decision, completion, and retention posture without evidence payloads.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1verification-summary/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get verification summary"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return current assurance, decision, completion, and retention posture without evidence payloads.","whenToUse":"Use this operation when an integration needs to get verification summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-workspaces-workspace-uuid-preferences","method":"GET","path":"/api/v2/me/workspaces/{workspace_uuid}/preferences","title":"PROFILE: Get workspace preferences","description":"Return the authenticated member's experience preferences for one workspace, including its default wallet environment.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Teams & Workspaces","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1workspaces~1{workspace_uuid}~1preferences/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get workspace preferences"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"workspace_uuid","location":"path","required":true,"type":"identifier","description":"Canonical workspace uuid.","example":"workspace-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated member's experience preferences for one workspace, including its default wallet environment.","whenToUse":"Use this operation when an integration needs to get workspace preferences before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Tenant & Brand Manager","Developers"]}},{"id":"put-api-v2-me-workspaces-workspace-uuid-preferences","method":"PUT","path":"/api/v2/me/workspaces/{workspace_uuid}/preferences","title":"PROFILE: Update workspace preferences","description":"Set or clear the authenticated member's default wallet environment for one workspace through a signed mutation.","chapter":"Authentication","chapterOrder":0,"capability":"Identity sessions and federation","owners":["identity-service"],"applications":["Trust Center","Identity & Login","Teams & Workspaces","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1workspaces~1{workspace_uuid}~1preferences/put","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update workspace preferences"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-workspaces-workspace-uuid-preferences-request-001"},{"name":"workspace_uuid","location":"path","required":true,"type":"identifier","description":"Canonical workspace uuid.","example":"workspace-uuid-01"},{"name":"default_wallet_network","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet | null","description":"Default wallet environment for this authenticated user in this workspace. Use null to clear the default.","example":"hybrid-mainnet"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Set or clear the authenticated member's default wallet environment for one workspace through a signed mutation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update workspace preferences.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Identity Review","Tenant & Brand Manager","Developers"]}},{"id":"post-api-v2-identities","method":"POST","path":"/api/v2/identities","title":"IDENTITY: create identity","description":"IDENTITY: create identity through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"Identity · create","owners":["identity-service"],"applications":["Overview","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/create","source":"Identity APIHandler.py · create_identity"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identities","scope":"admin:identity:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["create identity"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This raw identity-creation marker is not executable; use POST /api/v2/registrations for first-party account onboarding or the restricted workload-client lifecycle for machine identities.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: create identity through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this raw service-shaped marker. Use POST /api/v2/registrations for first-party personal or corporate onboarding and the restricted workload-client administration lifecycle for machine identities.","workflowRole":"create-or-command","sideEffects":"No executable public raw-identity creator exists. The legacy owner accepts internal database-shaped fields and therefore cannot be exposed as a V2 contract.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Never submit password verifiers, seeds, activation keys, permission identifiers, internal tenant fields, database metadata, or arbitrary identity records.","Promotion as a generic identity creator is not planned. Any future administrator-managed person lifecycle needs a separately named purpose-bound route, minimal schema, tenant authorization, notification, activation, audit, and conflict policy.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identities-identity-uuid","method":"GET","path":"/api/v2/identities/{identity_uuid}","title":"IDENTITY: get identity details","description":"IDENTITY: get identity details through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"Identity · get","owners":["identity-service"],"applications":["Overview","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/get/{identity_uuid}","source":"Identity APIHandler.py · get_identity_details"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identities-identity-uuid","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get identity details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"identity_uuid","location":"path","required":true,"type":"identifier","description":"Canonical identity uuid.","example":"identity-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get identity details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get identity details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-transfer-credentials-subject-profile-profile-uuid","method":"GET","path":"/api/v2/identity/transfer-credentials/subject/profile/{profile_uuid}","title":"IDENTITY: manage subject transfer credentials","description":"IDENTITY: manage subject transfer credentials through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"Identity · transfer credentials","owners":["identity-service"],"applications":["Overview","Transfer Compliance","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"Identity APIHandler.py · manage_subject_transfer_credentials"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-transfer-credentials-subject-profile-profile-uuid","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject transfer credentials"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage subject transfer credentials through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to manage subject transfer credentials before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Payments","Data Vault","Business Network","Evidence Streams"]}},{"id":"post-api-v2-identity-transfer-credentials-subject-profile-profile-uuid","method":"POST","path":"/api/v2/identity/transfer-credentials/subject/profile/{profile_uuid}","title":"IDENTITY: manage subject transfer credentials","description":"IDENTITY: manage subject transfer credentials through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"Identity · transfer credentials","owners":["identity-service"],"applications":["Overview","Transfer Compliance","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"Identity APIHandler.py · manage_subject_transfer_credentials"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-transfer-credentials-subject-profile-profile-uuid","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject transfer credentials"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-identity-transfer-credentials-subject-profile-profile-uuid-request-001"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"vault_uuid","location":"body","required":false,"type":"32-character identifier","description":"Subject primary vault; omission selects the primary vault and every other vault is rejected.","example":"5fd2f2a907b449858bb1ad55591f5578"},{"name":"network","location":"body","required":false,"type":"network code · max 32","description":"Wallet network; defaults to HYBRID.","example":"HYBRID"},{"name":"wallet_reference","location":"body","required":true,"type":"public wallet reference · max 255","description":"Public address or account reference. Private keys, seeds, recovery material, and credentials are forbidden.","example":"hyb1subjectwalletreference"},{"name":"verification_method","location":"body","required":false,"type":"identifier · max 64","description":"Externally completed proof method; defaults to SIGNED_CHALLENGE.","example":"SIGNED_CHALLENGE"},{"name":"challenge_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the issued possession challenge; challenge cleartext is never accepted.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"proof_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the independently verified possession proof; raw signatures and private material are never accepted.","example":"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"},{"name":"validity_days","location":"body","required":false,"type":"integer · 1–365","description":"Requested proof lifetime; defaults to 90 days.","example":90}],"responses":[{"status":501,"description":"This compatibility-shaped planning path is not executable; use POST /api/v2/transfer-compliance/wallet-control-proofs from live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"IDENTITY: manage subject transfer credentials through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this compatibility-shaped planning route. Use the implemented POST /api/v2/transfer-compliance/wallet-control-proofs operation from live OpenAPI for owner-scoped wallet-control proof registration.","workflowRole":"create-or-command","sideEffects":"No executable facade behavior exists. The canonical implemented operation retains only public wallet reference, proof commitments, network, validity, and owner evidence without accepting private material.","businessCases":["daily account review","exception triage","cross-module navigation","Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Resolve the authenticated subject and primary vault through canonical V2 owner projections; never use profile_uuid to administer another subject or bypass bearer ownership.","The documented body mirrors the canonical wallet-control-proof business input only for parity analysis. Do not generate or send it to this path, and never include private keys, seeds, raw possession signatures, challenges, identity documents, or credentials.","A wallet-control proof is readiness evidence, not formal credential issuance, consent, transfer approval, wallet authority, signing authority, broadcast authority, settlement, or value movement.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Notifications","Payments","Data Vault","Business Network","Evidence Streams"]}},{"id":"post-api-v2-account-activations","method":"POST","path":"/api/v2/account-activations","title":"AUTH: Activate account","description":"Consume a one-time activation credential, activate the account, and return the canonical activation receipt.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile","identity-service"],"applications":["Overview","Trust Center","Identity & Login"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/activate/XXXXXXXX","operation":"PROFILE: Activate Account"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1account-activations/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Activate account"],"parameters":[{"name":"token","location":"body","required":true,"type":"one-time hcat_ credential","description":"24-hour activation credential delivered out of band and consumed once.","example":"token-01"}],"responses":[{"status":200,"description":"One-time activation credential consumed and account activated.","example":null},{"status":400,"description":"The activation credential shape is invalid.","example":null},{"status":403,"description":"The activation credential is invalid, expired, or already consumed.","example":null},{"status":503,"description":"Identity is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Consume a one-time activation credential, activate the account, and return the canonical activation receipt.","whenToUse":"Use once with the exact hcat_ credential delivered for a pending registration.","workflowRole":"create-or-command","sideEffects":"Consumes the activation credential and marks the account active. It does not create a V2 session; call the session endpoint separately.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Submit the token only in the JSON body, never in a path, query, analytics event, or prompt.","An invalid, expired, superseded, or already consumed token fails closed with the same authorization class.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Access Control","Teams & Workspaces"]}},{"id":"get-api-v2-funding-bank-accounts","method":"GET","path":"/api/v2/funding/bank-accounts","title":"FUNDING: List linked bank accounts","description":"Return the authenticated profile's linked bank accounts with opaque identifiers, masked IBANs, currencies, and verification state; full account numbers and legacy database identifiers are excluded.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["funding-orchestrator","funding-service"],"applications":["Overview","Funding","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/bank_accounts","operation":"PROFILE: Get Linked Bank Accounts"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1bank-accounts/get","scope":"funding:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List linked bank accounts"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated profile's linked bank accounts with opaque identifiers, masked IBANs, currencies, and verification state; full account numbers and legacy database identifiers are excluded.","whenToUse":"Use this operation when an integration needs to list linked bank accounts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Payments","Indexer Controller","Identity & Login","Transfer Compliance"]}},{"id":"get-api-v2-growth-referrals","method":"GET","path":"/api/v2/growth/referrals","title":"GROWTH: Get referral summary","description":"Return referral codes and aggregate usage for the authenticated profile without exposing referred-user identities, contact details, commission data, downline graphs, or the legacy user JSON.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["account-read-model","identity-growth"],"applications":["Overview","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/referral_data","operation":"PROFILE: Get Referral Data"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1growth~1referrals/get","scope":"growth:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get referral summary"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing growth:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return referral codes and aggregate usage for the authenticated profile without exposing referred-user identities, contact details, commission data, downline graphs, or the legacy user JSON.","whenToUse":"Use this operation when an integration needs to get referral summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with growth:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-ledger-accounts-account-id-balances","method":"GET","path":"/api/v2/ledger/accounts/{account_id}/balances","title":"PROFILE: Get Wallet Balances","description":"PROFILE: Get Wallet Balances through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["custody-ledger"],"applications":["Overview","Wallets","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/balances","operation":"PROFILE: Get Wallet Balances"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ledger~1accounts~1{account_id}~1balances/get","scope":"ledger:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Wallet Balances"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ledger:read authority.","example":"Bearer hc_live_…"},{"name":"account_id","location":"path","required":true,"type":"identifier","description":"Canonical account id.","example":"account-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PROFILE: Get Wallet Balances through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get wallet balances before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","wallet onboarding","portfolio and balance review","network-aware token discovery and enablement"],"prerequisites":["A bearer credential with ledger:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Notifications","Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance"]}},{"id":"get-api-v2-me","method":"GET","path":"/api/v2/me","title":"PROFILE: Get current profile","description":"Return the authenticated identity's current purpose-limited profile projection.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile"],"applications":["Overview","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile_basic","operation":"PROFILE: Get Basic User Profile Data"},{"method":"GET","path":"/api/v1/profile","operation":"PROFILE: Get Full User Profile Data"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me/get","scope":"profile:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get current profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated identity's current purpose-limited profile projection.","whenToUse":"Use this operation when an integration needs to get current profile before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"patch-api-v2-me","method":"PATCH","path":"/api/v2/me","title":"PROFILE: Update current profile","description":"Update allowlisted current-profile fields through the authoritative Identity profile service.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile"],"applications":["Overview","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/personaldata","operation":"PROFILE: Submit Profile Data"},{"method":"POST","path":"/api/v1/profile/metadata","operation":"PROFILE: Submit Meta Data"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me/patch","scope":"profile:write","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update current profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for update current profile. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Update allowlisted current-profile fields through the authoritative Identity profile service.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update current profile.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-me-authentication-events","method":"GET","path":"/api/v2/me/authentication-events","title":"PROFILE: List authentication events","description":"List successful password and federated sign-ins with redacted device context and integrity-protected cursor pagination.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-access","identity-service"],"applications":["Overview","Trust Center","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/last_logins","operation":"PROFILE: Get Last Logins"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1authentication-events/get","scope":"sessions:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List authentication events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing sessions:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"integrity-protected opaque string","description":"Cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum successful sign-in records to return.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List successful password and federated sign-ins with redacted device context and integrity-protected cursor pagination.","whenToUse":"Use this operation when an integration needs to list authentication events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with sessions:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-me-avatar","method":"GET","path":"/api/v2/me/avatar","title":"PROFILE: Get Profile Avatar Image","description":"PROFILE: Get Profile Avatar Image through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["protected-object-service"],"applications":["Overview","Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/avatar","operation":"PROFILE: Get Profile Avatar Image"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-me-avatar","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Profile Avatar Image"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PROFILE: Get Profile Avatar Image through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get profile avatar image before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-me-avatar","method":"POST","path":"/api/v2/me/avatar","title":"PROFILE: Upload Profile Avatar Image","description":"PROFILE: Upload Profile Avatar Image through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["protected-object-service"],"applications":["Overview","Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/uploadavatar","operation":"PROFILE: Upload Profile Avatar Image"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-me-avatar","scope":"profile:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Upload Profile Avatar Image"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-me-avatar-request-001"},{"name":"image","location":"body","required":true,"type":"multipart binary · PNG | JPEG | WebP · max 5 MiB","description":"Avatar image bytes. The future owner must decode, inspect, strip metadata, and safely re-encode the image before publication.","example":"image-01"},{"name":"content_sha256","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Digest of the exact uploaded image part, used for integrity checking and idempotent reconciliation.","example":"10.00"},{"name":"alt_text","location":"body","required":false,"type":"string · max 300","description":"Accessible description of the avatar. It must not contain credentials, regulated evidence, or hidden authorization data.","example":"alt-text-01"},{"name":"crop","location":"body","required":false,"type":"object with x, y, width, height decimals in 0–1","description":"Optional normalized crop rectangle applied only after successful media validation.","example":"10.00"}],"responses":[{"status":202,"description":"When promoted, validated media enters owner-scoped quarantine and a processing receipt is returned; the current avatar remains active until inspection and safe re-encoding complete.","example":null},{"status":400,"description":"The multipart request, image part, digest, crop rectangle, alt text, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks profile:write or cannot update the authenticated subject's avatar.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another upload or an equivalent image is already being processed.","example":null},{"status":413,"description":"The encoded upload or decoded pixel budget exceeds the future media policy.","example":null},{"status":415,"description":"The declared or detected media type is not an allowlisted PNG, JPEG, or WebP image.","example":null},{"status":422,"description":"Integrity, decoding, malware, metadata, dimensions, animation, crop, or content-safety validation rejected the image.","example":null},{"status":503,"description":"The protected media owner, scanner, safe re-encoder, object store, or profile adapter is unavailable; the current avatar remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"PROFILE: Upload Profile Avatar Image through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use only after this plan appears in live OpenAPI, when the authenticated subject deliberately replaces their presentation avatar with a bounded PNG, JPEG, or WebP image.","workflowRole":"create-or-command","sideEffects":"When promoted, creates an owner-scoped quarantined media revision. The previous avatar remains current until scanning and safe re-encoding succeed; upload acceptance is not publication.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Send multipart/form-data with one image part, its exact SHA-256 digest, optional accessible alt text, and an optional normalized crop rectangle. Never use base64 JSON or a remote-fetch URL.","The server must derive the subject and object key, ignore client filenames for storage, reject SVG and animation, bound encoded bytes and decoded pixels, strip EXIF and embedded metadata, scan content, and publish only a safely re-encoded derivative.","An avatar is presentation data only. It is not identity evidence, a credential, KYC media, an authorization image, a signing key, or proof of account ownership.","On an ambiguous 202, reconcile through the future processing receipt or GET /api/v2/me/avatar before retrying the exact body and Idempotency-Key.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Notifications","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-me-capabilities","method":"GET","path":"/api/v2/me/capabilities","title":"PROFILE: Get effective capabilities","description":"Return effective profile scopes and security features for the authenticated identity.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile"],"applications":["Overview","Developers","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/advanceddata","operation":"PROFILE: Get Advanced Data"},{"method":"GET","path":"/api/v1/profile/features","operation":"PROFILE: Get Enabled Features"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1capabilities/get","scope":"profile:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get effective capabilities"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return effective profile scopes and security features for the authenticated identity.","whenToUse":"Use this operation when an integration needs to get effective capabilities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","API Reference","Integration Guides","Access Control","Identity & Login"]}},{"id":"put-api-v2-me-password","method":"PUT","path":"/api/v2/me/password","title":"AUTH: Change password","description":"Require bearer authorization, current-password proof, conditional authenticator step-up, and revoke active sessions.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile","identity-service"],"applications":["Overview","Trust Center","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/setpassword","operation":"PROFILE: Change Password"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1password/put","scope":"profile:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Change password"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-password-request-001"},{"name":"current_password","location":"body","required":true,"type":"string","description":"Current password used only as reauthentication proof.","example":"current-password-01"},{"name":"new_password","location":"body","required":true,"type":"printable string · 12–128","description":"Replacement password; must differ and satisfy current strength policy.","example":"new-password-01"},{"name":"step_up_token","location":"body","required":false,"type":"one-time hcsu_ token","description":"Fresh PASSWORD_CHANGE authorization required when TOTP is enabled.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Password replaced and every active interactive session revoked.","example":null},{"status":400,"description":"The replacement password fails policy or does not differ from the current password.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"Current-password proof or the required PASSWORD_CHANGE step-up failed.","example":null},{"status":503,"description":"Identity is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Require bearer authorization, current-password proof, conditional authenticator step-up, and revoke active sessions.","whenToUse":"Use from an authenticated account settings workflow after collecting current-password proof and, when TOTP is enabled, a fresh PASSWORD_CHANGE step-up.","workflowRole":"revise","sideEffects":"Changes the password and revokes all interactive sessions, including the bearer session used for the request.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Treat the successful response as the final message on the current session and immediately remove cached access and refresh credentials.","The step-up token is one-use, session-bound, purpose-bound, and cannot replace the bearer token.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Access Control","Teams & Workspaces"]}},{"id":"get-api-v2-me-watchlist","method":"GET","path":"/api/v2/me/watchlist","title":"PROFILE: Get Symbol Watchlist","description":"PROFILE: Get Symbol Watchlist through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["market-preferences"],"applications":["Overview","Trading","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/market_watchlist","operation":"PROFILE: Get Symbol Watchlist"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1watchlist/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Symbol Watchlist"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PROFILE: Get Symbol Watchlist through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get symbol watchlist before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Strategy Pools","Liquidity Management","Trading & Matching Ops","Identity & Login"]}},{"id":"delete-api-v2-me-watchlist-market-id","method":"DELETE","path":"/api/v2/me/watchlist/{market_id}","title":"PROFILE: Remove Symbol from Watchlist","description":"PROFILE: Remove Symbol from Watchlist through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["market-preferences"],"applications":["Overview","Trading","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/togglesymbolwatchlist","operation":"PROFILE: Toggle Symbol to Watchlist"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1watchlist~1{market_id}/delete","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Remove Symbol from Watchlist"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-me-watchlist-market-id-request-001"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"PROFILE: Remove Symbol from Watchlist through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to remove symbol from watchlist.","workflowRole":"revoke-or-delete","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["daily account review","exception triage","cross-module navigation","market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Notifications","Strategy Pools","Liquidity Management","Trading & Matching Ops","Identity & Login"]}},{"id":"put-api-v2-me-watchlist-market-id","method":"PUT","path":"/api/v2/me/watchlist/{market_id}","title":"PROFILE: Add Symbol to Watchlist","description":"PROFILE: Add Symbol to Watchlist through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["market-preferences"],"applications":["Overview","Trading","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/togglesymbolwatchlist","operation":"PROFILE: Toggle Symbol to Watchlist"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1watchlist~1{market_id}/put","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Add Symbol to Watchlist"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-watchlist-market-id-request-001"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"PROFILE: Add Symbol to Watchlist through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to add symbol to watchlist.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["daily account review","exception triage","cross-module navigation","market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Notifications","Strategy Pools","Liquidity Management","Trading & Matching Ops","Identity & Login"]}},{"id":"post-api-v2-password-reset-requests","method":"POST","path":"/api/v2/password-reset-requests","title":"PROFILE: Request Reset Link","description":"PROFILE: Request Reset Link through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile","identity-service"],"applications":["Overview","Trust Center","Identity & Login"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/resetpassword","operation":"PROFILE: Request Reset Link"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1password-reset-requests/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request Reset Link"],"parameters":[{"name":"email","location":"body","required":true,"type":"email address · max 128","description":"Account address; the response never reveals whether it exists.","example":"email-01"},{"name":"tenant_uuid","location":"body","required":false,"type":"tenant identifier","description":"Tenant boundary; omission selects global.","example":"tenant-uuid-01"}],"responses":[{"status":202,"description":"Enumeration-resistant receipt returned; eligible accounts receive reset delivery.","example":null},{"status":400,"description":"The email or tenant identifier is invalid.","example":null},{"status":503,"description":"Identity or encrypted reset delivery is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PROFILE: Request Reset Link through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use when a person cannot authenticate and has supplied a syntactically valid account email and tenant context.","workflowRole":"create-or-command","sideEffects":"Eligible accounts receive encrypted 30-minute reset delivery; ineligible accounts produce the same accepted response and no account-state disclosure.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Always present the response generically. Do not branch UX, logging, timing assumptions, or agent output on account existence.","This request does not change the password and does not revoke sessions.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Access Control","Teams & Workspaces"]}},{"id":"post-api-v2-password-resets","method":"POST","path":"/api/v2/password-resets","title":"PROFILE: Reset Password","description":"PROFILE: Reset Password through the canonical Hybrid-Chain V2 interface.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-profile","identity-service"],"applications":["Overview","Trust Center","Identity & Login"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/profile/newpassword","operation":"PROFILE: Reset Password"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1password-resets/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Reset Password"],"parameters":[{"name":"token","location":"body","required":true,"type":"one-time hcat_ credential","description":"30-minute password-reset credential delivered out of band and consumed once.","example":"token-01"},{"name":"new_password","location":"body","required":true,"type":"printable string · 12–128","description":"Replacement password subject to the registration strength policy.","example":"new-password-01"}],"responses":[{"status":200,"description":"Password verifier replaced and every active interactive session revoked.","example":null},{"status":400,"description":"The reset credential or replacement password is invalid.","example":null},{"status":403,"description":"The reset credential is expired, invalid, or already consumed.","example":null},{"status":503,"description":"Identity is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PROFILE: Reset Password through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use once with the delivered reset credential and a policy-compliant replacement password.","workflowRole":"create-or-command","sideEffects":"Consumes the reset credential, replaces password verifiers, and revokes every active interactive session.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Discard the token after success and require a new login on every device.","Do not retry an ambiguous response with a different password; first attempt a fresh login or request a new reset transaction.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Access Control","Teams & Workspaces"]}},{"id":"get-api-v2-tenant-brand","method":"GET","path":"/api/v2/tenant-brand","title":"PROFILE: Get tenant brand","description":"Return the authenticated tenant's presentation-safe names, theme, assets, links, and labels without exposing policy, credential, banking, registration, or infrastructure configuration.","chapter":"User Profile Data","chapterOrder":1,"capability":"User Profile Data","owners":["identity-service","tenant-configuration"],"applications":["Overview","Trust Center","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/profile/whitelabel","operation":"PROFILE: Get Profile Whitelabel Data"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1tenant-brand/get","scope":"profile:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get tenant brand"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Authenticated tenant's presentation-safe brand projection.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":404,"description":"No active brand is assigned to the authenticated tenant.","example":null},{"status":503,"description":"Identity is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated tenant's presentation-safe names, theme, assets, links, and labels without exposing policy, credential, banking, registration, or infrastructure configuration.","whenToUse":"Load after authentication when an application needs tenant-specific public names, mode behavior, assets, links, and vocabulary.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","The tenant is derived from the authenticated principal; callers cannot select or enumerate another tenant.","The projection intentionally excludes registration policy, provider credentials, bank configuration, storage secrets, and infrastructure settings. Treat URLs as presentation values, not authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Notifications","Transfer Compliance","Identity Review","Access Control","Teams & Workspaces"]}},{"id":"get-api-v2-identity-mobile-introspect","method":"GET","path":"/api/v2/identity/mobile/introspect","title":"IDENTITY: introspect mobile identity session","description":"IDENTITY: introspect mobile identity session through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/introspect","source":"Identity APIHandler.py · introspect_mobile_identity_session"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-mobile-introspect","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["introspect mobile identity session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: introspect mobile identity session through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to introspect mobile identity session before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-identity-mobile-refresh","method":"POST","path":"/api/v2/identity/mobile/refresh","title":"IDENTITY: refresh mobile identity session","description":"IDENTITY: refresh mobile identity session through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/refresh","source":"Identity APIHandler.py · refresh_mobile_identity_session"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-mobile-refresh","scope":"identity:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["refresh mobile identity session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing identity:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Identity compatibility marker; use the explicit implemented V2 authentication or security lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: refresh mobile identity session through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot validate credentials, issue or rotate tokens, create or revoke a session, change authenticators, register or revoke a signing key, mint step-up authority, or change account security state.","businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment"],"prerequisites":["A bearer credential with identity:compatibility authority and the required tenant, workspace, and role context.","the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen.","Use implemented POST /api/v2/auth/session-refreshes with the current single-use refresh credential; successful rotation invalidates the submitted credential.","Do not translate the legacy body field-for-field or submit access tokens, refresh credentials, passwords, authenticator codes, recovery codes, signing keys, step-up tokens, session selectors, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact implemented canonical operation. Authentication, refresh, revocation, signing-key, step-up, and authenticator lifecycles remain separate authority boundaries.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-identity-mobile-revoke","method":"POST","path":"/api/v2/identity/mobile/revoke","title":"IDENTITY: revoke mobile identity session","description":"IDENTITY: revoke mobile identity session through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/revoke","source":"Identity APIHandler.py · revoke_mobile_identity_session"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-mobile-revoke","scope":"identity:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["revoke mobile identity session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing identity:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Identity compatibility marker; use the explicit implemented V2 authentication or security lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: revoke mobile identity session through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot validate credentials, issue or rotate tokens, create or revoke a session, change authenticators, register or revoke a signing key, mint step-up authority, or change account security state.","businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment"],"prerequisites":["A bearer credential with identity:compatibility authority and the required tenant, workspace, and role context.","the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen.","Use implemented POST /api/v2/auth/sessions/{session_id}/revocations. The current session may revoke itself; revoking another session requires the exact documented authorization.","Do not translate the legacy body field-for-field or submit access tokens, refresh credentials, passwords, authenticator codes, recovery codes, signing keys, step-up tokens, session selectors, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact implemented canonical operation. Authentication, refresh, revocation, signing-key, step-up, and authenticator lifecycles remain separate authority boundaries.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-identity-mobile-security","method":"GET","path":"/api/v2/identity/mobile/security","title":"IDENTITY: manage mobile identity security","description":"IDENTITY: manage mobile identity security through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/security","source":"Identity APIHandler.py · manage_mobile_identity_security"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-mobile-security","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage mobile identity security"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage mobile identity security through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to manage mobile identity security before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-identity-mobile-security","method":"POST","path":"/api/v2/identity/mobile/security","title":"IDENTITY: manage mobile identity security","description":"IDENTITY: manage mobile identity security through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/security","source":"Identity APIHandler.py · manage_mobile_identity_security"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-mobile-security","scope":"identity:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage mobile identity security"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing identity:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Identity compatibility marker; use the explicit implemented V2 authentication or security lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage mobile identity security through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot validate credentials, issue or rotate tokens, create or revoke a session, change authenticators, register or revoke a signing key, mint step-up authority, or change account security state.","businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment"],"prerequisites":["A bearer credential with identity:compatibility authority and the required tenant, workspace, and role context.","the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen.","Use the explicit implemented V2 resource that owns the intended action: sessions and authentication events for session posture, signing-key endpoints for API request keys, step-up for a single purpose, and authenticator enrollment or disablement for TOTP lifecycle.","Do not translate the legacy body field-for-field or submit access tokens, refresh credentials, passwords, authenticator codes, recovery codes, signing keys, step-up tokens, session selectors, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact implemented canonical operation. Authentication, refresh, revocation, signing-key, step-up, and authenticator lifecycles remain separate authority boundaries.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-identity-mobile-session","method":"POST","path":"/api/v2/identity/mobile/session","title":"IDENTITY: create mobile identity session","description":"IDENTITY: create mobile identity session through the canonical Hybrid-Chain V2 interface.","chapter":"Session Management","chapterOrder":2,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Trust Center","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/session","source":"Identity APIHandler.py · create_mobile_identity_session"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-mobile-session","scope":"identity:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["create mobile identity session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing identity:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Identity compatibility marker; use the explicit implemented V2 authentication or security lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: create mobile identity session through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot validate credentials, issue or rotate tokens, create or revoke a session, change authenticators, register or revoke a signing key, mint step-up authority, or change account security state.","businessCases":["interactive session creation and rotation","session and signing-key inventory","self-service or administrative revocation","authenticator enrollment and recovery","purpose-bound step-up","role assignment"],"prerequisites":["A bearer credential with identity:compatibility authority and the required tenant, workspace, and role context.","the exact bearer scope, tenant, workspace, and role required by the selected operation","fresh device and session context for interactive credentials","RFC 9421 signing where the executable OpenAPI operation requires it","fresh purpose-bound step-up for sensitive self-service or administrative changes","caller-owned secure storage and redaction rules for access, refresh, recovery, and step-up credentials"],"agentGuidance":["A password proves one login factor; a bearer represents one bounded session; a refresh credential rotates one session; a workspace role, API signing key, and step-up token are separate authority checks. No one substitutes for another.","Never place access tokens, refresh credentials, passwords, authenticator seeds or codes, recovery codes, signing private keys, step-up tokens, or session credentials in URLs, prompts, analytics, generic action objects, or legacy compatibility bodies.","Session issuance is not account activation, refresh success invalidates the submitted refresh credential, revocation is not deletion, signing-key registration is not a bearer grant, and step-up authorizes only one documented purpose for a short bounded window.","Immediately stop using revoked, expired, rotated, or superseded sessions and keys. After an ambiguous security mutation, re-read canonical sessions, key metadata, authenticator posture, and audit evidence before deciding whether an exact retry is safe.","Administrative role and session plans remain non-executable until they appear in live OpenAPI and must preserve tenant isolation, least privilege, last-owner and lockout safety, version concurrency, attribution, and immutable audit history.","Treat POST /api/v2/identity/validate and POST /api/v2/identity/mobile/{session,refresh,revoke,security} as bodyless 501 migration markers. Use the implemented canonical GET /me, /auth, /security, and authenticator operations named in their guidance.","Access Control cannot grant or modify trading, matching, prediction execution, ingress, publisher, allowlist, market status, suspension, settlement, payment, or traffic authority while those controls remain frozen.","Use implemented POST /api/v2/auth/sessions with its exact OpenAPI credential, device, and conditional authenticator fields.","Do not translate the legacy body field-for-field or submit access tokens, refresh credentials, passwords, authenticator codes, recovery codes, signing keys, step-up tokens, session selectors, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact implemented canonical operation. Authentication, refresh, revocation, signing-key, step-up, and authenticator lifecycles remain separate authority boundaries.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-security-signing-keys","method":"POST","path":"/api/v2/security/signing-keys","title":"SECURITY: Register request-signing key","description":"Register an Ed25519 public JWK after proof of possession and purpose-bound step-up authorization.","chapter":"Session Management","chapterOrder":2,"capability":"Session Management","owners":["developer-platform","identity-access"],"applications":["Developers","Identity & Login","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/sessions/new","operation":"SESSION: Create new API Key"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1security~1signing-keys/post","scope":"security:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register request-signing key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"public_key_jwk","location":"body","required":true,"type":"OKP Ed25519 public JWK","description":"Public request-verification key; private key material is forbidden.","example":"public-key-jwk-01"},{"name":"proof","location":"body","required":true,"type":"base64url Ed25519 signature","description":"Proof over the canonical signing-key registration statement.","example":"proof-01"},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh API_SIGNING_KEY_REGISTRATION authorization.","example":"step-up-token-01"},{"name":"label","location":"body","required":false,"type":"string","description":"Human-readable machine or device label.","example":"label-01"},{"name":"rotated_from_key_id","location":"body","required":false,"type":"key identifier","description":"Optional active predecessor key linked for rotation provenance.","example":"rotated-from-key-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Register an Ed25519 public JWK after proof of possession and purpose-bound step-up authorization.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to register request-signing key.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Trust Center","Teams & Workspaces"]}},{"id":"get-api-v2-identity-whitelabels","method":"GET","path":"/api/v2/identity/whitelabels","title":"IDENTITY: get all affiliate programs for whitelabeling","description":"IDENTITY: get all affiliate programs for whitelabeling through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Identity · whitelabels","owners":["identity-service"],"applications":["Trust Center","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/whitelabels","source":"Identity APIHandler.py · get_all_affiliate_programs_for_whitelabeling"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-whitelabels","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get all affiliate programs for whitelabeling"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get all affiliate programs for whitelabeling through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all affiliate programs for whitelabeling before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Access Control","Billing Operations"]}},{"id":"get-api-v2-identity-whitelabels-hash-whitelabel-hash","method":"GET","path":"/api/v2/identity/whitelabels/hash/{whitelabel_hash}","title":"IDENTITY: get whitelabel meta for whitelabel hash","description":"IDENTITY: get whitelabel meta for whitelabel hash through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Identity · whitelabels","owners":["identity-service"],"applications":["Trust Center","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/whitelabels/hash/{whitelabel_hash}","source":"Identity APIHandler.py · get_whitelabel_meta_for_whitelabel_hash"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-whitelabels-hash-whitelabel-hash","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get whitelabel meta for whitelabel hash"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"whitelabel_hash","location":"path","required":true,"type":"identifier","description":"Canonical whitelabel hash.","example":"whitelabel-hash-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get whitelabel meta for whitelabel hash through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get whitelabel meta for whitelabel hash before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Access Control","Billing Operations"]}},{"id":"get-api-v2-identity-whitelabels-profile-profile-uuid-hash","method":"GET","path":"/api/v2/identity/whitelabels/profile/{profile_uuid}/hash","title":"IDENTITY: get whitelabel hash for profile uuid","description":"IDENTITY: get whitelabel hash for profile uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Identity · whitelabels","owners":["identity-service"],"applications":["Trust Center","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/whitelabels/profile/{profile_uuid}/hash","source":"Identity APIHandler.py · get_whitelabel_hash_for_profile_uuid"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-whitelabels-profile-profile-uuid-hash","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get whitelabel hash for profile uuid"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get whitelabel hash for profile uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get whitelabel hash for profile uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Access Control","Billing Operations"]}},{"id":"get-api-v2-identity-whitelabels-profile-profile-uuid-symbol","method":"GET","path":"/api/v2/identity/whitelabels/profile/{profile_uuid}/symbol","title":"IDENTITY: get whitelabel symbol for profile uuid","description":"IDENTITY: get whitelabel symbol for profile uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Identity · whitelabels","owners":["identity-service"],"applications":["Trust Center","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/whitelabels/profile/{profile_uuid}/symbol","source":"Identity APIHandler.py · get_whitelabel_symbol_for_profile_uuid"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-whitelabels-profile-profile-uuid-symbol","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get whitelabel symbol for profile uuid"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get whitelabel symbol for profile uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get whitelabel symbol for profile uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Access Control","Billing Operations"]}},{"id":"put-api-v2-me-active-workspace","method":"PUT","path":"/api/v2/me/active-workspace","title":"WORKSPACES: Set active workspace","description":"Select one of the authenticated subject's active memberships.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1active-workspace/put","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Set active workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-me-active-workspace-request-001"},{"name":"workspace_id","location":"body","required":true,"type":"identifier","description":"Workspace selected from the caller's active memberships.","example":"workspace-id-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Select one of the authenticated subject's active memberships.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to set active workspace.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-workspaces-workspace-id-invitations","method":"GET","path":"/api/v2/workspaces/{workspace_id}/invitations","title":"WORKSPACES: List invitations","description":"List recipient and delivery lifecycle state for workspace invitations without revealing one-time tokens.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1invitations/get","scope":"workspaces:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List invitations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List recipient and delivery lifecycle state for workspace invitations without revealing one-time tokens.","whenToUse":"Use this operation when an integration needs to list invitations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"delete-api-v2-workspaces-workspace-id-invitations-invitation-id","method":"DELETE","path":"/api/v2/workspaces/{workspace_id}/invitations/{invitation_id}","title":"WORKSPACES: Revoke invitation","description":"Revoke a pending invitation idempotently and cancel pending delivery.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1invitations~1{invitation_id}/delete","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke invitation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-workspaces-workspace-id-invitations-invitation-id-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"invitation_id","location":"path","required":true,"type":"identifier","description":"Canonical invitation id.","example":"invitation-id-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke a pending invitation idempotently and cancel pending delivery.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke invitation.","workflowRole":"revoke-or-delete","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-workspace-id-invitations-invitation-id-resend","method":"POST","path":"/api/v2/workspaces/{workspace_id}/invitations/{invitation_id}/resend","title":"WORKSPACES: Resend invitation","description":"Idempotently requeue an unexpired pending invitation for delivery without minting or revealing a token.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1invitations~1{invitation_id}~1resend/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Resend invitation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-workspace-id-invitations-invitation-id-resend-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"invitation_id","location":"path","required":true,"type":"identifier","description":"Canonical invitation id.","example":"invitation-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Idempotently requeue an unexpired pending invitation for delivery without minting or revealing a token.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to resend invitation.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-workspaces-workspace-id-members","method":"GET","path":"/api/v2/workspaces/{workspace_id}/members","title":"WORKSPACES: List members","description":"List the active, privacy-minimized membership roster for an accessible workspace.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1members/get","scope":"workspaces:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List members"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the active, privacy-minimized membership roster for an accessible workspace.","whenToUse":"Use this operation when an integration needs to list members before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"delete-api-v2-workspaces-workspace-id-members-membership-id","method":"DELETE","path":"/api/v2/workspaces/{workspace_id}/members/{membership_id}","title":"WORKSPACES: Revoke member","description":"Revoke a non-owner membership while retaining audit evidence.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1members~1{membership_id}/delete","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke member"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-workspaces-workspace-id-members-membership-id-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"membership_id","location":"path","required":true,"type":"identifier","description":"Canonical membership id.","example":"membership-id-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke a non-owner membership while retaining audit evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke member.","workflowRole":"revoke-or-delete","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"put-api-v2-workspaces-workspace-id-members-membership-id-role","method":"PUT","path":"/api/v2/workspaces/{workspace_id}/members/{membership_id}/role","title":"WORKSPACES: Change member role","description":"Change a non-owner membership role using optimistic versioning.","chapter":"Workspace Management","chapterOrder":3,"capability":"Teams & workspaces","owners":["identity-service"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1members~1{membership_id}~1role/put","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Change member role"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-workspaces-workspace-id-members-membership-id-role-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"membership_id","location":"path","required":true,"type":"identifier","description":"Canonical membership id.","example":"membership-id-01"},{"name":"role","location":"body","required":true,"type":"ADMIN | MEMBER | AUDITOR","description":"Replacement non-owner role.","example":"role-01"},{"name":"version","location":"body","required":true,"type":"integer · ≥1","description":"Current membership version used for optimistic concurrency.","example":1}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Change a non-owner membership role using optimistic versioning.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to change member role.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-admin-tenants","method":"GET","path":"/api/v2/admin/tenants","title":"TENANTS: List tenants","description":"List tenant identities, domains, status, configuration head, and entitlement posture.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List tenants"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"q","location":"query","required":false,"type":"string · 1–120","description":"Case-insensitive search across tenant key, symbol, name, and description.","example":"treasury"},{"name":"status","location":"query","required":false,"type":"ACTIVE | DRAFT | SUSPENDED | ARCHIVED","description":"Exact tenant lifecycle filter. This is not market status.","example":"ACTIVE"},{"name":"environment","location":"query","required":false,"type":"PRODUCTION | TEST | DEVELOPMENT","description":"Exact deployment-environment classification filter.","example":"environment-01"},{"name":"administrator_profile_uuid","location":"query","required":false,"type":"32-character lowercase hexadecimal identifier","description":"Return tenants for which this profile has an active tenant authority assignment.","example":"10.00"},{"name":"limit","location":"query","required":false,"type":"integer · 1–500","description":"Maximum newest directory records to return; defaults to 250. The current Core directory is bounded rather than cursor-paginated.","example":250}],"responses":[{"status":200,"description":"Filtered tenant directory page with authoritative lifecycle, configuration head, domain, entitlement, and administrator summaries.","example":null},{"status":400,"description":"The query string cannot be decoded into the documented parameter types.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":422,"description":"A filter, limit, or administrator identifier is outside the documented policy.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List tenant identities, domains, status, configuration head, and entitlement posture.","whenToUse":"Use this administrative directory to discover tenant identities and configuration heads before opening a detail or initiating a governed change.","workflowRole":"discover-or-read","sideEffects":"Read-only no-store projection. It grants no tenant, domain, product, infrastructure, traffic, or trading authority.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Use q for human discovery and exact lifecycle, environment, or administrator filters for reconciliation. Preserve offset and filters together while paging.","A tenant lifecycle status is distinct from market status. Never infer trading availability, ingress, routing, or publisher posture from this directory.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants","method":"POST","path":"/api/v2/admin/tenants","title":"TENANTS: Create tenant","description":"Create a tenant identity and its first unpublished configuration revision.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create tenant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-request-001"},{"name":"tenant_uuid","location":"body","required":false,"type":"32-character lowercase hexadecimal identifier","description":"Optional caller-selected tenant identifier. Omit it to let Core allocate one.","example":"f8317aef81764e1f923037c1b76df8de"},{"name":"configuration","location":"body","required":true,"type":"complete TenantConfiguration object","description":"Full revision 1 configuration: identity, brand, complete domain and entitlement sets, and non-secret settings. This is not a patch.","example":{"brand":{"primary_color":"#0057FF"},"domains":[{"hostname":"northstar.example.com","is_primary":true,"purpose":"PORTAL","redirect_hostname":null}],"entitlements":[{"capability_code":"REPORTING","policy":{},"status":"ENABLED"}],"identity":{"description":"Northstar customer environment","environment":"TEST","lifecycle_status":"DRAFT","name":"Northstar","owner_workspace_uuid":"","parent_tenant_uuid":"","region_code":"US-AZ","symbol":"NST","tenant_key":"northstar"},"settings":{"default_locale":"en-US"}}},{"name":"change_summary","location":"body","required":true,"type":"string · 1–320","description":"Retained human-readable reason for provisioning the initial DRAFT revision.","example":"Provision Northstar test tenant."}],"responses":[{"status":201,"description":"Tenant identity and immutable revision 1 created in DRAFT; no domain routing, infrastructure, traffic, or trading authority is activated.","example":null},{"status":400,"description":"The complete configuration, rationale, signature, identifier, or Idempotency-Key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":409,"description":"Tenant identity, key, symbol, domain, or Idempotency-Key conflicts with retained state.","example":null},{"status":422,"description":"Core tenant policy or the trading-domain freeze rejected the configuration.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; no tenant is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a tenant identity and its first unpublished configuration revision.","whenToUse":"Use when an authorized platform administrator is ready to provision a tenant identity and its first complete configuration revision.","workflowRole":"create-or-command","sideEffects":"Creates the tenant and immutable revision 1 in DRAFT. It does not publish configuration, verify domains, configure DNS or TLS, allocate infrastructure, route traffic, or enable trading.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Send one complete TenantConfiguration rather than a patch. The identity object, full domains and entitlements sets, brand, and settings become the retained draft proposal.","Reuse the same Idempotency-Key only for a byte-equivalent retry. Reconcile an ambiguous response through the directory or caller-selected tenant_uuid before creating another tenant.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-admin-tenants-tenant-uuid","method":"GET","path":"/api/v2/admin/tenants/{tenant_uuid}","title":"TENANTS: Get tenant","description":"Return tenant identity, domains, effective branding, entitlements, and revision history.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get tenant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"}],"responses":[{"status":200,"description":"Complete authoritative tenant projection including identity, effective brand, domains, entitlements, administrators, and immutable revision history.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":404,"description":"The tenant does not exist.","example":null},{"status":422,"description":"The tenant identifier is malformed.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return tenant identity, domains, effective branding, entitlements, and revision history.","whenToUse":"Use as the authoritative preflight and reconciliation read for one tenant before drafting, publishing, reverting, or changing tenant-local authority.","workflowRole":"discover-or-read","sideEffects":"Read-only no-store projection of effective state and immutable history.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Treat configuration_version and revision UUIDs as concurrency inputs, not presentation labels.","Domains and entitlements describe effective tenant configuration only; they do not prove DNS control, TLS issuance, bearer scopes, infrastructure allocation, or trading permission.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"patch-api-v2-admin-tenants-tenant-uuid","method":"PATCH","path":"/api/v2/admin/tenants/{tenant_uuid}","title":"TENANTS: Update tenant","description":"Update eligible tenant identity and lifecycle properties.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-admin-tenants-tenant-uuid","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update tenant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-admin-tenants-tenant-uuid-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current tenant-configuration version for optimistic concurrency.","example":7},{"name":"display_name","location":"body","required":false,"type":"string · 2–160","description":"Optional replacement public tenant name.","example":"Northstar"},{"name":"support_contact","location":"body","required":false,"type":"verified contact object","description":"Optional bounded support contact without credentials or processor identifiers.","example":{"email":"support@example.com"}},{"name":"default_locale","location":"body","required":false,"type":"BCP 47 locale","description":"Optional presentation locale.","example":"en-US"},{"name":"default_timezone","location":"body","required":false,"type":"IANA timezone","description":"Optional presentation timezone.","example":"America/Phoenix"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed non-secret administrative rationale.","example":"Update customer support contact."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh TENANT_CONFIGURATION_UPDATE authorization.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Tenant presentation and support configuration revised with a new optimistic version; membership, scopes, entitlements, domains, and trading controls remain unchanged.","example":null},{"status":400,"description":"A field, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing, expired, or invalid.","example":null},{"status":403,"description":"Tenant authority, required role, exact scope, or fresh purpose-bound step-up is missing.","example":null},{"status":404,"description":"The tenant or selected tenant-owned resource does not exist in the administrator boundary.","example":null},{"status":409,"description":"The expected version, lifecycle, uniqueness, dependency, active publication, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Schema, domain, entitlement, configuration, retention, lockout, or platform policy rejected the request.","example":null},{"status":503,"description":"Tenant configuration, Identity, policy, verification, publication, or evidence ownership is unavailable; state remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update eligible tenant identity and lifecycle properties.","whenToUse":"Do not call this planning route yet. It reserves version-bound revision of presentation and support configuration only.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Send at least one admitted field and expected_version. It cannot change tenant identity, membership, roles, entitlements, domains, billing, credentials, or any frozen trading control.","Promotion requires admin:tenants:write, TENANT_CONFIGURATION_UPDATE step-up, tenant isolation, version locking, contact verification, idempotency, immutable before/after commitments, and lockout-safe failure tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-authorities","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/authorities","title":"TENANTS: Assign authority","description":"Assign TENANT_ADMIN or TENANT_MODERATOR authority with retained actor attribution and rationale.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Governance","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1authorities/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Assign authority"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-authorities-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"profile_uuid","location":"body","required":true,"type":"32-character lowercase hexadecimal identifier","description":"Existing administrator profile receiving tenant-local authority.","example":"9d9dd75d5072462ba35e5529f1f4f09e"},{"name":"role_code","location":"body","required":true,"type":"TENANT_ADMIN | TENANT_MODERATOR","description":"Exact tenant-local administrative role. It grants no infrastructure, traffic, or trading authority.","example":"TENANT_MODERATOR"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Retained attributed rationale for the assignment.","example":"Assign content operations moderator."}],"responses":[{"status":200,"description":"Tenant-local TENANT_ADMIN or TENANT_MODERATOR assignment retained with trusted actor attribution and current administrator projection.","example":null},{"status":400,"description":"The identifiers, role, reason, signature, or Idempotency-Key are malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"The tenant or target profile does not exist.","example":null},{"status":409,"description":"The assignment or Idempotency-Key conflicts with retained state.","example":null},{"status":422,"description":"Core authority or lockout policy rejected the assignment.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; no authority is assigned.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Assign TENANT_ADMIN or TENANT_MODERATOR authority with retained actor attribution and rationale.","whenToUse":"Use when a known profile should receive TENANT_ADMIN or TENANT_MODERATOR authority for one tenant.","workflowRole":"create-or-command","sideEffects":"Creates a tenant-local authority assignment and retained audit event. It does not grant platform infrastructure, traffic, publisher, market, matching, or trading authority.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","tenant branding","custom-domain lifecycle","entitlement management"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","The gateway derives the actor from the authenticated credential; never send or trust caller-authored actor identity.","Use the narrowest role and a substantive reason. Reconcile ambiguous completion through tenant detail before retrying with the same Idempotency-Key.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-authorities-assignment-uuid-revocations","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/authorities/{assignment_uuid}/revocations","title":"TENANTS: Revoke authority","description":"Revoke an eligible tenant administrator assignment while protecting owner authority.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Governance","Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1authorities~1{assignment_uuid}~1revocations/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke authority"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-authorities-assignment-uuid-revocations-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"assignment_uuid","location":"path","required":true,"type":"identifier","description":"Canonical assignment uuid.","example":"assignment-uuid-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Retained attributed rationale for revocation. Owner-lockout protection remains authoritative in Core.","example":"Operator no longer administers this tenant."}],"responses":[{"status":200,"description":"Eligible tenant-local authority revoked with retained actor attribution; owner-lockout protections remain authoritative.","example":null},{"status":400,"description":"The identifiers, reason, signature, or Idempotency-Key are malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"The tenant or tenant-owned assignment does not exist.","example":null},{"status":409,"description":"The assignment lifecycle or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Core owner-lockout or authority policy rejected revocation.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; authority remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke an eligible tenant administrator assignment while protecting owner authority.","whenToUse":"Use when an active tenant-local assignment should be revoked and owner-lockout policy permits the change.","workflowRole":"create-or-command","sideEffects":"Revokes the selected tenant-local assignment and retains actor attribution and rationale. Historical authority evidence remains immutable.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","tenant branding","custom-domain lifecycle","entitlement management"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","The assignment must belong to the path tenant. Core rejects revocation that would violate protected owner authority.","Revocation changes tenant administration only; it is not session revocation, credential deactivation, traffic control, or trading suspension.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-admin-tenants-tenant-uuid-configuration-revisions","method":"GET","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions","title":"TENANTS: List revisions","description":"List draft, reviewed, published, superseded, and reverted configuration revisions.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1configuration-revisions/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List revisions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"All immutable tenant configuration revisions with UUID, numeric version, base version, lifecycle, complete configuration, lineage, actor, and timestamps.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":404,"description":"The tenant does not exist.","example":null},{"status":422,"description":"The tenant identifier is malformed.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List draft, reviewed, published, superseded, and reverted configuration revisions.","whenToUse":"Use to audit immutable configuration history, select a draft for publication, or select historical state for a new reversion draft.","workflowRole":"discover-or-read","sideEffects":"Read-only revision collection. It does not validate, review, publish, or revert anything.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Every item contains a complete configuration and lineage. Compare revision_uuid, revision, base_configuration_version, lifecycle, and configuration together.","Do not infer that the newest revision is effective: only PUBLISHED identifies the active source revision.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions","title":"TENANTS: Create revision","description":"Create a draft revision containing domain, branding, navigation, feature, and entitlement changes.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1configuration-revisions/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"base_configuration_version","location":"body","required":true,"type":"integer · ≥1","description":"Current published tenant configuration version. A stale value fails atomically with 409.","example":3},{"name":"configuration","location":"body","required":true,"type":"complete TenantConfiguration object","description":"Full desired tenant configuration. Draft revisions are immutable; create another draft to make another change.","example":{"brand":{},"domains":[],"entitlements":[],"identity":{"description":"Northstar customer environment","environment":"PRODUCTION","lifecycle_status":"ACTIVE","name":"Northstar","owner_workspace_uuid":"","parent_tenant_uuid":"","region_code":"US-AZ","symbol":"NST","tenant_key":"northstar"},"settings":{}}},{"name":"change_summary","location":"body","required":true,"type":"string · 1–320","description":"Retained operator summary explaining why this complete revision is being proposed.","example":"Refresh production presentation configuration."}],"responses":[{"status":201,"description":"New immutable DRAFT containing the complete desired configuration; the effective tenant projection remains unchanged.","example":null},{"status":400,"description":"The tenant identifier, complete configuration, base version, rationale, signature, or Idempotency-Key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"The tenant does not exist.","example":null},{"status":409,"description":"The base version, uniqueness constraint, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Core tenant policy or the trading-domain freeze rejected the configuration.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; no draft is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a draft revision containing domain, branding, navigation, feature, and entitlement changes.","whenToUse":"Use after reading current tenant detail when a complete desired tenant configuration is ready to retain as a new immutable DRAFT.","workflowRole":"create-or-command","sideEffects":"Creates one immutable DRAFT from the supplied base_configuration_version. Effective tenant state remains unchanged.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","This is replacement-by-revision, not JSON Merge Patch. Include the complete identity, brand, domain set, entitlement set, and settings you want a later publication to apply atomically.","Trading, matching, prediction, publisher, ingress, allowlist, market-state, and traffic controls are rejected while frozen.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid","method":"GET","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions/{revision_uuid}","title":"TENANTS: Get revision","description":"Return one complete tenant configuration revision and validation posture.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1configuration-revisions~1{revision_uuid}/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"revision_uuid","location":"path","required":true,"type":"identifier","description":"Canonical revision uuid.","example":"revision-uuid-01"}],"responses":[{"status":200,"description":"One complete immutable revision selected by canonical revision UUID.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":404,"description":"The tenant or tenant-owned revision does not exist.","example":null},{"status":422,"description":"A tenant or revision identifier is malformed.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one complete tenant configuration revision and validation posture.","whenToUse":"Use to inspect the exact complete revision selected for publication, audit, comparison, or reversion.","workflowRole":"discover-or-read","sideEffects":"Read-only revision projection; no lifecycle transition occurs.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","The revision must belong to the path tenant. A UUID from another tenant returns not found rather than crossing the tenant boundary.","Re-read immediately before publication so expected_configuration_version and draft lineage are current.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"patch-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid","method":"PATCH","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions/{revision_uuid}","title":"TENANTS: Update revision","description":"Update an unpublished tenant configuration draft.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"revision_uuid","location":"path","required":true,"type":"identifier","description":"Canonical revision uuid.","example":"revision-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current DRAFT revision version.","example":3},{"name":"changes","location":"body","required":true,"type":"schema-governed configuration patch object","description":"Typed allowlisted changes; secrets, authority grants, raw executable content, and trading controls are forbidden.","example":{"brand":{"primary_color":"#0057FF"}}},{"name":"change_summary","location":"body","required":true,"type":"string · 8–500","description":"Human-readable summary retained with the draft revision.","example":"Refresh tenant brand color."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh TENANT_REVISION_UPDATE authorization.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Eligible DRAFT revision updated and a new schema commitment returned; nothing is published.","example":null},{"status":400,"description":"A field, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing, expired, or invalid.","example":null},{"status":403,"description":"Tenant authority, required role, exact scope, or fresh purpose-bound step-up is missing.","example":null},{"status":404,"description":"The tenant or selected tenant-owned resource does not exist in the administrator boundary.","example":null},{"status":409,"description":"The expected version, lifecycle, uniqueness, dependency, active publication, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Schema, domain, entitlement, configuration, retention, lockout, or platform policy rejected the request.","example":null},{"status":503,"description":"Tenant configuration, Identity, policy, verification, publication, or evidence ownership is unavailable; state remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update an unpublished tenant configuration draft.","whenToUse":"Do not call this planning route yet. It reserves schema-governed edits to one DRAFT configuration revision.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","changes accepts typed allowlisted configuration only. Secrets, arbitrary executable content, credential material, domain authority, scope grants, and trading controls are forbidden.","Editing a draft does not review or publish it. Promotion requires expected-version locking, schema compatibility, safe rendering checks, content commitments, idempotency, and evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-publications","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions/{revision_uuid}/publications","title":"TENANTS: Publish revision","description":"Atomically publish a current tenant configuration draft.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1configuration-revisions~1{revision_uuid}~1publications/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Publish revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-publications-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"revision_uuid","location":"path","required":true,"type":"identifier","description":"Canonical revision uuid.","example":"revision-uuid-01"},{"name":"expected_configuration_version","location":"body","required":true,"type":"integer · ≥1","description":"Current published tenant configuration version. The selected DRAFT must branch from this exact version.","example":3}],"responses":[{"status":200,"description":"Selected current DRAFT published atomically; identity, brand, domains, entitlements, and settings now reflect that exact revision.","example":null},{"status":400,"description":"An identifier, expected version, signature, or Idempotency-Key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"The tenant or tenant-owned revision does not exist.","example":null},{"status":409,"description":"The expected version, draft base, lifecycle, uniqueness constraint, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Core tenant policy rejected publication.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; the effective configuration is unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically publish a current tenant configuration draft.","whenToUse":"Use only after inspecting a current DRAFT and confirming that its complete configuration should become effective atomically.","workflowRole":"create-or-command","sideEffects":"Publishes the selected DRAFT and atomically replaces effective identity, brand, domains, entitlements, and settings. It does not configure external DNS, TLS, ingress, infrastructure, traffic, or trading authority.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","expected_configuration_version must equal the current effective version and the draft must branch from that version; otherwise resolve the conflict before retrying.","Changed or new domain configuration remains a tenant projection and cannot be treated as external domain possession or routing activation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-reversions","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions/{revision_uuid}/reversions","title":"TENANTS: Revert revision","description":"Create a new governed draft from a prior tenant configuration state; publication remains separate.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1configuration-revisions~1{revision_uuid}~1reversions/post","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revert revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-reversions-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"revision_uuid","location":"path","required":true,"type":"identifier","description":"Canonical revision uuid.","example":"revision-uuid-01"},{"name":"expected_configuration_version","location":"body","required":true,"type":"integer · ≥1","description":"Current published tenant configuration version used to detect concurrent publication.","example":9},{"name":"change_summary","location":"body","required":true,"type":"string · 1–320","description":"Retained reason for copying the selected historical state into a new DRAFT.","example":"Prepare restoration of the last verified configuration."}],"responses":[{"status":201,"description":"New DRAFT copied from the selected historical configuration with retained lineage; nothing is published by this operation.","example":null},{"status":400,"description":"An identifier, expected version, rationale, signature, or Idempotency-Key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"The tenant or tenant-owned revision does not exist.","example":null},{"status":409,"description":"The expected version or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Core tenant policy rejected the reversion draft.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable; no draft is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a new governed draft from a prior tenant configuration state; publication remains separate.","whenToUse":"Use after reading current state when historical configuration should be copied into a new governed DRAFT for inspection.","workflowRole":"create-or-command","sideEffects":"Creates a new immutable DRAFT with lineage to the selected historical revision. Current effective configuration remains unchanged until a separate publication succeeds.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Reversion never mutates history and never silently rolls production back. Inspect the returned draft and publish it separately if it remains appropriate.","Bind expected_configuration_version to the current effective version and retain a clear change_summary for audit and operator handoff.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-reviews","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/configuration-revisions/{revision_uuid}/reviews","title":"TENANTS: Review revision","description":"Record validation and four-eyes review of a tenant configuration revision.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-reviews","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Review revision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-configuration-revisions-revision-uuid-reviews-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"revision_uuid","location":"path","required":true,"type":"identifier","description":"Canonical revision uuid.","example":"revision-uuid-01"},{"name":"decision","location":"body","required":true,"type":"APPROVE | REJECT | REQUEST_INFORMATION","description":"Review outcome.","example":"decision-01"},{"name":"reason_code","location":"body","required":true,"type":"identifier","description":"Structured review rationale.","example":"reason-code-01"},{"name":"evidence_commitment","location":"body","required":false,"type":"sha256 digest","description":"Supporting evidence commitment.","example":"evidence-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record validation and four-eyes review of a tenant configuration revision.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to review revision.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-admin-tenants-tenant-uuid-domains","method":"GET","path":"/api/v2/admin/tenants/{tenant_uuid}/domains","title":"TENANTS: List domains","description":"List custom domains, verification state, certificate posture, and primary-domain assignment.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1domains/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List domains"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Effective domain projection for the currently published tenant configuration; values do not grant DNS, TLS, ingress, or routing authority.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":404,"description":"The tenant does not exist.","example":null},{"status":422,"description":"The tenant identifier is malformed.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List custom domains, verification state, certificate posture, and primary-domain assignment.","whenToUse":"Use when an integration needs the effective domain declarations from the currently published tenant configuration.","workflowRole":"discover-or-read","sideEffects":"Read-only configuration projection. It performs no DNS challenge, certificate issuance, ingress change, redirect activation, or traffic routing.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Use the complete configuration-revision workflow to propose domain changes. Standalone add and remove routes remain planning contracts.","Treat hostname, purpose, primary, and redirect fields as desired tenant configuration—not proof of external control or live reachability.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"post-api-v2-admin-tenants-tenant-uuid-domains","method":"POST","path":"/api/v2/admin/tenants/{tenant_uuid}/domains","title":"TENANTS: Add domain","description":"Add a custom domain and create its ownership-verification challenge.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-tenants-tenant-uuid-domains","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Add domain"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-tenants-tenant-uuid-domains-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"domain","location":"body","required":true,"type":"lowercase ASCII DNS name","description":"Exact tenant domain without scheme, path, wildcard, or credentials.","example":"portal.example.com"},{"name":"purpose","location":"body","required":true,"type":"APPLICATION | EMAIL","description":"Purpose selecting verification and conflict policy.","example":"APPLICATION"},{"name":"verification_method","location":"body","required":true,"type":"DNS_TXT","description":"Exact out-of-band possession method.","example":"DNS_TXT"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh TENANT_DOMAIN_REGISTRATION authorization.","example":"hcsu_…"}],"responses":[{"status":201,"description":"PENDING_VERIFICATION domain binding and one-time DNS TXT challenge returned; no routing or email authority is active.","example":null},{"status":400,"description":"A field, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing, expired, or invalid.","example":null},{"status":403,"description":"Tenant authority, required role, exact scope, or fresh purpose-bound step-up is missing.","example":null},{"status":404,"description":"The tenant or selected tenant-owned resource does not exist in the administrator boundary.","example":null},{"status":409,"description":"The expected version, lifecycle, uniqueness, dependency, active publication, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Schema, domain, entitlement, configuration, retention, lockout, or platform policy rejected the request.","example":null},{"status":503,"description":"Tenant configuration, Identity, policy, verification, publication, or evidence ownership is unavailable; state remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Add a custom domain and create its ownership-verification challenge.","whenToUse":"Do not call this planning route yet. It reserves a PENDING_VERIFICATION tenant-domain claim using one-time DNS possession evidence.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Registration does not activate routing, email, cookies, CORS, branding, identity, TLS, or certificate issuance. Those require verified state and separate publisher or infrastructure ownership.","Reject schemes, paths, wildcards, Unicode confusables, public suffixes, reserved names, cross-tenant conflicts, and caller-supplied verification success.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"delete-api-v2-admin-tenants-tenant-uuid-domains-domain-uuid","method":"DELETE","path":"/api/v2/admin/tenants/{tenant_uuid}/domains/{domain_uuid}","title":"TENANTS: Remove domain","description":"Remove an eligible non-primary domain through a configuration revision.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-admin-tenants-tenant-uuid-domains-domain-uuid","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Remove domain"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-admin-tenants-tenant-uuid-domains-domain-uuid-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"domain_uuid","location":"path","required":true,"type":"identifier","description":"Canonical domain uuid.","example":"domain-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current domain-binding version.","example":2},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed non-secret removal reason.","example":"Domain is no longer operated by this tenant."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh TENANT_DOMAIN_REMOVAL authorization.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Eligible domain binding removed from future tenant use while verification and publication history remain retained.","example":null},{"status":400,"description":"A field, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing, expired, or invalid.","example":null},{"status":403,"description":"Tenant authority, required role, exact scope, or fresh purpose-bound step-up is missing.","example":null},{"status":404,"description":"The tenant or selected tenant-owned resource does not exist in the administrator boundary.","example":null},{"status":409,"description":"The expected version, lifecycle, uniqueness, dependency, active publication, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Schema, domain, entitlement, configuration, retention, lockout, or platform policy rejected the request.","example":null},{"status":503,"description":"Tenant configuration, Identity, policy, verification, publication, or evidence ownership is unavailable; state remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Remove an eligible non-primary domain through a configuration revision.","whenToUse":"Do not call this planning route yet. It reserves removal of an eligible tenant domain after active bindings and dependencies are reconciled.","workflowRole":"revoke-or-delete","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Removal blocks future tenant use but preserves verification, certificate, routing, and publication history. It cannot revoke already-issued external DNS or TLS state by assertion.","Promotion requires TENANT_DOMAIN_REMOVAL step-up, version locking, last-domain and lockout protection, routing and certificate coordination, idempotency, and immutable evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-admin-tenants-tenant-uuid-entitlements","method":"GET","path":"/api/v2/admin/tenants/{tenant_uuid}/entitlements","title":"TENANTS: List entitlements","description":"List tenant product and feature entitlements with source and expiry.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1tenants~1{tenant_uuid}~1entitlements/get","scope":"admin:tenants:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List entitlements"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:read authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Effective product-entitlement projection for the currently published configuration; entitlements are not bearer scopes or trading permissions.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks admin:tenants:read.","example":null},{"status":404,"description":"The tenant does not exist.","example":null},{"status":422,"description":"The tenant identifier is malformed.","example":null},{"status":503,"description":"The authoritative tenant control plane is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List tenant product and feature entitlements with source and expiry.","whenToUse":"Use to inspect effective tenant product availability and domain-owned policy before presenting or authorizing a product workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only product-policy projection. It grants no bearer scope, role, credential, billing settlement, infrastructure, or trading permission.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:read authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","Use the complete configuration-revision workflow to propose entitlement changes. Standalone entitlement mutation remains a planning contract.","A consuming agent must still satisfy the target endpoint's bearer scope, ownership, role, policy, and runtime gates.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"put-api-v2-admin-tenants-tenant-uuid-entitlements-entitlement-code","method":"PUT","path":"/api/v2/admin/tenants/{tenant_uuid}/entitlements/{entitlement_code}","title":"TENANTS: Set entitlement","description":"Grant, revise, suspend, or expire one tenant entitlement through a draft revision.","chapter":"Workspace Management","chapterOrder":3,"capability":"Tenant and brand management","owners":["tenant-configuration-service"],"applications":["Tenant & Brand Manager","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#put-api-v2-admin-tenants-tenant-uuid-entitlements-entitlement-code","scope":"admin:tenants:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set entitlement"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:tenants:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-admin-tenants-tenant-uuid-entitlements-entitlement-code-request-001"},{"name":"tenant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical tenant uuid.","example":"tenant-uuid-01"},{"name":"entitlement_code","location":"path","required":true,"type":"identifier","description":"Canonical entitlement code.","example":"entitlement-code-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥0","description":"Current entitlement version; zero means no prior record.","example":1},{"name":"status","location":"body","required":true,"type":"ENABLED | DISABLED","description":"Requested product entitlement posture within platform policy.","example":"ENABLED"},{"name":"limits","location":"body","required":false,"type":"schema-governed non-negative limit object","description":"Optional limits bounded by the entitlement catalog; cannot grant scopes or domain authority.","example":{"seats":25}},{"name":"expires_at","location":"body","required":false,"type":"future RFC 3339 timestamp | null","description":"Optional expiry; null means catalog default policy.","example":"2027-01-01T00:00:00Z"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed administrative rationale.","example":"Approved enterprise subscription."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh TENANT_ENTITLEMENT_UPDATE authorization.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Tenant product entitlement revised within catalog policy; it grants no bearer scope or domain authority.","example":null},{"status":400,"description":"A field, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing, expired, or invalid.","example":null},{"status":403,"description":"Tenant authority, required role, exact scope, or fresh purpose-bound step-up is missing.","example":null},{"status":404,"description":"The tenant or selected tenant-owned resource does not exist in the administrator boundary.","example":null},{"status":409,"description":"The expected version, lifecycle, uniqueness, dependency, active publication, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Schema, domain, entitlement, configuration, retention, lockout, or platform policy rejected the request.","example":null},{"status":503,"description":"Tenant configuration, Identity, policy, verification, publication, or evidence ownership is unavailable; state remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Grant, revise, suspend, or expire one tenant entitlement through a draft revision.","whenToUse":"Do not call this planning route yet. It reserves versioned enablement, disablement, limits, or expiry for one catalog-defined product entitlement.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["tenant branding","custom-domain lifecycle","entitlement management","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with admin:tenants:write authority and the required tenant, workspace, and role context.","tenant administration authority","domain ownership or entitlement evidence where applicable"],"agentGuidance":["Never change live configuration outside the revision and review workflow.","Separate presentation-safe brand data from secret or infrastructure configuration.","An entitlement is product availability policy, not a bearer scope, role, credential, billing settlement, domain authority, infrastructure allocation, or trading permission.","TRADING, matching, prediction-market execution, ingress, publisher, market status, and traffic remain frozen and cannot be enabled through this contract.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Billing Operations","Identity & Login"]}},{"id":"get-api-v2-me-active-workspace","method":"GET","path":"/api/v2/me/active-workspace","title":"WORKSPACE: Get Active Workspace","description":"WORKSPACE: Get Active Workspace through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/workspaces/active","operation":"WORKSPACE: Get Active Workspace"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1me~1active-workspace/get","scope":"workspaces:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Active Workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Get Active Workspace through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get active workspace before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-me-active-workspace","method":"POST","path":"/api/v2/me/active-workspace","title":"WORKSPACE: Set Active Workspace","description":"WORKSPACE: Set Active Workspace through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/activate","operation":"WORKSPACE: Set Active Workspace"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-me-active-workspace","scope":"workspaces:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set Active Workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy workspace compatibility marker; use the canonical implemented workspace lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Set Active Workspace through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless 501 compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. It cannot select a workspace, invite or refer a user, revoke membership, or change a role.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Use implemented PUT /api/v2/me/active-workspace with its exact workspace_uuid body and optimistic membership checks.","Verify the implemented replacement in live OpenAPI and do not translate the legacy body field-for-field.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspace-invitations-acceptance","method":"POST","path":"/api/v2/workspace-invitations/acceptance","title":"WORKSPACE: Accept Workspace Invitation","description":"WORKSPACE: Accept Workspace Invitation through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/workspaces/accept/XXXXXXX","operation":"WORKSPACE: Accept Workspace Invitation"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspace-invitations~1acceptance/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Accept Workspace Invitation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspace-invitations-acceptance-request-001"},{"name":"token","location":"body","required":true,"type":"one-time invitation token","description":"Opaque token delivered to the invited email address.","example":"token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"WORKSPACE: Accept Workspace Invitation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to accept workspace invitation.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-workspaces","method":"GET","path":"/api/v2/workspaces","title":"WORKSPACE: Get Available Workspaces","description":"WORKSPACE: Get Available Workspaces through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/workspaces/all","operation":"WORKSPACE: Get Available Workspaces"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces/get","scope":"workspaces:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Available Workspaces"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Get Available Workspaces through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get available workspaces before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces","method":"POST","path":"/api/v2/workspaces","title":"WORKSPACE: Create new Workspace","description":"WORKSPACE: Create new Workspace through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/create","operation":"WORKSPACE: Create new Workspace"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create new Workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-request-001"},{"name":"name","location":"body","required":true,"type":"string · 1–160","description":"Human-readable workspace name.","example":"name-01"},{"name":"purpose","location":"body","required":false,"type":"PERSONAL | TEAM | TREASURY | TRADING | CONTRACTS","description":"Workspace operating purpose; defaults to TEAM.","example":"purpose-01"},{"name":"isolation_policy","location":"body","required":false,"type":"STANDARD | SEGREGATED | MPC","description":"Workspace isolation boundary; defaults to STANDARD.","example":"isolation-policy-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"WORKSPACE: Create new Workspace through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create new workspace.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-workspaces-id-custody-ceremonies","method":"GET","path":"/api/v2/workspaces/{id}/custody-ceremonies","title":"WORKSPACE: Get Workspace Seed","description":"WORKSPACE: Get Workspace Seed through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["dark-mesh"],"applications":["Wallets","Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/workspaces/seed","operation":"WORKSPACE: Get Workspace Seed"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-workspaces-id-custody-ceremonies","scope":"workspaces:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Workspace Seed"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"id","location":"path","required":true,"type":"identifier","description":"Canonical id.","example":"id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Get Workspace Seed through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get workspace seed before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","workspace onboarding","team membership lifecycle"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control","Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-id-custody-ceremonies","method":"POST","path":"/api/v2/workspaces/{id}/custody-ceremonies","title":"WORKSPACE: Secure new Workspace","description":"WORKSPACE: Secure new Workspace through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["dark-mesh"],"applications":["Wallets","Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/secure","operation":"WORKSPACE: Secure new Workspace"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-workspaces-id-custody-ceremonies","scope":"workspaces:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Secure new Workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-id-custody-ceremonies-request-001"},{"name":"id","location":"path","required":true,"type":"identifier","description":"Canonical id.","example":"id-01"},{"name":"network_id","location":"body","required":true,"type":"supported network identifier","description":"Network for the future custody wallet; it must match the authenticated workspace policy.","example":"hybrid-testnet"},{"name":"purpose","location":"body","required":true,"type":"TREASURY | SETTLEMENT | APPLICATION | RECOVERY","description":"Purpose selecting the server-owned custody, participant, threshold, and recovery policy.","example":"TREASURY"},{"name":"wallet_label","location":"body","required":true,"type":"string · 2–160","description":"Workspace-visible wallet label; it is presentation metadata and never an authority identifier.","example":"Primary treasury"},{"name":"policy_profile","location":"body","required":true,"type":"approved custody-policy code","description":"Server-owned policy profile freshly resolved for this workspace and network; callers do not submit threshold participants or key material.","example":"MPC_STANDARD_3_OF_5"},{"name":"recovery_policy","location":"body","required":true,"type":"approved recovery-policy code","description":"Pre-reviewed recovery posture; it cannot bypass participant, delay, approval, or evidence controls.","example":"GOVERNED_RECOVERY_V1"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh CUSTODY_CEREMONY_CREATION authorization bound to workspace, network, purpose, and policies.","example":"hcsu_…"}],"responses":[{"status":201,"description":"When promoted, a PREPARED custody ceremony with immutable workspace, network, purpose, participant-policy, threshold-policy, and recovery-policy commitments is returned; no wallet is active and no key material is disclosed.","example":null},{"status":200,"description":"The same Idempotency-Key and equivalent logical ceremony are replayed without creating another ceremony.","example":null},{"status":400,"description":"The network, purpose, label, policy, recovery policy, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks workspaces:write, custody administration, or fresh CUSTODY_CEREMONY_CREATION authorization.","example":null},{"status":404,"description":"The workspace or requested server-owned policy profile does not exist in the authenticated boundary.","example":null},{"status":409,"description":"Workspace, network, policy, active-ceremony, or Idempotency-Key state conflicts.","example":null},{"status":422,"description":"Purpose, custody, participant-domain, threshold, recovery, compliance, or network policy rejected preparation.","example":null},{"status":503,"description":"Workspace, Dark Mesh, custody policy, participant registry, or evidence ownership is unavailable; no ceremony is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"WORKSPACE: Secure new Workspace through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this planning route yet. It reserves preparation of one workspace- and network-bound custody ceremony under a server-owned participant, threshold, recovery, and evidence policy.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would create PREPARED ceremony commitments only; it would not return a seed, derive or activate a wallet, distribute shares, authorize signing, move value, or expose participant secrets.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","workspace onboarding","team membership lifecycle"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","The bearer and path identify the workspace. The service resolves participant identities, distinct operator domains, threshold, algorithms, attestation, and recovery controls from the approved policy profile.","Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password files, operator credentials, or caller-selected participant public keys.","PREPARED, ENROLLING, ATTESTED, ACTIVATION_REQUIRED, and ACTIVE are distinct. Re-read ceremony evidence and wallet state before describing readiness.","Promotion requires workspaces:write, CUSTODY_CEREMONY_CREATION step-up, RFC 9421 signing, network and policy isolation, participant-domain diversity, threshold conformance, idempotency, immutable evidence, timeout cleanup, and no-key-material response tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control","Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-workspaces-workspace-id","method":"GET","path":"/api/v2/workspaces/{workspace_id}","title":"WORKSPACE: Get Workspace Details","description":"WORKSPACE: Get Workspace Details through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/workspaces/details","operation":"WORKSPACE: Get Workspace Details"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}/get","scope":"workspaces:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Workspace Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Get Workspace Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get workspace details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-workspace-id-invitations","method":"POST","path":"/api/v2/workspaces/{workspace_id}/invitations","title":"WORKSPACE: Invite User to Workspace","description":"WORKSPACE: Invite User to Workspace through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-service","identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/invite","operation":"WORKSPACE: Invite User to Workspace"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1invitations/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Invite User to Workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-workspace-id-invitations-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"email","location":"body","required":true,"type":"email address · max 254","description":"Existing or prospective member email address.","example":"email-01"},{"name":"role","location":"body","required":false,"type":"ADMIN | MEMBER | AUDITOR","description":"Role granted when the invitation is accepted; defaults to MEMBER. OWNER cannot be invited.","example":"role-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"WORKSPACE: Invite User to Workspace through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to invite user to workspace.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-workspace-id-members-membership-id","method":"POST","path":"/api/v2/workspaces/{workspace_id}/members/{membership_id}","title":"WORKSPACE: Revoke Workspace Invitation","description":"WORKSPACE: Revoke Workspace Invitation through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/revoke","operation":"WORKSPACE: Revoke Workspace Invitation"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-workspaces-workspace-id-members-membership-id","scope":"workspaces:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke Workspace Invitation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"membership_id","location":"path","required":true,"type":"identifier","description":"Canonical membership id.","example":"membership-id-01"}],"responses":[{"status":501,"description":"Non-executable legacy workspace compatibility marker; use the canonical implemented workspace lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Revoke Workspace Invitation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless 501 compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. It cannot select a workspace, invite or refer a user, revoke membership, or change a role.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Use implemented DELETE /api/v2/workspaces/{workspace_id}/members/{membership_id}; membership revocation is not invitation revocation.","Verify the implemented replacement in live OpenAPI and do not translate the legacy body field-for-field.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-workspace-id-members-membership-id-role","method":"POST","path":"/api/v2/workspaces/{workspace_id}/members/{membership_id}/role","title":"WORKSPACE: Change Role of User","description":"WORKSPACE: Change Role of User through the canonical Hybrid-Chain V2 interface.","chapter":"Workspace Management","chapterOrder":3,"capability":"Workspace Management","owners":["identity-workspace"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/workspaces/role","operation":"WORKSPACE: Change Role of User"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-workspaces-workspace-id-members-membership-id-role","scope":"workspaces:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Change Role of User"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"membership_id","location":"path","required":true,"type":"identifier","description":"Canonical membership id.","example":"membership-id-01"}],"responses":[{"status":501,"description":"Non-executable legacy workspace compatibility marker; use the canonical implemented workspace lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WORKSPACE: Change Role of User through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless 501 compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. It cannot select a workspace, invite or refer a user, revoke membership, or change a role.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Use implemented PUT /api/v2/workspaces/{workspace_id}/members/{membership_id}/role with current version and lockout protections.","Verify the implemented replacement in live OpenAPI and do not translate the legacy body field-for-field.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-ai-wallets","method":"GET","path":"/api/v2/ai-wallets","title":"AI WALLETS: List bindings","description":"List workspace-scoped AI agent bindings and their lifecycle, capability, policy, and budget posture.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List bindings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"state","location":"query","required":false,"type":"ACTIVE | PAUSED | REVOKED","description":"Optional lifecycle filter.","example":"state-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum bindings to return.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"List workspace-scoped AI agent bindings and their lifecycle, capability, policy, and budget posture.","whenToUse":"Use this operation when an integration needs to list bindings before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets","method":"POST","path":"/api/v2/ai-wallets","title":"AI WALLETS: Create binding","description":"Assign one Signed Workload Identity to an active purpose-built AI operational MPC wallet with an explicit least-privilege capability and budget policy; primary treasury binding is forbidden.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets","scope":"ai-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-request-001"},{"name":"workload_client_id","location":"body","required":true,"type":"hcwc_ identifier","description":"Registered active Signed Workload Identity.","example":"workload-client-id-01"},{"name":"operational_wallet_uuid","location":"body","required":true,"type":"32-character identifier","description":"Active purpose-built AI_OPERATIONAL MPC wallet in the authenticated workspace and network.","example":"operational-wallet-uuid-01"},{"name":"agent_label","location":"body","required":true,"type":"string · 1–120","description":"Human-readable agent assignment label.","example":"agent-label-01"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Exact network context; must match the authenticated workload and operational wallet.","example":"network-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Assign one Signed Workload Identity to an active purpose-built AI operational MPC wallet with an explicit least-privilege capability and budget policy; primary treasury binding is forbidden.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create binding.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id","method":"GET","path":"/api/v2/ai-wallets/{binding_id}","title":"AI WALLETS: Get binding","description":"Return one workspace-scoped AI wallet binding and its current policy and budget summary.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return one workspace-scoped AI wallet binding and its current policy and budget summary.","whenToUse":"Use this operation when an integration needs to get binding before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-activity","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/activity","title":"AI WALLETS: List activity","description":"List append-only binding, policy, and intent decisions with retained policy-version evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1activity/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List activity"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum events to return.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"List append-only binding, policy, and intent decisions with retained policy-version evidence.","whenToUse":"Use this operation when an integration needs to list activity before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-approvals","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/approvals","title":"AI WALLETS: List transaction reviews","description":"List retained transaction review records, explicit readiness gates, and non-execution evidence without exposing an approval mutation.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1approvals/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List transaction reviews"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"List retained transaction review records, explicit readiness gates, and non-execution evidence without exposing an approval mutation.","whenToUse":"Use this operation when an integration needs to list transaction reviews before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-approvals-approval-id","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/approvals/{approval_id}","title":"AI WALLETS: Get transaction review","description":"Return one immutable transaction review record, its digests, simulation posture, readiness gate, MPC progress, and any broadcast evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1approvals~1{approval_id}/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get transaction review"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"approval_id","location":"path","required":true,"type":"identifier","description":"Canonical approval id.","example":"approval-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return one immutable transaction review record, its digests, simulation posture, readiness gate, MPC progress, and any broadcast evidence.","whenToUse":"Use this operation when an integration needs to get transaction review before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-budget","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/budget","title":"AI WALLETS: Get budget","description":"Return daily and monthly limits, reservations, and remaining capacity as decimal strings.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1budget/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get budget"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return daily and monthly limits, reservations, and remaining capacity as decimal strings.","whenToUse":"Use this operation when an integration needs to get budget before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-execution-mode","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/execution-mode","title":"AI WALLETS: Get execution mode","description":"Return the persisted execution mode and every unmet autonomy gate; this read never creates or changes authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1execution-mode/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get execution mode"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return the persisted execution mode and every unmet autonomy gate; this read never creates or changes authority.","whenToUse":"Use this operation when an integration needs to get execution mode before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations","Contract Studio","Barriers"]}},{"id":"post-api-v2-ai-wallets-binding-id-intent-evaluations","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/intent-evaluations","title":"AI WALLETS: Dry-run policy evaluation","description":"Evaluate a typed native-asset action without creating an intent, reservation, event, transaction, signature, approval, or broadcast.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1intent-evaluations/post","scope":"ai-wallets:evaluate","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Dry-run policy evaluation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:evaluate authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"type","location":"body","required":true,"type":"TRANSFER | TRADE | CONTRACT_CALL | RECURRING_PAYMENT","description":"Typed action mapped to one least-privilege wallet capability.","example":"type-01"},{"name":"asset","location":"body","required":true,"type":"uppercase native asset code · 2–24","description":"Asset resolved against one exact committed budget envelope.","example":"asset-01"},{"name":"amount","location":"body","required":true,"type":"positive decimal string","description":"Native-unit amount; floating-point JSON numbers and exponent notation are rejected.","example":"10.00"},{"name":"destination","location":"body","required":true,"type":"object","description":"Exact destination namespace and identifier checked against the committed allowlist.","example":{}},{"name":"rationale","location":"body","required":false,"type":"structured rationale object","description":"Optional explanation for the dry run; no intent or evidence is retained.","example":{}},{"name":"purpose","location":"body","required":false,"type":"string","description":"Optional concise purpose used when rationale is omitted.","example":"purpose-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Evaluate a typed native-asset action without creating an intent, reservation, event, transaction, signature, approval, or broadcast.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to dry-run policy evaluation.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:evaluate authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-intents","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/intents","title":"AI WALLETS: List intents","description":"List workspace- and binding-scoped AI action intents and their retained decisions.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1intents/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List intents"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"state","location":"query","required":false,"type":"DENIED | PENDING_APPROVAL | AUTHORIZED | CANCELLED | SETTLED","description":"Optional decision or lifecycle filter.","example":"state-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum intents to return.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"List workspace- and binding-scoped AI action intents and their retained decisions.","whenToUse":"Use this operation when an integration needs to list intents before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets-binding-id-intents","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/intents","title":"AI WALLETS: Evaluate intent","description":"Evaluate a typed AI action against current capabilities, allowlists, budget, velocity, and approval policy.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets-binding-id-intents","scope":"ai-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Evaluate intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-binding-id-intents-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"capability","location":"body","required":true,"type":"TRANSFER | SWAP | CONTRACT_CALL | PAYMENT","description":"Requested typed action.","example":"capability-01"},{"name":"asset","location":"body","required":true,"type":"asset symbol · 1–32","description":"Asset checked against the policy allowlist.","example":"asset-01"},{"name":"amount","location":"body","required":true,"type":"positive decimal string","description":"Policy and budget amount; floating-point JSON numbers are rejected.","example":"10.00"},{"name":"destination","location":"body","required":false,"type":"string · max 255","description":"Destination checked against the policy allowlist when required.","example":"destination-01"},{"name":"external_reference","location":"body","required":true,"type":"string · 1–255","description":"Caller-stable business reference.","example":"external-reference-01"},{"name":"metadata","location":"body","required":false,"type":"object","description":"Non-authoritative attribution metadata; secrets are forbidden.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Evaluate a typed AI action against current capabilities, allowlists, budget, velocity, and approval policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to evaluate intent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-intents-intent-id","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/intents/{intent_id}","title":"AI WALLETS: Get intent","description":"Return one exact retained intent, decision, reason-code set, and policy version.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1intents~1{intent_id}/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"intent_id","location":"path","required":true,"type":"identifier","description":"Canonical intent id.","example":"intent-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return one exact retained intent, decision, reason-code set, and policy version.","whenToUse":"Use this operation when an integration needs to get intent before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets-binding-id-intents-intent-id-cancel","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/intents/{intent_id}/cancel","title":"AI WALLETS: Cancel intent","description":"Cancel an eligible pending intent and release its reserved budget without signing or broadcasting.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets-binding-id-intents-intent-id-cancel","scope":"ai-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Cancel intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-binding-id-intents-intent-id-cancel-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"intent_id","location":"path","required":true,"type":"identifier","description":"Canonical intent id.","example":"intent-id-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Audit rationale for cancellation.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Cancel an eligible pending intent and release its reserved budget without signing or broadcasting.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel intent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets-binding-id-pause","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/pause","title":"AI WALLETS: Pause binding","description":"Fail closed by pausing new intent authorization while retaining binding and audit evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets-binding-id-pause","scope":"ai-wallets:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Pause binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-binding-id-pause-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Audit rationale for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Fail closed by pausing new intent authorization while retaining binding and audit evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to pause binding.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:govern authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-policies","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/policies","title":"AI WALLETS: List policy history","description":"Return retained policy versions and commitments so an integrator can reconstruct the authority contract governing any historical decision.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1policies/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List policy history"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return retained policy versions and commitments so an integrator can reconstruct the authority contract governing any historical decision.","whenToUse":"Use this operation when an integration needs to list policy history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-ai-wallets-binding-id-policy","method":"GET","path":"/api/v2/ai-wallets/{binding_id}/policy","title":"AI WALLETS: Get policy","description":"Return the complete versioned capability, allowlist, budget, velocity, and approval policy.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1ai-wallets~1{binding_id}~1policy/get","scope":"ai-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return the complete versioned capability, allowlist, budget, velocity, and approval policy.","whenToUse":"Use this operation when an integration needs to get policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"put-api-v2-ai-wallets-binding-id-policy","method":"PUT","path":"/api/v2/ai-wallets/{binding_id}/policy","title":"AI WALLETS: Replace policy","description":"Replace the complete policy through optimistic concurrency; omitted controls fail closed.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#put-api-v2-ai-wallets-binding-id-policy","scope":"ai-wallets:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Replace policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-ai-wallets-binding-id-policy-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"version","location":"body","required":true,"type":"integer · ≥1","description":"Current policy version for optimistic concurrency.","example":1},{"name":"policy","location":"body","required":true,"type":"AI wallet policy object","description":"Complete replacement policy; omitted controls fail closed.","example":{}}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Replace the complete policy through optimistic concurrency; omitted controls fail closed.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to replace policy.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:govern authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets-binding-id-resume","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/resume","title":"AI WALLETS: Resume binding","description":"Resume intent evaluation under the binding's current versioned policy without widening authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets-binding-id-resume","scope":"ai-wallets:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Resume binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-binding-id-resume-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Audit rationale for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Resume intent evaluation under the binding's current versioned policy without widening authority.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to resume binding.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:govern authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"post-api-v2-ai-wallets-binding-id-revoke","method":"POST","path":"/api/v2/ai-wallets/{binding_id}/revoke","title":"AI WALLETS: Revoke binding","description":"Permanently revoke an AI wallet binding while retaining policy, intent, and audit evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"AI wallet control","owners":["core-ai-wallet-control"],"applications":["Wallets","AI Wallet Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-ai-wallets-binding-id-revoke","scope":"ai-wallets:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ai-wallets:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-ai-wallets-binding-id-revoke-request-001"},{"name":"binding_id","location":"path","required":true,"type":"identifier","description":"Canonical binding id.","example":"binding-id-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Audit rationale for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","The gateway derives profile and workspace context from the authenticated principal; clients cannot supply or override either boundary.","Policy evaluation is fail-closed. An accepted intent is a reserved authorization record, never a signature or broadcast transaction.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Permanently revoke an AI wallet binding while retaining policy, intent, and audit evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke binding.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with ai-wallets:govern authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-wallets","method":"GET","path":"/api/v2/wallets","title":"WALLETS: List wallets","description":"List custody wallets, activation posture, balances, network addresses, and policy state.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallets","scope":"wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List custody wallets, activation posture, balances, network addresses, and policy state.","whenToUse":"Use this operation when an integration needs to list wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets","method":"POST","path":"/api/v2/wallets","title":"WALLETS: Create wallet","description":"Create an MPC wallet draft with explicit network, participant, threshold, and recovery policy.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-request-001"},{"name":"name","location":"body","required":true,"type":"string · 1–160","description":"Human-readable wallet label.","example":"name-01"},{"name":"network_id","location":"body","required":true,"type":"identifier","description":"Target network.","example":"network-id-01"},{"name":"participant_ids","location":"body","required":true,"type":"identifier[]","description":"Distinct MPC participants.","example":[]},{"name":"threshold","location":"body","required":true,"type":"integer","description":"Minimum participant signatures.","example":1},{"name":"recovery_policy","location":"body","required":true,"type":"object","description":"Timelock and recovery-authority policy.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an MPC wallet draft with explicit network, participant, threshold, and recovery policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-wallet-uuid","method":"GET","path":"/api/v2/wallets/{wallet_uuid}","title":"WALLETS: Get wallet","description":"Return one wallet's public custody projection without exposing shares, seeds, nonces, or private key material.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallets-wallet-uuid","scope":"wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one wallet's public custody projection without exposing shares, seeds, nonces, or private key material.","whenToUse":"Use this operation when an integration needs to get wallet before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"patch-api-v2-wallets-wallet-uuid","method":"PATCH","path":"/api/v2/wallets/{wallet_uuid}","title":"WALLETS: Update wallet policy","description":"Update eligible wallet labels, approved-address policy, or recovery settings through the custody boundary.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-wallets-wallet-uuid","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update wallet policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-wallets-wallet-uuid-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current wallet-policy version used for optimistic concurrency.","example":4},{"name":"label","location":"body","required":false,"type":"string · 2–160","description":"Replacement workspace-visible label; omitted leaves it unchanged.","example":"Primary treasury"},{"name":"approved_address_policy","location":"body","required":false,"type":"approved policy object","description":"Bounded destination-approval controls; cannot weaken network, step-up, delay, screening, or evidence policy.","example":{"approval_quorum":2,"mode":"ALLOWLIST_ONLY"}},{"name":"recovery_policy","location":"body","required":false,"type":"approved recovery-policy code","description":"Replacement pre-reviewed recovery posture; omitted leaves it unchanged.","example":"GOVERNED_RECOVERY_V1"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Substantive non-secret operator reason retained with the policy revision.","example":"Increase destination approval quorum."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh WALLET_POLICY_UPDATE authorization bound to wallet and expected version.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, eligible presentation and policy fields are revised atomically and the new version and policy commitment are returned; wallet keys, balances, activation, and pending transfers remain unchanged.","example":null},{"status":400,"description":"The version, change set, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks wallets:write, wallet policy authority, or fresh WALLET_POLICY_UPDATE authorization.","example":null},{"status":404,"description":"The wallet does not exist in the authenticated workspace and network boundary.","example":null},{"status":409,"description":"The wallet version is stale, a ceremony or transfer makes the policy transition unsafe, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Label, approved-address, recovery, threshold, compliance, lifecycle, or network policy rejected the change.","example":null},{"status":503,"description":"Custody, policy, Dark Mesh, screening, or evidence ownership is unavailable; wallet policy remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update eligible wallet labels, approved-address policy, or recovery settings through the custody boundary.","whenToUse":"Do not call this planning route yet. It reserves an optimistic-concurrency revision of eligible wallet presentation, approved-destination, or recovery policy without changing custody keys or value.","workflowRole":"revise","sideEffects":"No executable public mutation exists. A future success could replace admitted policy fields and append a revision commitment only; it could not rotate keys, change threshold participants, activate or revoke the wallet, alter balances, approve a destination, or authorize a transfer.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind expected_version and send at least one admitted change. Unknown fields, null-as-delete tricks, raw owner selectors, and attempts to weaken fixed network or custody invariants fail closed.","Policy changes affecting active approved destinations, recovery delays, or in-flight ceremonies and transfers require owner reconciliation while locked.","Never send seeds, private keys, MPC shares, signing nonces, passwords, encrypted password blobs, or recovery secret material.","Promotion requires wallets:write, WALLET_POLICY_UPDATE step-up, RFC 9421 signing, version locking, policy monotonicity and conflict tests, idempotency, immutable before/after commitments, and failure atomicity.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-activation-challenges","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/activation-challenges","title":"WALLETS: Create activation challenge","description":"Create a short-lived challenge binding the wallet, authenticated client, policy, and current key epoch.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-activation-challenges","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create activation challenge"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-activation-challenges-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"client_id","location":"body","required":true,"type":"identifier","description":"Client requesting activation.","example":"client-id-01"},{"name":"policy_hash","location":"body","required":true,"type":"sha256 digest","description":"Current wallet-policy commitment.","example":"policy-hash-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a short-lived challenge binding the wallet, authenticated client, policy, and current key epoch.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create activation challenge.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-activations","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/activations","title":"WALLETS: Activate wallet","description":"Complete an authorized threshold activation ceremony using a valid activation challenge.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-activations","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Activate wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-activations-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"challenge_id","location":"body","required":true,"type":"identifier","description":"Unexpired activation challenge.","example":"challenge-id-01"},{"name":"authorization","location":"body","required":true,"type":"threshold authorization object","description":"Participant approvals and proof bundle.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Complete an authorized threshold activation ceremony using a valid activation challenge.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to activate wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-wallet-uuid-approved-addresses","method":"GET","path":"/api/v2/wallets/{wallet_uuid}/approved-addresses","title":"WALLETS: List approved addresses","description":"List active and historical approved destination records.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallets-wallet-uuid-approved-addresses","scope":"wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List approved addresses"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List active and historical approved destination records.","whenToUse":"Use this operation when an integration needs to list approved addresses before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-approved-addresses","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/approved-addresses","title":"WALLETS: Approve address","description":"Submit a destination for governed wallet-address approval.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-approved-addresses","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Approve address"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-approved-addresses-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"address","location":"body","required":true,"type":"network address","description":"Destination address.","example":"address-01"},{"name":"network_id","location":"body","required":true,"type":"identifier","description":"Address network.","example":"network-id-01"},{"name":"label","location":"body","required":true,"type":"string","description":"Operator-readable destination label.","example":"label-01"},{"name":"evidence","location":"body","required":false,"type":"object","description":"Optional ownership or due-diligence evidence.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Submit a destination for governed wallet-address approval.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to approve address.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"delete-api-v2-wallets-wallet-uuid-approved-addresses-address-uuid","method":"DELETE","path":"/api/v2/wallets/{wallet_uuid}/approved-addresses/{address_uuid}","title":"WALLETS: Revoke approved address","description":"Revoke an approved destination while preserving audit evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-wallets-wallet-uuid-approved-addresses-address-uuid","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke approved address"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-wallets-wallet-uuid-approved-addresses-address-uuid-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"address_uuid","location":"path","required":true,"type":"identifier","description":"Canonical address uuid.","example":"address-uuid-01"},{"name":"expected_wallet_version","location":"body","required":true,"type":"integer · ≥1","description":"Current wallet-policy version used to prevent revocation against changed custody policy.","example":5},{"name":"expected_address_version","location":"body","required":true,"type":"integer · ≥1","description":"Current approved-address version used for optimistic concurrency.","example":2},{"name":"reason_code","location":"body","required":true,"type":"OWNER_REVOKED | COMPROMISE_SUSPECTED | DESTINATION_RETIRED | COMPLIANCE_HOLD","description":"Structured reason selecting delay, incident, screening, notification, and evidence policy.","example":"DESTINATION_RETIRED"},{"name":"reason_detail","location":"body","required":false,"type":"string · 8–500","description":"Optional safe explanation without credentials, private customer data, or signing material.","example":"Destination is no longer operated by the beneficiary."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh APPROVED_ADDRESS_REVOCATION authorization bound to wallet, destination, versions, and reason.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, the eligible approved destination is REVOKED, future transfer use is blocked, and immutable revocation evidence is returned; historical transfers remain intact.","example":null},{"status":400,"description":"The wallet version, address version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks wallets:write, destination authority, reason-specific compliance authority, or fresh APPROVED_ADDRESS_REVOCATION authorization.","example":null},{"status":404,"description":"The wallet or approved destination does not exist in the authenticated boundary.","example":null},{"status":409,"description":"A version is stale, revocation is already terminal, an in-flight transfer crossed its protection boundary, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Reason, delay, screening, incident, active-transfer, retention, or lifecycle policy rejected revocation.","example":null},{"status":503,"description":"Custody, transfer, screening, incident, or evidence ownership is unavailable; destination approval remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke an approved destination while preserving audit evidence.","whenToUse":"Do not call this planning route yet. It reserves evidence-preserving revocation of one approved destination after wallet policy, screening, incident posture, and in-flight transfers are reconciled.","workflowRole":"revoke-or-delete","sideEffects":"No executable public mutation exists. A future success would block new use and retain REVOKED history; it would not erase the destination, cancel or reverse a submitted transfer, change balances, revoke a wallet, or remove prior evidence.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind both wallet and address versions. COMPROMISE_SUSPECTED and COMPLIANCE_HOLD require their separately configured incident or compliance authority and may impose immediate deny plus retained investigation state.","Revocation and deletion are different. Historical transfer and approval records remain immutable; presentation may mask the address according to retention policy.","After an ambiguous response, re-read the approved-address record and affected transfer intents before retrying the same Idempotency-Key and body.","Promotion requires wallets:write, APPROVED_ADDRESS_REVOCATION step-up, RFC 9421 signing, version and transfer locking, reason-specific authority, deterministic delay behavior, idempotency, notifications, and immutable evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-wallet-uuid-signing-ceremonies","method":"GET","path":"/api/v2/wallets/{wallet_uuid}/signing-ceremonies","title":"WALLETS: List signing ceremonies","description":"List ceremony state and retained participant evidence for a wallet.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallets-wallet-uuid-signing-ceremonies","scope":"wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List signing ceremonies"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List ceremony state and retained participant evidence for a wallet.","whenToUse":"Use this operation when an integration needs to list signing ceremonies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-signing-ceremonies","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/signing-ceremonies","title":"WALLETS: Request signing ceremony","description":"Request a policy-bound threshold signing ceremony for an immutable transaction digest.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-signing-ceremonies","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Request signing ceremony"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-signing-ceremonies-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"transaction_digest","location":"body","required":true,"type":"sha256 digest","description":"Immutable transaction digest.","example":"transaction-digest-01"},{"name":"purpose","location":"body","required":true,"type":"string","description":"Human- and audit-readable signing purpose.","example":"purpose-01"},{"name":"expires_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Ceremony expiry.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request a policy-bound threshold signing ceremony for an immutable transaction digest.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request signing ceremony.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-transfer-estimates","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/transfer-estimates","title":"WALLETS: Estimate transfer","description":"Return a fee-aware, non-authorizing transfer estimate.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-transfer-estimates","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Estimate transfer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-transfer-estimates-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"destination","location":"body","required":true,"type":"network address","description":"Proposed destination.","example":"destination-01"},{"name":"asset","location":"body","required":true,"type":"asset identifier","description":"Transfer asset.","example":"asset-01"},{"name":"amount","location":"body","required":true,"type":"decimal string","description":"Positive base-unit-safe amount.","example":"10.00"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Return a fee-aware, non-authorizing transfer estimate.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to estimate transfer.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-wallet-uuid-transfer-intents","method":"POST","path":"/api/v2/wallets/{wallet_uuid}/transfer-intents","title":"WALLETS: Create transfer intent","description":"Create an unsigned transfer intent for subsequent policy and threshold authorization.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallets-wallet-uuid-transfer-intents","scope":"wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create transfer intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-wallet-uuid-transfer-intents-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"destination","location":"body","required":true,"type":"network address","description":"Approved destination.","example":"destination-01"},{"name":"asset","location":"body","required":true,"type":"asset identifier","description":"Transfer asset.","example":"asset-01"},{"name":"amount","location":"body","required":true,"type":"decimal string","description":"Positive base-unit-safe amount.","example":"10.00"},{"name":"estimate_id","location":"body","required":true,"type":"identifier","description":"Fresh fee estimate.","example":"estimate-id-01"},{"name":"purpose","location":"body","required":true,"type":"string","description":"Business purpose.","example":"purpose-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an unsigned transfer intent for subsequent policy and threshold authorization.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create transfer intent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-custom-asset-inspections","method":"POST","path":"/api/v2/wallets/custom-asset-inspections","title":"WALLETS: Inspect custom token","description":"Verify token metadata and catalog posture for one exact network-and-contract pair without changing wallet state.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/mpc-wallets/custom-assets/inspect","source":"APIRoutes.py · Handler_WalletPortfolio.handle_custom_asset_inspection · side-effect-free network-bound token inspection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1custom-asset-inspections/post","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Inspect custom token"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"network_id","location":"body","required":true,"type":"CAIP-2 network identifier","description":"Exact network selected from GET /api/v2/wallets/token-import-networks. It is never inferred from the contract address.","example":"eip155:1"},{"name":"contract_address","location":"body","required":true,"type":"20-byte hexadecimal EVM address","description":"Token contract on the selected network. The same address on another network identifies a different asset.","example":"0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Verify token metadata and catalog posture for one exact network-and-contract pair without changing wallet state.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to inspect custom token.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-custom-assets","method":"POST","path":"/api/v2/wallets/custom-assets","title":"WALLETS: Enable custom token","description":"Idempotently enable one inspected network-and-contract asset in the authenticated workspace's portfolio; this is metadata enablement, not wallet or value authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/mpc-wallets/custom-assets","source":"APIRoutes.py · Handler_WalletPortfolio.handle_custom_asset_import · signed idempotent owner-scoped token enablement"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1custom-assets/post","scope":"wallets:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Enable custom token"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-custom-assets-request-001"},{"name":"network_id","location":"body","required":true,"type":"CAIP-2 network identifier","description":"Exact network selected from GET /api/v2/wallets/token-import-networks. It is never inferred from the contract address.","example":"eip155:1"},{"name":"contract_address","location":"body","required":true,"type":"20-byte hexadecimal EVM address","description":"Previously inspected token contract on the selected network.","example":"0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"},{"name":"acknowledge_unapproved_token_risk","location":"body","required":false,"type":"boolean","description":"Must be true only when inspection reports the token is outside the reviewed catalog; reviewed assets do not require it.","example":false}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Idempotently enable one inspected network-and-contract asset in the authenticated workspace's portfolio; this is metadata enablement, not wallet or value authority.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to enable custom token.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-enrollments","method":"GET","path":"/api/v2/wallets/enrollments","title":"WALLETS: List network enrollment intents","description":"Return owner- and workspace-scoped MPC enrollment state for exactly one explicit Hybrid network without granting DKG, activation, signing, broadcast, or value authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/mpc-wallets/enrollments","source":"APIRoutes.py · enrollment reads · owner-scoped and explicit Hybrid network"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1enrollments/get","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List network enrollment intents"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return owner- and workspace-scoped MPC enrollment state for exactly one explicit Hybrid network without granting DKG, activation, signing, broadcast, or value authority.","whenToUse":"Use this operation when an integration needs to list network enrollment intents before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallets-enrollments","method":"POST","path":"/api/v2/wallets/enrollments","title":"WALLETS: Create network enrollment intent","description":"Create one idempotent owner- and workspace-bound enrollment intent on an explicit Hybrid network while keeping customer authorization, 7-of-13 DKG, and activation separate.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/mpc-wallets/enrollments","source":"APIRoutes.py · non-Mainnet enrollment intent creation · signed idempotent and non-authorizing"},{"catalog":"core","method":"POST","path":"/mpc-wallets/mainnet-enrollments","source":"APIRoutes.py · Mainnet BTC/ETH enrollment intent creation · signed idempotent and non-authorizing"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1enrollments/post","scope":"wallets:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create network enrollment intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-wallets-enrollments-request-001"},{"name":"network_id","location":"body","required":true,"type":"Hybrid control-plane network identifier","description":"Exact network: hybrid-devnet, hybrid-testnet, or hybrid-mainnet. It is never inferred from an asset or prior enrollment.","example":"hybrid-devnet"},{"name":"acknowledge_distributed_custody","location":"body","required":false,"type":"boolean","description":"Required true only for Mainnet to acknowledge the separate 7-of-13 distributed-custody ceremony.","example":false},{"name":"acknowledge_activation_is_separate","location":"body","required":false,"type":"boolean","description":"Required true only for Mainnet to acknowledge that enrollment does not activate deposits or withdrawals.","example":false}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create one idempotent owner- and workspace-bound enrollment intent on an explicit Hybrid network while keeping customer authorization, 7-of-13 DKG, and activation separate.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create network enrollment intent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-portfolio","method":"GET","path":"/api/v2/wallets/portfolio","title":"WALLETS: Get portfolio","description":"Return the authenticated workspace's MPC custody portfolio, chain-capability posture, token-import networks, reviewed token catalog, enabled assets, and recent activity without granting any wallet authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/mpc-wallets/portfolio","source":"APIRoutes.py · Handler_WalletPortfolio.handle_portfolio · signed workspace-scoped custody and token-catalog projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1portfolio/get","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get portfolio"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated workspace's MPC custody portfolio, chain-capability posture, token-import networks, reviewed token catalog, enabled assets, and recent activity without granting any wallet authority.","whenToUse":"Use this operation when an integration needs to get portfolio before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-token-catalog","method":"GET","path":"/api/v2/wallets/token-catalog","title":"WALLETS: List network token catalog","description":"Return reviewed and owner-enabled token assets for one mandatory explicit network without activating a wallet or granting signing, broadcast, trading, or value authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/mpc-wallets/portfolio","source":"Gateway network filter of Handler_WalletPortfolio asset_catalog · mandatory CAIP-2 selection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1token-catalog/get","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List network token catalog"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"network_id","location":"query","required":true,"type":"CAIP-2 network identifier","description":"Exact supported token network. Omission and unsupported networks fail closed.","example":"eip155:1"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return reviewed and owner-enabled token assets for one mandatory explicit network without activating a wallet or granting signing, broadcast, trading, or value authority.","whenToUse":"Use this operation when an integration needs to list network token catalog before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-token-catalog-releases","method":"GET","path":"/api/v2/wallets/token-catalog-releases","title":"WALLETS: Read network token catalog release proofs","description":"Return immutable release provenance, source hashes, and the aggregate catalog commitment for one mandatory explicit network without granting wallet or value authority.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/wallet-asset-catalog-releases","source":"APIRoutes.py · Handler_Explorer.handle_view_explorer_wallet_asset_catalog_releases · immutable network-scoped catalog provenance"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1token-catalog-releases/get","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read network token catalog release proofs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return immutable release provenance, source hashes, and the aggregate catalog commitment for one mandatory explicit network without granting wallet or value authority.","whenToUse":"Use this operation when an integration needs to read network token catalog release proofs before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallets-token-import-networks","method":"GET","path":"/api/v2/wallets/token-import-networks","title":"WALLETS: List token-import networks","description":"Return the exact CAIP-2 network choices currently accepted for custom-token inspection and import; clients must never infer a network from a contract address.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"MPC wallet lifecycle","owners":["custody-service"],"applications":["Wallets"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["custody-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/mpc-wallets/portfolio","source":"Gateway projection of Handler_WalletPortfolio token_import_networks · explicit CAIP-2 choices"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1wallets~1token-import-networks/get","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List token-import networks"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the exact CAIP-2 network choices currently accepted for custom-token inspection and import; clients must never infer a network from a contract address.","whenToUse":"Use this operation when an integration needs to list token-import networks before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-operational-wallets","method":"GET","path":"/api/v2/operational-wallets","title":"OPERATIONAL WALLETS: List wallets","description":"List purpose-built AI and merchant MPC wallets in the authenticated workspace and signed network context.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets/get","scope":"operational-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"network_id","location":"query","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Exact operational-wallet network boundary.","example":"hybrid-testnet"},{"name":"wallet_type","location":"query","required":false,"type":"AI_OPERATIONAL | MERCHANT_ROTATIONAL","description":"Optional purpose boundary.","example":"wallet-type-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"List purpose-built AI and merchant MPC wallets in the authenticated workspace and signed network context.","whenToUse":"Use this operation when an integration needs to list wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"post-api-v2-operational-wallets","method":"POST","path":"/api/v2/operational-wallets","title":"OPERATIONAL WALLETS: Create wallet","description":"Create a purpose-built AI or merchant operational wallet that requires an independent MPC enrollment and settles only to the same-context primary treasury.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets/post","scope":"operational-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-operational-wallets-request-001"},{"name":"wallet_type","location":"body","required":true,"type":"AI_OPERATIONAL | MERCHANT_ROTATIONAL","description":"Purpose boundary for the independently enrolled MPC wallet.","example":"wallet-type-01"},{"name":"label","location":"body","required":true,"type":"string · 2–120","description":"Human-readable operational wallet label.","example":"label-01"},{"name":"purpose_reference","location":"body","required":false,"type":"string · max 160","description":"Stable business or agent purpose reference; it grants no authority.","example":"purpose-reference-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Create a purpose-built AI or merchant operational wallet that requires an independent MPC enrollment and settles only to the same-context primary treasury.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"get-api-v2-operational-wallets-wallet-uuid","method":"GET","path":"/api/v2/operational-wallets/{wallet_uuid}","title":"OPERATIONAL WALLETS: Get wallet","description":"Return one purpose-built operational MPC wallet, its independent enrollment and activation posture, balance, and primary treasury settlement target.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1{wallet_uuid}/get","scope":"operational-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"network_id","location":"query","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Exact operational-wallet network boundary.","example":"hybrid-testnet"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return one purpose-built operational MPC wallet, its independent enrollment and activation posture, balance, and primary treasury settlement target.","whenToUse":"Use this operation when an integration needs to get wallet before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"post-api-v2-operational-wallets-wallet-uuid-pause","method":"POST","path":"/api/v2/operational-wallets/{wallet_uuid}/pause","title":"OPERATIONAL WALLETS: Pause wallet","description":"Pause new operational use while retaining the wallet, balance, settlement target, and audit evidence.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1{wallet_uuid}~1pause/post","scope":"operational-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Pause wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-operational-wallets-wallet-uuid-pause-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Meaningful retained audit reason for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Pause new operational use while retaining the wallet, balance, settlement target, and audit evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to pause wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"post-api-v2-operational-wallets-wallet-uuid-resume","method":"POST","path":"/api/v2/operational-wallets/{wallet_uuid}/resume","title":"OPERATIONAL WALLETS: Resume wallet","description":"Resume an independently activated operational wallet without changing its workspace, network, purpose, or settlement target.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1{wallet_uuid}~1resume/post","scope":"operational-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Resume wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-operational-wallets-wallet-uuid-resume-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Meaningful retained audit reason for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Resume an independently activated operational wallet without changing its workspace, network, purpose, or settlement target.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to resume wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"post-api-v2-operational-wallets-wallet-uuid-revoke","method":"POST","path":"/api/v2/operational-wallets/{wallet_uuid}/revoke","title":"OPERATIONAL WALLETS: Revoke wallet","description":"Permanently retire an operational wallet while retaining enrollment, activation, settlement, and event commitments.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1{wallet_uuid}~1revoke/post","scope":"operational-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-operational-wallets-wallet-uuid-revoke-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Meaningful retained audit reason for the lifecycle change.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Permanently retire an operational wallet while retaining enrollment, activation, settlement, and event commitments.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke wallet.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"post-api-v2-operational-wallets-wallet-uuid-settlements","method":"POST","path":"/api/v2/operational-wallets/{wallet_uuid}/settlements","title":"OPERATIONAL WALLETS: Request treasury settlement","description":"Create an idempotent settlement request from an active operational wallet to the immutable primary treasury in the same workspace and network.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1{wallet_uuid}~1settlements/post","scope":"operational-wallets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request treasury settlement"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-operational-wallets-wallet-uuid-settlements-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"amount","location":"body","required":true,"type":"positive decimal string","description":"Amount requested for settlement from this operational wallet.","example":"10.00"},{"name":"currency","location":"body","required":true,"type":"network-native asset","description":"Must match the wallet balance currency.","example":"currency-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–320","description":"Meaningful retained settlement rationale.","example":"reason-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Create an idempotent settlement request from an active operational wallet to the immutable primary treasury in the same workspace and network.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request treasury settlement.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["A bearer credential with operational-wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","Access Control","Automations","Payments","Digital Assets"]}},{"id":"get-api-v2-operational-wallets-summary","method":"GET","path":"/api/v2/operational-wallets/summary","title":"OPERATIONAL WALLETS: Get allocation summary","description":"Return primary, AI, merchant, deployed operational, and pending-settlement allocation for the authenticated workspace and network.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Operational MPC wallets","owners":["core-operational-wallets"],"applications":["Overview","Wallets","AI Wallet Control","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1operational-wallets~1summary/get","scope":"operational-wallets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get allocation summary"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing operational-wallets:read authority.","example":"Bearer hc_live_…"},{"name":"network_id","location":"query","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Exact operational-wallet network boundary.","example":"hybrid-testnet"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"The request or required headers are malformed.","example":null},{"status":404,"description":"The resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The request conflicts with wallet or binding state, policy version, or a prior idempotent operation.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Workspace and network context are derived from the authenticated principal and signed network assertion; callers cannot widen either boundary.","Each AI or merchant operational wallet has an independent MPC enrollment. The primary treasury cannot be assigned to an agent or merchant rotation.","Settlement is allowed only from an operational wallet to the immutable primary treasury in the same workspace and network.","Private key material, MPC shares, seeds, signing nonces, and participant secrets are never accepted or returned."]},"businessContext":{"purpose":"Return primary, AI, merchant, deployed operational, and pending-settlement allocation for the authenticated workspace and network.","whenToUse":"Use this operation when an integration needs to get allocation summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","wallet onboarding","portfolio and balance review","network-aware token discovery and enablement"],"prerequisites":["A bearer credential with operational-wallets:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Notifications","Trust Center","Governance","Funding","Access Control","Automations"]}},{"id":"get-api-v2-wallet","method":"GET","path":"/api/v2/wallet","title":"WALLET: Get Simplified Wallet Balances and Meta Data","description":"WALLET: Get Simplified Wallet Balances and Meta Data through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet","operation":"WALLET: Get Simplified Wallet Balances and Meta Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Simplified Wallet Balances and Meta Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get Simplified Wallet Balances and Meta Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get simplified wallet balances and meta data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-additional-deposit-options-link","method":"GET","path":"/api/v2/wallet/additional_deposit_options_link","title":"WALLET: Get Additional Funding Options Link","description":"WALLET: Get Additional Funding Options Link through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets","Funding"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/additional_deposit_options_link","operation":"WALLET: Get Additional Funding Options Link"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-additional-deposit-options-link","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Additional Funding Options Link"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get Additional Funding Options Link through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get additional funding options link before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","deposit monitoring","wallet funding-route preparation"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","AI Wallet Control","Payments","Indexer Controller"]}},{"id":"post-api-v2-wallet-addwallet","method":"POST","path":"/api/v2/wallet/addwallet","title":"WALLET: Whitelist a new External Wallet for Withdrawals","description":"WALLET: Whitelist a new External Wallet for Withdrawals through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/addwallet","operation":"WALLET: Whitelist a new External Wallet for Withdrawals"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-addwallet","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Whitelist a new External Wallet for Withdrawals"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Whitelist a new External Wallet for Withdrawals through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/wallets/{wallet_uuid}/approved-addresses for a governed destination approval only when it appears in live OpenAPI.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-deposit","method":"GET","path":"/api/v2/wallet/deposit","title":"WALLET: Get Crypto Deposit PubKeys","description":"WALLET: Get Crypto Deposit PubKeys through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets","Funding"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/deposit","operation":"WALLET: Get Crypto Deposit PubKeys"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-deposit","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Crypto Deposit PubKeys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get Crypto Deposit PubKeys through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get crypto deposit pubkeys before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","deposit monitoring","wallet funding-route preparation"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","AI Wallet Control","Payments","Indexer Controller"]}},{"id":"post-api-v2-wallet-estimate","method":"POST","path":"/api/v2/wallet/estimate","title":"WALLET: Estimate Transaction Fees","description":"WALLET: Estimate Transaction Fees through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/estimate","operation":"WALLET: Estimate Transaction Fees"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-estimate","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Estimate Transaction Fees"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Estimate Transaction Fees through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/wallets/{wallet_uuid}/transfer-estimates only when present in live OpenAPI; an estimate grants no transfer authority.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-ico-tokens","method":"GET","path":"/api/v2/wallet/ico_tokens","title":"WALLET: Get All Available ICO Tokens","description":"WALLET: Get All Available ICO Tokens through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/ico_tokens","operation":"WALLET: Get All Available ICO Tokens"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-ico-tokens","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Available ICO Tokens"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get All Available ICO Tokens through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all available ico tokens before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-invalidatersakey","method":"POST","path":"/api/v2/wallet/invalidatersakey","title":"WALLET: Remove Transit RSA Public Key","description":"WALLET: Remove Transit RSA Public Key through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["dark-mesh"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/invalidatersakey","operation":"WALLET: Remove Transit RSA Public Key"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-invalidatersakey","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Remove Transit RSA Public Key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Remove Transit RSA Public Key through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Legacy transit RSA keys are retired. Revoke or rotate a purpose-bound registered public signing or encryption key through its exact owning security lifecycle.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-master-password-seed-email-0","method":"GET","path":"/api/v2/wallet/master_password_seed&email=0","title":"WALLET: Get Master Password Seed","description":"WALLET: Get Master Password Seed through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/master_password_seed&email=0","operation":"WALLET: Get Master Password Seed"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-master-password-seed-email-0","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Master Password Seed"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get Master Password Seed through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get master password seed before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-removewallet","method":"POST","path":"/api/v2/wallet/removewallet","title":"WALLET: Remove External Crypto Wallet","description":"WALLET: Remove External Crypto Wallet through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/removewallet","operation":"WALLET: Remove External Crypto Wallet"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-removewallet","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Remove External Crypto Wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Remove External Crypto Wallet through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use the approved-address revocation lifecycle when present in live OpenAPI; do not delete historical destinations or transfer evidence.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-securesend","method":"POST","path":"/api/v2/wallet/securesend","title":"WALLET: Instantly Transfer Funds (Secure Send)","description":"WALLET: Instantly Transfer Funds (Secure Send) through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/securesend","operation":"WALLET: Instantly Transfer Funds (Secure Send)"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-securesend","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Instantly Transfer Funds (Secure Send)"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Instantly Transfer Funds (Secure Send) through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use a canonical transfer estimate followed by one transfer intent when both appear in live OpenAPI; no instant value-movement shortcut is executable.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-setmasterpassword","method":"POST","path":"/api/v2/wallet/setmasterpassword","title":"WALLET: Set Master Password","description":"WALLET: Set Master Password through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/setmasterpassword","operation":"WALLET: Set Master Password"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-setmasterpassword","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set Master Password"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Set Master Password through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","No wallet master-password mutation exists. Use Identity credential and purpose-bound custody authorization lifecycles without transmitting a password to custody.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-sign-payload","method":"POST","path":"/api/v2/wallet/sign_payload","title":"WALLET: Sign a Payload Message","description":"WALLET: Sign a Payload Message through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["dark-mesh"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/sign_payload","operation":"WALLET: Sign a Payload Message"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-sign-payload","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Sign a Payload Message"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Sign a Payload Message through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/wallets/{wallet_uuid}/signing-ceremonies only when present in live OpenAPI; arbitrary message signing is not exposed.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-swap","method":"POST","path":"/api/v2/wallet/swap","title":"WALLET: Swap/Convert Currencies","description":"WALLET: Swap/Convert Currencies through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/swap","operation":"WALLET: Swap/Convert Currencies"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-swap","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Swap/Convert Currencies"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Swap/Convert Currencies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","No canonical wallet swap mutation is executable. Asset conversion requires a separately owned quote, intent, policy, execution, and settlement lifecycle.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-transactions","method":"GET","path":"/api/v2/wallet/transactions","title":"WALLET: Get All Transactions","description":"WALLET: Get All Transactions through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/transactions","operation":"WALLET: Get All Transactions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-transactions","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Transactions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get All Transactions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all transactions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-transfer","method":"POST","path":"/api/v2/wallet/transfer","title":"WALLET: Transfer Liquidity between Wallets","description":"WALLET: Transfer Liquidity between Wallets through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets","Liquidity Management"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/transfer","operation":"WALLET: Transfer Liquidity between Wallets"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-transfer","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Transfer Liquidity between Wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Transfer Liquidity between Wallets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use a canonical transfer estimate and transfer intent only when present in live OpenAPI; transfer creation never accepts secrets or caller-authored balances.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-transitkey","method":"POST","path":"/api/v2/wallet/transitkey","title":"WALLET: Add new Transit RSA Public Key","description":"WALLET: Add new Transit RSA Public Key through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["dark-mesh"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/transitkey","operation":"WALLET: Add new Transit RSA Public Key"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-transitkey","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Add new Transit RSA Public Key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Add new Transit RSA Public Key through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Legacy transit RSA enrollment is retired. Register only purpose-bound public keys through the exact Identity, messaging, or custody owner contract.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-verifyaddress","method":"GET","path":"/api/v2/wallet/verifyaddress","title":"WALLET: Validate an External Wallet Address","description":"WALLET: Validate an External Wallet Address through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/verifyaddress","operation":"WALLET: Validate an External Wallet Address"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-verifyaddress","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Validate an External Wallet Address"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Validate an External Wallet Address through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to validate an external wallet address before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-verifyuser","method":"GET","path":"/api/v2/wallet/verifyuser","title":"WALLET: Validate a User's Email Address","description":"WALLET: Validate a User's Email Address through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/verifyuser","operation":"WALLET: Validate a User's Email Address"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-verifyuser","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Validate a User's Email Address"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Validate a User's Email Address through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to validate a user's email address before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-wallet-withdraw","method":"POST","path":"/api/v2/wallet/withdraw","title":"WALLET: Withdraw Crypto (to an External Wallet)","description":"WALLET: Withdraw Crypto (to an External Wallet) through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/wallet/withdraw","operation":"WALLET: Withdraw Crypto (to an External Wallet)"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-wallet-withdraw","scope":"wallets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Withdraw Crypto (to an External Wallet)"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Wallet compatibility marker; use the documented canonical custody lifecycle only when its exact operation appears in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Withdraw Crypto (to an External Wallet) through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a bodyless, non-executable compatibility marker retained to give legacy wallet integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot whitelist, revoke, estimate, sign, transfer, withdraw, swap, configure credentials, enroll keys, move value, or alter a wallet.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use a canonical transfer estimate and transfer intent to an active approved destination only when present in live OpenAPI.","Verify the exact canonical replacement in GET /api/v2/openapi.json before calling it. A planned registry profile remains non-executable documentation.","Do not translate legacy bodies field-for-field. Raw profile, wallet, address, account, or balance selectors; passwords; password hashes; seeds; private keys; MPC shares; signing nonces; and caller-authored fee or settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"get-api-v2-wallet-withdrawalwallets","method":"GET","path":"/api/v2/wallet/withdrawalwallets","title":"WALLET: Get all Whitelisted External Withdrawal Wallets","description":"WALLET: Get all Whitelisted External Withdrawal Wallets through the canonical Hybrid-Chain V2 interface.","chapter":"Vault / Wallet Functions","chapterOrder":4,"capability":"Vault / Wallet Functions","owners":["custody-ledger"],"applications":["Wallets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/wallet/withdrawalwallets","operation":"WALLET: Get all Whitelisted External Withdrawal Wallets"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-wallet-withdrawalwallets","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Whitelisted External Withdrawal Wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"WALLET: Get all Whitelisted External Withdrawal Wallets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all whitelisted external withdrawal wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control"]}},{"id":"post-api-v2-pay-get-payment-request-details","method":"POST","path":"/api/v2/pay/get_payment_request_details","title":"PAY: Get Payment Request Details","description":"PAY: Get Payment Request Details through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/get_payment_request_details","operation":"PAY: Get Payment Request Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-get-payment-request-details","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Payment Request Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PAY: Get Payment Request Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Use canonical payment-request reads when available; no exact detail route is executable yet, so do not post an identifier to a read-shaped legacy mutation.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-pay-get-payment-requests","method":"POST","path":"/api/v2/pay/get_payment_requests","title":"PAY: Get All Payment Requests","description":"PAY: Get All Payment Requests through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/get_payment_requests","operation":"PAY: Get All Payment Requests"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-get-payment-requests","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Payment Requests"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PAY: Get All Payment Requests through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Use implemented GET /api/v2/payment-requests with its owner-scoped direction, state, cursor, and limit parameters.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-pay-new-multi-payment","method":"POST","path":"/api/v2/pay/new_multi_payment","title":"PAY: Initiate a Mass-Multi-Currency Payment","description":"PAY: Initiate a Mass-Multi-Currency Payment through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/new_multi_payment","operation":"PAY: Initiate a Mass-Multi-Currency Payment"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-new-multi-payment","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Initiate a Mass-Multi-Currency Payment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PAY: Initiate a Mass-Multi-Currency Payment through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Use implemented POST /api/v2/payments once per exact payment intent. No bulk multi-currency payment mutation is executable; future batching requires explicit atomicity and per-item results.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-pay-new-payment-request","method":"POST","path":"/api/v2/pay/new_payment_request","title":"PAY: Create new Payment Request","description":"PAY: Create new Payment Request through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/new_payment_request","operation":"PAY: Create new Payment Request"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-new-payment-request","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create new Payment Request"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PAY: Create new Payment Request through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Use implemented POST /api/v2/payment-requests for one exact-decimal request with optional payer, expiry, memo, and reconciliation reference.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-pay-new-pix-payment-request","method":"POST","path":"/api/v2/pay/new_pix_payment_request","title":"Top-Up with PIX Payment System","description":"Top-Up with PIX Payment System through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/new_pix_payment_request","operation":"Top-Up with PIX Payment System"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-new-pix-payment-request","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Top-Up with PIX Payment System"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Top-Up with PIX Payment System through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","No canonical PIX funding or payment-request owner is executable yet. Do not infer availability from the retired legacy name.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-pay-pay-payment-request","method":"POST","path":"/api/v2/pay/pay_payment_request","title":"PAY: Pay Payment Request","description":"PAY: Pay Payment Request through the canonical Hybrid-Chain V2 interface.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payment Functions","owners":["payments-orchestrator"],"applications":["Payments"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/pay/pay_payment_request","operation":"PAY: Pay Payment Request"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-pay-pay-payment-request","scope":"payments:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Pay Payment Request"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PAY: Pay Payment Request through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Use implemented POST /api/v2/payment-requests/{request_uuid}/payments; it creates AUTHORIZATION_REQUIRED intent and never asserts reservation, submission, or settlement.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"get-api-v2-payment-requests","method":"GET","path":"/api/v2/payment-requests","title":"PAYMENTS: List payment requests","description":"List owner-visible incoming or outgoing exact-decimal payment requests, filter by lifecycle state, and distinguish OPEN requests from requests with an authorization-required intent.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/payment-requests","source":"APIRoutes.py · Handler_PaymentsV2.handle_payment_requests · signed workspace-scoped request projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payment-requests/get","scope":"payments:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List payment requests"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"32-character lowercase hexadecimal cursor","description":"Cursor returned by the preceding page; reuse only with identical state and direction filters.","example":"b4f2ed5fcfa7474d90f976a838670b14"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return; defaults to 50.","example":50},{"name":"state","location":"query","required":false,"type":"OPEN | PAYMENT_PENDING | SATISFIED | CANCELLED | EXPIRED","description":"Exact payment-request lifecycle filter.","example":"OPEN"},{"name":"direction","location":"query","required":false,"type":"incoming | outgoing | all","description":"Relationship to the authenticated workspace; defaults to all.","example":"all"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List owner-visible incoming or outgoing exact-decimal payment requests, filter by lifecycle state, and distinguish OPEN requests from requests with an authorization-required intent.","whenToUse":"Use this read to discover requests the authenticated workspace may pay, inspect requests it issued, or reconcile request status before creating or cancelling a linked intent.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-isolated projection. It does not accept a request, authorize a payer, reserve funds, create an intent, or establish settlement.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:read authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","incoming means the workspace is the named payer; outgoing means it is the payee that issued the request; all is their union.","OPEN is eligible for intent creation subject to visibility and expiry. PAYMENT_PENDING only means an AUTHORIZATION_REQUIRED intent is attached; it is not paid state.","Reuse next_cursor only with the same direction and state filters. Treat an expired presentation as ineligible even if historical stored state has not yet been materialized.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-payment-requests","method":"POST","path":"/api/v2/payment-requests","title":"PAYMENTS: Create payment request","description":"Create an owner-isolated exact-decimal request for a named payer workspace or a shareable request with an optional expiry and reconciliation reference.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/payment-requests","source":"APIRoutes.py · Handler_PaymentsV2.handle_payment_requests · signed idempotent exact-decimal request creation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payment-requests/post","scope":"payments:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create payment request"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-payment-requests-request-001"},{"name":"amount","location":"body","required":true,"type":"positive exact decimal string","description":"Requested amount with no more than 18 decimal places.","example":"125.50"},{"name":"currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Request denomination.","example":"USDC"},{"name":"payer_workspace_id","location":"body","required":false,"type":"workspace identifier","description":"Optional sole payer workspace; omit to make the request shareable.","example":"workspace-payer"},{"name":"memo","location":"body","required":false,"type":"string · max 500","description":"Payer-visible request context.","example":"Invoice 2026-0042"},{"name":"external_reference","location":"body","required":false,"type":"string · max 128","description":"Payee-owned reconciliation reference.","example":"invoice-2026-0042"},{"name":"expires_at","location":"body","required":false,"type":"future RFC 3339 timestamp · ≤365 days","description":"Optional request expiry.","example":"2026-12-31T23:59:59Z"}],"responses":[{"status":201,"description":"An OPEN exact-decimal payment request is returned with request and state commitments; no value is reserved or moved.","example":null},{"status":400,"description":"The body, request signature, or Idempotency-Key is missing or malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks payments:write or the RFC 9421 signature is invalid.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with a different logical request.","example":null},{"status":422,"description":"Amount, currency, payer, expiry, memo, or reconciliation policy rejected the request.","example":null},{"status":503,"description":"The Payments control plane is unavailable; no request is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an owner-isolated exact-decimal request for a named payer workspace or a shareable request with an optional expiry and reconciliation reference.","whenToUse":"Use this operation when the authenticated payee workspace needs a durable exact-decimal request that another workspace can discover and later bind to a payment intent.","workflowRole":"create-or-command","sideEffects":"Creates one OPEN request and immutable commitments. It does not reserve, debit, authorize, submit, settle, create an invoice, or change a balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Specify payer_workspace_id to restrict payment to one workspace, or omit it for a shareable request. Shareable does not mean public enumeration or payment authority.","Use external_reference for your own reconciliation key and memo only for safe recipient-visible context. Never place credentials, bank details, or private customer evidence in either field.","The response's false balance_mutation_performed and settlement_authority_granted values are normative safety signals.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-payment-requests-request-uuid-payments","method":"POST","path":"/api/v2/payment-requests/{request_uuid}/payments","title":"PAYMENTS: Create request-bound payment intent","description":"Atomically bind the latest OPEN request terms to an owner-safe source and record an AUTHORIZATION_REQUIRED intent without reserving funds or moving value.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/payment-requests/{request_uuid}/payments","source":"APIRoutes.py · Handler_PaymentsV2.handle_pay_payment_request · signed idempotent request-bound intent creation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payment-requests~1{request_uuid}~1payments/post","scope":"payments:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create request-bound payment intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-payment-requests-request-uuid-payments-request-001"},{"name":"request_uuid","location":"path","required":true,"type":"identifier","description":"Canonical request uuid.","example":"request-uuid-01"},{"name":"expected_request_version","location":"body","required":true,"type":"integer · ≥1","description":"Current payment-request version used for optimistic concurrency.","example":1},{"name":"expected_amount","location":"body","required":true,"type":"positive exact decimal string","description":"Exact amount last read from the request; partial or caller-repriced payment is forbidden.","example":"125.00"},{"name":"settlement_currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Exact currency copied from the latest payment-request read.","example":"USDC"},{"name":"payment_source_reference","location":"body","required":true,"type":"owner-safe funding or operational-wallet reference","description":"Opaque source resolved inside the Payments owner. Raw wallet UUIDs, account credentials, seeds, and private keys are forbidden.","example":"funding-source-01"},{"name":"payment_method","location":"body","required":true,"type":"INTERNAL_BALANCE | HYBRID_WALLET | APPROVED_RAIL","description":"Selected future authorization path. Recording the intent does not authorize, reserve, or submit through that method.","example":"HYBRID_WALLET"}],"responses":[{"status":201,"description":"An AUTHORIZATION_REQUIRED payment intent is returned with immutable request, source, amount, currency, method, and state commitments; no value is moved.","example":null},{"status":200,"description":"The same Idempotency-Key and byte-equivalent logical payment are replayed without creating another intent.","example":null},{"status":400,"description":"The version, amount, currency, source, method, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks payments:write, payer visibility, or a valid RFC 9421 signature.","example":null},{"status":404,"description":"The payment request or source does not exist in the authenticated owner and network boundary.","example":null},{"status":409,"description":"The request version, amount, currency, lifecycle, expiry, active-intent state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Payment method, source reference, exact-decimal terms, payer, payee, or request policy validation failed.","example":null},{"status":503,"description":"The Payments control plane is unavailable; no payment intent is created and no value is reserved.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically bind the latest OPEN request terms to an owner-safe source and record an AUTHORIZATION_REQUIRED intent without reserving funds or moving value.","whenToUse":"Use this operation after the payer workspace has re-read an incoming OPEN request and is ready to record which owner-safe source and method should enter a later authorization workflow.","workflowRole":"create-or-command","sideEffects":"Creates one AUTHORIZATION_REQUIRED intent, links it atomically, and moves the request to PAYMENT_PENDING. It does not reserve funds, sign, submit, broadcast, confirm, settle, fulfill, or mark the request paid.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Bind the latest request version, exact amount, and currency. Partial payment, repricing, overpayment, and destination substitution fail closed.","payment_source_reference is opaque operational context, not proof of ownership or balance. Never send passwords, seeds, private keys, MPC shares, signing nonces, banking credentials, or reusable authorization secrets.","A created intent requires future separately authorized source validation, compliance, reservation, signing/submission, confirmation, and settlement operations. Re-read both resources before reporting progress.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"get-api-v2-payments","method":"GET","path":"/api/v2/payments","title":"PAYMENTS: List payment intents","description":"List owner-visible incoming or outgoing payment intents and reconcile their explicit pre-settlement lifecycle and safety flags.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/payments","source":"APIRoutes.py · Handler_PaymentsV2.handle_payments · signed workspace-scoped intent projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payments/get","scope":"payments:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List payment intents"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"32-character lowercase hexadecimal cursor","description":"Cursor returned by the preceding page; reuse only with identical state and direction filters.","example":"b4f2ed5fcfa7474d90f976a838670b14"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return; defaults to 50.","example":50},{"name":"state","location":"query","required":false,"type":"uppercase payment lifecycle state","description":"Exact payment-intent lifecycle filter.","example":"AUTHORIZATION_REQUIRED"},{"name":"direction","location":"query","required":false,"type":"incoming | outgoing | all","description":"Relationship to the authenticated workspace; defaults to all.","example":"all"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List owner-visible incoming or outgoing payment intents and reconcile their explicit pre-settlement lifecycle and safety flags.","whenToUse":"Use this collection read to reconcile payment intents involving the authenticated workspace, drive accounts-payable or receivable queues, and select a record for a fresh detail read.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-isolated projection. It never authorizes, reserves, cancels, submits, confirms, settles, or changes a balance.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:read authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","AUTHORIZATION_REQUIRED means only that an intent was recorded. CANCELLED means this pre-authorization intent was stopped; neither state proves a rail or ledger event.","Use direction to distinguish payer-side outgoing intents from payee-side incoming intents. A workspace cannot enumerate unrelated payment activity.","Evaluate explicit safety flags rather than deriving authority from status labels, timestamps, notifications, or external references.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-payments","method":"POST","path":"/api/v2/payments","title":"PAYMENTS: Create direct payment intent","description":"Record one direct exact-decimal AUTHORIZATION_REQUIRED intent between workspaces without reserving, signing, submitting, confirming, or settling value.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/payments","source":"APIRoutes.py · Handler_PaymentsV2.handle_payments · signed idempotent direct intent creation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payments/post","scope":"payments:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create direct payment intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-payments-request-001"},{"name":"payee_workspace_id","location":"body","required":true,"type":"workspace identifier","description":"Recipient workspace; cannot equal the authenticated payer workspace.","example":"workspace-payee"},{"name":"payment_source_reference","location":"body","required":true,"type":"owner-safe funding or operational-wallet reference","description":"Opaque source reference resolved by Payments; never submit credentials or custody secrets.","example":"wallet-operating"},{"name":"payment_method","location":"body","required":true,"type":"INTERNAL_BALANCE | HYBRID_WALLET | APPROVED_RAIL","description":"Future authorization path; intent creation does not invoke it.","example":"HYBRID_WALLET"},{"name":"purpose_code","location":"body","required":true,"type":"uppercase identifier","description":"Structured accounting or compliance purpose.","example":"INVOICE"},{"name":"amount","location":"body","required":true,"type":"positive exact decimal string","description":"Positive amount with no more than 18 decimal places.","example":"125.50"},{"name":"currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Intent denomination.","example":"USDC"},{"name":"memo","location":"body","required":false,"type":"string · max 500","description":"Recipient-visible context.","example":"Invoice 2026-0042"},{"name":"external_reference","location":"body","required":false,"type":"string · max 128","description":"Caller-owned reconciliation reference.","example":"invoice-2026-0042"}],"responses":[{"status":201,"description":"An AUTHORIZATION_REQUIRED direct payment intent is returned with immutable commitments and explicit false value-movement flags.","example":null},{"status":400,"description":"The body, request signature, or Idempotency-Key is missing or malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks payments:write or the RFC 9421 signature is invalid.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with a different logical payment.","example":null},{"status":422,"description":"Payee, source reference, method, purpose, amount, currency, memo, or reconciliation policy rejected the intent.","example":null},{"status":503,"description":"The Payments control plane is unavailable; no intent is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record one direct exact-decimal AUTHORIZATION_REQUIRED intent between workspaces without reserving, signing, submitting, confirming, or settling value.","whenToUse":"Use this operation for a direct workspace-to-workspace payment intent when no payment request is needed and a later authorization workflow will validate the selected source and method.","workflowRole":"create-or-command","sideEffects":"Creates one AUTHORIZATION_REQUIRED intent and immutable commitments. It does not reserve, debit, sign, submit to a rail, confirm, settle, notify fulfillment, or alter balances.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","The authenticated workspace is always the payer; payee_workspace_id cannot select the same workspace. Source and method are declared intent inputs, not authorization or availability evidence.","Use exact decimal strings and an uppercase currency. purpose_code should map to your accounting or compliance workflow; external_reference is the caller's reconciliation key.","Future value movement requires a separate explicitly authorized operation. Do not describe HTTP 201 from this endpoint as payment execution.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"get-api-v2-payments-payment-uuid","method":"GET","path":"/api/v2/payments/{payment_uuid}","title":"PAYMENTS: Get payment intent","description":"Return one owner-visible payment intent with exact terms, commitments, version, cancellation evidence, and explicit non-settlement flags.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/payments/{payment_uuid}","source":"APIRoutes.py · Handler_PaymentsV2.handle_payments · signed owner-visible intent projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payments~1{payment_uuid}/get","scope":"payments:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get payment intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:read authority.","example":"Bearer hc_live_…"},{"name":"payment_uuid","location":"path","required":true,"type":"identifier","description":"Canonical payment uuid.","example":"payment-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one owner-visible payment intent with exact terms, commitments, version, cancellation evidence, and explicit non-settlement flags.","whenToUse":"Use this operation before cancellation, after any ambiguous mutation, or whenever an integration needs the latest version and commitments for one payer- or payee-visible intent.","workflowRole":"discover-or-read","sideEffects":"Read-only detail projection. It cannot grant authorization, reserve a source, contact a rail, reconcile a ledger, or change payment state.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:read authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","A 404 deliberately covers both absence and lack of workspace visibility.","Use version, status, request_commitment, and state_commitment for reconciliation. Never infer missing downstream states.","authorization_required, reservation_created, rail_submission_created, balance_mutation_performed, settlement_authority_granted, and reconciliation_required are explicit machine-readable interpretation boundaries.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"post-api-v2-payments-payment-uuid-cancellations","method":"POST","path":"/api/v2/payments/{payment_uuid}/cancellations","title":"PAYMENTS: Cancel payment intent","description":"Cancel an exact latest AUTHORIZATION_REQUIRED intent, retain cancellation evidence, and reopen an unexpired linked request without reversing value or rail activity.","chapter":"Payment Functions","chapterOrder":5,"capability":"Payments","owners":["payment-service"],"applications":["Payments"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["payments-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/payments/{payment_uuid}/cancellations","source":"APIRoutes.py · Handler_PaymentsV2.handle_payment_cancellation · signed idempotent pre-authorization cancellation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1payments~1{payment_uuid}~1cancellations/post","scope":"payments:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel payment intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing payments:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-payments-payment-uuid-cancellations-request-001"},{"name":"payment_uuid","location":"path","required":true,"type":"identifier","description":"Canonical payment uuid.","example":"payment-uuid-01"},{"name":"expected_payment_version","location":"body","required":true,"type":"integer · ≥1","description":"Current payment version used to prevent cancellation after another transition.","example":1},{"name":"expected_state","location":"body","required":true,"type":"AUTHORIZATION_REQUIRED","description":"Exact only cancellable state in this control-plane release.","example":"AUTHORIZATION_REQUIRED"},{"name":"reason_code","location":"body","required":true,"type":"OWNER_CANCELLED","description":"Exact owner-controlled cancellation reason. Administrative and machine-failure transitions require separate governed operations.","example":"OWNER_CANCELLED"}],"responses":[{"status":200,"description":"The exact AUTHORIZATION_REQUIRED intent becomes CANCELLED, evidence is retained, and any linked unexpired request returns to OPEN; no value is reversed.","example":null},{"status":400,"description":"The version, state, reason, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks payments:write, payer ownership, or a valid RFC 9421 signature.","example":null},{"status":404,"description":"The payment does not exist in the authenticated owner and network boundary.","example":null},{"status":409,"description":"The version or state is stale, the payment is not AUTHORIZATION_REQUIRED, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Cancellation reason or lifecycle policy rejected the request.","example":null},{"status":503,"description":"The Payments control plane is unavailable; payment and linked-request state remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an exact latest AUTHORIZATION_REQUIRED intent, retain cancellation evidence, and reopen an unexpired linked request without reversing value or rail activity.","whenToUse":"Use this operation only after re-reading an outgoing intent that remains exactly AUTHORIZATION_REQUIRED and deciding not to continue into a future value-moving authorization workflow.","workflowRole":"create-or-command","sideEffects":"Atomically records CANCELLED and immutable evidence. A linked unexpired request returns to OPEN; an expired request becomes EXPIRED. No reservation, rail event, ledger entry, refund, or balance reversal occurs.","businessCases":["direct payment intent creation","payment request issuance and collection","request-bound payer authorization","pre-submission cancellation","payment and rail status reconciliation","merchant and invoice payment evidence"],"prerequisites":["A bearer credential with payments:write authority and the required tenant, workspace, and role context.","payments:read or payments:write as named by the exact operation","the correct payer, payee, or request-owner workspace relationship","RFC 9421 request signing plus a stable Idempotency-Key for each implemented mutation","a caller-owned rule that treats control-plane intent state as distinct from reservation, rail, ledger, settlement, refund, and fulfillment state"],"agentGuidance":["Request creation, intent creation, authorization, reservation, submission, confirmation, settlement, refund, and fulfillment are distinct states; no state implies another.","Preserve every amount as an exact decimal string and bind dependent mutations to last-read versions, amounts, currencies, and commitments.","The current mutation surface records and cancels pre-authorization intent only. Every response explicitly says whether authorization is required and whether a reservation, rail submission, balance mutation, or settlement authority exists.","Never send raw wallet or account selectors, passwords, seeds, private keys, MPC shares, banking credentials, caller-authored paid flags, or settlement assertions.","After an ambiguous response, re-read the owner-scoped request and payment before retrying the same Idempotency-Key and byte-equivalent body.","Treat legacy /api/v2/pay/* mutations as bodyless 501 migration markers and use only canonical replacements present in live OpenAPI.","Bind expected_payment_version and expected_state=AUTHORIZATION_REQUIRED. A stale version or any other state returns conflict rather than guessing whether cancellation is safe.","Only the payer workspace can cancel. Payee visibility does not grant cancellation authority.","After an ambiguous response, re-read the payment and linked request before retrying the exact Idempotency-Key and body. Cancellation does not cancel an invoice, refund value, revoke a wallet, or reverse fulfillment.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","Commerce","Transfer Compliance"]}},{"id":"get-api-v2-commerce-invoices","method":"GET","path":"/api/v2/commerce/invoices","title":"COMMERCE: List invoices","description":"List merchant invoices and payment lifecycle state.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1invoices/get","scope":"commerce:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List invoices"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"merchant_uuid","location":"query","required":true,"type":"32-character merchant identifier","description":"Owning merchant whose invoices are listed.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"cursor","location":"query","required":false,"type":"32-character hexadecimal cursor","description":"Cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records; defaults to 50.","example":50},{"name":"status","location":"query","required":false,"type":"invoice lifecycle state","description":"Exact invoice state filter.","example":"ACTIVE"},{"name":"external_order_reference","location":"query","required":false,"type":"merchant reconciliation reference","description":"Exact merchant order reference.","example":"external-order-reference-01"}],"responses":[{"status":200,"description":"When promoted, the authenticated workspace receives the owner-scoped Commerce projection and page metadata under no-store; read state grants no checkout, payment, settlement, fulfillment, or authority transition.","example":null},{"status":400,"description":"A cursor, limit, filter, identifier, or timestamp boundary is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:read or access to the selected merchant boundary.","example":null},{"status":404,"description":"The selected owner-scoped Commerce resource does not exist.","example":null},{"status":422,"description":"The filter combination, lifecycle value, merchant binding, or time range is outside policy.","example":null},{"status":503,"description":"Commerce, catalog, invoice, checkout, wallet observation, or evidence ownership is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List merchant invoices and payment lifecycle state.","whenToUse":"List one merchant's invoices for operational queues and reconciliation without treating lifecycle labels as payment or fulfillment proof.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-scoped projection of invoices; it cannot activate a merchant, publish a product, create checkout, assert payment, settle a wallet, fulfill an order, move value, or grant authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Derive workspace and owner from the bearer and use only opaque identifiers returned by Commerce. Never enumerate another workspace or submit profile, tenant, vault, database, custody, or secret selectors.","Treat every lifecycle field as a projection of its own resource. Merchant activation, product availability, invoice payment, wallet observation, settlement, and fulfillment remain independent.","Page cursors are opaque and filter-bound. Exact decimal values remain strings; nullable lifecycle timestamps and evidence references must not be invented or coerced.","Re-fetch GET /api/v2/openapi.json before generating or releasing an integration so the client matches the deployed contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-invoices","method":"POST","path":"/api/v2/commerce/invoices","title":"COMMERCE: Create invoice","description":"Create a checkout-backed merchant invoice with customer, line items, settlement, and expiry terms.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1invoices/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create invoice"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-invoices-request-001"},{"name":"merchant_uuid","location":"body","required":true,"type":"workspace merchant identifier","description":"Merchant issuing the invoice and owning its checkout and settlement policy.","example":"merchant-01"},{"name":"external_order_reference","location":"body","required":false,"type":"merchant-unique string · max 128","description":"Optional merchant order reference used for reconciliation; it grants no payment or fulfillment authority.","example":"ORDER-2026-0042"},{"name":"customer","location":"body","required":true,"type":"data-minimized customer object","description":"Customer reference plus only the contact fields required by merchant policy. Government identifiers, payment credentials, and regulated evidence are forbidden.","example":{"email":"buyer@example.com","reference":"customer-2048"}},{"name":"line_items","location":"body","required":true,"type":"invoice line[] · 1–100","description":"Product reference, positive exact-decimal quantity, and optional description for each line. Commerce resolves current product price and computes every total.","example":[{"description":"Team seats","product_uuid":"product-01","quantity":"2"}]},{"name":"settlement_currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Settlement denomination selected from the merchant and product policies; it does not assert a conversion rate or payment.","example":"USD"},{"name":"expires_at","location":"body","required":false,"type":"future RFC 3339 timestamp","description":"Optional checkout expiry within merchant policy. Omission uses the merchant default.","example":"2026-09-02T18:00:00Z"},{"name":"customer_note","location":"body","required":false,"type":"string · max 500","description":"Optional presentation note without secrets, payment instructions, or regulated evidence.","example":"Thank you for your order."},{"name":"metadata","location":"body","required":false,"type":"bounded string map · max 20 entries","description":"Optional non-secret merchant reconciliation metadata.","example":{"sales_channel":"agent-assisted"}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh COMMERCE_INVOICE_CREATION authorization bound to merchant, customer reference, computed terms, currency, and expiry.","example":"hcsu_…"}],"responses":[{"status":201,"description":"An OPEN invoice with server-computed exact totals, a linked Payments V2 request, expiry, and immutable terms commitment is returned; it is not paid or fulfilled.","example":null},{"status":200,"description":"The same Idempotency-Key and equivalent invoice terms are replayed without creating another invoice or checkout capability.","example":null},{"status":400,"description":"The merchant, order reference, customer, line items, currency, expiry, note, metadata, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, merchant invoice authority, customer-data authority, or fresh COMMERCE_INVOICE_CREATION authorization.","example":null},{"status":404,"description":"The merchant or selected product does not exist in the authenticated workspace boundary.","example":null},{"status":409,"description":"Merchant, product, price, currency, external-order, checkout-capacity, or Idempotency-Key state conflicts.","example":null},{"status":422,"description":"Line-item quantity, price, currency, tax, customer minimization, expiry, checkout, rotational-wallet, compliance, or invoice policy rejected creation.","example":null},{"status":503,"description":"Commerce, catalog, checkout, rotational-wallet, Payments, or evidence ownership is unavailable; no invoice is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a checkout-backed merchant invoice with customer, line items, settlement, and expiry terms.","whenToUse":"Create one structured invoice after re-reading the ACTIVE merchant and every ACTIVE product, minimizing customer data, and selecting exact quantities, settlement currency, and optional expiry.","workflowRole":"create-or-command","sideEffects":"Atomically creates an OPEN invoice with server-computed totals and a shareable Payments V2 request. It does not assert payment, reserve customer funds, settle a wallet, fulfill an order, deliver an asset, calculate legal tax, or create a refund.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Send product references and exact-decimal quantities. Commerce re-reads products, prices, currencies, merchant policy, and computes subtotal, adjustments, tax posture, and total; caller-authored totals are forbidden.","Minimize customer data. Use an opaque customer reference and only policy-required delivery contacts; never send government identifiers, payment credentials, wallet secrets, banking data, raw compliance evidence, or reusable authentication material.","Invoice, checkout, rotational wallet, payment confirmation, settlement, order, fulfillment, delivery, dispute, and refund states are separate. An OPEN invoice and checkout URL are not proof of any later state.","Promotion requires commerce:write, COMMERCE_INVOICE_CREATION step-up, merchant and product isolation, exact totals, customer-data policy, expiry, checkout-capacity atomicity, idempotency, immutable terms evidence, and no-duplicate-invoice tests.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-commerce-invoices-invoice-uuid","method":"GET","path":"/api/v2/commerce/invoices/{invoice_uuid}","title":"COMMERCE: Get invoice","description":"Return invoice terms, checkout destination, payment detection, and settlement evidence.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1invoices~1{invoice_uuid}/get","scope":"commerce:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get invoice"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"invoice_uuid","location":"path","required":true,"type":"identifier","description":"Canonical invoice uuid.","example":"invoice-uuid-01"}],"responses":[{"status":200,"description":"When promoted, the authenticated workspace receives the owner-scoped Commerce projection and page metadata under no-store; read state grants no checkout, payment, settlement, fulfillment, or authority transition.","example":null},{"status":400,"description":"A cursor, limit, filter, identifier, or timestamp boundary is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:read or access to the selected merchant boundary.","example":null},{"status":404,"description":"The selected owner-scoped Commerce resource does not exist.","example":null},{"status":422,"description":"The filter combination, lifecycle value, merchant binding, or time range is outside policy.","example":null},{"status":503,"description":"Commerce, catalog, invoice, checkout, wallet observation, or evidence ownership is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return invoice terms, checkout destination, payment detection, and settlement evidence.","whenToUse":"Re-read one invoice's immutable terms, versions, checkout posture, observations, payment evidence, settlement references, and fulfillment references before any follow-up action.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-scoped projection of one invoice; it cannot activate a merchant, publish a product, create checkout, assert payment, settle a wallet, fulfill an order, move value, or grant authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Derive workspace and owner from the bearer and use only opaque identifiers returned by Commerce. Never enumerate another workspace or submit profile, tenant, vault, database, custody, or secret selectors.","Treat every lifecycle field as a projection of its own resource. Merchant activation, product availability, invoice payment, wallet observation, settlement, and fulfillment remain independent.","Page cursors are opaque and filter-bound. Exact decimal values remain strings; nullable lifecycle timestamps and evidence references must not be invented or coerced.","Re-fetch GET /api/v2/openapi.json before generating or releasing an integration so the client matches the deployed contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-invoices-invoice-uuid-cancellations","method":"POST","path":"/api/v2/commerce/invoices/{invoice_uuid}/cancellations","title":"COMMERCE: Cancel invoice","description":"Cancel an unpaid eligible invoice.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1invoices~1{invoice_uuid}~1cancellations/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel invoice"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-invoices-invoice-uuid-cancellations-request-001"},{"name":"invoice_uuid","location":"path","required":true,"type":"identifier","description":"Canonical invoice uuid.","example":"invoice-uuid-01"},{"name":"expected_invoice_version","location":"body","required":true,"type":"integer · ≥1","description":"Current invoice version used for optimistic concurrency.","example":5},{"name":"expected_status","location":"body","required":true,"type":"DRAFT | OPEN | PAYMENT_PENDING","description":"Last merchant-visible status. Any authoritative final payment evidence makes cancellation ineligible.","example":"OPEN"},{"name":"reason_code","location":"body","required":true,"type":"MERCHANT_CANCELLED | CUSTOMER_REQUEST | ORDER_UNAVAILABLE | COMPLIANCE_HOLD","description":"Structured cancellation reason retained with invoice and checkout evidence.","example":"MERCHANT_CANCELLED"},{"name":"reason_detail","location":"body","required":false,"type":"string · 8–500","description":"Optional non-secret explanation without payment credentials or regulated customer evidence.","example":"The underlying order is no longer available."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh COMMERCE_INVOICE_CANCELLATION authorization bound to invoice version and reason.","example":"hcsu_…"}],"responses":[{"status":200,"description":"An eligible unpaid invoice becomes CANCELLED, its linked OPEN payment request is cancelled, and immutable cancellation evidence is returned.","example":null},{"status":400,"description":"The version, status, reason, detail, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, merchant invoice authority, compliance authority for its reason, or fresh COMMERCE_INVOICE_CANCELLATION authorization.","example":null},{"status":404,"description":"The invoice does not exist in the authenticated merchant boundary.","example":null},{"status":409,"description":"The invoice version or state is stale, final payment evidence exists, fulfillment is committed, cancellation is terminal, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Reason, payment, checkout, order, fulfillment, compliance, refund, or lifecycle policy rejected cancellation.","example":null},{"status":503,"description":"Commerce, Payments, checkout, order, or evidence ownership is unavailable; invoice and checkout state remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an unpaid eligible invoice.","whenToUse":"Cancel one exact unpaid OPEN or PAYMENT_PENDING invoice after reconciling the latest invoice version and linked Payments V2 request.","workflowRole":"create-or-command","sideEffects":"Records CANCELLED and cancels an eligible linked OPEN payment request. It does not reverse payment, refund value, cancel a fulfilled order, return inventory, or settle a wallet.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind current invoice version and DRAFT, OPEN, or PAYMENT_PENDING status. Any authoritative final payment or fulfillment commitment makes direct cancellation ineligible and requires a separate refund or exception workflow.","The bearer identifies merchant and workspace. COMPLIANCE_HOLD additionally requires separately configured compliance authority; customer evidence and payment credentials never belong in reason_detail.","After an ambiguous result, re-read invoice, checkout, payment confirmations, order, and fulfillment before retrying the exact request.","Promotion requires commerce:write, COMMERCE_INVOICE_CANCELLATION step-up, version locking, payment and fulfillment reconciliation, checkout revocation, immutable evidence, notification policy, and no-paid-invoice cancellation tests.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-commerce-merchants","method":"GET","path":"/api/v2/commerce/merchants","title":"COMMERCE: List merchant profiles","description":"List merchant profiles available to the active workspace.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1merchants/get","scope":"commerce:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List merchant profiles"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"32-character hexadecimal cursor","description":"Cursor returned by the preceding page; reuse only with identical filters.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records; defaults to 50.","example":50},{"name":"status","location":"query","required":false,"type":"PENDING_REVIEW | ACTIVE | SUSPENDED | REJECTED | ARCHIVED","description":"Exact merchant lifecycle filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · 1–200","description":"Public-name or merchant-reference search.","example":"treasury"}],"responses":[{"status":200,"description":"When promoted, the authenticated workspace receives the owner-scoped Commerce projection and page metadata under no-store; read state grants no checkout, payment, settlement, fulfillment, or authority transition.","example":null},{"status":400,"description":"A cursor, limit, filter, identifier, or timestamp boundary is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:read or access to the selected merchant boundary.","example":null},{"status":404,"description":"The selected owner-scoped Commerce resource does not exist.","example":null},{"status":422,"description":"The filter combination, lifecycle value, merchant binding, or time range is outside policy.","example":null},{"status":503,"description":"Commerce, catalog, invoice, checkout, wallet observation, or evidence ownership is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List merchant profiles available to the active workspace.","whenToUse":"Discover owner-visible merchants and their review posture before selecting a merchant for catalog, invoice, wallet-observation, or settlement planning.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-scoped projection of merchant profiles; it cannot activate a merchant, publish a product, create checkout, assert payment, settle a wallet, fulfill an order, move value, or grant authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Derive workspace and owner from the bearer and use only opaque identifiers returned by Commerce. Never enumerate another workspace or submit profile, tenant, vault, database, custody, or secret selectors.","Treat every lifecycle field as a projection of its own resource. Merchant activation, product availability, invoice payment, wallet observation, settlement, and fulfillment remain independent.","Page cursors are opaque and filter-bound. Exact decimal values remain strings; nullable lifecycle timestamps and evidence references must not be invented or coerced.","Re-fetch GET /api/v2/openapi.json before generating or releasing an integration so the client matches the deployed contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-merchants","method":"POST","path":"/api/v2/commerce/merchants","title":"COMMERCE: Create merchant profile","description":"Create a merchant operating profile with settlement and checkout policy.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1merchants/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create merchant profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-merchants-request-001"},{"name":"public_name","location":"body","required":true,"type":"string · 2–160","description":"Customer-visible merchant name; the authenticated workspace and legal owner are derived.","example":"Northstar Marketplace"},{"name":"support_email","location":"body","required":true,"type":"email address · max 254","description":"Customer-visible support contact verified under merchant policy.","example":"support@example.com"},{"name":"settlement_currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Default merchant settlement denomination.","example":"THYB"},{"name":"settlement_destination_reference","location":"body","required":true,"type":"approved operational-wallet reference","description":"Opaque eligible merchant operational wallet or treasury destination; raw keys and wallet database IDs are forbidden.","example":"merchant-wallet-01"},{"name":"checkout_policy","location":"body","required":true,"type":"bounded object","description":"Allowed expiry, payment rails, tolerance, refund, and customer-data minimization policy; it cannot override platform or compliance rules.","example":{"accepted_rails":["HYBRID_WALLET"],"expires_in_minutes":30,"settlement_tolerance_bps":0}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh MERCHANT_PROFILE_CREATION authorization for the exact workspace and destination.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A PENDING_REVIEW merchant profile and its destination and policy commitments are returned; checkout and settlement remain disabled.","example":null},{"status":200,"description":"An equivalent workspace merchant profile is returned idempotently without creating another owner.","example":null},{"status":400,"description":"The name, support contact, currency, destination, policy, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, workspace merchant-administration authority, destination ownership, or fresh MERCHANT_PROFILE_CREATION authorization.","example":null},{"status":404,"description":"The settlement destination does not exist in the authenticated workspace and network boundary.","example":null},{"status":409,"description":"An active or pending merchant already exists, destination or policy state changed, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Name, contact, destination, currency, checkout, compliance, network, or merchant eligibility policy validation failed.","example":null},{"status":503,"description":"Commerce, wallet, compliance, or evidence ownership is unavailable; no merchant profile is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a merchant operating profile with settlement and checkout policy.","whenToUse":"Create one workspace-isolated merchant profile after selecting a support contact, settlement denomination, owner-safe destination reference, and bounded checkout policy.","workflowRole":"create-or-command","sideEffects":"Creates PENDING_REVIEW merchant policy and immutable commitments only. Checkout, catalog publication, invoice creation, custody, signing, settlement, and fulfillment remain disabled until their separate lifecycle gates pass.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Workspace and legal owner come from the bearer. Never submit profile, tenant, workspace, vault, raw wallet database IDs, private keys, seeds, MPC shares, signing nonces, processor customer IDs, or banking credentials.","settlement_destination_reference is an opaque policy reference; merchant creation does not validate possession or activate settlement.","Use a fresh MERCHANT_PROFILE_CREATION step-up and a stable Idempotency-Key. After ambiguity, list merchants before retrying the byte-equivalent request.","Activate the reviewed profile with the dedicated version-aware activation operation before publishing products or creating invoices.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-merchants-merchant-uuid-activations","method":"POST","path":"/api/v2/commerce/merchants/{merchant_uuid}/activations","title":"COMMERCE: Activate merchant profile","description":"Activate a reviewed merchant profile at an exact version so its catalog and invoice lifecycle can proceed without granting settlement authority.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1merchants~1{merchant_uuid}~1activations/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Activate merchant profile"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-merchants-merchant-uuid-activations-request-001"},{"name":"merchant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical merchant uuid.","example":"merchant-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Latest merchant version used for optimistic concurrency; stale review state fails closed.","example":1},{"name":"review_reference","location":"body","required":true,"type":"owner-safe reference · 1–128","description":"Opaque reference to completed merchant review evidence; do not embed regulated evidence or credentials.","example":"review-2026-0042"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh MERCHANT_PROFILE_ACTIVATION authorization bound to the reviewed merchant and version.","example":"hcsu_…"}],"responses":[{"status":200,"description":"The reviewed merchant is ACTIVE with an incremented version and committed review reference; no settlement authority is granted.","example":null},{"status":400,"description":"The identifier, expected version, review reference, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write or fresh MERCHANT_PROFILE_ACTIVATION authorization.","example":null},{"status":404,"description":"The merchant does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The merchant is not PENDING_REVIEW, its version changed, or the Idempotency-Key conflicts.","example":null},{"status":503,"description":"Merchant activation or evidence ownership is unavailable; the merchant remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Activate a reviewed merchant profile at an exact version so its catalog and invoice lifecycle can proceed without granting settlement authority.","whenToUse":"Activate a PENDING_REVIEW merchant only after its support contact, destination reference, checkout policy, and review evidence have been approved and its latest version has been re-read.","workflowRole":"create-or-command","sideEffects":"Transitions exactly one merchant to ACTIVE and commits its review reference. It permits later product publication and invoice creation but grants no custody, signing, settlement, payment-finality, or fulfillment authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind expected_version to the latest merchant projection; a stale version returns conflict.","review_reference must be an owner-safe opaque evidence reference, not raw compliance evidence or credentials.","Use a fresh MERCHANT_PROFILE_ACTIVATION step-up and stable Idempotency-Key. Re-read the merchant after an ambiguous outcome.","ACTIVE is checkout eligibility only; continue to treat settlement and fulfillment as separate authoritative lifecycles.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-commerce-products","method":"GET","path":"/api/v2/commerce/products","title":"COMMERCE: List products","description":"List reusable merchant catalog products.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1products/get","scope":"commerce:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List products"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"merchant_uuid","location":"query","required":true,"type":"32-character merchant identifier","description":"Owning merchant whose catalog is listed.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"cursor","location":"query","required":false,"type":"32-character hexadecimal cursor","description":"Cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records; defaults to 50.","example":50},{"name":"status","location":"query","required":false,"type":"DRAFT | ACTIVE | ARCHIVED","description":"Exact product lifecycle filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · 1–200","description":"Name or SKU search.","example":"treasury"}],"responses":[{"status":200,"description":"When promoted, the authenticated workspace receives the owner-scoped Commerce projection and page metadata under no-store; read state grants no checkout, payment, settlement, fulfillment, or authority transition.","example":null},{"status":400,"description":"A cursor, limit, filter, identifier, or timestamp boundary is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:read or access to the selected merchant boundary.","example":null},{"status":404,"description":"The selected owner-scoped Commerce resource does not exist.","example":null},{"status":422,"description":"The filter combination, lifecycle value, merchant binding, or time range is outside policy.","example":null},{"status":503,"description":"Commerce, catalog, invoice, checkout, wallet observation, or evidence ownership is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List reusable merchant catalog products.","whenToUse":"List one merchant's reusable catalog products before constructing invoice line items or presenting purchasable terms.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-scoped projection of catalog products; it cannot activate a merchant, publish a product, create checkout, assert payment, settle a wallet, fulfill an order, move value, or grant authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Derive workspace and owner from the bearer and use only opaque identifiers returned by Commerce. Never enumerate another workspace or submit profile, tenant, vault, database, custody, or secret selectors.","Treat every lifecycle field as a projection of its own resource. Merchant activation, product availability, invoice payment, wallet observation, settlement, and fulfillment remain independent.","Page cursors are opaque and filter-bound. Exact decimal values remain strings; nullable lifecycle timestamps and evidence references must not be invented or coerced.","Re-fetch GET /api/v2/openapi.json before generating or releasing an integration so the client matches the deployed contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-products","method":"POST","path":"/api/v2/commerce/products","title":"COMMERCE: Create product","description":"Create a reusable product with pricing, currency, fulfillment, and metadata.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1products/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create product"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-products-request-001"},{"name":"merchant_uuid","location":"body","required":true,"type":"workspace merchant identifier","description":"Active or review-eligible merchant that will own the catalog product.","example":"merchant-01"},{"name":"sku","location":"body","required":true,"type":"merchant-unique string · 1–96","description":"Stable merchant SKU used for reconciliation; case and whitespace are normalized under merchant policy.","example":"COURSE-FOUNDATIONS"},{"name":"name","location":"body","required":true,"type":"string · 2–160","description":"Customer-visible product name.","example":"Hybrid Foundations Course"},{"name":"description","location":"body","required":false,"type":"string · max 2000","description":"Optional customer-visible description without credentials, regulated evidence, or executable content.","example":"On-demand training with one year of access."},{"name":"unit_price","location":"body","required":true,"type":"positive exact decimal string","description":"Canonical unit price represented without binary floating-point conversion.","example":"125.00"},{"name":"currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Price denomination admitted by the merchant checkout policy.","example":"USD"},{"name":"tax_code","location":"body","required":false,"type":"merchant policy code · max 64","description":"Optional tax classification reference; Commerce does not calculate or attest tax compliance merely because a code is stored.","example":"DIGITAL_SERVICE"},{"name":"fulfillment_policy","location":"body","required":true,"type":"bounded object","description":"Typed delivery kind, timing, and evidence requirements. It cannot assert that fulfillment occurred.","example":{"delivery_sla_seconds":300,"evidence_required":true,"kind":"DIGITAL_ACCESS"}},{"name":"metadata","location":"body","required":false,"type":"bounded string map · max 20 entries","description":"Optional non-secret integration metadata. Keys and values are length-bounded and cannot carry customer evidence, URLs with credentials, or authority assertions.","example":{"catalog":"training"}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh COMMERCE_PRODUCT_CREATION authorization bound to merchant, SKU, price, currency, and fulfillment policy.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A merchant-owned DRAFT product with canonical price, fulfillment policy, and immutable creation commitment is returned; no checkout, invoice, payment, or fulfillment is created.","example":null},{"status":200,"description":"The same Idempotency-Key and equivalent product definition are replayed without creating another catalog record.","example":null},{"status":400,"description":"The merchant, SKU, name, description, exact price, currency, tax code, fulfillment policy, metadata, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, merchant catalog authority, or fresh COMMERCE_PRODUCT_CREATION authorization.","example":null},{"status":404,"description":"The merchant does not exist in the authenticated workspace boundary.","example":null},{"status":409,"description":"The SKU, merchant lifecycle, catalog policy, or Idempotency-Key conflicts with retained state.","example":null},{"status":422,"description":"Price precision, currency, fulfillment, tax classification, metadata, checkout, compliance, or catalog policy rejected the product.","example":null},{"status":503,"description":"Commerce catalog, merchant policy, currency, fulfillment, or evidence ownership is unavailable; no product is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a reusable product with pricing, currency, fulfillment, and metadata.","whenToUse":"Create one reusable merchant-owned catalog draft after resolving its SKU, exact price, denomination, public description, tax classification, and fulfillment evidence policy.","workflowRole":"create-or-command","sideEffects":"Creates a DRAFT catalog record and immutable terms commitment only. It does not publish the offer, create checkout, issue an invoice, reserve inventory, collect payment, calculate tax, deliver anything, or move value.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use exact decimal strings for unit_price; binary floating-point numbers are rejected.","The merchant must be owner-visible and catalog-eligible. SKU uniqueness is scoped to that merchant.","fulfillment_policy describes expected delivery behavior but is never fulfillment evidence; metadata must remain non-secret.","Use a fresh COMMERCE_PRODUCT_CREATION step-up. Publish the reviewed draft separately before selecting it for an invoice.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-products-product-uuid-publications","method":"POST","path":"/api/v2/commerce/products/{product_uuid}/publications","title":"COMMERCE: Publish product","description":"Publish one reviewed catalog draft at an exact version so it can be selected for invoice line items.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1products~1{product_uuid}~1publications/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Publish product"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-products-product-uuid-publications-request-001"},{"name":"product_uuid","location":"path","required":true,"type":"identifier","description":"Canonical product uuid.","example":"product-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Latest DRAFT product version used for optimistic concurrency.","example":1},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh COMMERCE_PRODUCT_PUBLICATION authorization bound to the catalog draft and version.","example":"hcsu_…"}],"responses":[{"status":200,"description":"The reviewed product is ACTIVE with an incremented version; no inventory, checkout, payment, or fulfillment state is created.","example":null},{"status":400,"description":"The identifier, expected version, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write or fresh COMMERCE_PRODUCT_PUBLICATION authorization.","example":null},{"status":404,"description":"The product does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The product is not DRAFT, its version changed, its merchant is not ACTIVE, or the Idempotency-Key conflicts.","example":null},{"status":503,"description":"Product publication or evidence ownership is unavailable; the product remains unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Publish one reviewed catalog draft at an exact version so it can be selected for invoice line items.","whenToUse":"Publish one reviewed DRAFT product after re-reading both the product version and its ACTIVE owning merchant.","workflowRole":"create-or-command","sideEffects":"Transitions the exact draft to ACTIVE while retaining its committed terms. It makes the product invoice-eligible but does not reserve stock, create checkout, collect payment, start delivery, or grant fulfillment authority.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind expected_version to the latest draft; changed terms require another review and a fresh request.","The owning merchant must remain ACTIVE at publication time.","Use a fresh COMMERCE_PRODUCT_PUBLICATION step-up and stable Idempotency-Key; re-read after ambiguity.","Product ACTIVE means offer eligibility only. Reconcile inventory and fulfillment from their own authorities.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-commerce-rotational-wallet-synchronizations","method":"POST","path":"/api/v2/commerce/rotational-wallet-synchronizations","title":"COMMERCE: Synchronize rotational wallets","description":"Request idempotent synchronization and reconciliation of merchant rotational wallets.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Wallets","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1rotational-wallet-synchronizations/post","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Synchronize rotational wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-rotational-wallet-synchronizations-request-001"},{"name":"merchant_uuid","location":"body","required":true,"type":"identifier","description":"Merchant profile owning every selected rotational wallet.","example":"merchant-01"},{"name":"wallet_references","location":"body","required":true,"type":"owner-safe rotational-wallet reference[] · 1–100 unique","description":"Explicit eligible wallets to observe. Private keys, seeds, password material, and raw database identifiers are forbidden.","example":["rotation-01","rotation-02"]},{"name":"observation_cutoff","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Upper observation time bound used to make reconciliation reproducible.","example":"2026-09-01T18:00:00Z"},{"name":"mode","location":"body","required":true,"type":"VERIFY_ONLY | APPLY_OBSERVATIONS","description":"VERIFY_ONLY reports differences. APPLY_OBSERVATIONS may retain verified deposits and invoice associations but cannot settle balances.","example":"VERIFY_ONLY"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ROTATIONAL_WALLET_SYNCHRONIZATION authorization bound to merchant, wallets, cutoff, and mode.","example":"hcsu_…"}],"responses":[{"status":200,"description":"A bounded VERIFY_ONLY synchronization result and commitment are returned with state_changed=false; it is not payment or settlement.","example":null},{"status":400,"description":"The merchant, wallet set, cutoff, mode, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, merchant ownership, wallet visibility, or fresh ROTATIONAL_WALLET_SYNCHRONIZATION authorization.","example":null},{"status":404,"description":"The merchant or one or more rotational wallets do not exist in the authenticated workspace and network boundary.","example":null},{"status":409,"description":"A wallet is already assigned, settled, retired, beyond the observation cutoff, concurrently changing, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Ownership, network, observation, confirmation, invoice association, duplicate-detection, or synchronization policy validation failed.","example":null},{"status":503,"description":"Commerce, wallet, chain indexer, invoice, or evidence ownership is unavailable; no observations are retained.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request idempotent synchronization and reconciliation of merchant rotational wallets.","whenToUse":"Run a bounded, reproducible VERIFY_ONLY pass over explicitly selected merchant rotational-wallet references at a fixed observation cutoff.","workflowRole":"create-or-command","sideEffects":"Returns a verification commitment with state_changed false. APPLY_OBSERVATIONS remains rejected; the operation cannot retain deposits, mark invoices paid, settle balances, transfer value, sign, or fulfill an order.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","merchant onboarding and policy review","catalog and structured invoice creation"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Select explicit owner-safe wallet references and a fixed observation cutoff. The service resolves chain addresses and owner state; never send passwords, password hashes, seeds, private keys, MPC shares, signing nonces, or caller-authored balances.","Every observation must bind network, asset, amount, transaction, confirmations/finality, rotational wallet, invoice association, and evidence commitment. Duplicate and reorganization handling must be deterministic.","HTTP 202 would mean bounded work was accepted. Re-read synchronization receipt, invoice, payment, and wallet state before describing a deposit or payment as reconciled.","Promotion requires commerce:write, ROTATIONAL_WALLET_SYNCHRONIZATION step-up, indexer freshness, wallet ownership, cutoff enforcement, idempotency, duplicate/reorg policy, immutable evidence, and strict separation from settlement.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Digital Assets"]}},{"id":"get-api-v2-commerce-rotational-wallets","method":"GET","path":"/api/v2/commerce/rotational-wallets","title":"COMMERCE: List rotational wallets","description":"List invoice-scoped rotational wallets and reconciliation posture.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Wallets","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1commerce~1rotational-wallets/get","scope":"commerce:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List rotational wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"merchant_uuid","location":"query","required":true,"type":"32-character merchant identifier","description":"Owning merchant for the observed wallet set.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"network_id","location":"query","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Exact chain observation boundary.","example":"hybrid-testnet"}],"responses":[{"status":200,"description":"When promoted, the authenticated workspace receives the owner-scoped Commerce projection and page metadata under no-store; read state grants no checkout, payment, settlement, fulfillment, or authority transition.","example":null},{"status":400,"description":"A cursor, limit, filter, identifier, or timestamp boundary is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:read or access to the selected merchant boundary.","example":null},{"status":404,"description":"The selected owner-scoped Commerce resource does not exist.","example":null},{"status":422,"description":"The filter combination, lifecycle value, merchant binding, or time range is outside policy.","example":null},{"status":503,"description":"Commerce, catalog, invoice, checkout, wallet observation, or evidence ownership is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List invoice-scoped rotational wallets and reconciliation posture.","whenToUse":"List one merchant's invoice-scoped wallet observation and settlement-eligibility posture without obtaining custody or signing authority.","workflowRole":"discover-or-read","sideEffects":"Read-only owner-scoped projection of rotational wallets; it cannot activate a merchant, publish a product, create checkout, assert payment, settle a wallet, fulfill an order, move value, or grant authority.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","merchant onboarding and policy review","catalog and structured invoice creation"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Derive workspace and owner from the bearer and use only opaque identifiers returned by Commerce. Never enumerate another workspace or submit profile, tenant, vault, database, custody, or secret selectors.","Treat every lifecycle field as a projection of its own resource. Merchant activation, product availability, invoice payment, wallet observation, settlement, and fulfillment remain independent.","Page cursors are opaque and filter-bound. Exact decimal values remain strings; nullable lifecycle timestamps and evidence references must not be invented or coerced.","Re-fetch GET /api/v2/openapi.json before generating or releasing an integration so the client matches the deployed contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Digital Assets"]}},{"id":"post-api-v2-commerce-rotational-wallets-wallet-uuid-settlements","method":"POST","path":"/api/v2/commerce/rotational-wallets/{wallet_uuid}/settlements","title":"COMMERCE: Settle rotational wallet","description":"Authorize fee-aware settlement of one rotational wallet into its merchant destination.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant commerce","owners":["commerce-service"],"applications":["Wallets","Commerce"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-commerce-rotational-wallets-wallet-uuid-settlements","scope":"commerce:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Settle rotational wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-commerce-rotational-wallets-wallet-uuid-settlements-request-001"},{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"},{"name":"expected_wallet_version","location":"body","required":true,"type":"integer · ≥1","description":"Current rotational-wallet version used to reject settlement against changed observation or ownership state.","example":7},{"name":"expected_available_balance","location":"body","required":true,"type":"non-negative exact decimal string","description":"Last-read eligible balance. Commerce re-resolves confirmed deposits, reservations, fees, and pending settlements while locked.","example":"250.00000000"},{"name":"settlement_currency","location":"body","required":true,"type":"uppercase asset or ISO currency code","description":"Exact wallet denomination admitted by merchant settlement policy.","example":"THYB"},{"name":"destination_reference","location":"body","required":true,"type":"approved merchant settlement destination reference","description":"Opaque destination already bound to the merchant; callers never submit a raw custody database identifier or signing material.","example":"merchant-destination-01"},{"name":"fee_policy","location":"body","required":true,"type":"MINIMUM_CONFIRMED | EXACT_QUOTE","description":"Fee treatment. EXACT_QUOTE requires a still-valid owner-issued quote; caller-authored fee values are rejected.","example":"MINIMUM_CONFIRMED"},{"name":"fee_quote_reference","location":"body","required":false,"type":"owner-issued fee quote identifier","description":"Required only with EXACT_QUOTE and resolved inside the authoritative wallet owner.","example":"fee-quote-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Substantive, non-secret settlement reason retained with review and evidence.","example":"Scheduled merchant treasury sweep."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh MERCHANT_ROTATIONAL_WALLET_SETTLEMENT authorization bound to wallet, version, balance, destination, currency, and fee policy.","example":"hcsu_…"}],"responses":[{"status":202,"description":"When promoted, an eligible settlement request is accepted with locked wallet, balance, destination, currency, fee-policy, authorization, and idempotency commitments; acceptance is not signing, broadcast, confirmation, or settlement finality.","example":null},{"status":200,"description":"The same Idempotency-Key and equivalent completed or still-pending settlement request are replayed without creating another value-moving intent.","example":null},{"status":400,"description":"The wallet, expected version, balance, currency, destination, fee policy, quote, reason, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks commerce:write, merchant settlement authority, destination authority, or fresh MERCHANT_ROTATIONAL_WALLET_SETTLEMENT authorization.","example":null},{"status":404,"description":"The rotational wallet, merchant destination, or fee quote does not exist in the authenticated owner and network boundary.","example":null},{"status":409,"description":"Wallet version, available balance, observation finality, destination, fee quote, active settlement, or Idempotency-Key state conflicts.","example":null},{"status":422,"description":"Invoice association, reservation, confirmation, fee, dust, minimum balance, currency, network, compliance, custody, or settlement policy rejected the request.","example":null},{"status":503,"description":"Commerce, wallet, indexer, Payments, compliance, MPC signing, network, or evidence ownership is unavailable; no settlement intent is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Authorize fee-aware settlement of one rotational wallet into its merchant destination.","whenToUse":"Do not call this planning route yet; merchant settlement and value-moving capabilities remain frozen. It reserves a separately authorized sweep only after one rotational wallet's owner, version, confirmed observations, invoice associations, available balance, destination, currency, fee policy, and compliance posture are freshly reconciled.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future HTTP 202 would create a settlement intent and retained commitments only; it would not prove MPC authorization, signing, submission, broadcast, confirmation, treasury credit, invoice payment, fulfillment, or final settlement.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","merchant onboarding and policy review","catalog and structured invoice creation"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Bind expected_wallet_version and expected_available_balance as an exact decimal string. The owner must lock deposits, reservations, pending settlements, dust, and fee state and reject stale expectations atomically.","destination_reference is pre-approved and owner-safe. Never send a raw wallet database UUID, destination chosen outside merchant policy, password, password hash, seed, private key, MPC share, signing nonce, authenticator code, processor secret, or caller-authored fee.","HTTP 202 is only admission. Re-read settlement intent, authorization, signing, network, confirmation, and destination-credit evidence before describing funds as settled.","Promotion requires the separate trading/value-movement approval boundary, commerce:write, MERCHANT_ROTATIONAL_WALLET_SETTLEMENT step-up, RFC 9421 signing, destination and compliance authority, MPC policy, exact fees, idempotency, atomic reservations, immutable evidence, and no-value-on-failure tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Digital Assets"]}},{"id":"get-api-v2-merchant-all","method":"GET","path":"/api/v2/merchant/all","title":"MERCHANT: Get All Merchants","description":"MERCHANT: Get All Merchants through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/all","operation":"MERCHANT: Get All Merchants"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-all","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Merchants"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get All Merchants through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all merchants before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-all-invoices","method":"GET","path":"/api/v2/merchant/all_invoices","title":"MERCHANT: Get All Invoices","description":"MERCHANT: Get All Invoices through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/all_invoices","operation":"MERCHANT: Get All Invoices"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-all-invoices","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Invoices"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get All Invoices through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all invoices before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-cancel-invoice","method":"POST","path":"/api/v2/merchant/cancel_invoice","title":"MERCHANT: Cancel Invoice","description":"MERCHANT: Cancel Invoice through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/cancel_invoice","operation":"MERCHANT: Cancel Invoice"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-cancel-invoice","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Cancel Invoice"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Cancel Invoice through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/commerce/invoices/{invoice_uuid}/cancellations for version-aware unpaid-invoice cancellation when executable.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-checkout","method":"GET","path":"/api/v2/merchant/checkout","title":"MERCHANT: Get Checkout Data","description":"MERCHANT: Get Checkout Data through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/checkout","operation":"MERCHANT: Get Checkout Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-checkout","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Checkout Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get Checkout Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get checkout data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-create","method":"POST","path":"/api/v2/merchant/create","title":"MERCHANT: Create new Merchant","description":"MERCHANT: Create new Merchant through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/create","operation":"MERCHANT: Create new Merchant"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-create","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create new Merchant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Create new Merchant through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/commerce/merchants for workspace-derived merchant onboarding when executable.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-details","method":"GET","path":"/api/v2/merchant/details","title":"MERCHANT: Get Merchant Details","description":"MERCHANT: Get Merchant Details through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/details","operation":"MERCHANT: Get Merchant Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-details","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Merchant Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get Merchant Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get merchant details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-details","method":"POST","path":"/api/v2/merchant/details","title":"MERCHANT: Set Merchant Details","description":"MERCHANT: Set Merchant Details through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/details","operation":"MERCHANT: Set Merchant Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-details","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set Merchant Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Set Merchant Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","No canonical merchant-profile update is executable yet. Use GET /api/v2/commerce/merchants for reads and wait for a version-aware update contract.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-enabled-status","method":"POST","path":"/api/v2/merchant/enabled_status","title":"MERCHANT: Change Enabled Status","description":"MERCHANT: Change Enabled Status through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/enabled_status","operation":"MERCHANT: Change Enabled Status"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-enabled-status","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Change Enabled Status"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Change Enabled Status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/commerce/merchants/{merchant_uuid}/activations for the one-way reviewed PENDING_REVIEW-to-ACTIVE transition. No generic enable/disable toggle is executable.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-invoice-status","method":"GET","path":"/api/v2/merchant/invoice_status","title":"MERCHANT: Get Invoice Status","description":"MERCHANT: Get Invoice Status through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/invoice_status","operation":"MERCHANT: Get Invoice Status"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-invoice-status","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Invoice Status"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get Invoice Status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get invoice status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-new-invoice","method":"POST","path":"/api/v2/merchant/new_invoice","title":"MERCHANT: Create new Invoice","description":"MERCHANT: Create new Invoice through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/new_invoice","operation":"MERCHANT: Create new Invoice"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-new-invoice","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create new Invoice"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Create new Invoice through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/commerce/invoices for structured line items, server-derived totals, checkout policy, and payment evidence when executable.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-overview","method":"GET","path":"/api/v2/merchant/overview","title":"MERCHANT: Get Merchants Overview","description":"MERCHANT: Get Merchants Overview through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/overview","operation":"MERCHANT: Get Merchants Overview"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-overview","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Merchants Overview"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get Merchants Overview through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get merchants overview before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"post-api-v2-merchant-reserve-wallet","method":"POST","path":"/api/v2/merchant/reserve_wallet","title":"MERCHANT: Reserve Payment Wallet","description":"MERCHANT: Reserve Payment Wallet through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Wallets","Payments","Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/reserve_wallet","operation":"MERCHANT: Reserve Payment Wallet"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-reserve-wallet","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Reserve Payment Wallet"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Reserve Payment Wallet through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","No public wallet-reservation mutation is executable. Discover rotational wallets and use synchronization only for observations; reservation and assignment require an owned lifecycle.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-rotational-wallets","method":"GET","path":"/api/v2/merchant/rotational_wallets","title":"MERCHANT: Get All Rotational Wallets","description":"MERCHANT: Get All Rotational Wallets through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Wallets","Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/rotational_wallets","operation":"MERCHANT: Get All Rotational Wallets"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-rotational-wallets","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Rotational Wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get All Rotational Wallets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all rotational wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","merchant onboarding and policy review","catalog and structured invoice creation"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Digital Assets"]}},{"id":"post-api-v2-merchant-settle-balances","method":"POST","path":"/api/v2/merchant/settle_balances","title":"MERCHANT: Settle Balances","description":"MERCHANT: Settle Balances through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/merchant/settle_balances","operation":"MERCHANT: Settle Balances"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-merchant-settle-balances","scope":"commerce:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Settle Balances"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy payment or merchant compatibility marker is non-executable. Follow businessContext.agentGuidance to the canonical V2 lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Settle Balances through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained to give legacy payment and merchant integrations a deterministic migration answer.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:write authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Use POST /api/v2/commerce/rotational-wallets/{wallet_uuid}/settlements only when live OpenAPI exposes it; never submit passwords, seeds, private keys, or caller-authored balances.","Verify the exact replacement in GET /api/v2/openapi.json before calling it. Planned registry profiles remain non-executable documentation.","Do not translate legacy bodies field-for-field. Owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, and settlement assertions are forbidden.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-settlements","method":"GET","path":"/api/v2/merchant/settlements","title":"MERCHANT: Get All Settlements","description":"MERCHANT: Get All Settlements through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/settlements","operation":"MERCHANT: Get All Settlements"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-settlements","scope":"commerce:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Settlements"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing commerce:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Get All Settlements through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all settlements before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with commerce:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets"]}},{"id":"get-api-v2-merchant-sync-rotational-wallets","method":"GET","path":"/api/v2/merchant/sync_rotational_wallets","title":"MERCHANT: Sync All Rotational Wallets","description":"MERCHANT: Sync All Rotational Wallets through the canonical Hybrid-Chain V2 interface.","chapter":"Merchant Functions","chapterOrder":6,"capability":"Merchant Functions","owners":["merchant-commerce"],"applications":["Wallets","Commerce"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/merchant/sync_rotational_wallets","operation":"MERCHANT: Sync All Rotational Wallets"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-merchant-sync-rotational-wallets","scope":"wallets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Sync All Rotational Wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing wallets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MERCHANT: Sync All Rotational Wallets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to sync all rotational wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","merchant onboarding and policy review","catalog and structured invoice creation"],"prerequisites":["A bearer credential with wallets:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Digital Assets"]}},{"id":"post-api-v2-dex-cancel","method":"POST","path":"/api/v2/dex/cancel","title":"DEX: Cancel DEX Order","description":"DEX: Cancel DEX Order through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/dex/cancel","operation":"DEX: Cancel DEX Order"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-dex-cancel","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel DEX Order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-dex-cancel-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel dex order. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"DEX: Cancel DEX Order through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel dex order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"post-api-v2-dex-cancel-all","method":"POST","path":"/api/v2/dex/cancel_all","title":"DEX: Cancel all DEX Orders","description":"DEX: Cancel all DEX Orders through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/dex/cancel_all","operation":"DEX: Cancel all DEX Orders"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-dex-cancel-all","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel all DEX Orders"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-dex-cancel-all-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel all dex orders. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"DEX: Cancel all DEX Orders through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel all dex orders.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-dex-market-chart","method":"GET","path":"/api/v2/dex/market_chart","title":"DEX: Get DEX Candle Data","description":"DEX: Get DEX Candle Data through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/market_chart","operation":"DEX: Get DEX Candle Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-dex-market-chart","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get DEX Candle Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get DEX Candle Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get dex candle data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-dex-order-meta","method":"GET","path":"/api/v2/dex/order_meta","title":"DEX: Get DEX Order","description":"DEX: Get DEX Order through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/order_meta","operation":"DEX: Get DEX Order"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-dex-order-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get DEX Order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get DEX Order through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get dex order before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-dex-trade-meta","method":"GET","path":"/api/v2/dex/trade_meta","title":"DEX: Get DEX Trade","description":"DEX: Get DEX Trade through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/trade_meta","operation":"DEX: Get DEX Trade"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-dex-trade-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get DEX Trade"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get DEX Trade through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get dex trade before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-dex-trades","method":"GET","path":"/api/v2/dex/trades","title":"DEX: Get all DEX Trades","description":"DEX: Get all DEX Trades through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/trades","operation":"DEX: Get all DEX Trades"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-dex-trades","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all DEX Trades"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get all DEX Trades through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all dex trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-markets-market-id-order-book","method":"GET","path":"/api/v2/markets/{market_id}/order-book","title":"DEX: Get DEX Orderbook","description":"DEX: Get DEX Orderbook through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/orderbook","operation":"DEX: Get DEX Orderbook"},{"method":"GET","path":"/api/v1/exchange/orderbook","operation":"MTF: Get MTF Orderbook"},{"method":"GET","path":"/api/v1/virtex/orderbook","operation":"VIRTUAL: Get Virtual Orderbook"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1order-book/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get DEX Orderbook"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"depth","location":"query","required":false,"type":"integer · 1–200","description":"Maximum price levels per side.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get DEX Orderbook through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get dex orderbook before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-orders","method":"GET","path":"/api/v2/orders","title":"DEX: Get all DEX Orders","description":"DEX: Get all DEX Orders through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/orders","operation":"DEX: Get all DEX Orders"},{"method":"GET","path":"/api/v1/exchange/orders","operation":"MTF: Get all MTF Orders"},{"method":"GET","path":"/api/v1/virtex/orders","operation":"VIRTUAL: Get all Virtual Orders"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get all DEX Orders"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"market_id","location":"query","required":false,"type":"market identifier","description":"Optional exact canonical market filter.","example":"market-id-01"},{"name":"state","location":"query","required":false,"type":"open | closed | all","description":"Lifecycle group; defaults to open.","example":"open"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum owner-scoped orders to return.","example":50},{"name":"cursor","location":"query","required":false,"type":"opaque order cursor","description":"next_cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"DEX: Get all DEX Orders through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all dex orders before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"post-api-v2-orders","method":"POST","path":"/api/v2/orders","title":"DEX: Create DEX Order","description":"DEX: Create DEX Order through the canonical Hybrid-Chain V2 interface.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Decentralized Trading","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/dex/create_order","operation":"DEX: Create DEX Order"},{"method":"POST","path":"/api/v1/exchange/create_order","operation":"MTF: Create MTF Market Order"},{"method":"POST","path":"/api/v1/virtex/create_order","operation":"VIRTUAL: Create Virtual Market Order"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders/post","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create DEX Order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-orders-request-001"},{"name":"venue","location":"body","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex. Internal pool UUIDs cannot be supplied.","example":"venue-01"},{"name":"market","location":"body","required":true,"type":"market identifier","description":"Canonical market.","example":"market-01"},{"name":"side","location":"body","required":true,"type":"BUY | SELL","description":"Order side.","example":"side-01"},{"name":"order_type","location":"body","required":false,"type":"MARKET | LIMIT | STOP | STOP_LIMIT | ICEBERG | TRAILING | TRAILING_STOP | TAKE_PROFIT | TAKE_PROFIT_MARKET | TAKE_PROFIT_LIMIT","description":"Order type; defaults to MARKET.","example":"order-type-01"},{"name":"time_in_force","location":"body","required":false,"type":"GTC | IOC | FOK | BOC","description":"Execution duration; defaults to GTC.","example":"time-in-force-01"},{"name":"quantity","location":"body","required":false,"type":"decimal string","description":"Base-asset quantity; exactly one of quantity or notional_amount is required.","example":"10.00"},{"name":"notional_amount","location":"body","required":false,"type":"decimal string","description":"Quote notional; supported only by compatible order types.","example":"10.00"},{"name":"limit_price","location":"body","required":false,"type":"decimal string","description":"Required by limit-style orders.","example":"10.00"},{"name":"trigger_price","location":"body","required":false,"type":"decimal string","description":"Required by stop, trailing, and take-profit order types.","example":"10.00"},{"name":"tip_quantity","location":"body","required":false,"type":"decimal string","description":"Required for ICEBERG orders.","example":"10.00"},{"name":"trailing_amount","location":"body","required":false,"type":"decimal string","description":"Absolute trailing distance; mutually exclusive with trailing_percent.","example":"10.00"},{"name":"trailing_percent","location":"body","required":false,"type":"decimal string","description":"Percentage trailing distance; mutually exclusive with trailing_amount.","example":"10.00"},{"name":"expiry_timestamp","location":"body","required":false,"type":"13-digit Unix milliseconds","description":"Future deadline; Rust NXG expires the order durably before processing later commands on an explicitly Rust-owned market.","example":"expiry-timestamp-01"},{"name":"reporting_identifier","location":"body","required":false,"type":"string · max 255","description":"Sub-client or regulatory attribution that never changes the authenticated owner.","example":"reporting-identifier-01"},{"name":"external_reference","location":"body","required":true,"type":"string · 1–255","description":"Caller-stable business reference.","example":"external-reference-01"},{"name":"client_reference","location":"body","required":false,"type":"string · max 32","description":"Optional client display reference.","example":"client-reference-01"},{"name":"leverage","location":"body","required":false,"type":"integer · 1–20","description":"Risk leverage; defaults to 1.","example":1},{"name":"aggregation_meta","location":"body","required":false,"type":"object","description":"Opaque attribution metadata; it grants no authority.","example":{}},{"name":"reduce_only","location":"body","required":false,"type":"boolean","description":"Restricts execution to reducing an existing position.","example":true},{"name":"combos","location":"body","required":false,"type":"order[] · max 16","description":"Child orders inherit parent market, venue, attribution, and derived references; nesting is forbidden.","example":[]}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"DEX: Create DEX Order through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create dex order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-balances","method":"GET","path":"/api/v2/balances","title":"TRADING: List collateral balances","description":"Return purpose-limited available and reserved collateral balances.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1balances/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List collateral balances"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return purpose-limited available and reserved collateral balances.","whenToUse":"Use this operation when an integration needs to list collateral balances before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets","method":"GET","path":"/api/v2/markets","title":"TRADING: List markets","description":"List canonical market definitions for the DEX, securities, or virtual venue without embedding prices, order books, or user state.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/markets","operation":"DEX: Get DEX Markets"},{"method":"GET","path":"/api/v1/exchange/markets","operation":"MTF: Get MTF Markets"},{"method":"GET","path":"/api/v1/virtex/markets","operation":"VIRTUAL: Get Virtual Markets"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List markets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue catalog; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List canonical market definitions for the DEX, securities, or virtual venue without embedding prices, order books, or user state.","whenToUse":"Use this operation when an integration needs to list markets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id","method":"GET","path":"/api/v2/markets/{market_id}","title":"TRADING: Get market","description":"Return one canonical venue-scoped market definition without embedding prices, order books, or user state.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get market"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue catalog; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one canonical venue-scoped market definition without embedding prices, order books, or user state.","whenToUse":"Use this operation when an integration needs to get market before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id-candles","method":"GET","path":"/api/v2/markets/{market_id}/candles","title":"TRADING: List candles","description":"Aggregate bounded venue-scoped trades into deterministic OHLCV intervals.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1candles/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List candles"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"interval","location":"query","required":false,"type":"1m | 5m | 15m | 1h | 4h | 1d","description":"UTC candle bucket interval; defaults to 1m.","example":"1m"},{"name":"minutes","location":"query","required":false,"type":"integer · 1–43200","description":"Lookback window in minutes; defaults to 1440.","example":1440},{"name":"limit","location":"query","required":false,"type":"integer · 1–1000","description":"Maximum newest-first non-empty buckets.","example":200}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Aggregate bounded venue-scoped trades into deterministic OHLCV intervals.","whenToUse":"Use this operation when an integration needs to list candles before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id-events","method":"GET","path":"/api/v2/markets/{market_id}/events","title":"TRADING: List market events","description":"Return sequenced venue events for one canonical market.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1events/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List market events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"sequence_start","location":"query","required":false,"type":"string","description":"Optional authoritative event sequence lower bound.","example":"sequence-start-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return sequenced venue events for one canonical market.","whenToUse":"Use this operation when an integration needs to list market events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id-funding-rates","method":"GET","path":"/api/v2/markets/{market_id}/funding-rates","title":"TRADING: Get funding rates","description":"Return the configured funding rate for a perpetual market.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Funding","Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1funding-rates/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get funding rates"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the configured funding rate for a perpetual market.","whenToUse":"Use this operation when an integration needs to get funding rates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-markets-market-id-restrictions","method":"GET","path":"/api/v2/markets/{market_id}/restrictions","title":"TRADING: Get restrictions","description":"Return owner-specific matching restrictions without exposing other traders.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1restrictions/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get restrictions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return owner-specific matching restrictions without exposing other traders.","whenToUse":"Use this operation when an integration needs to get restrictions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id-trades","method":"GET","path":"/api/v2/markets/{market_id}/trades","title":"TRADING: List market trades","description":"Return a bounded recent execution window for one canonical venue-scoped market with duplicate matching sides collapsed.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/dex/market_history","operation":"DEX: Get DEX Historical Data"},{"method":"GET","path":"/api/v1/exchange/market_history","operation":"MTF: Get MTF Market History"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1trades/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List market trades"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"minutes","location":"query","required":false,"type":"integer · 1–43200","description":"Lookback window in minutes.","example":1440},{"name":"limit","location":"query","required":false,"type":"integer · 1–1000","description":"Maximum distinct trades.","example":200}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return a bounded recent execution window for one canonical venue-scoped market with duplicate matching sides collapsed.","whenToUse":"Use this operation when an integration needs to list market trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-orders-order-uuid","method":"GET","path":"/api/v2/orders/{order_uuid}","title":"TRADING: Get order","description":"Return an order, fills, fees, cancellation state, and retained execution evidence.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders~1{order_uuid}/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"order_uuid","location":"path","required":true,"type":"identifier","description":"Canonical order uuid.","example":"order-uuid-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return an order, fills, fees, cancellation state, and retained execution evidence.","whenToUse":"Use this operation when an integration needs to get order before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-orders-order-uuid-cancellations","method":"POST","path":"/api/v2/orders/{order_uuid}/cancellations","title":"TRADING: Cancel order","description":"Request cancellation of an eligible open order.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders~1{order_uuid}~1cancellations/post","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-orders-order-uuid-cancellations-request-001"},{"name":"order_uuid","location":"path","required":true,"type":"identifier","description":"Canonical order uuid.","example":"order-uuid-01"},{"name":"venue","location":"body","required":false,"type":"dex | securities | virtual","description":"Venue containing the order; defaults to dex.","example":"venue-01"},{"name":"reason","location":"body","required":false,"type":"string","description":"Optional operator-readable cancellation rationale.","example":"reason-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request cancellation of an eligible open order.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-orders-order-uuid-replacements","method":"POST","path":"/api/v2/orders/{order_uuid}/replacements","title":"TRADING: Replace order","description":"Atomically cancel and replace an eligible order with revised terms.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders~1{order_uuid}~1replacements/post","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Replace order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-orders-order-uuid-replacements-request-001"},{"name":"order_uuid","location":"path","required":true,"type":"identifier","description":"Canonical order uuid.","example":"order-uuid-01"},{"name":"venue","location":"body","required":false,"type":"dex | securities | virtual","description":"Venue containing the order.","example":"venue-01"},{"name":"quantity","location":"body","required":false,"type":"decimal string","description":"New total open quantity.","example":"10.00"},{"name":"limit_price","location":"body","required":false,"type":"decimal string","description":"New limit price.","example":"10.00"},{"name":"trigger_price","location":"body","required":false,"type":"decimal string","description":"New stop or take-profit trigger.","example":"10.00"},{"name":"tip_quantity","location":"body","required":false,"type":"decimal string","description":"New iceberg display quantity.","example":"10.00"},{"name":"trailing_amount","location":"body","required":false,"type":"decimal string","description":"New absolute trailing offset.","example":"10.00"},{"name":"trailing_percent","location":"body","required":false,"type":"decimal string","description":"New percentage trailing offset.","example":"10.00"},{"name":"expiry_timestamp","location":"body","required":false,"type":"13-digit Unix milliseconds","description":"New future deadline; at least one replacement field is required.","example":"expiry-timestamp-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically cancel and replace an eligible order with revised terms.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to replace order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-orders-cancellations","method":"POST","path":"/api/v2/orders/cancellations","title":"TRADING: Cancel all orders","description":"Cancel every eligible owner-scoped order, optionally restricted to one market and venue.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1orders~1cancellations/post","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel all orders"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-orders-cancellations-request-001"},{"name":"venue","location":"body","required":false,"type":"dex | securities | virtual","description":"Venue containing the orders; defaults to dex.","example":"venue-01"},{"name":"market","location":"body","required":false,"type":"market identifier","description":"Optional exact market restriction.","example":"market-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel every eligible owner-scoped order, optionally restricted to one market and venue.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel all orders.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-positions","method":"GET","path":"/api/v2/positions","title":"TRADING: List positions","description":"List current and historical trading positions and realized/unrealized performance.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1positions/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List positions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"market_id","location":"query","required":false,"type":"market identifier","description":"Optional exact canonical market filter.","example":"market-id-01"},{"name":"reporting_identifier","location":"query","required":false,"type":"string · max 255","description":"Optional sub-client or regulatory attribution filter.","example":"reporting-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List current and historical trading positions and realized/unrealized performance.","whenToUse":"Use this operation when an integration needs to list positions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-positions-market-id-closures","method":"POST","path":"/api/v2/positions/{market_id}/closures","title":"TRADING: Close position","description":"Submit a reduce-only market command whose side is derived from the live owner-scoped position.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1positions~1{market_id}~1closures/post","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Close position"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-positions-market-id-closures-request-001"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"body","required":false,"type":"dex | securities | virtual","description":"Venue containing the position; defaults to dex.","example":"venue-01"},{"name":"quantity","location":"body","required":false,"type":"decimal string","description":"Positive quantity to close; omitted closes the full live position.","example":"10.00"},{"name":"reporting_identifier","location":"body","required":false,"type":"string · max 255","description":"Optional sub-client or regulatory attribution.","example":"reporting-identifier-01"},{"name":"external_reference","location":"body","required":true,"type":"string · 1–255","description":"Caller-stable business reference.","example":"external-reference-01"}],"responses":[{"status":202,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Submit a reduce-only market command whose side is derived from the live owner-scoped position.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to close position.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-trades","method":"GET","path":"/api/v2/trades","title":"TRADING: List trades","description":"List authenticated trade executions with market, order, settlement, and fee filters.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trades/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List trades"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"},{"name":"market_id","location":"query","required":false,"type":"market identifier","description":"Optional exact canonical market filter.","example":"market-id-01"},{"name":"limit","location":"query","required":false,"type":"integer · 1–500","description":"Maximum owner-scoped trades to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List authenticated trade executions with market, order, settlement, and fee filters.","whenToUse":"Use this operation when an integration needs to list trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-trades-trade-uuid","method":"GET","path":"/api/v2/trades/{trade_uuid}","title":"TRADING: Get trade","description":"Return one exact owner-scoped trade execution.","chapter":"Decentralized Trading","chapterOrder":7,"capability":"Markets and execution","owners":["matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trades~1{trade_uuid}/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get trade"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"trade_uuid","location":"path","required":true,"type":"identifier","description":"Canonical trade uuid.","example":"trade-uuid-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one exact owner-scoped trade execution.","whenToUse":"Use this operation when an integration needs to get trade before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-markets-market-id-last-trade","method":"GET","path":"/api/v2/markets/{market_id}/last-trade","title":"TRADING: Get last trade","description":"Return the latest distinct execution for one canonical venue-scoped market, or an explicit null when no trade exists.","chapter":"Decentralized Trading","chapterOrder":8,"capability":"Markets and execution","owners":["matching-and-trading-read-model","matching-engine"],"applications":["Trading","Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["application-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/last_prices","operation":"MTF: Get MTF Last Prices"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1markets~1{market_id}~1last-trade/get","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get last trade"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"market_id","location":"path","required":true,"type":"identifier","description":"Canonical market id.","example":"market-id-01"},{"name":"venue","location":"query","required":false,"type":"dex | securities | virtual","description":"Authoritative venue; defaults to dex.","example":"dex"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the latest distinct execution for one canonical venue-scoped market, or an explicit null when no trade exists.","whenToUse":"Use this operation when an integration needs to get last trade before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-exchange-cancel","method":"POST","path":"/api/v2/exchange/cancel","title":"MTF: Cancel MTF Order","description":"MTF: Cancel MTF Order through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/exchange/cancel","operation":"MTF: Cancel MTF Order"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-exchange-cancel","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel MTF Order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-exchange-cancel-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel mtf order. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"MTF: Cancel MTF Order through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel mtf order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"post-api-v2-exchange-cancel-all","method":"POST","path":"/api/v2/exchange/cancel_all","title":"MTF: Cancel all MTF Orders","description":"MTF: Cancel all MTF Orders through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/exchange/cancel_all","operation":"MTF: Cancel all MTF Orders"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-exchange-cancel-all","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel all MTF Orders"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-exchange-cancel-all-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel all mtf orders. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"MTF: Cancel all MTF Orders through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel all mtf orders.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-exchange-events","method":"GET","path":"/api/v2/exchange/events","title":"MTF: Get MTF Liquidity Pool Events","description":"MTF: Get MTF Liquidity Pool Events through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading","Liquidity Management"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/events","operation":"MTF: Get MTF Liquidity Pool Events"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-events","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get MTF Liquidity Pool Events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get MTF Liquidity Pool Events through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get mtf liquidity pool events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Trading & Matching Ops","Wallets"]}},{"id":"get-api-v2-exchange-fundingrates","method":"GET","path":"/api/v2/exchange/fundingrates","title":"MTF: Get MTF Funding Rates","description":"MTF: Get MTF Funding Rates through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Funding","Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/fundingrates","operation":"MTF: Get MTF Funding Rates"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-fundingrates","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get MTF Funding Rates"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get MTF Funding Rates through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get mtf funding rates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Payments","Indexer Controller","Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-exchange-order-meta","method":"GET","path":"/api/v2/exchange/order_meta","title":"MTF: Get MTF Order Details","description":"MTF: Get MTF Order Details through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/order_meta","operation":"MTF: Get MTF Order Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-order-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get MTF Order Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get MTF Order Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get mtf order details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-exchange-orderbook-restrictions","method":"GET","path":"/api/v2/exchange/orderbook_restrictions","title":"MTF: Get MTF Orderbook Restrictions","description":"MTF: Get MTF Orderbook Restrictions through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/orderbook_restrictions","operation":"MTF: Get MTF Orderbook Restrictions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-orderbook-restrictions","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get MTF Orderbook Restrictions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get MTF Orderbook Restrictions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get mtf orderbook restrictions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-exchange-trade-meta","method":"GET","path":"/api/v2/exchange/trade_meta","title":"MTF: Get MTF Trade Details","description":"MTF: Get MTF Trade Details through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/trade_meta","operation":"MTF: Get MTF Trade Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-trade-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get MTF Trade Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get MTF Trade Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get mtf trade details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-exchange-trades","method":"GET","path":"/api/v2/exchange/trades","title":"MTF: Get all MTF Trades","description":"MTF: Get all MTF Trades through the canonical Hybrid-Chain V2 interface.","chapter":"Securities Trading","chapterOrder":8,"capability":"Securities Trading","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/exchange/trades","operation":"MTF: Get all MTF Trades"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-exchange-trades","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all MTF Trades"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"MTF: Get all MTF Trades through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all mtf trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"post-api-v2-virtex-cancel","method":"POST","path":"/api/v2/virtex/cancel","title":"VIRTUAL: Cancel Virtual Order","description":"VIRTUAL: Cancel Virtual Order through the canonical Hybrid-Chain V2 interface.","chapter":"Virtual Exchange","chapterOrder":9,"capability":"Virtual Exchange","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/virtex/cancel","operation":"VIRTUAL: Cancel Virtual Order"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-virtex-cancel","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel Virtual Order"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-virtex-cancel-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel virtual order. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"VIRTUAL: Cancel Virtual Order through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel virtual order.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"post-api-v2-virtex-cancel-all","method":"POST","path":"/api/v2/virtex/cancel_all","title":"VIRTUAL: Cancel all Virtual Orders","description":"VIRTUAL: Cancel all Virtual Orders through the canonical Hybrid-Chain V2 interface.","chapter":"Virtual Exchange","chapterOrder":9,"capability":"Virtual Exchange","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/virtex/cancel_all","operation":"VIRTUAL: Cancel all Virtual Orders"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-virtex-cancel-all","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel all Virtual Orders"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-virtex-cancel-all-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel all virtual orders. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"VIRTUAL: Cancel all Virtual Orders through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel all virtual orders.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-virtex-order-meta","method":"GET","path":"/api/v2/virtex/order_meta","title":"VIRTUAL: Get Virtual Order Details","description":"VIRTUAL: Get Virtual Order Details through the canonical Hybrid-Chain V2 interface.","chapter":"Virtual Exchange","chapterOrder":9,"capability":"Virtual Exchange","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/virtex/order_meta","operation":"VIRTUAL: Get Virtual Order Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-virtex-order-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Virtual Order Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"VIRTUAL: Get Virtual Order Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get virtual order details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-virtex-trade-meta","method":"GET","path":"/api/v2/virtex/trade_meta","title":"VIRTUAL: Get Virtual Trade Details","description":"VIRTUAL: Get Virtual Trade Details through the canonical Hybrid-Chain V2 interface.","chapter":"Virtual Exchange","chapterOrder":9,"capability":"Virtual Exchange","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/virtex/trade_meta","operation":"VIRTUAL: Get Virtual Trade Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-virtex-trade-meta","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Virtual Trade Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"VIRTUAL: Get Virtual Trade Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get virtual trade details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-virtex-trades","method":"GET","path":"/api/v2/virtex/trades","title":"VIRTUAL: Get all Virtual Trades","description":"VIRTUAL: Get all Virtual Trades through the canonical Hybrid-Chain V2 interface.","chapter":"Virtual Exchange","chapterOrder":9,"capability":"Virtual Exchange","owners":["matching-and-trading-read-model"],"applications":["Trading"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/virtex/trades","operation":"VIRTUAL: Get all Virtual Trades"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-virtex-trades","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Virtual Trades"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"VIRTUAL: Get all Virtual Trades through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all virtual trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-asset-collections","method":"GET","path":"/api/v2/asset-collections","title":"ASSETS: List collections","description":"List digital-asset collections and publication state.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-collections","source":"Core Handler_AssetCollections public collection projection via the gateway BrowseAssetCollections port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1asset-collections/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List collections"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque offset cursor","description":"Cursor returned by the preceding page; valid only with the same status and q filters.","example":"offset-24"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public collections to return; defaults to 24.","example":24},{"name":"status","location":"query","required":false,"type":"canonical lifecycle state · max 32","description":"Case-insensitive exact lifecycle-state filter. The current public projection admits ACTIVE collections.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · 1–200","description":"Case-insensitive search across collection name, description, and category code.","example":"renewable"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List digital-asset collections and publication state.","whenToUse":"Use to discover public ACTIVE collection identities and metadata commitments before filtering or selecting published assets.","workflowRole":"discover-or-read","sideEffects":"Read-only public collection projection. It cannot publish a private collection, create or mint an asset, expose issuer-private metadata, set royalties, price an item, or grant marketplace authority.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Reuse next_cursor only with the same status and q filters. category_code is a server-governed discovery label, not a compliance, security, or investment classification.","A public collection does not imply that every member asset is public, minted, listed, transferable, eligible, or available for trading. Resolve each asset separately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-collections","method":"POST","path":"/api/v2/asset-collections","title":"ASSETS: Create collection","description":"Create a collection with authority, metadata, royalty, and visibility policy.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-collections","scope":"assets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create collection"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-collections-request-001"},{"name":"name","location":"body","required":true,"type":"string","description":"Collection name.","example":"name-01"},{"name":"slug","location":"body","required":true,"type":"URL-safe string","description":"Workspace-unique collection slug.","example":"slug-01"},{"name":"description","location":"body","required":false,"type":"string","description":"Collection purpose.","example":"description-01"},{"name":"royalty_bps","location":"body","required":true,"type":"integer · 0–10000","description":"Secondary-sale royalty.","example":1},{"name":"metadata","location":"body","required":true,"type":"object","description":"Canonical public metadata.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a collection with authority, metadata, royalty, and visibility policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create collection.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-asset-collections-collection-uuid","method":"GET","path":"/api/v2/asset-collections/{collection_uuid}","title":"ASSETS: Get collection","description":"Return one public collection identity, classification, metadata commitment, and lifecycle state.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-collections/{collection_uuid}","source":"Core Handler_AssetCollections public collection detail via the gateway ReadAssetCollection port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1asset-collections~1{collection_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get collection"],"parameters":[{"name":"collection_uuid","location":"path","required":true,"type":"identifier","description":"Canonical collection uuid.","example":"collection-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one public collection identity, classification, metadata commitment, and lifecycle state.","whenToUse":"Use after collection discovery when an integration needs one public collection's canonical identity, category, metadata commitment, lifecycle state, and display fields.","workflowRole":"discover-or-read","sideEffects":"Read-only public projection. It excludes private issuer records, arbitrary metadata, pricing, holdings, listings, payment state, and authority selectors.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Use collection_uuid as the stable identity and metadata_hash as the integrity commitment. image_uri is optional presentation content and is not provenance evidence.","Resolve collection member assets through GET /api/v2/assets with the relevant filters and verify each asset's own lifecycle and proof chain.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-collections-collection-uuid-publications","method":"POST","path":"/api/v2/asset-collections/{collection_uuid}/publications","title":"ASSETS: Publish collection","description":"Publish an eligible collection and freeze its public identity.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-collections-collection-uuid-publications","scope":"assets:publish","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Publish collection"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:publish authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-collections-collection-uuid-publications-request-001"},{"name":"collection_uuid","location":"path","required":true,"type":"identifier","description":"Canonical collection uuid.","example":"collection-uuid-01"},{"name":"expected_metadata_hash","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Digest of the exact collection metadata last read by the issuer. Publication fails rather than exposing different metadata.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Optimistic-concurrency version from the current issuer-visible collection projection.","example":3},{"name":"visibility","location":"body","required":true,"type":"PUBLIC","description":"Exact publication transition. This operation does not implement unpublication or visibility toggling.","example":"PUBLIC"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_COLLECTION_PUBLICATION authorization bound to this collection and metadata commitment.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, the exact eligible collection becomes PUBLIC and returns its immutable metadata and publication commitments; an equivalent completed publication is idempotent.","example":null},{"status":400,"description":"The metadata hash, version, visibility, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:publish, issuer ownership, or fresh ASSET_COLLECTION_PUBLICATION authority.","example":null},{"status":404,"description":"The collection does not exist in the authenticated issuer and network boundary.","example":null},{"status":409,"description":"Metadata or version is stale, lifecycle is ineligible, publication conflicts with retained state, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Metadata, compliance, network, royalty, authority, or publication policy validation failed.","example":null},{"status":503,"description":"The asset registry, evidence owner, or publisher is unavailable; the collection remains private.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Publish an eligible collection and freeze its public identity.","whenToUse":"Do not call this planning route yet. It reserves a one-way reviewed publication of one issuer-owned private collection after its metadata, royalty, authority, and compliance posture are final.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would make the exact committed collection identity publicly discoverable and append publication evidence; it would not mint assets, move holdings, create listings, or enable trading.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:publish authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Read the current issuer-visible collection immediately before submission and bind both expected_metadata_hash and expected_version. On 409, re-read and re-review instead of publishing newer metadata accidentally.","visibility is exactly PUBLIC. Unpublication, arbitrary visibility toggling, and overwriting a published identity are intentionally excluded; corrections require a separately governed, version-aware lifecycle.","Publication must verify issuer ownership, active network, royalty bounds, metadata safety and commitment, referenced authorities, compliance policy, and absence of unresolved review holds while locked.","Promotion requires assets:publish, ASSET_COLLECTION_PUBLICATION step-up, RFC 9421 signing, idempotency, immutable evidence, public projection consistency, and failure tests proving private state on every error.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-asset-listings","method":"GET","path":"/api/v2/asset-listings","title":"ASSETS: List market listings","description":"List active and historical asset listings, orders, and settlement posture.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-asset-listings","scope":"assets:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List market listings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List active and historical asset listings, orders, and settlement posture.","whenToUse":"Use this operation when an integration needs to list market listings before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-listings","method":"POST","path":"/api/v2/asset-listings","title":"ASSETS: Create listing","description":"Create a signed asset listing with quantity, unit price, settlement currencies, tolerance, and expiry.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-listings","scope":"assets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create listing"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-listings-request-001"},{"name":"asset_uuid","location":"body","required":true,"type":"identifier","description":"Asset offered.","example":"asset-uuid-01"},{"name":"quantity","location":"body","required":true,"type":"decimal string","description":"Offered quantity.","example":"10.00"},{"name":"unit_price","location":"body","required":true,"type":"decimal string","description":"Unit price.","example":"10.00"},{"name":"base_currency","location":"body","required":true,"type":"asset or ISO currency","description":"Listing denomination.","example":"base-currency-01"},{"name":"accepted_settlement_currencies","location":"body","required":true,"type":"string[]","description":"Accepted settlement assets.","example":[]},{"name":"settlement_tolerance_bps","location":"body","required":true,"type":"integer · 0–10000","description":"Permitted conversion slippage.","example":1},{"name":"expires_at","location":"body","required":false,"type":"RFC 3339 timestamp","description":"Listing expiry.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a signed asset listing with quantity, unit price, settlement currencies, tolerance, and expiry.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create listing.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-listings-listing-uuid-cancellations","method":"POST","path":"/api/v2/asset-listings/{listing_uuid}/cancellations","title":"ASSETS: Cancel listing","description":"Cancel an active listing and preserve an immutable lifecycle record.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-listings-listing-uuid-cancellations","scope":"assets:list","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Cancel listing"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:list authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-listings-listing-uuid-cancellations-request-001"},{"name":"listing_uuid","location":"path","required":true,"type":"identifier","description":"Canonical listing uuid.","example":"listing-uuid-01"},{"name":"expected_listing_version","location":"body","required":true,"type":"integer · ≥1","description":"Current listing version used to prevent cancellation of revised terms.","example":4},{"name":"expected_status","location":"body","required":true,"type":"ACTIVE | PAUSED","description":"Last issuer-visible cancellable lifecycle state.","example":"ACTIVE"},{"name":"reason_code","location":"body","required":true,"type":"SELLER_CANCELLED | TERMS_CHANGED | INVENTORY_UNAVAILABLE | COMPLIANCE_HOLD","description":"Structured cancellation reason retained in lifecycle evidence.","example":"SELLER_CANCELLED"},{"name":"reason_detail","location":"body","required":false,"type":"string · 8–500","description":"Optional non-secret explanation. It must not contain credentials, customer evidence, or regulated identity data.","example":"Seller withdrew the current terms."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_LISTING_CANCELLATION authorization bound to the listing version and reason.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, the eligible listing is CANCELLED, reservations are released according to policy, and immutable cancellation evidence is returned; an equivalent completed cancellation is idempotent.","example":null},{"status":400,"description":"The version, expected state, reason, detail, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:list, seller ownership, compliance authority for its reason, or fresh ASSET_LISTING_CANCELLATION authorization.","example":null},{"status":404,"description":"The listing does not exist in the authenticated seller and network boundary.","example":null},{"status":409,"description":"Listing version or state is stale, an order already consumed reserved inventory, cancellation is terminal, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"The reason, inventory release, active-order, compliance, evidence, or lifecycle policy rejected cancellation.","example":null},{"status":503,"description":"The listing owner, holdings reservation, order owner, or evidence ledger is unavailable; listing and inventory state remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an active listing and preserve an immutable lifecycle record.","whenToUse":"Do not call this planning route yet. It reserves seller- or compliance-authorized cancellation of one exact ACTIVE or PAUSED listing after current version, open orders, and inventory reservations are reconciled.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would mark the listing CANCELLED, release only eligible unconsumed reservations, and append cancellation evidence; it would not cancel paid orders, reverse delivery, refund payment, or alter asset supply.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:list authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Read the current listing and its open orders immediately before cancellation. Bind expected_listing_version and expected_status; a replacement, accepted order, delivery transition, or stale read must fail with 409.","The bearer identifies the seller. Never send seller, owner, workspace, vault, wallet, or database selectors. COMPLIANCE_HOLD additionally requires the configured compliance authority and retained reason policy.","An already completed equivalent cancellation is idempotent. After an ambiguous response, re-read the listing, reservations, and affected orders before reusing the same Idempotency-Key and body.","Promotion requires assets:list, ASSET_LISTING_CANCELLATION step-up, seller isolation, version locking, order and reservation reconciliation, atomic release and evidence, notification policy, and no-paid-order cancellation tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-listings-listing-uuid-replacements","method":"POST","path":"/api/v2/asset-listings/{listing_uuid}/replacements","title":"ASSETS: Replace listing","description":"Atomically cancel and replace an active listing with revised market terms.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-listings-listing-uuid-replacements","scope":"assets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Replace listing"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-listings-listing-uuid-replacements-request-001"},{"name":"listing_uuid","location":"path","required":true,"type":"identifier","description":"Canonical listing uuid.","example":"listing-uuid-01"},{"name":"quantity","location":"body","required":false,"type":"decimal string","description":"Replacement quantity.","example":"10.00"},{"name":"unit_price","location":"body","required":false,"type":"decimal string","description":"Replacement unit or limit price.","example":"10.00"},{"name":"reason","location":"body","required":true,"type":"string","description":"Audit rationale for replacement.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically cancel and replace an active listing with revised market terms.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to replace listing.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-asset-market-orders-order-uuid-reconciliations","method":"POST","path":"/api/v2/asset-market-orders/{order_uuid}/reconciliations","title":"ASSETS: Reconcile market delivery","description":"Verify one Commerce-owned payment confirmation against an asset-market order and, only when every immutable term matches, request atomic delivery of the order's reserved items.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Funding","Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-asset-market-orders-order-uuid-reconciliations","scope":"assets:reconcile","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Reconcile market delivery"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:reconcile authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-asset-market-orders-order-uuid-reconciliations-request-001"},{"name":"order_uuid","location":"path","required":true,"type":"identifier","description":"Canonical order uuid.","example":"order-uuid-01"},{"name":"payment_confirmation_uuid","location":"body","required":true,"type":"identifier","description":"Stable confirmation issued by the authoritative Commerce payment owner. Caller-authored payment status, amount, or recipient fields are forbidden.","example":"pay-confirmation-01"},{"name":"payment_confirmation_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Commitment to the exact signed Commerce confirmation being reconciled.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"expected_order_state","location":"body","required":true,"type":"PAYMENT_PENDING | PAID","description":"Last state read from this owner-visible order. FULFILLED is reconciled by reading the order rather than replaying delivery.","example":"PAYMENT_PENDING"},{"name":"expected_order_version","location":"body","required":true,"type":"integer · ≥1","description":"Optimistic-concurrency version from the latest order projection.","example":4},{"name":"reconciliation_mode","location":"body","required":true,"type":"VERIFY_ONLY | DELIVER_IF_MATCHED","description":"VERIFY_ONLY reports deterministic differences. DELIVER_IF_MATCHED may request atomic reserved-item delivery only after every payment and order invariant matches.","example":"VERIFY_ONLY"},{"name":"evidence_references","location":"body","required":false,"type":"identifier[] · max 20","description":"Commitment-safe references to retained Commerce or chain evidence. Raw receipts, credentials, customer data, and secrets are forbidden.","example":["commerce-evidence-01"]},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_MARKET_ORDER_RECONCILIATION authorization required even for VERIFY_ONLY so evidence access and any delivery transition share one explicit authority boundary.","example":"hcsu_…"}],"responses":[{"status":202,"description":"When promoted, a reconciliation receipt reports verified payment and order commitments, deterministic differences, and whether atomic delivery was requested; acceptance is not fulfillment.","example":null},{"status":400,"description":"The confirmation reference, commitment, mode, evidence references, signature, step-up token, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:reconcile, order visibility, or fresh ASSET_MARKET_ORDER_RECONCILIATION authority.","example":null},{"status":404,"description":"The order or Commerce-owned payment confirmation does not exist in the authenticated owner boundary.","example":null},{"status":409,"description":"Order version or state is stale, payment terms do not exactly match, inventory is no longer reserved, delivery is already final, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"The authoritative confirmation fails signature, amount, currency, recipient, finality, network, or evidence policy.","example":null},{"status":503,"description":"Commerce confirmation, asset ledger, evidence owner, or atomic delivery is unavailable; no asset state changes.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Verify one Commerce-owned payment confirmation against an asset-market order and, only when every immutable term matches, request atomic delivery of the order's reserved items.","whenToUse":"Do not call this planning route yet. It reserves a service-evidence reconciliation boundary between a Commerce-owned payment confirmation and one reserved digital-asset market order.","workflowRole":"create-or-command","sideEffects":"No executable public reconciliation exists. A future DELIVER_IF_MATCHED transition would atomically debit seller holdings, credit buyer holdings, finalize reserved items, and retain linked payment and delivery proofs only after every immutable term matches.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with assets:reconcile authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Never accept caller-authored paid, confirmed, amount, currency, buyer, seller, or transfer facts as payment authority. Resolve and verify payment_confirmation_uuid at the authoritative Commerce owner and compare its signed commitment.","VERIFY_ONLY must change nothing. DELIVER_IF_MATCHED must lock the order and every reserved holding, re-check version, state, item quantities, subtotal, currency, settlement tolerance, network, and final payment evidence, then commit delivery and proof records atomically.","HTTP 202 would mean reconciliation work was accepted, not that payment is final or assets were delivered. Re-read the order and verify its retained payment and delivery proof commitments.","Promotion requires assets:reconcile, purpose-bound step-up, Commerce service authentication, payment-finality rules, owner and network isolation, optimistic concurrency, duplicate prevention, reservation recovery, atomic delivery, immutable evidence, and failure-injection tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller","Strategy Pools","Liquidity Management","Trading & Matching Ops"]}},{"id":"get-api-v2-asset-mints-mint-uuid","method":"GET","path":"/api/v2/asset-mints/{mint_uuid}","title":"ASSETS: Get mint evidence","description":"Return one minimized mint receipt and its cross-checked public proof.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mints/{mint_uuid}","source":"Core Handler_Assets public mint evidence via the gateway ReadPublicAssetMint port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1asset-mints~1{mint_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get mint evidence"],"parameters":[{"name":"mint_uuid","location":"path","required":true,"type":"identifier","description":"Canonical mint uuid.","example":"mint-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one minimized mint receipt and its cross-checked public proof.","whenToUse":"Use when an integration has a canonical mint UUID and needs the exact public quantity, lifecycle state, timestamps, and cross-checked retained proof for issuance reconciliation.","workflowRole":"discover-or-read","sideEffects":"Read-only public receipt. It cannot issue or transfer supply, establish holder ownership, prove payment, or confer issuer or mint authority.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Preserve quantity as an exact decimal string and interpret it with the referenced asset's decimals. The gateway rejects a mint whose proof event or subject does not match the mint and asset identifiers.","A completed mint proves a source issuance event, not current circulating supply, reserve, holder balance, market availability, price, or redemption eligibility. Reconcile those independently where authoritative contracts exist.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-asset-proofs-proof-uuid","method":"GET","path":"/api/v2/asset-proofs/{proof_uuid}","title":"ASSETS: Get asset proof","description":"Return one retained public asset proof for independent verification and audit correlation.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-proofs/{proof_uuid}","source":"Core Handler_Assets public proof detail via the gateway ReadPublicAssetProof port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1asset-proofs~1{proof_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get asset proof"],"parameters":[{"name":"proof_uuid","location":"path","required":true,"type":"identifier","description":"Canonical proof uuid.","example":"proof-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one retained public asset proof for independent verification and audit correlation.","whenToUse":"Use when a receipt, audit record, or lifecycle event already references one canonical proof UUID and the integration needs that exact public verification record.","workflowRole":"discover-or-read","sideEffects":"Read-only public evidence. Resolving a proof changes no asset, supply, holding, listing, payment, or authority state.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Cross-check proof_uuid with the requested identifier and bind the returned subject_uuid and event_uuid to the business record being verified. Never accept a proof merely because its signature field is non-empty.","Resolve the verification key only through the separately governed public trust boundary identified by signature_key_id; never accept caller-supplied replacement key material.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-assets","method":"GET","path":"/api/v2/assets","title":"ASSETS: List assets","description":"List published asset identities, exact supply projections, lifecycle state, and collection membership.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets","source":"Core Handler_Assets public asset projection via the gateway BrowsePublicAssets port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1assets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List assets"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque offset cursor","description":"Cursor returned by the preceding page; valid only with the same status, asset_type, and q filters.","example":"offset-24"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public assets to return; defaults to 24.","example":24},{"name":"status","location":"query","required":false,"type":"canonical lifecycle state · max 32","description":"Case-insensitive exact lifecycle-state filter such as PUBLISHED.","example":"PUBLISHED"},{"name":"asset_type","location":"query","required":false,"type":"canonical asset classification · max 64","description":"Case-insensitive exact classification filter such as SECURITY_TOKEN, FUNGIBLE_TOKEN, CERTIFICATE, or COLLECTIBLE.","example":"SECURITY_TOKEN"},{"name":"q","location":"query","required":false,"type":"string · 1–200","description":"Case-insensitive search across asset UUID, name, symbol, and public description.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List published asset identities, exact supply projections, lifecycle state, and collection membership.","whenToUse":"Use this implemented public catalog to discover published tokens and digital assets by lifecycle, classification, identifier, name, symbol, or description before selecting a specific asset.","workflowRole":"discover-or-read","sideEffects":"Read-only, public, minimized projection. It cannot create an asset, reveal private drafts or holders, issue supply, produce a quote, calculate buying power, redeem holdings, create a listing, move value, or grant authority.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Use asset_uuid as the stable identity; symbols and names are presentation fields and may not be globally unique. Preserve maximum_supply and minted_supply as exact decimal strings and interpret them using decimals.","Reuse next_cursor only with the same status, asset_type, and q filters. Null base_currency, media_uri, or published_at means the public source did not provide that optional value; do not invent one.","This route replaces legacy token availability and most token-detail discovery. It deliberately excludes live quote, performance, buying-power, redemption, private issuer, vault, holding, listing, and custody state.","Collection publication, asset publication, minting, holdings, listing, payment, delivery, and trading are separate lifecycles. A catalog record authorizes none of them.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-assets","method":"POST","path":"/api/v2/assets","title":"ASSETS: Issue asset","description":"Create an asset issuance intent with supply, precision, authority, metadata, and compliance policy.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-assets","scope":"assets:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Issue asset"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-assets-request-001"},{"name":"name","location":"body","required":true,"type":"string","description":"Asset name.","example":"name-01"},{"name":"symbol","location":"body","required":true,"type":"string","description":"Unique display symbol.","example":"symbol-01"},{"name":"asset_type","location":"body","required":true,"type":"identifier","description":"Fungible, non-fungible, security, or platform asset class.","example":"asset-type-01"},{"name":"initial_supply","location":"body","required":true,"type":"decimal string","description":"Initial supply.","example":"10.00"},{"name":"decimals","location":"body","required":true,"type":"integer · 0–18","description":"Display precision.","example":1},{"name":"collection_uuid","location":"body","required":false,"type":"identifier","description":"Optional parent collection.","example":"collection-uuid-01"},{"name":"metadata","location":"body","required":true,"type":"object","description":"Canonical public metadata.","example":{}},{"name":"authorities","location":"body","required":true,"type":"object","description":"Issuance, mint, burn, pause, and recovery authorities.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an asset issuance intent with supply, precision, authority, metadata, and compliance policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to issue asset.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-assets-asset-uuid","method":"GET","path":"/api/v2/assets/{asset_uuid}","title":"ASSETS: Get asset","description":"Return canonical public metadata, precision, exact supply projection, collection binding, lifecycle state, and timestamps.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}","source":"Core Handler_Assets public asset detail via the gateway ReadPublicAsset port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1assets~1{asset_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get asset"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return canonical public metadata, precision, exact supply projection, collection binding, lifecycle state, and timestamps.","whenToUse":"Use after catalog discovery when an integration needs one published asset's canonical identity, collection binding, precision, exact supply projection, metadata commitment, lifecycle state, and public timestamps.","workflowRole":"discover-or-read","sideEffects":"Read-only, public, minimized projection. It exposes no issuer-private record, owner balance, holding, listing, quote, custody selector, mint key, redemption address, or transfer authority.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Treat metadata_hash as a commitment to separately governed metadata, not as the metadata itself. Treat media_uri as display content only and never as provenance or lifecycle proof.","maximum_supply and minted_supply are exact decimal strings. Never parse them through binary floating point; use decimals and enforce the published decimals scale.","For inventory or issuance verification, follow with the implemented history and proof reads. For current market price or owner buying power, use their separately owned contracts only when present in live OpenAPI.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-assets-asset-uuid-burns","method":"POST","path":"/api/v2/assets/{asset_uuid}/burns","title":"ASSETS: Burn asset","description":"Create a governed burn operation against eligible holdings.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-assets-asset-uuid-burns","scope":"assets:supply","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Burn asset"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:supply authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-assets-asset-uuid-burns-request-001"},{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"},{"name":"holding_reference","location":"body","required":true,"type":"owner-safe holding identifier","description":"Opaque eligible holding to debit. The authoritative owner resolves its subject, network, asset, and available balance.","example":"holding-01"},{"name":"quantity","location":"body","required":true,"type":"positive exact decimal string","description":"Quantity to retire without floating-point conversion; it cannot exceed the locked available holding.","example":"5.00000000"},{"name":"expected_asset_version","location":"body","required":true,"type":"integer · ≥1","description":"Current asset version used for optimistic concurrency.","example":8},{"name":"expected_holding_balance","location":"body","required":true,"type":"non-negative exact decimal string","description":"Available balance last read for the holding; a stale value fails closed.","example":"25.00000000"},{"name":"reason_code","location":"body","required":true,"type":"RETIRE | REDEEM | CORRECT_ISSUANCE | GOVERNANCE","description":"Structured reason governing eligibility, evidence, notification, and accounting treatment.","example":"REDEEM"},{"name":"evidence_commitment","location":"body","required":false,"type":"64-character hexadecimal SHA-256 digest","description":"Commitment to separately retained redemption, correction, or governance evidence. Raw evidence and credentials are forbidden.","example":"eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_BURN authorization bound to the exact holding, quantity, asset version, balance, and reason.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, eligible supply is atomically retired and the resulting total supply, holding balance, reason, and evidence commitments are returned.","example":null},{"status":400,"description":"The holding, decimal quantity, version, expected balance, reason, evidence commitment, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:supply, burn authority over the holding, or fresh ASSET_BURN authorization.","example":null},{"status":404,"description":"The asset, holding, subject authority, or referenced evidence does not exist in the allowed owner and network boundary.","example":null},{"status":409,"description":"Asset version or holding balance is stale, lifecycle or reason is ineligible, quantity is unavailable, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Precision, supply floor, balance, reason-specific evidence, compliance, authority, or accounting policy validation failed.","example":null},{"status":503,"description":"The asset registry, holdings ledger, evidence owner, or atomic transaction boundary is unavailable; supply and holdings are unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a governed burn operation against eligible holdings.","whenToUse":"Do not call this planning route yet. It reserves exact-decimal retirement of an eligible holding for redemption, retirement, correction, or separately approved governance after current supply and balance are reconciled.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would atomically debit the exact holding, reduce total supply, and append reason-bound evidence; it could not create negative balances, reverse another transfer, or erase historical ownership.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:supply authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Read the asset and holding immediately before submission. Bind expected_asset_version and expected_holding_balance; on 409, re-read and form a new intent rather than burning against stale state.","The holding owner, issuer, and governance eligibility depend on reason_code. The authoritative owner must enforce the applicable consent, redemption evidence, correction authority, legal hold, compliance, and accounting policy.","evidence_commitment references separately retained evidence only. Raw identity evidence, receipts containing customer data, credentials, private keys, seeds, MPC material, and secrets are forbidden.","Promotion requires assets:supply, ASSET_BURN step-up, locked non-negative supply and balance invariants, reason-specific authority, immutable history, idempotency, and rollback tests across holding, supply, accounting, and evidence owners.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-assets-asset-uuid-history","method":"GET","path":"/api/v2/assets/{asset_uuid}/history","title":"ASSETS: List asset history","description":"Return ordered, minimized public lifecycle events for one published asset.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}/history","source":"Core Handler_Assets ordered public lifecycle projection via the gateway ReadPublicAssetHistory port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1assets~1{asset_uuid}~1history/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List asset history"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return ordered, minimized public lifecycle events for one published asset.","whenToUse":"Use to reconcile the ordered public lifecycle of one published asset after resolving its canonical asset_uuid.","workflowRole":"discover-or-read","sideEffects":"Read-only public evidence. It cannot replay an event, infer a private holding, authorize a mutation, reverse history, or establish payment, delivery, redemption, or settlement finality.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Events are ordered oldest to newest with event_uuid as the deterministic tie-breaker. Quantity is optional and remains an exact decimal string when the event is quantitative.","Use event_type as a server-issued classification, then verify consequential events through their retained proofs. Absence from a bounded public history is not proof that a private or unrelated event never existed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-assets-asset-uuid-mints","method":"POST","path":"/api/v2/assets/{asset_uuid}/mints","title":"ASSETS: Mint asset","description":"Create a governed mint operation within the asset's cap and authority policy.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-assets-asset-uuid-mints","scope":"assets:supply","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Mint asset"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:supply authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-assets-asset-uuid-mints-request-001"},{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"},{"name":"recipient_reference","location":"body","required":true,"type":"owner-safe wallet or holding reference","description":"Opaque recipient reference resolved by the asset owner. Raw profile selectors, private keys, seeds, and custody credentials are forbidden.","example":"recipient-wallet-01"},{"name":"quantity","location":"body","required":true,"type":"positive exact decimal string","description":"Quantity to issue without floating-point conversion; scale must fit the asset precision.","example":"25.00000000"},{"name":"expected_asset_version","location":"body","required":true,"type":"integer · ≥1","description":"Current asset version used for optimistic concurrency.","example":7},{"name":"expected_total_supply","location":"body","required":true,"type":"non-negative exact decimal string","description":"Total supply last read by the issuer; cap and concurrent-mint checks are performed while locked.","example":"1000.00000000"},{"name":"commerce_order_reference","location":"body","required":false,"type":"identifier","description":"Optional Commerce-owned issuance or purchase reference. It grants no payment authority and must be supplied with its commitment.","example":"commerce-order-01"},{"name":"commerce_order_commitment","location":"body","required":false,"type":"64-character hexadecimal SHA-256 digest","description":"Optional commitment to the exact authoritative Commerce order; required when commerce_order_reference is present.","example":"dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_MINT authorization bound to asset, recipient, quantity, supply expectation, and optional Commerce evidence.","example":"hcsu_…"}],"responses":[{"status":201,"description":"When promoted, an atomic mint receipt returns the issued quantity, resulting total supply and holding balance, and retained authority and evidence commitments.","example":null},{"status":200,"description":"The same Idempotency-Key and byte-equivalent completed mint are replayed without issuing supply twice.","example":null},{"status":400,"description":"The recipient, decimal quantity, version, expected supply, optional Commerce pair, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:supply, active mint authority, or fresh ASSET_MINT authorization.","example":null},{"status":404,"description":"The asset, recipient, mint authority, or referenced Commerce order was not found in the allowed network boundary.","example":null},{"status":409,"description":"Asset version or supply is stale, recipient or lifecycle is ineligible, the cap would be exceeded, Commerce terms differ, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Precision, quantity, cap, compliance, authority, recipient, network, or evidence policy validation failed.","example":null},{"status":503,"description":"The asset registry, holdings ledger, Commerce owner, evidence owner, or atomic transaction boundary is unavailable; supply is unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a governed mint operation within the asset's cap and authority policy.","whenToUse":"Do not call this planning route yet. It reserves governed issuance of additional exact-decimal supply to one eligible recipient after re-reading asset, authority, cap, and current supply state.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would atomically increase total supply and the resolved recipient holding and append mint evidence; it would not infer payment, publish the asset, list it, or move any unrelated value.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:supply authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Preserve quantity and expected_total_supply as exact decimal strings. The owner must lock asset and holding rows, enforce precision and cap, and reject stale supply rather than silently minting against newer state.","recipient_reference is resolved inside the authoritative owner and grants no access to another subject. Never submit profile IDs, database keys, private keys, seeds, MPC shares, signing nonces, or custody credentials.","If minting is linked to commerce, send both the opaque Commerce order reference and its commitment. The owner must verify authoritative terms; caller-authored paid, amount, currency, recipient, or completion fields are forbidden.","Promotion requires assets:supply, active issuer mint authority, ASSET_MINT step-up, RFC 9421 signing, recipient eligibility, cap and compliance enforcement, idempotency, atomic supply/holding/evidence changes, and duplicate/failure injection tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-assets-asset-uuid-proofs","method":"GET","path":"/api/v2/assets/{asset_uuid}/proofs","title":"ASSETS: List asset proofs","description":"Return the retained public proof chain for one published asset.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["asset-registry-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}/proofs","source":"Core Handler_Assets public proof-chain projection via the gateway ReadPublicAssetProofs port"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1assets~1{asset_uuid}~1proofs/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List asset proofs"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the retained public proof chain for one published asset.","whenToUse":"Use when an integration must verify retained public commitments for one published asset rather than trusting display metadata or lifecycle labels.","workflowRole":"discover-or-read","sideEffects":"Read-only public evidence. A proof signature is not a bearer, signing credential, mint key, custody key, or permission to perform the evidenced action.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Validate payload_hash, previous_proof_hash, event_uuid, subject_uuid, collection_uuid, network, signature_algorithm, signature_key_id, signature, status, and timestamps under the owner's published verification policy.","Do not treat a syntactically valid signature as current business eligibility. Reconcile revocation, key status, network, lifecycle, and the exact subject and event before relying on the proof.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-assets-asset-uuid-publications","method":"POST","path":"/api/v2/assets/{asset_uuid}/publications","title":"ASSETS: Publish asset","description":"Publish an eligible asset and its immutable public metadata.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Digital assets","owners":["asset-registry-service"],"applications":["Trading","Digital Assets"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-assets-asset-uuid-publications","scope":"assets:publish","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Publish asset"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:publish authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-assets-asset-uuid-publications-request-001"},{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"},{"name":"expected_metadata_hash","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Digest of the exact asset metadata last read by the issuer.","example":"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"},{"name":"expected_collection_publication_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Commitment proving the owning collection is already PUBLIC and ACTIVE under the same network policy.","example":"cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Optimistic-concurrency version from the current issuer-visible asset projection.","example":5},{"name":"visibility","location":"body","required":true,"type":"PUBLIC","description":"Exact publication transition. This operation never changes supply or ownership.","example":"PUBLIC"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ASSET_PUBLICATION authorization bound to this asset and its immutable publication commitments.","example":"hcsu_…"}],"responses":[{"status":200,"description":"When promoted, the exact eligible asset becomes PUBLIC and returns immutable asset, collection, and publication commitments; supply and ownership are unchanged.","example":null},{"status":400,"description":"The metadata hash, collection commitment, version, visibility, step-up token, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks assets:publish, issuer ownership, or fresh ASSET_PUBLICATION authority.","example":null},{"status":404,"description":"The asset or owning collection does not exist in the authenticated issuer and network boundary.","example":null},{"status":409,"description":"Asset metadata or version is stale, the collection is not PUBLIC and ACTIVE, the asset lifecycle is ineligible, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Metadata, collection binding, supply disclosure, compliance, authority, or publication policy validation failed.","example":null},{"status":503,"description":"The asset registry, collection owner, evidence owner, or publisher is unavailable; the asset remains private.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Publish an eligible asset and its immutable public metadata.","whenToUse":"Do not call this planning route yet. It reserves publication of one issuer-owned asset only after the exact asset metadata and its owning collection are reviewed and immutable for public use.","workflowRole":"create-or-command","sideEffects":"No executable public mutation exists. A future success would expose the asset's committed public identity and publication proof; it would not mint supply, transfer ownership, create a listing, accept payment, or authorize trading.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation"],"prerequisites":["A bearer credential with assets:publish authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Bind the last-read asset metadata hash, asset version, and exact PUBLIC collection commitment. A private, paused, archived, changed, or cross-network collection must fail closed.","Publication is separate from issuance and minting: an asset may be a private draft with zero supply, and publishing that draft must not change total supply or any holding.","Treat public metadata as an immutable referenced identity. Future corrections require an explicit governed revision contract, not replay of this publication command or the legacy publish/unpublish toggle.","Promotion requires assets:publish, ASSET_PUBLICATION step-up, issuer and collection ownership, metadata and policy validation, idempotency, atomic public projection and evidence, and no-partial-publication tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-launchpad-diligence-cases-diligence-case-id-audit-export","method":"GET","path":"/api/v2/launchpad/diligence-cases/{diligence_case_id}/audit-export","title":"LAUNCHPAD: Export review audit record","description":"Export a reconstructable private audit record for one authorized diligence case without widening underlying Data Vault access.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-cases~1{diligence_case_id}~1audit-export/get","scope":"launchpad:review","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Export review audit record"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:review authority.","example":"Bearer hc_live_…"},{"name":"diligence_case_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence case id.","example":"diligence-case-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Export a reconstructable private audit record for one authorized diligence case without widening underlying Data Vault access.","whenToUse":"Use when an authorized auditor or compliance process needs a portable, reconstructable record of one diligence case.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:review authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","The export preserves references and commitments; it does not widen access to protected Data Vault content.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-diligence-cases-diligence-case-id-evidence-views","method":"POST","path":"/api/v2/launchpad/diligence-cases/{diligence_case_id}/evidence-views","title":"LAUNCHPAD: Pin review evidence view","description":"Re-authorize every referenced Data Vault version and freeze the exact evidence view on which a reviewer will make a decision.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-cases~1{diligence_case_id}~1evidence-views/post","scope":"launchpad:review","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Pin review evidence view"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:review authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-diligence-cases-diligence-case-id-evidence-views-request-001"},{"name":"diligence_case_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence case id.","example":"diligence-case-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"Required headers or the canonical source-file digest are missing or malformed.","example":null},{"status":502,"description":"Data Vault omitted or returned an inconsistent exact upload content proof.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Re-authorize every referenced Data Vault version and freeze the exact evidence view on which a reviewer will make a decision.","whenToUse":"Use immediately before a review decision to freeze the complete, re-authorized evidence set the reviewer actually examined.","workflowRole":"create-or-command","sideEffects":"Creates an immutable evidence-view manifest; it does not approve the case or alter source evidence.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:review authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","If evidence changes, create a new view and decide against that new manifest rather than mutating the prior view.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-diligence-cases-diligence-case-id-review-decisions","method":"POST","path":"/api/v2/launchpad/diligence-cases/{diligence_case_id}/review-decisions","title":"LAUNCHPAD: Record review decision","description":"Append an attributed review outcome and rationale against one pinned evidence-view manifest; history is immutable.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-cases~1{diligence_case_id}~1review-decisions/post","scope":"launchpad:review","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record review decision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:review authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-diligence-cases-diligence-case-id-review-decisions-request-001"},{"name":"diligence_case_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence case id.","example":"diligence-case-id-01"},{"name":"evidence_view_manifest_id","location":"body","required":true,"type":"UUID","description":"Exact pinned evidence view on which the judgment is based.","example":"44444444-4444-4444-8444-444444444444"},{"name":"outcome","location":"body","required":true,"type":"ACCEPTED | CHANGE_REQUESTED | QUALIFIED | EXCEPTION_GRANTED","description":"Attributed review outcome.","example":"ACCEPTED"},{"name":"rationale","location":"body","required":true,"type":"string · 1–4000","description":"Retained reviewer rationale.","example":"All required evidence versions were available and internally consistent."},{"name":"change_request_item_ids","location":"body","required":false,"type":"UUID[] · 0–100","description":"Diligence item identifiers requiring revision; used with CHANGE_REQUESTED.","example":[]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Append an attributed review outcome and rationale against one pinned evidence-view manifest; history is immutable.","whenToUse":"Use after examining a pinned evidence view to append the reviewer's attributed outcome, rationale, and any change-requested items.","workflowRole":"create-or-command","sideEffects":"Appends an immutable review decision. It neither edits evidence nor authorizes publication by itself.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:review authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Bind the decision to the exact evidence-view manifest and use change-request item IDs only from this case.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-diligence-cases-diligence-case-id-review-record","method":"GET","path":"/api/v2/launchpad/diligence-cases/{diligence_case_id}/review-record","title":"LAUNCHPAD: Get review record","description":"Return the complete authorized review lineage: requirement version, evidence-view commitments, decisions, and attestations.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-cases~1{diligence_case_id}~1review-record/get","scope":"launchpad:review","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get review record"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:review authority.","example":"Bearer hc_live_…"},{"name":"diligence_case_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence case id.","example":"diligence-case-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the complete authorized review lineage: requirement version, evidence-view commitments, decisions, and attestations.","whenToUse":"Use to inspect the authorized end-to-end diligence lineage before relying on a decision, creating a release, or performing an audit.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:review authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Evaluate requirement version, evidence-view manifest, decisions, attestations, and supersession together.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-diligence-cases-diligence-case-id-submissions","method":"POST","path":"/api/v2/launchpad/diligence-cases/{diligence_case_id}/submissions","title":"LAUNCHPAD: Submit evidence package","description":"Explicitly submit an evidence-complete private diligence case into the reviewer queue at its expected immutable case version.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-cases~1{diligence_case_id}~1submissions/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Submit evidence package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-diligence-cases-diligence-case-id-submissions-request-001"},{"name":"diligence_case_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence case id.","example":"diligence-case-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for submit evidence package. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Explicitly submit an evidence-complete private diligence case into the reviewer queue at its expected immutable case version.","whenToUse":"Use only after every required exact-version evidence item is attached and the issuer is ready to place that case into the reviewer queue.","workflowRole":"create-or-command","sideEffects":"Transitions the exact evidence-complete case version to READY_FOR_REVIEW. It does not approve evidence, create a disclosure, or publish anything.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Treat attachment and submission as separate issuer actions; after an ambiguous response, re-read the workbench before retrying with the same logical intent.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-diligence-items-diligence-item-id-artifact-links","method":"POST","path":"/api/v2/launchpad/diligence-items/{diligence_item_id}/artifact-links","title":"LAUNCHPAD: Link diligence evidence","description":"Attach an exact authorized Data Vault version to one required diligence item after gateway-side evidence re-attestation.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1diligence-items~1{diligence_item_id}~1artifact-links/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Link diligence evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-diligence-items-diligence-item-id-artifact-links-request-001"},{"name":"diligence_item_id","location":"path","required":true,"type":"identifier","description":"Canonical diligence item id.","example":"diligence-item-id-01"},{"name":"object_id","location":"body","required":true,"type":"Data Vault identifier","description":"Authorized Data Vault object selected for this requirement.","example":"vault-object-01J8FQ"},{"name":"version_id","location":"body","required":true,"type":"Data Vault version identifier","description":"Exact immutable object version re-resolved and attested by the gateway.","example":"vault-version-01J8FR"},{"name":"source_sha256","location":"body","required":true,"type":"SHA-256 · lowercase hex","description":"SHA-256 of original document bytes, verified against the exact upload's domain-separated Vault commitment; never an audit-event hash.","example":"dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"Required headers or the canonical source-file digest are missing or malformed.","example":null},{"status":502,"description":"Data Vault omitted or returned an inconsistent exact upload content proof.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Attach an exact authorized Data Vault version to one required diligence item after gateway-side evidence re-attestation.","whenToUse":"Use to satisfy one diligence requirement with an exact authorized Data Vault version before a reviewer pins the evidence view.","workflowRole":"create-or-command","sideEffects":"Appends a case-scoped evidence link after re-attestation; it does not mark the requirement reviewed or accepted.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","A successful link proves referential readiness at that moment, not the truth or sufficiency of the evidence.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-directory","method":"GET","path":"/api/v2/launchpad/directory","title":"LAUNCHPAD: List finalized offerings","description":"Discover offerings only after a signed release reaches validator finality; drafts, diligence evidence, and incomplete submissions remain private.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1directory/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List finalized offerings"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum finalized directory records to return; defaults to 50.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Discover offerings only after a signed release reaches validator finality; drafts, diligence evidence, and incomplete submissions remain private.","whenToUse":"Use to discover offerings whose signed disclosure release has reached validator finality. It is the safe public entry point for listing, search, research, and investor-facing discovery.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Absence means there is no currently discoverable finalized release; never infer private preparation state.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-issuers","method":"POST","path":"/api/v2/launchpad/issuers","title":"LAUNCHPAD: Create issuer","description":"Bind the authenticated workspace's verified company authority to one private issuer record; callers cannot nominate another issuer owner.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1issuers/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create issuer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-issuers-request-001"},{"name":"public_name","location":"body","required":true,"type":"string · 1–200","description":"Public legal or trading name for the issuer. Workspace and company authority are derived from the bearer, never accepted from the body.","example":"Acme Energy, Inc."}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Bind the authenticated workspace's verified company authority to one private issuer record; callers cannot nominate another issuer owner.","whenToUse":"Use once, after the active workspace has verified company authority, to establish the private issuer boundary that owns offering preparation.","workflowRole":"create-or-command","sideEffects":"Creates a private issuer record bound to bearer-derived workspace and company authority. It does not publish an issuer or create a security.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Do not create duplicate issuers to work around an authority or verification failure.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-issuers-issuer-id","method":"GET","path":"/api/v2/launchpad/issuers/{issuer_id}","title":"LAUNCHPAD: Get public issuer","description":"Return the minimized public identity and publication posture of an issuer that has finalized disclosure evidence.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1issuers~1{issuer_id}/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get public issuer"],"parameters":[{"name":"issuer_id","location":"path","required":true,"type":"identifier","description":"Canonical issuer id.","example":"issuer-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the minimized public identity and publication posture of an issuer that has finalized disclosure evidence.","whenToUse":"Use from public discovery to read the minimized issuer identity and publication posture supported by finalized disclosure evidence.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","This projection is not the private issuer workbench and intentionally omits unpublished preparation data.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-issuers-issuer-id-offerings","method":"POST","path":"/api/v2/launchpad/issuers/{issuer_id}/offerings","title":"LAUNCHPAD: Create offering workspace","description":"Create a private offering workspace under the authenticated issuer; this does not publish, issue, mint, list, or trade a security.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1issuers~1{issuer_id}~1offerings/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create offering workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-issuers-issuer-id-offerings-request-001"},{"name":"issuer_id","location":"path","required":true,"type":"identifier","description":"Canonical issuer id.","example":"issuer-id-01"},{"name":"name","location":"body","required":true,"type":"string · 1–200","description":"Private working name for the proposed offering; it is not evidence of issuance, approval, or public availability.","example":"Initial Decentralized Listing"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a private offering workspace under the authenticated issuer; this does not publish, issue, mint, list, or trade a security.","whenToUse":"Use when an authorized issuer is ready to open a private workspace for preparing one proposed offering.","workflowRole":"create-or-command","sideEffects":"Creates a private offering workspace. It does not issue, mint, list, sell, admit, or trade a security.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Create separate offerings for separate disclosure and review lineages.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-issuers-issuer-id-requirement-pack-versions","method":"POST","path":"/api/v2/launchpad/issuers/{issuer_id}/requirement-pack-versions","title":"LAUNCHPAD: Create diligence requirement pack","description":"Freeze a versioned issuer diligence checklist so later edits cannot silently change the requirements governing an existing case.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1issuers~1{issuer_id}~1requirement-pack-versions/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create diligence requirement pack"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-issuers-issuer-id-requirement-pack-versions-request-001"},{"name":"issuer_id","location":"path","required":true,"type":"identifier","description":"Canonical issuer id.","example":"issuer-id-01"},{"name":"pack_key","location":"body","required":true,"type":"identifier · 1–255","description":"Stable issuer-local requirement family key.","example":"ordinary-equity-core"},{"name":"name","location":"body","required":true,"type":"string · 1–200","description":"Human-readable name for this immutable requirement-pack version.","example":"Ordinary Equity Core Due Diligence"},{"name":"requirements","location":"body","required":true,"type":"requirement object[] · 1–100","description":"Ordered requirements. Each item includes requirement_key, title, description, evidence_required, review_required, and ordinal.","example":[{"description":"Current formation, registration, and good-standing evidence.","evidence_required":true,"ordinal":1,"requirement_key":"corporate-existence","review_required":true,"title":"Corporate existence"}]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Freeze a versioned issuer diligence checklist so later edits cannot silently change the requirements governing an existing case.","whenToUse":"Use before opening diligence to freeze the exact ordered evidence and review requirements that will govern a case.","workflowRole":"create-or-command","sideEffects":"Creates an immutable requirement-pack version; later versions do not alter existing diligence cases.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Resolve requirement keys and review obligations before creating the version because it is not edited in place.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-issuers-issuer-id-verified-company-binding","method":"POST","path":"/api/v2/launchpad/issuers/{issuer_id}/verified-company-binding","title":"LAUNCHPAD: Bind verified company to legacy issuer","description":"Migrate one unpublished legacy issuer from its workspace-derived company reference to the authenticated subject's current verified-company authority. The caller supplies only the expected issuer version.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1issuers~1{issuer_id}~1verified-company-binding/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Bind verified company to legacy issuer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-issuers-issuer-id-verified-company-binding-request-001"},{"name":"issuer_id","location":"path","required":true,"type":"identifier","description":"Canonical issuer id.","example":"issuer-id-01"},{"name":"expected_issuer_version","location":"body","required":true,"type":"integer · >=1","description":"Current issuer version used for optimistic concurrency. Company identity, authority source, method, subject, and workspace are derived independently by Gateway and Identity.","example":1}],"responses":[{"status":200,"description":"Legacy issuer is now bound to the authenticated subject's verified-company authority; immutable history and versioning are preserved.","example":null},{"status":400,"description":"Required headers, path identifier, JSON body, or idempotency key are malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks launchpad:write, current workspace authority, or a subject-bound approved corporate Identity assertion.","example":null},{"status":404,"description":"The issuer does not exist in the current workspace.","example":null},{"status":409,"description":"The issuer is nonlegacy, already bound, stale, duplicated, has release history, or conflicts with a prior idempotent command.","example":null},{"status":422,"description":"The derived company authority or retained legacy state is inconsistent.","example":null},{"status":502,"description":"An authoritative dependency returned an invalid response.","example":null},{"status":503,"description":"Identity or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Migrate one unpublished legacy issuer from its workspace-derived company reference to the authenticated subject's current verified-company authority. The caller supplies only the expected issuer version.","whenToUse":"Use once to reconcile an unpublished issuer created before verified-company authority became mandatory.","workflowRole":"create-or-command","sideEffects":"Atomically replaces only the legacy workspace-derived company reference, increments issuer version, and appends an immutable binding event and idempotency receipt. It creates no workspace, folder, evidence, release, publication, security, or trade.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","The browser sends only expected_issuer_version. Gateway derives the current subject-bound corporate approval from Identity and rejects caller-selected company identifiers.","Do not use this route for already verified issuers, issuers with any release history, workspace transfers, company changes, or duplicate legal entities.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-listing-data","method":"GET","path":"/api/v2/launchpad/listing-data","title":"LAUNCHPAD: Read listing folder binding","description":"Resolve the active workspace's Listing Data folder reference without granting sharing or publication access.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1listing-data/get","scope":"vault:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read listing folder binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Resolve the active workspace's Listing Data folder reference without granting sharing or publication access.","whenToUse":"Use to show the Listing Data shortcut only when the active workspace has a stored listing-folder binding.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Resolve the exact folder ID in the active Data Vault. Never substitute a same-name folder or grant publication access.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-listings","method":"GET","path":"/api/v2/launchpad/listings","title":"LAUNCHPAD: List authorized private listings","description":"List listing names and workspace identifiers across live Account/Identity memberships. Discovery grants no file, mutation or publication authority.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1listings/get","scope":"vault:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List authorized private listings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List listing names and workspace identifiers across live Account/Identity memberships. Discovery grants no file, mutation or publication authority.","whenToUse":"Use to populate the private listing selector from current workspace memberships.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","A live Account/Identity workspace-membership projection. Corporate verification, a prepared release and file ACL grants are not prerequisites for listing-name discovery."],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","No caller-supplied workspace filter is accepted. Account and Identity own the live membership projection; missing or oversized projections fail closed.","Selection must activate the real workspace using its owning service. Listing discovery grants no evidence, signing or publication access.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-offerings-offering-id","method":"GET","path":"/api/v2/launchpad/offerings/{offering_id}","title":"LAUNCHPAD: Get public offering","description":"Return one publicly discoverable offering and its finalized release posture without exposing private preparation or review state.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get public offering"],"parameters":[{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one publicly discoverable offering and its finalized release posture without exposing private preparation or review state.","whenToUse":"Use after public discovery when a person or agent needs one offering's current finalized disclosure and release posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","A public offering projection does not establish investor eligibility, sale availability, or trading admission.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-agent-query","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/agent/query","title":"LAUNCHPAD: Query finalized evidence","description":"Ask a bounded question over finalized disclosed claims and receive citation-bearing answers tied to release and manifest evidence.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1agent~1query/post","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Query finalized evidence"],"parameters":[{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"question","location":"body","required":true,"type":"string · 1–500","description":"Bounded natural-language question answered only from finalized disclosed claims.","example":"What revenue did the issuer disclose?"},{"name":"as_of","location":"body","required":false,"type":"RFC 3339 timestamp","description":"Optional historical cutoff for append-only disclosure reconstruction.","example":"2026-09-01T12:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Ask a bounded question over finalized disclosed claims and receive citation-bearing answers tied to release and manifest evidence.","whenToUse":"Use for a bounded natural-language question whose answer must be grounded only in finalized public claims for this offering.","workflowRole":"create-or-command","sideEffects":"Read-only evidence query. It cannot expose private diligence, infer undisclosed facts, recommend an investment, or initiate a transaction.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Retain and display every returned release, claim, artifact, and manifest citation with the answer.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-artifact-links","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/artifact-links","title":"LAUNCHPAD: Link offering evidence","description":"Bind an offering to an exact Data Vault object version after the gateway re-resolves access, readiness, media type, and SHA-256 evidence.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1artifact-links/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Link offering evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-artifact-links-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"object_id","location":"body","required":true,"type":"Data Vault identifier","description":"Authorized Data Vault object selected as offering evidence.","example":"vault-object-01J8FQ"},{"name":"version_id","location":"body","required":true,"type":"Data Vault version identifier","description":"Exact immutable object version re-resolved and attested by the gateway.","example":"vault-version-01J8FR"},{"name":"source_sha256","location":"body","required":true,"type":"SHA-256 · lowercase hex","description":"SHA-256 of original document bytes, verified against the exact upload's domain-separated Vault commitment; never an audit-event hash.","example":"dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"},{"name":"classification","location":"body","required":false,"type":"PUBLIC_AFTER_FINALITY | private classification","description":"Disclosure policy for the evidence link; defaults to PUBLIC_AFTER_FINALITY.","example":"PUBLIC_AFTER_FINALITY"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":400,"description":"Required headers or the canonical source-file digest are missing or malformed.","example":null},{"status":502,"description":"Data Vault omitted or returned an inconsistent exact upload content proof.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Bind an offering to an exact Data Vault object version after the gateway re-resolves access, readiness, media type, and SHA-256 evidence.","whenToUse":"Use during private preparation to bind a disclosure claim to an exact authorized Data Vault object version.","workflowRole":"create-or-command","sideEffects":"Appends a version-pinned evidence link after gateway re-attestation; it does not disclose the object until an eligible release is finalized.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Select the immutable version ID, not the object's mutable current head or filename.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-claims","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/claims","title":"LAUNCHPAD: Append offering claim","description":"Append a typed issuer assertion with exact supporting artifact references; corrections supersede prior claims instead of rewriting history.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1claims/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Append offering claim"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-claims-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"predicate","location":"body","required":true,"type":"identifier · 1–255","description":"Stable claim topic used for disclosure history and agent citation.","example":"annual-revenue"},{"name":"value","location":"body","required":true,"type":"typed value object","description":"Typed claim value. The website currently sends {type: TEXT, value: string}; consumers must follow live OpenAPI for supported types.","example":{"type":"TEXT","value":"USD 12.4 million for FY2025"}},{"name":"classification","location":"body","required":false,"type":"claim classification","description":"Disclosure and assurance classification; defaults to MANAGEMENT_ASSERTION.","example":"MANAGEMENT_ASSERTION"},{"name":"evidence_artifact_ids","location":"body","required":false,"type":"UUID[] · 0–100","description":"Exact offering artifact references supporting the claim.","example":["33333333-3333-4333-8333-333333333333"]},{"name":"supersedes_claim_id","location":"body","required":false,"type":"UUID | null","description":"Exact earlier claim superseded by this append-only correction; null for a new topic.","example":"supersedes-claim-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Append a typed issuer assertion with exact supporting artifact references; corrections supersede prior claims instead of rewriting history.","whenToUse":"Use to record a typed issuer assertion and its exact supporting artifact links for later review and disclosure.","workflowRole":"create-or-command","sideEffects":"Appends a claim. A correction creates a new claim that explicitly supersedes the old one; history is never rewritten.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Keep value type, reporting units, evidence references, and classification explicit so agents can interpret the assertion safely.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-offerings-offering-id-deal","method":"GET","path":"/api/v2/launchpad/offerings/{offering_id}/deal","title":"LAUNCHPAD: Get public investment deal","description":"Return finalized issuer disclosure, immutable subscription terms, enabled funding rails, capital-formation status, and an optional verified sales-agent referral disclosure without exposing private diligence or investor data.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1deal/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get public investment deal"],"parameters":[{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"r","location":"query","required":false,"type":"public referral identifier · 1–64","description":"Optional verified sales attribution code. It is display and first-touch attribution only, never a credential or payment instruction.","example":"partner-7"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return finalized issuer disclosure, immutable subscription terms, enabled funding rails, capital-formation status, and an optional verified sales-agent referral disclosure without exposing private diligence or investor data.","whenToUse":"Use for the permanent public research and subscription entry page after the offering has finalized disclosure evidence and frozen subscription terms.","workflowRole":"discover-or-read","sideEffects":"Public read only. An optional verified referral code changes attribution disclosure but grants no access, eligibility, allocation, funding, issuance, or trading authority.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Preserve the offering ID and optional r value across sign-in or registration, then re-fetch the deal before contractual acceptance.","Display disabled rails as unavailable and never invent bank instructions, crypto addresses, prices, availability, or commission promises.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-diligence-cases","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/diligence-cases","title":"LAUNCHPAD: Open diligence case","description":"Open a private review case pinned to one security-class draft and one immutable requirement-pack version.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1diligence-cases/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Open diligence case"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-diligence-cases-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"security_class_id","location":"body","required":true,"type":"UUID","description":"Exact proposed security-class draft governed by this review.","example":"11111111-1111-4111-8111-111111111111"},{"name":"requirement_pack_version_id","location":"body","required":true,"type":"UUID","description":"Immutable requirement-pack version; later pack versions do not alter this case.","example":"22222222-2222-4222-8222-222222222222"},{"name":"name","location":"body","required":true,"type":"string · 1–200","description":"Private review-case name.","example":"Ordinary Equity Listing Review"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Open a private review case pinned to one security-class draft and one immutable requirement-pack version.","whenToUse":"Use when the proposed class and immutable requirement pack are ready to enter an independent evidence-review workflow.","workflowRole":"create-or-command","sideEffects":"Creates a private diligence case pinned to one class draft and one requirement-pack version.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Do not open a new case merely because evidence changes; use the retained case workflow and append-only evidence lineage.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-offerings-offering-id-disclosures","method":"GET","path":"/api/v2/launchpad/offerings/{offering_id}/disclosures","title":"LAUNCHPAD: Read offering disclosures","description":"Read the public append-only disclosure history for one offering, optionally reconstructed as of a timestamp.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1disclosures/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read offering disclosures"],"parameters":[{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"as_of","location":"query","required":false,"type":"RFC 3339 timestamp","description":"Reconstruct public disclosure state at or before this time; omit for the latest finalized state.","example":"2026-09-01T12:00:00Z"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Read the public append-only disclosure history for one offering, optionally reconstructed as of a timestamp.","whenToUse":"Use to reconstruct the public append-only disclosure history for an offering, optionally as it existed at a specific time.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Honor supersession rather than deleting prior releases; keep asserted-effective, finalized, and availability times distinct.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-distribution-agreements","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/distribution-agreements","title":"LAUNCHPAD: Register sales distribution agreement","description":"Register an issuer-approved, legally verified sales-agent agreement with a bounded commission rate and validity window. Public referral identifiers grant no account, workspace, allocation, or payment authority.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1distribution-agreements/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register sales distribution agreement"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-distribution-agreements-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"sales_agent_identity_id","location":"body","required":true,"type":"authenticated identity reference · 1–255","description":"Exact sales-agent identity covered by the externally verified agreement; it is not supplied as transaction authority.","example":"sales-agent-identity-7"},{"name":"referral_code","location":"body","required":true,"type":"public referral identifier · 1–64","description":"Stable public attribution code. It grants no access, allocation, recommendation, or payment authority.","example":"partner-7"},{"name":"contract_verification_reference","location":"body","required":true,"type":"external verified-contract reference · 1–255","description":"Immutable reference to the legally verified distribution agreement outside Launchpad.","example":"contract-verification-2026-44"},{"name":"commission_basis_points","location":"body","required":true,"type":"integer · 0–10000","description":"Commission rate applied only after an attributed allocation is paid and issued.","example":250},{"name":"valid_from","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Inclusive agreement-validity instant.","example":"2026-09-01T00:00:00Z"},{"name":"valid_until","location":"body","required":false,"type":"RFC 3339 timestamp | null","description":"Optional exclusive agreement expiry.","example":"2027-09-01T00:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register an issuer-approved, legally verified sales-agent agreement with a bounded commission rate and validity window. Public referral identifiers grant no account, workspace, allocation, or payment authority.","whenToUse":"Use only after the issuer has an independently verified legal distribution contract with the named sales agent.","workflowRole":"create-or-command","sideEffects":"Creates an immutable active agreement and public referral code. No commission is paid or accrued by this operation.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","The referral code is public attribution, not a credential or recommendation.","Commission eligibility begins only after an attributed subscription is paid, allocated, and issued under this exact active agreement.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-offerings-offering-id-folder-setup","method":"GET","path":"/api/v2/launchpad/offerings/{offering_id}/folder-setup","title":"LAUNCHPAD: Recover folder setup intent","description":"Read the initiating actor's durable setup intent after fresh dedicated-workspace and Data Vault access checks. This is not a folder creation, binding or encryption-readiness receipt.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1folder-setup/get","scope":"launchpad:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Recover folder setup intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"}],"responses":[{"status":200,"description":"Original immutable intent recovered, or null on read when absent. Not a storage success receipt.","example":null},{"status":400,"description":"Malformed path, typed intent, headers or idempotency key.","example":null},{"status":401,"description":"Bearer credential is missing or invalid.","example":null},{"status":403,"description":"Current launchpad:write or vault:read scope is missing.","example":null},{"status":404,"description":"The listing or selected accessible folder was not found.","example":null},{"status":409,"description":"Intent, initiator, listing or binding revision conflicts with retained state.","example":null},{"status":422,"description":"Current workspace, Vault, root-folder access or owner policy rejects the operation.","example":null},{"status":502,"description":"The owner returned an incomplete or mismatched intent receipt.","example":null},{"status":503,"description":"Identity, Data Vault or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Read the initiating actor's durable setup intent after fresh dedicated-workspace and Data Vault access checks. This is not a folder creation, binding or encryption-readiness receipt.","whenToUse":"Use after tab loss or reload to recover the initiating user's retained folder setup intent.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","Current launchpad:write and vault:read authority in the actual dedicated workspace and an available Data Vault owner.","An existing private listing and, on recovery, the same initiating subject. This workflow record verifies no company, creates no encryption material, and grants no publication authority."],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require launchpad:write and vault:read in the current dedicated workspace. A null result means no retained intent, not no actual folder. The setup is not proof of owner creation or completed binding; recover exact owner receipts separately.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-folder-setup","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/folder-setup","title":"LAUNCHPAD: Retain folder setup intent","description":"Retain one immutable folder setup intent per listing and expected binding revision. Rebuild workspace authority; do not create, bind, share or publish storage objects.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1folder-setup/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Retain folder setup intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-folder-setup-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"folder_name","location":"body","required":true,"type":"string · 1–128","description":"Exact nonblank folder name, with no control characters. A name never identifies an existing folder for recovery.","example":"Example listing"},{"name":"existing_folder_id","location":"body","required":false,"type":"identifier · 32 | null","description":"Explicit selected root-folder UUID, or omit/null to retain a creation intent. The actual owner rechecks root location and access.","example":"existing-folder-id-01"},{"name":"expected_binding_version","location":"body","required":true,"type":"integer · >=0","description":"Zero for first setup, otherwise the current binding revision for explicit existing-folder replacement.","example":0}],"responses":[{"status":200,"description":"Original immutable intent recovered, or null on read when absent. Not a storage success receipt.","example":null},{"status":201,"description":"Immutable private setup intent retained; no folder has been created or bound.","example":null},{"status":400,"description":"Malformed path, typed intent, headers or idempotency key.","example":null},{"status":401,"description":"Bearer credential is missing or invalid.","example":null},{"status":403,"description":"Current launchpad:write or vault:read scope is missing.","example":null},{"status":404,"description":"The listing or selected accessible folder was not found.","example":null},{"status":409,"description":"Intent, initiator, listing or binding revision conflicts with retained state.","example":null},{"status":422,"description":"Current workspace, Vault, root-folder access or owner policy rejects the operation.","example":null},{"status":502,"description":"The owner returned an incomplete or mismatched intent receipt.","example":null},{"status":503,"description":"Identity, Data Vault or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Retain one immutable folder setup intent per listing and expected binding revision. Rebuild workspace authority; do not create, bind, share or publish storage objects.","whenToUse":"Use before a new recoverable listing folder operation, after selecting the actual dedicated workspace.","workflowRole":"create-or-command","sideEffects":"Retains private workflow intent, command receipt and audit/outbox event; creates no folder, ACL, encryption material, publication or workspace.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","Current launchpad:write and vault:read authority in the actual dedicated workspace and an available Data Vault owner.","An existing private listing and, on recovery, the same initiating subject. This workflow record verifies no company, creates no encryption material, and grants no publication authority."],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require launchpad:write and vault:read. Retain the setup ID and derive the documented separate owner retry references from it. Never replace an uncertain request with a new actor or a guessed same-name folder.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-offerings-offering-id-folder-setup-setup-id-confirmation","method":"GET","path":"/api/v2/launchpad/offerings/{offering_id}/folder-setup/{setup_id}/confirmation","title":"LAUNCHPAD: Read confirmed listing folder","description":"Recover the retained original folder reference after fresh actor, workspace and root-folder access checks. No binding, sharing or publication is implied.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1folder-setup~1{setup_id}~1confirmation/get","scope":"launchpad:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read confirmed listing folder"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"setup_id","location":"path","required":true,"type":"identifier","description":"Canonical setup id.","example":"setup-id-01"}],"responses":[{"status":200,"description":"Original confirmed folder reference recovered, or null on read if unconfirmed. Current access is required; no binding or publication is implied.","example":null},{"status":400,"description":"Malformed path, typed intent, headers or idempotency key.","example":null},{"status":401,"description":"Bearer credential is missing or invalid.","example":null},{"status":403,"description":"Current launchpad:write or vault:read scope is missing.","example":null},{"status":404,"description":"The listing or selected accessible folder was not found.","example":null},{"status":409,"description":"Intent, initiator, listing or binding revision conflicts with retained state.","example":null},{"status":422,"description":"Current workspace, Vault, root-folder access or owner policy rejects the operation.","example":null},{"status":502,"description":"The owner returned an incomplete or mismatched intent receipt.","example":null},{"status":503,"description":"Identity, Data Vault or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Recover the retained original folder reference after fresh actor, workspace and root-folder access checks. No binding, sharing or publication is implied.","whenToUse":"Read the initiating actor's retained confirmed folder before resuming binding after an interrupted setup.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","Current launchpad:write and vault:read authority in the actual dedicated workspace and an available Data Vault owner.","An existing private listing and, on recovery, the same initiating subject. This workflow record verifies no company, creates no encryption material, and grants no publication authority."],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require current launchpad:write and vault:read; recheck the exact folder's current root location and access. Null means unconfirmed, not that no folder exists. A saved reference does not restore revoked access or prove binding completion.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-folder-setup-setup-id-confirmation","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/folder-setup/{setup_id}/confirmation","title":"LAUNCHPAD: Confirm original listing folder","description":"Resolve the original keyed Core folder receipt, or the explicitly selected existing root folder, before retaining an immutable confirmation. Never create a replacement or accept browser-supplied proof.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1folder-setup~1{setup_id}~1confirmation/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Confirm original listing folder"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-folder-setup-setup-id-confirmation-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"setup_id","location":"path","required":true,"type":"identifier","description":"Canonical setup id.","example":"setup-id-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · 1","description":"The immutable setup intent version. Gateway resolves the original folder and registration independently; no folder ID or proof is accepted from the browser.","example":1}],"responses":[{"status":200,"description":"Original confirmed folder reference recovered, or null on read if unconfirmed. Current access is required; no binding or publication is implied.","example":null},{"status":201,"description":"Independently verified original folder reference retained; nothing bound, shared or published.","example":null},{"status":400,"description":"Malformed path, typed intent, headers or idempotency key.","example":null},{"status":401,"description":"Bearer credential is missing or invalid.","example":null},{"status":403,"description":"Current launchpad:write or vault:read scope is missing.","example":null},{"status":404,"description":"The listing or selected accessible folder was not found.","example":null},{"status":409,"description":"Intent, initiator, listing or binding revision conflicts with retained state.","example":null},{"status":422,"description":"Current workspace, Vault, root-folder access or owner policy rejects the operation.","example":null},{"status":502,"description":"The owner returned an incomplete or mismatched intent receipt.","example":null},{"status":503,"description":"Identity, Data Vault or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Resolve the original keyed Core folder receipt, or the explicitly selected existing root folder, before retaining an immutable confirmation. Never create a replacement or accept browser-supplied proof.","whenToUse":"Confirm the latest retained setup after Account creation or explicit existing-folder selection.","workflowRole":"create-or-command","sideEffects":"Retains the independently resolved private folder reference, immutable event, outbox item and command receipt. Creates no folder, membership, ACL grant or publication.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","Current launchpad:write and vault:read authority in the actual dedicated workspace and an available Data Vault owner.","An existing private listing and, on recovery, the same initiating subject. This workflow record verifies no company, creates no encryption material, and grants no publication authority."],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Send only expected_version: 1. Gateway resolves Core's original scoped creation receipt or the exact selected folder, then checks current root access. Missing receipt never falls back to creation. Continue binding with listing-folder-bind:<setup UUID> only after confirmation succeeds.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-listing-data","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/listing-data","title":"LAUNCHPAD: Bind listing folder","description":"Bind an accessible top-level Data Vault folder in a dedicated workspace at an expected version. Gateway re-resolves folder and workspace authority.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1listing-data/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Bind listing folder"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-listing-data-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"folder_id","location":"body","required":true,"type":"identifier · 32","description":"Actual top-level folder UUID in the active workspace's Data Vault, never its display name.","example":"cccccccccccccccccccccccccccccccc"},{"name":"expected_version","location":"body","required":true,"type":"integer · >=0","description":"Zero for first binding; otherwise the current binding version. No files are published or shared by binding.","example":0}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Bind an accessible top-level Data Vault folder in a dedicated workspace at an expected version. Gateway re-resolves folder and workspace authority.","whenToUse":"Use after an administrator selects an existing top-level listing folder in a dedicated workspace.","workflowRole":"create-or-command","sideEffects":"Retains a versioned folder reference and audit event. It never moves, shares or publishes documents.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require launchpad:write and vault:read. Supply the current expected binding version and reuse the idempotency key only for an identical retry.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-releases","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/releases","title":"LAUNCHPAD: Create disclosure release","description":"Create a disclosure or correction release from current eligible claims and evidence; a correction must name the exact release it supersedes.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1releases/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create disclosure release"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-releases-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"release_type","location":"body","required":true,"type":"DISCLOSURE | CORRECTION","description":"Release class. CORRECTION appends history and requires supersedes_release_id.","example":"DISCLOSURE"},{"name":"supersedes_release_id","location":"body","required":false,"type":"UUID | null","description":"Exact finalized release superseded by a correction; must be null for DISCLOSURE.","example":"supersedes-release-id-01"},{"name":"asserted_effective_at","location":"body","required":false,"type":"RFC 3339 timestamp | null","description":"Optional issuer-asserted business-effective time, distinct from freeze, signature, submission, finality, and availability timestamps.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a disclosure or correction release from current eligible claims and evidence; a correction must name the exact release it supersedes.","whenToUse":"Use after eligible review when the issuer is ready to assemble a disclosure or explicit correction from current claims and evidence.","workflowRole":"create-or-command","sideEffects":"Creates a private release draft. It is not frozen, signed, submitted, finalized, replicated, or publicly discoverable.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","A CORRECTION must name the exact finalized release it supersedes.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-security-classes","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/security-classes","title":"LAUNCHPAD: Create security-class draft","description":"Describe a proposed security class inside the private offering workspace without creating, issuing, minting, or admitting an asset to trading.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1security-classes/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create security-class draft"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-security-classes-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"class_code","location":"body","required":true,"type":"identifier · 1–255","description":"Issuer-local code for the proposed class.","example":"COMMON"},{"name":"name","location":"body","required":true,"type":"string · 1–200","description":"Human-readable proposed class name.","example":"Common Stock"},{"name":"reporting_currency","location":"body","required":true,"type":"ISO 4217 code","description":"Three-letter reporting currency for disclosed figures; this does not create a settlement rail.","example":"USD"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Describe a proposed security class inside the private offering workspace without creating, issuing, minting, or admitting an asset to trading.","whenToUse":"Use to describe the proposed economic and reporting class that diligence and disclosure will reference.","workflowRole":"create-or-command","sideEffects":"Creates a private security-class draft only; no token, supply, custody position, sale, or market is created.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Treat class codes as issuer-local identifiers and preserve decimal or currency semantics exactly.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-subscription-agreement-acceptances","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/subscription-agreement-acceptances","title":"LAUNCHPAD: Accept the current subscription agreement","description":"Resolve the current public deal server-side and ask Identity to retain an issuer-signed acceptance receipt for the authenticated investor, exact disclosure release, terms, units, funding rail, and required acknowledgements.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1subscription-agreement-acceptances/post","scope":"launchpad:subscribe","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Accept the current subscription agreement"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:subscribe authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-subscription-agreement-acceptances-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"requested_units","location":"body","required":true,"type":"integer · 1–9223372036854775807","description":"Exact number of units accepted in the agreement; this is not an allocation.","example":125},{"name":"selected_funding_rail_key","location":"body","required":true,"type":"enabled funding-rail key","description":"Exact enabled rail returned by the current public deal. Selection moves no funds.","example":"crypto:usdc:ethereum"},{"name":"affirmations","location":"body","required":true,"type":"string[] · exact required acknowledgement set","description":"Explicit acceptance of the finalized disclosure, risk/no-guarantee notice, separate funding/allocation steps, and electronic signature consent.","example":["FINAL_DISCLOSURE_REVIEWED","RISK_AND_NO_GUARANTEE_ACCEPTED","FUNDING_AND_ALLOCATION_SEPARATE","ELECTRONIC_SIGNATURE_CONSENT"]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Resolve the current public deal server-side and ask Identity to retain an issuer-signed acceptance receipt for the authenticated investor, exact disclosure release, terms, units, funding rail, and required acknowledgements.","whenToUse":"Use after an authenticated investor has reviewed the finalized deal and explicitly accepted every required contractual acknowledgement.","workflowRole":"create-or-command","sideEffects":"Identity retains an issuer-signed acceptance credential and returns a minimized receipt. It does not reserve or move funds, allocate units, issue an asset, admit a market, trade, or accrue commission.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:subscribe authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Gateway resolves the current terms, release manifest and enabled rail; never accept those authority facts from the browser.","Keep the receipt with the requested units and rail. A later changed quantity or rail requires a new acceptance.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-subscription-configuration","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/subscription-configuration","title":"LAUNCHPAD: Freeze subscription terms","description":"Freeze the issuer-administered price, unit capacity, subscription window, contractual template reference, and initially enabled crypto funding rails. Bank funding remains explicitly disabled until separately released.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1subscription-configuration/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Freeze subscription terms"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-subscription-configuration-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"security_class_id","location":"body","required":true,"type":"UUID","description":"Exact proposed security-class draft governed by these terms.","example":"11111111-1111-4111-8111-111111111111"},{"name":"offered_units","location":"body","required":true,"type":"integer · 1–9223372036854775807","description":"Maximum fixed-price units available for this subscription term version.","example":1000000},{"name":"unit_price_minor","location":"body","required":true,"type":"integer · 1–9223372036854775807","description":"Exact unit price in settlement-currency minor units; never use binary floating point.","example":2500},{"name":"settlement_currency","location":"body","required":true,"type":"three-letter uppercase currency code","description":"Currency whose minor-unit convention governs unit_price_minor.","example":"USD"},{"name":"subscription_opens_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Inclusive opening instant for authenticated subscription requests.","example":"2026-10-01T00:00:00Z"},{"name":"subscription_closes_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Exclusive closing instant, strictly after the opening instant.","example":"2026-10-31T23:59:59Z"},{"name":"crypto_funding_rails","location":"body","required":true,"type":"object[] · at least 1 unique asset/network pair","description":"Initially enabled digital-asset rails. Each entry contains asset_code and network. The service also returns bank transfer as explicitly disabled.","example":[{"asset_code":"USDC","network":"ETHEREUM"}]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Freeze the issuer-administered price, unit capacity, subscription window, contractual template reference, and initially enabled crypto funding rails. Bank funding remains explicitly disabled until separately released.","whenToUse":"Use after issuer authority, the ordinary-equity draft, and public disclosure inputs are ready to freeze a versioned fixed-price subscription window.","workflowRole":"create-or-command","sideEffects":"Supersedes the prior term version, freezes exact price and capacity, enables the declared crypto rails, and records bank transfer as disabled. It does not accept investors or move value.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require issuer launchpad:write authority and preserve all amount fields as integer minor units or whole units.","After an ambiguous response, re-read the public deal before retrying the same idempotency key; never create parallel term versions to guess at success.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-subscriptions","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/subscriptions","title":"LAUNCHPAD: Request contractual subscription","description":"Verify the authenticated investor's Identity-issued agreement receipt against the current deal, then record exact requested units, selected enabled rail, and optional immutable first-touch attribution. This does not reserve or move funds, allocate, issue, admit, or trade the instrument.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1subscriptions/post","scope":"launchpad:subscribe","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request contractual subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:subscribe authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-subscriptions-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"requested_units","location":"body","required":true,"type":"integer · 1–9223372036854775807","description":"Exact number of units contractually requested; this is not an allocation.","example":125},{"name":"subscription_agreement_reference","location":"body","required":true,"type":"Identity acceptance receipt · hcla_ + 32 lowercase hex","description":"Immutable signed acceptance receipt returned by Identity for these exact current deal facts.","example":"hcla_0123456789abcdef0123456789abcdef"},{"name":"selected_funding_rail_key","location":"body","required":true,"type":"enabled funding-rail key","description":"Exact enabled rail returned by the public deal, such as crypto:usdc:ethereum. Selection moves no funds.","example":"crypto:usdc:ethereum"},{"name":"referral_code","location":"body","required":false,"type":"public referral identifier · 1–64 | null","description":"Optional first-touch sales attribution from the public deal URL. It grants no authority and cannot be replaced after acceptance.","example":"partner-7"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Verify the authenticated investor's Identity-issued agreement receipt against the current deal, then record exact requested units, selected enabled rail, and optional immutable first-touch attribution. This does not reserve or move funds, allocate, issue, admit, or trade the instrument.","whenToUse":"Use immediately after Identity returns the signed acceptance receipt for the same authenticated investor, units, rail, and current deal.","workflowRole":"create-or-command","sideEffects":"Creates a REQUESTED subscription intent and immutable optional first-touch attribution. It does not reserve funds, allocate units, issue an asset, admit a market, trade, or accrue commission.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:subscribe authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require launchpad:subscribe and an hcla_ Identity receipt; Gateway re-verifies it before forwarding.","Use only a currently enabled rail key returned by the deal and reconcile the subscription receipt before any separately authorized funding action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-offerings-offering-id-workspace-transfer","method":"POST","path":"/api/v2/launchpad/offerings/{offering_id}/workspace-transfer","title":"LAUNCHPAD: Transfer unpublished draft workspace","description":"Explicitly reassociate a single unpublished draft at an expected issuer version. Require live admin access to source and active dedicated destination; no files, ACLs or corporate identity are changed.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1offerings~1{offering_id}~1workspace-transfer/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer unpublished draft workspace"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-offerings-offering-id-workspace-transfer-request-001"},{"name":"offering_id","location":"path","required":true,"type":"identifier","description":"Canonical offering id.","example":"offering-id-01"},{"name":"source_workspace_id","location":"body","required":true,"type":"identifier · 32","description":"Expected current draft workspace; not an authority assertion.","example":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},{"name":"target_workspace_id","location":"body","required":true,"type":"identifier · 32","description":"Must equal the currently active dedicated workspace.","example":"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"},{"name":"expected_issuer_version","location":"body","required":true,"type":"integer · >=1","description":"Current issuer version; stale transfers are rejected.","example":1},{"name":"reason","location":"body","required":true,"type":"string · 1–1000","description":"Explicit administrator reason retained in immutable transfer history.","example":"Move the unreviewed draft to its dedicated workspace; leave files untouched."}],"responses":[{"status":200,"description":"Versioned issuer workspace-transfer receipt; no files, sharing or corporate identity changed.","example":null},{"status":400,"description":"Required headers, JSON body or idempotency key are malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired or invalid.","example":null},{"status":403,"description":"The active principal lacks the required Launchpad scope.","example":null},{"status":404,"description":"The offering or issuer does not exist.","example":null},{"status":409,"description":"The draft/version/destination is ineligible, another transfer won, or the idempotency key conflicts.","example":null},{"status":422,"description":"The expected destination or live admin/Vault authority is invalid, missing or rejected.","example":null},{"status":502,"description":"An authoritative dependency returned an invalid response.","example":null},{"status":503,"description":"Identity, Data Vault or Launchpad is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Explicitly reassociate a single unpublished draft at an expected issuer version. Require live admin access to source and active dedicated destination; no files, ACLs or corporate identity are changed.","whenToUse":"Use only after explicit consent to move a single unreviewed draft into its dedicated workspace.","workflowRole":"create-or-command","sideEffects":"Changes the issuer workspace association and appends a transfer event. No file bytes, ACLs, corporate identity or publication state are changed.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Activate the destination via Account first. Live admin memberships in both workspaces and current destination Vault access are mandatory on every attempt, including retries. Evidence, room bindings, reviews or any releases require a separate governed migration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-release-feed","method":"GET","path":"/api/v2/launchpad/release-feed","title":"LAUNCHPAD: Read finalized release feed","description":"Read the cursor-paginated append-only sequence of finalized Launchpad releases for indexer and agent reconciliation.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1release-feed/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read finalized release feed"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum finalized release events to return; defaults to 100.","example":100},{"name":"cursor","location":"query","required":false,"type":"opaque release-feed cursor","description":"Cursor returned by the preceding page and valid only for this append-only feed.","example":"0011aabb"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Read the cursor-paginated append-only sequence of finalized Launchpad releases for indexer and agent reconciliation.","whenToUse":"Use to incrementally reconcile finalized disclosure and correction releases into an index, cache, research corpus, or monitoring agent.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Advance only with the returned opaque cursor and preserve release sequence and supersession lineage.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-releases-release-id","method":"GET","path":"/api/v2/launchpad/releases/{release_id}","title":"LAUNCHPAD: Get finalized release","description":"Return one finalized release, its sequence, signatures, finality, availability, and supersession posture.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1releases~1{release_id}/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get finalized release"],"parameters":[{"name":"release_id","location":"path","required":true,"type":"identifier","description":"Canonical release id.","example":"release-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one finalized release, its sequence, signatures, finality, availability, and supersession posture.","whenToUse":"Use to reconcile one finalized public release's sequence, signatures, finality, availability, and supersession posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Require finalized state for public reliance and do not collapse submission, finality, replication, and indexing into one event.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-releases-release-id-freezes","method":"POST","path":"/api/v2/launchpad/releases/{release_id}/freezes","title":"LAUNCHPAD: Freeze release","description":"Freeze the exact claim, artifact, review, and supersession commitments into an immutable release manifest.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1releases~1{release_id}~1freezes/post","scope":"launchpad:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Freeze release"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-releases-release-id-freezes-request-001"},{"name":"release_id","location":"path","required":true,"type":"identifier","description":"Canonical release id.","example":"release-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Freeze the exact claim, artifact, review, and supersession commitments into an immutable release manifest.","whenToUse":"Use after release contents and eligibility are complete to make the exact manifest immutable before signing.","workflowRole":"create-or-command","sideEffects":"Freezes the release manifest. It does not sign, submit, finalize, replicate, index, or publish the release.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Re-read the frozen manifest and commitment before requesting a signature.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-releases-release-id-manifest","method":"GET","path":"/api/v2/launchpad/releases/{release_id}/manifest","title":"LAUNCHPAD: Get canonical manifest","description":"Return the frozen canonical manifest and commitments needed to independently verify a finalized release.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1releases~1{release_id}~1manifest/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get canonical manifest"],"parameters":[{"name":"release_id","location":"path","required":true,"type":"identifier","description":"Canonical release id.","example":"release-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the frozen canonical manifest and commitments needed to independently verify a finalized release.","whenToUse":"Use when an integration must independently verify the canonical frozen claims, evidence, review, and supersession commitments behind a finalized release.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Canonicalize and hash exactly as specified by the returned manifest metadata; never verify a reconstructed display page instead.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-releases-release-id-signatures","method":"POST","path":"/api/v2/launchpad/releases/{release_id}/signatures","title":"LAUNCHPAD: Sign frozen release","description":"Sign the frozen manifest with authority derived from the authenticated principal; the caller cannot nominate a signer.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1releases~1{release_id}~1signatures/post","scope":"launchpad:sign","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Sign frozen release"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:sign authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-releases-release-id-signatures-request-001"},{"name":"release_id","location":"path","required":true,"type":"identifier","description":"Canonical release id.","example":"release-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Sign the frozen manifest with authority derived from the authenticated principal; the caller cannot nominate a signer.","whenToUse":"Use after verifying the frozen manifest when the authenticated principal has current derived issuer signing authority.","workflowRole":"create-or-command","sideEffects":"Appends a signature over the exact frozen manifest; signer identity is derived and cannot be nominated by the caller.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:sign authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","A signature is issuer authorization evidence, not validator finality or public availability.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-releases-release-id-submissions","method":"POST","path":"/api/v2/launchpad/releases/{release_id}/submissions","title":"LAUNCHPAD: Submit signed release","description":"Submit an eligible signed manifest for validator finality; submission, finalization, and replicated availability remain separate states.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1releases~1{release_id}~1submissions/post","scope":"launchpad:publish","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Submit signed release"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:publish authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-releases-release-id-submissions-request-001"},{"name":"release_id","location":"path","required":true,"type":"identifier","description":"Canonical release id.","example":"release-id-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Submit an eligible signed manifest for validator finality; submission, finalization, and replicated availability remain separate states.","whenToUse":"Use only after the release is frozen, validly signed, and otherwise eligible to request validator finality.","workflowRole":"create-or-command","sideEffects":"Submits the signed manifest to the finality workflow. Acceptance does not mean finalized, replicated, indexed, or publicly available.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:publish authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","After an ambiguous result, re-read the release rather than submitting a new logical request.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"post-api-v2-launchpad-review-decisions-review-decision-id-attestations","method":"POST","path":"/api/v2/launchpad/review-decisions/{review_decision_id}/attestations","title":"LAUNCHPAD: Attest review decision","description":"Append an independent auditor statement and optional qualification to an existing immutable review decision.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1review-decisions~1{review_decision_id}~1attestations/post","scope":"launchpad:attest","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Attest review decision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:attest authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-launchpad-review-decisions-review-decision-id-attestations-request-001"},{"name":"review_decision_id","location":"path","required":true,"type":"identifier","description":"Canonical review decision id.","example":"review-decision-id-01"},{"name":"statement","location":"body","required":true,"type":"string · 1–4000","description":"Independent auditor statement appended to the selected decision.","example":"I independently reviewed the pinned evidence commitments."},{"name":"qualification","location":"body","required":false,"type":"string · 1–4000 | null","description":"Optional limitation or qualification; null means none.","example":"qualification-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Append an independent auditor statement and optional qualification to an existing immutable review decision.","whenToUse":"Use when an independently authorized auditor has reviewed an existing decision and is ready to append a statement or qualification.","workflowRole":"create-or-command","sideEffects":"Appends an immutable attestation to the selected decision; it cannot replace the review outcome or authorize publication.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:attest authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","State material qualifications explicitly rather than implying an unqualified endorsement.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-reviewer-queue","method":"GET","path":"/api/v2/launchpad/reviewer-queue","title":"LAUNCHPAD: Get reviewer queue","description":"Return only diligence cases currently visible to the authenticated reviewer under Launchpad review policy.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1reviewer-queue/get","scope":"launchpad:review","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get reviewer queue"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:review authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return only diligence cases currently visible to the authenticated reviewer under Launchpad review policy.","whenToUse":"Use when an eligible reviewer needs the diligence cases currently assigned or visible under review policy.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:review authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Queue visibility grants no issuer, auditor, signer, publisher, or Data Vault authority beyond the specific review workflow.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-launchpad-workbench","method":"GET","path":"/api/v2/launchpad/workbench","title":"LAUNCHPAD: Get issuer workbench","description":"Return the authenticated issuer's private preparation snapshot, milestones, and exact evidence-link posture.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Issuer Launchpad","owners":["launchpad-service"],"applications":["Issuer Launchpad"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1launchpad~1workbench/get","scope":"launchpad:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get issuer workbench"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing launchpad:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated issuer's private preparation snapshot, milestones, and exact evidence-link posture.","whenToUse":"Use for an issuer-facing preparation dashboard that needs private offerings, milestones, missing requirements, evidence links, reviews, and release readiness.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["private issuer and offering preparation","ordinary-equity class and requirement definition","exact-version Data Vault evidence assembly","independent diligence review and attestation","signed disclosure and correction publication","public investment-deal discovery and referral distribution"],"prerequisites":["A bearer credential with launchpad:write authority and the required tenant, workspace, and role context.","an authenticated active workspace with verified company authority for private issuer operations","launchpad:write, launchpad:review, launchpad:attest, launchpad:sign, launchpad:publish, or launchpad:subscribe according to the exact operation","ready, currently authorized Data Vault object versions and an immutable requirement-pack version","an eligible review decision before release preparation and derived signing authority before submission","a finalized public release before public deal distribution","an Identity-issued contractual acceptance receipt for the exact current deal and an investor eligibility policy before funding","caller-owned policies for evidence freshness, disclosure suitability, validator finality, funding, allocation, issuance, admission, supersession, and replicated availability"],"agentGuidance":["Private issuer drafts, offering workspaces, requirement packs, diligence cases, evidence views, decisions, and audit exports are not public listings; only validator-finalized releases enter public discovery.","The bearer determines workspace, issuer, reviewer, auditor, signer, and investor authority. Never submit caller-selected owner, issuer authority, reviewer identity, signer identity, validator identity, investor identity, or internal service address.","Use stable canonical identifiers and exact Data Vault object and version pairs. A filename, display label, current object head, screenshot, or copied hash is not a substitute for gateway re-attestation.","A proposed security class or subscription request is not issuance, minting, custody, admission, sale completion, trading, settlement, investor eligibility, or proof of payment. Launchpad contracts grant none of those authorities.","A public sales referral identifier is attribution only. It is never a credential, entitlement, allocation preference, investment recommendation, or payment instruction.","Gateway resolves the current disclosure release, immutable terms and enabled funding rail before Identity signs an investor acceptance receipt; the browser never supplies those authority facts or fabricates a receipt.","Commission becomes eligible only from an active verified distribution agreement after attributed subscription, confirmed payment, allocation, and issuance. Clicks, registrations, requests, reservations, cancellations, or rejected subscriptions never earn commission.","An evidence view pins what was reviewed; a decision records judgment; an attestation records an independent statement. None silently alters source evidence or authorizes publication.","Freeze, sign, submit, finalize, replicate, subscribe, fund, allocate, issue, admit, and trade are distinct states. Re-read the authoritative record after ambiguous responses and never infer a later state.","Corrections must name the exact prior release and append a new sequence; never erase, rewrite, or conceal the superseded disclosure.","Agent answers are bounded to finalized disclosed claims and must retain release, claim, artifact, and manifest citations. An answer is not investment advice, verification of undisclosed facts, or authority to transact.","Keep private evidence contents, access locators, credentials, contractual documents, signing material, regulated identity data, bank details, wallet secrets, and internal review notes out of shared prompts, logs, analytics, URLs, and agent memory.","Use milestone state to guide the next allowed action; never treat workbench readiness as public finality.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Trust Center","Contract Studio","Funding","Digital Assets","Trading"]}},{"id":"get-api-v2-tokens-available","method":"GET","path":"/api/v2/tokens/available","title":"TOKENS: Get all Security Tokens","description":"TOKENS: Get all Security Tokens through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/available","operation":"TOKENS: Get all Security Tokens"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-available","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Security Tokens"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get all Security Tokens through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy planning path. Use implemented GET /api/v2/assets with asset_type=SECURITY_TOKEN (and any applicable status or q filters) for the public token catalog.","workflowRole":"discover-or-read","sideEffects":"None. This non-executable planning entry cannot reveal private inventory, create eligibility, enable trading, or grant token authority.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","The canonical catalog is public and uses cursor pagination. Preserve exact supply strings and use asset_uuid rather than symbol as the identity.","Verify GET /api/v2/assets in live OpenAPI before generating a request.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-buying-power","method":"GET","path":"/api/v2/tokens/buying_power","title":"TOKENS: Get Token Buying Power","description":"TOKENS: Get Token Buying Power through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/buying_power","operation":"TOKENS: Get Token Buying Power"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-buying-power","scope":"ledger:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Token Buying Power"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing ledger:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get Token Buying Power through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this planning path while trading integrations are frozen. Buying power is an owner-scoped risk result that requires current available and reserved balances, margin policy, restrictions, quote currency, venue, and open-order exposure.","workflowRole":"discover-or-read","sideEffects":"None. This route is non-executable and cannot reserve collateral, approve an order, bypass restrictions, or establish a transferable balance.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with ledger:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Do not derive buying power from a public asset record, wallet display balance, or caller-authored price. Use authoritative ledger balances and market restrictions only through a separately implemented contract.","Re-read immediately before any future order because balances, reservations, restrictions, and prices are time-sensitive.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-details","method":"GET","path":"/api/v2/tokens/details","title":"TOKENS: Get Token Details","description":"TOKENS: Get Token Details through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/details","operation":"TOKENS: Get Token Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-details","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Token Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"token_uuid","location":"query","required":true,"type":"legacy token identifier","description":"Legacy security-token identifier. Do not call this planning route; use the canonical replacement described in agent guidance.","example":"11111111111111111111111111111111"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get Token Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy planning path. Resolve the token's canonical asset_uuid and call implemented GET /api/v2/assets/{asset_uuid}.","workflowRole":"discover-or-read","sideEffects":"None. The legacy detail path is not executable and grants no supply, holding, quote, trading, redemption, or custody authority.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use the canonical asset detail for identity, precision, supply projection, metadata commitment, status, and timestamps; use history and proofs for evidence.","Do not translate legacy token metadata field-for-field or expose chain issuance-wallet, reserve-wallet, ABI, or database selectors.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-inventory","method":"GET","path":"/api/v2/tokens/inventory","title":"TOKENS: Get Token Inventory","description":"TOKENS: Get Token Inventory through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/inventory","operation":"TOKENS: Get Token Inventory"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-inventory","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Token Inventory"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"token_uuid","location":"query","required":true,"type":"legacy token identifier","description":"Legacy security-token identifier. Do not call this planning route; use the canonical replacement described in agent guidance.","example":"11111111111111111111111111111111"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get Token Inventory through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy planning path. Use implemented asset detail, history, proof, and mint-evidence reads to reconcile published supply facts without invoking live chain wallets from a public request.","workflowRole":"discover-or-read","sideEffects":"None. The legacy inventory path is not executable and cannot query private reserve wallets, create balances, establish holder ownership, or change supply.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","GET /api/v2/assets/{asset_uuid} reports the current minimized source supply projection; GET /api/v2/assets/{asset_uuid}/history and /proofs plus GET /api/v2/asset-mints/{mint_uuid} provide retained public evidence.","Current circulating, reserve, and per-chain totals require a separately governed chain-indexer contract and must not be inferred by subtracting caller-authored values.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-tokens-mint","method":"POST","path":"/api/v2/tokens/mint","title":"TOKENS: Mint a new Security Token","description":"TOKENS: Mint a new Security Token through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/tokens/mint","operation":"TOKENS: Mint a new Security Token"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-tokens-mint","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Mint a new Security Token"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Mint a new Security Token through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use POST /api/v2/assets/{asset_uuid}/mints after creating and governing the canonical asset; the legacy security-token request accepted an unsafe, unverified shape and is retired.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-performance","method":"GET","path":"/api/v2/tokens/performance","title":"TOKENS: Get Token Performance","description":"TOKENS: Get Token Performance through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/performance","operation":"TOKENS: Get Token Performance"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-performance","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Token Performance"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"token_uuid","location":"query","required":true,"type":"legacy token identifier","description":"Legacy security-token identifier. Do not call this planning route; use the canonical replacement described in agent guidance.","example":"11111111111111111111111111111111"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get Token Performance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this planning path while trading integrations are frozen. Future performance analytics must declare source observations, interval, benchmark, corporate actions, currency, timestamp, and methodology.","workflowRole":"discover-or-read","sideEffects":"None. This route is non-executable and cannot guarantee returns, establish valuation, authorize an order, or substitute for current market data.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Never infer performance from minted supply or one current quote. Use bounded authoritative time-series observations and keep price return, total return, and asset lifecycle events distinct.","Historical performance is not execution authority or a forecast.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-quote","method":"GET","path":"/api/v2/tokens/quote","title":"TOKENS: Get Token Quote","description":"TOKENS: Get Token Quote through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/quote","operation":"TOKENS: Get Token Quote"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-quote","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Token Quote"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"token_uuid","location":"query","required":true,"type":"legacy token identifier","description":"Legacy security-token identifier. Do not call this planning route; use the canonical replacement described in agent guidance.","example":"11111111111111111111111111111111"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get Token Quote through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this planning path while trading integrations are frozen. A future quote must come from the authoritative market-data owner and identify market, venue, side, size, currency, timestamp, and expiry.","workflowRole":"discover-or-read","sideEffects":"None. This route is non-executable and provides no executable quote, order authorization, liquidity promise, price guarantee, or settlement term.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Do not substitute asset base_currency, metadata, last mint quantity, screenshots, or caller-authored prices for a market quote.","Only use a quote operation after its exact schema and freshness rules appear in live OpenAPI and the separate trading freeze is explicitly lifted.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-redeem","method":"GET","path":"/api/v2/tokens/redeem","title":"TOKENS: Redeem a Security Token","description":"TOKENS: Redeem a Security Token through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/redeem","operation":"TOKENS: Redeem a Security Token"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-redeem","scope":"assets:supply","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Redeem a Security Token"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:supply authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Redeem a Security Token through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this retired GET-shaped contract. Redemption changes supply and holdings and therefore requires a signed, idempotent, version-bound command such as the planned asset burn lifecycle with reason_code=REDEEM after it is implemented and separately approved.","workflowRole":"discover-or-read","sideEffects":"None. This non-executable planning entry returns no deposit address, burns no holding, creates no payout, and grants no custody, settlement, or redemption authority.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:supply authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Never send tokens to a hard-coded or caller-supplied redemption address. Resolve an eligible holding and redemption policy inside the authoritative owner and bind exact quantity, balance, asset version, consent, and evidence.","A burn or redemption request is not payout settlement. Verify both supply retirement and separately owned payment or settlement evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-tokens-securities","method":"GET","path":"/api/v2/tokens/securities","title":"TOKENS: Get all Securities","description":"TOKENS: Get all Securities through the canonical Hybrid-Chain V2 interface.","chapter":"Tokenized Securities","chapterOrder":10,"capability":"Tokenized Securities","owners":["asset-tokenization"],"applications":["Trading","Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/tokens/securities","operation":"TOKENS: Get all Securities"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-tokens-securities","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Securities"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"TOKENS: Get all Securities through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy planning path. Use implemented GET /api/v2/assets?asset_type=SECURITY_TOKEN for issued tokenized securities and the separately owned public reference-data or Explorer equity catalog for underlying instruments.","workflowRole":"discover-or-read","sideEffects":"None. This planning entry cannot determine offering eligibility, investment suitability, regulatory classification, issuance authority, or market availability.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Keep the underlying instrument identity separate from the issued digital asset UUID and verify their explicit owner-governed binding when such a contract is published.","A catalog classification is not legal, compliance, suitability, price, or trading advice.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-prediction-all","method":"GET","path":"/api/v2/prediction/all","title":"PREDICTION: Get all Predictions","description":"PREDICTION: Get all Predictions through the canonical Hybrid-Chain V2 interface.","chapter":"Prediction Markets","chapterOrder":11,"capability":"Prediction Markets","owners":["prediction-products"],"applications":["Trading","Prediction Markets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/prediction/all","operation":"PREDICTION: Get all Predictions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-prediction-all","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Predictions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PREDICTION: Get all Predictions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all predictions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","prediction discovery","contract detail review","performance and outcome monitoring"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Price Feeds","Prediction Market Ops"]}},{"id":"post-api-v2-prediction-create","method":"POST","path":"/api/v2/prediction/create","title":"PREDICTION: Create new Prediction","description":"PREDICTION: Create new Prediction through the canonical Hybrid-Chain V2 interface.","chapter":"Prediction Markets","chapterOrder":11,"capability":"Prediction Markets","owners":["prediction-products"],"applications":["Trading","Prediction Markets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/prediction/create","operation":"PREDICTION: Create new Prediction"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-prediction-create","scope":"trading:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create new Prediction"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-prediction-create-request-001"},{"name":"title","location":"body","required":true,"type":"string · 3–160","description":"Human-readable prediction question.","example":"title-01"},{"name":"description","location":"body","required":false,"type":"string · max 2000","description":"Neutral context and interpretation guidance.","example":"description-01"},{"name":"outcomes","location":"body","required":true,"type":"string[] · 2–20 unique values","description":"Complete mutually exclusive outcome labels.","example":[]},{"name":"closes_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Deadline after which participation is closed.","example":"2026-09-30T20:00:00Z"},{"name":"oracle_policy","location":"body","required":true,"type":"object","description":"Named evidence sources, review threshold, dispute window, and resolution rules.","example":{}},{"name":"category","location":"body","required":false,"type":"string · max 80","description":"Discovery category; grants no eligibility.","example":"category-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"PREDICTION: Create new Prediction through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create new prediction.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","prediction discovery","contract detail review","performance and outcome monitoring"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Price Feeds","Prediction Market Ops"]}},{"id":"get-api-v2-prediction-details","method":"GET","path":"/api/v2/prediction/details","title":"PREDICTION: Get Prediction Details","description":"PREDICTION: Get Prediction Details through the canonical Hybrid-Chain V2 interface.","chapter":"Prediction Markets","chapterOrder":11,"capability":"Prediction Markets","owners":["prediction-products"],"applications":["Trading","Prediction Markets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/prediction/details","operation":"PREDICTION: Get Prediction Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-prediction-details","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Prediction Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PREDICTION: Get Prediction Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get prediction details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","prediction discovery","contract detail review","performance and outcome monitoring"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Price Feeds","Prediction Market Ops"]}},{"id":"get-api-v2-prediction-performance","method":"GET","path":"/api/v2/prediction/performance","title":"PREDICTION: Get Prediction Performance","description":"PREDICTION: Get Prediction Performance through the canonical Hybrid-Chain V2 interface.","chapter":"Prediction Markets","chapterOrder":11,"capability":"Prediction Markets","owners":["prediction-products"],"applications":["Trading","Prediction Markets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/prediction/performance","operation":"PREDICTION: Get Prediction Performance"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-prediction-performance","scope":"trading:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Prediction Performance"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"PREDICTION: Get Prediction Performance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get prediction performance before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","prediction discovery","contract detail review","performance and outcome monitoring"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Price Feeds","Prediction Market Ops"]}},{"id":"get-api-v2-barriers-available","method":"GET","path":"/api/v2/barriers/available","title":"BARRIERS: Get all Barrier Products","description":"BARRIERS: Get all Barrier Products through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/available","operation":"BARRIERS: Get all Barrier Products"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-available","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get all Barrier Products"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get all Barrier Products through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all barrier products before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-close","method":"POST","path":"/api/v2/barriers/close","title":"BARRIERS: Close Barrier Products","description":"BARRIERS: Close Barrier Products through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/barriers/close","operation":"BARRIERS: Close Barrier Products"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-close","scope":"barriers:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Close Barrier Products"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-close-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for close barrier products. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"BARRIERS: Close Barrier Products through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to close barrier products.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-details","method":"GET","path":"/api/v2/barriers/details","title":"BARRIERS: Get Barrier Details","description":"BARRIERS: Get Barrier Details through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/details","operation":"BARRIERS: Get Barrier Details"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-details","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Barrier Details"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get Barrier Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get barrier details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-history","method":"GET","path":"/api/v2/barriers/history","title":"BARRIERS: Get Barriers History","description":"BARRIERS: Get Barriers History through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/history","operation":"BARRIERS: Get Barriers History"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-history","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Barriers History"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get Barriers History through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get barriers history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-issue","method":"POST","path":"/api/v2/barriers/issue","title":"BARRIERS: Issue a new Barrier Product","description":"BARRIERS: Issue a new Barrier Product through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/barriers/issue","operation":"BARRIERS: Issue a new Barrier Product"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-issue","scope":"barriers:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Issue a new Barrier Product"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-issue-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for issue a new barrier product. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"BARRIERS: Issue a new Barrier Product through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to issue a new barrier product.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-performance","method":"GET","path":"/api/v2/barriers/performance","title":"BARRIERS: Get Barrier Performance","description":"BARRIERS: Get Barrier Performance through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/performance","operation":"BARRIERS: Get Barrier Performance"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-performance","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Barrier Performance"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get Barrier Performance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get barrier performance before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-portfolio","method":"GET","path":"/api/v2/barriers/portfolio","title":"BARRIERS: Get Portfolio Performance","description":"BARRIERS: Get Portfolio Performance through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/portfolio","operation":"BARRIERS: Get Portfolio Performance"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-portfolio","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Portfolio Performance"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get Portfolio Performance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get portfolio performance before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-positions","method":"GET","path":"/api/v2/barriers/positions","title":"BARRIERS: Get Barriers Positions","description":"BARRIERS: Get Barriers Positions through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/barriers/positions","operation":"BARRIERS: Get Barriers Positions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-positions","scope":"barriers:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Barriers Positions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"BARRIERS: Get Barriers Positions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get barriers positions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-quote","method":"POST","path":"/api/v2/barriers/quote","title":"BARRIERS: Quote a Barrier Product","description":"BARRIERS: Quote a Barrier Product through the canonical Hybrid-Chain V2 interface.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Barrier Product Constructor","owners":["structured-products"],"applications":["Barriers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/barriers/quote","operation":"BARRIERS: Quote a Barrier Product"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-quote","scope":"barriers:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Quote a Barrier Product"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-quote-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for quote a barrier product. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"BARRIERS: Quote a Barrier Product through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to quote a barrier product.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers","method":"GET","path":"/api/v2/barriers","title":"BARRIERS: List barriers","description":"List programmable transaction barriers and lifecycle state.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers","scope":"barriers:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List barriers"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List programmable transaction barriers and lifecycle state.","whenToUse":"Use this operation when an integration needs to list barriers before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers","method":"POST","path":"/api/v2/barriers","title":"BARRIERS: Create barrier","description":"Create a draft barrier from conditions, observations, payout rules, authorities, and expiry.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers","scope":"barriers:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-request-001"},{"name":"name","location":"body","required":true,"type":"string","description":"Barrier name.","example":"name-01"},{"name":"conditions","location":"body","required":true,"type":"condition[]","description":"Typed price, time, event, or evidence predicates.","example":[]},{"name":"payout","location":"body","required":true,"type":"object","description":"Bounded payout behavior.","example":{}},{"name":"feed_bindings","location":"body","required":true,"type":"object[]","description":"Authoritative observation sources.","example":[]},{"name":"expires_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Barrier expiry.","example":"2026-09-30T20:00:00Z"},{"name":"authority_policy","location":"body","required":true,"type":"object","description":"Activation, cancellation, and settlement authority.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a draft barrier from conditions, observations, payout rules, authorities, and expiry.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create barrier.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-barrier-uuid","method":"GET","path":"/api/v2/barriers/{barrier_uuid}","title":"BARRIERS: Get barrier","description":"Return one barrier definition, observations, state transitions, and evidence.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-barrier-uuid","scope":"barriers:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one barrier definition, observations, state transitions, and evidence.","whenToUse":"Use this operation when an integration needs to get barrier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"patch-api-v2-barriers-barrier-uuid","method":"PATCH","path":"/api/v2/barriers/{barrier_uuid}","title":"BARRIERS: Update barrier","description":"Update an editable barrier draft before activation.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-barriers-barrier-uuid","scope":"barriers:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Update barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-barriers-barrier-uuid-request-001"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for update barrier. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update an editable barrier draft before activation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update barrier.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-barrier-uuid-activations","method":"POST","path":"/api/v2/barriers/{barrier_uuid}/activations","title":"BARRIERS: Activate barrier","description":"Activate a validated governed barrier without browser-side execution.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-barrier-uuid-activations","scope":"barriers:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Activate barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-barrier-uuid-activations-request-001"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"},{"name":"challenge_id","location":"body","required":true,"type":"identifier","description":"Unexpired activation challenge.","example":"challenge-id-01"},{"name":"authorization","location":"body","required":true,"type":"threshold authorization object","description":"Participant approvals and proof bundle.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Activate a validated governed barrier without browser-side execution.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to activate barrier.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-barrier-uuid-cancellations","method":"POST","path":"/api/v2/barriers/{barrier_uuid}/cancellations","title":"BARRIERS: Cancel barrier","description":"Cancel an eligible barrier according to its immutable lifecycle policy.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-barrier-uuid-cancellations","scope":"barriers:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Cancel barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-barrier-uuid-cancellations-request-001"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for cancel barrier. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an eligible barrier according to its immutable lifecycle policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to cancel barrier.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-barriers-barrier-uuid-observations","method":"GET","path":"/api/v2/barriers/{barrier_uuid}/observations","title":"BARRIERS: List observations","description":"List signed price, time, event, and evidence observations evaluated by the barrier.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-barriers-barrier-uuid-observations","scope":"barriers:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List observations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:read authority.","example":"Bearer hc_live_…"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List signed price, time, event, and evidence observations evaluated by the barrier.","whenToUse":"Use this operation when an integration needs to list observations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:read authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"post-api-v2-barriers-barrier-uuid-validations","method":"POST","path":"/api/v2/barriers/{barrier_uuid}/validations","title":"BARRIERS: Validate barrier","description":"Validate barrier syntax, feed bindings, payout bounds, and authority policy.","chapter":"Barrier Product Constructor","chapterOrder":12,"capability":"Programmable barriers","owners":["barrier-service"],"applications":["Barriers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-barriers-barrier-uuid-validations","scope":"barriers:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Validate barrier"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing barriers:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-barriers-barrier-uuid-validations-request-001"},{"name":"barrier_uuid","location":"path","required":true,"type":"identifier","description":"Canonical barrier uuid.","example":"barrier-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for validate barrier. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Validate barrier syntax, feed bindings, payout bounds, and authority policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to validate barrier.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards"],"prerequisites":["A bearer credential with barriers:write authority and the required tenant, workspace, and role context.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations"]}},{"id":"get-api-v2-nft-categories-all","method":"GET","path":"/api/v2/nft/categories/all","title":"NFT: Get All NFT Categories","description":"NFT: Get All NFT Categories through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/categories/all","operation":"NFT: Get All NFT Categories"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-categories-all","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All NFT Categories"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All NFT Categories through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all nft categories before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-collection-new","method":"POST","path":"/api/v2/nft/collection/new","title":"NFT: Create New Collection","description":"NFT: Create New Collection through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/collection/new","operation":"NFT: Create New Collection"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-collection-new","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create New Collection"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Create New Collection through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use POST /api/v2/asset-collections to create a private draft, then POST /api/v2/asset-collections/{collection_uuid}/publications only after review.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-collection-update","method":"POST","path":"/api/v2/nft/collection/update","title":"NFT: Update Collection Meta-Data","description":"NFT: Update Collection Meta-Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/collection/update","operation":"NFT: Update Collection Meta-Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-collection-update","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update Collection Meta-Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Update Collection Meta-Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","No canonical metadata-update mutation is executable yet. Read the current collection or Explorer projection and wait for a version-aware Digital Assets update contract; never replay the legacy arbitrary metadata body.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-collections-all","method":"GET","path":"/api/v2/nft/collections/all","title":"NFT: Get All Collections","description":"NFT: Get All Collections through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/collections/all","operation":"NFT: Get All Collections"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-collections-all","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Collections"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Collections through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all collections before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-collections-created","method":"GET","path":"/api/v2/nft/collections/created","title":"NFT: Get All Created Collections","description":"NFT: Get All Created Collections through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/collections/created","operation":"NFT: Get All Created Collections"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-collections-created","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Created Collections"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Created Collections through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all created collections before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-collections-items","method":"GET","path":"/api/v2/nft/collections/items","title":"NFT: Get All Collection Items","description":"NFT: Get All Collection Items through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/collections/items","operation":"NFT: Get All Collection Items"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-collections-items","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Collection Items"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Collection Items through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all collection items before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-collections-meta","method":"GET","path":"/api/v2/nft/collections/meta","title":"NFT: Get Collection Meta Data","description":"NFT: Get Collection Meta Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/collections/meta","operation":"NFT: Get Collection Meta Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-collections-meta","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Collection Meta Data"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get Collection Meta Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get collection meta data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-creator-collections","method":"GET","path":"/api/v2/nft/creator/collections","title":"NFT: Get NFT Collections of Creator","description":"NFT: Get NFT Collections of Creator through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/creator/collections","operation":"NFT: Get NFT Collections of Creator"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-creator-collections","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get NFT Collections of Creator"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get NFT Collections of Creator through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get nft collections of creator before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-creator-profile","method":"GET","path":"/api/v2/nft/creator/profile","title":"NFT: Get NFT Creator Profile Data","description":"NFT: Get NFT Creator Profile Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/creator/profile","operation":"NFT: Get NFT Creator Profile Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-creator-profile","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get NFT Creator Profile Data"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get NFT Creator Profile Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get nft creator profile data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-creator-update","method":"POST","path":"/api/v2/nft/creator/update","title":"NFT: Update Creator Profile Data","description":"NFT: Update Creator Profile Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/creator/update","operation":"NFT: Update Creator Profile Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-creator-update","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update Creator Profile Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Update Creator Profile Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use PATCH /api/v2/me/profile only for the implemented account profile fields. No creator-marketplace extension mutation is executable yet.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tags-all","method":"GET","path":"/api/v2/nft/tags/all","title":"NFT: Get Created NFT Tags","description":"NFT: Get Created NFT Tags through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tags/all","operation":"NFT: Get Created NFT Tags"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tags-all","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Created NFT Tags"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get Created NFT Tags through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get created nft tags before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tags-allocate","method":"POST","path":"/api/v2/nft/tags/allocate","title":"NFT: Allocate NFT Tag to NFT Item","description":"NFT: Allocate NFT Tag to NFT Item through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tags/allocate","operation":"NFT: Allocate NFT Tag to NFT Item"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tags-allocate","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Allocate NFT Tag to NFT Item"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Allocate NFT Tag to NFT Item through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","No canonical tag-allocation owner is executable yet. Use canonical collection and asset metadata only where their exact schemas admit classification; never synthesize an arbitrary tag mutation.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tags-create","method":"POST","path":"/api/v2/nft/tags/create","title":"NFT: Create NFT Tag","description":"NFT: Create NFT Tag through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tags/create","operation":"NFT: Create NFT Tag"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tags-create","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create NFT Tag"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Create NFT Tag through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","No canonical tag-registry mutation is executable yet. Discover assets and collections through Digital Assets or Explorer and wait for an owned, schema-governed classification contract.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-accept-offer","method":"POST","path":"/api/v2/nft/tokens/accept-offer","title":"NFT: Accept Bid/Sell NFT","description":"NFT: Accept Bid/Sell NFT through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/accept-offer","operation":"NFT: Accept Bid/Sell NFT"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-accept-offer","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Accept Bid/Sell NFT"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Accept Bid/Sell NFT through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Do not accept a caller-authored bid. Reconcile the canonical listing and its Commerce-owned payment/order evidence; use the planned asset-market reconciliation contract only after it appears in live OpenAPI.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-all","method":"GET","path":"/api/v2/nft/tokens/all","title":"NFT: Get All NFTs","description":"NFT: Get All NFTs through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/all","operation":"NFT: Get All NFTs"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-all","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All NFTs"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All NFTs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all nfts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-buy-nft","method":"POST","path":"/api/v2/nft/tokens/buy-nft","title":"NFT: Instant-Buy NFT","description":"NFT: Instant-Buy NFT through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/buy-nft","operation":"NFT: Instant-Buy NFT"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-buy-nft","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Instant-Buy NFT"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Instant-Buy NFT through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use canonical asset listings for offer terms and Commerce for checkout/payment evidence. No atomic instant-buy Digital Assets command is executable yet.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-created","method":"GET","path":"/api/v2/nft/tokens/created","title":"NFT: Get All Created NFTs","description":"NFT: Get All Created NFTs through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/created","operation":"NFT: Get All Created NFTs"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-created","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Created NFTs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Created NFTs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all created nfts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-history","method":"GET","path":"/api/v2/nft/tokens/history","title":"NFT: Get NFT Lifecycle History","description":"NFT: Get NFT Lifecycle History through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/history","operation":"NFT: Get NFT Lifecycle History"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-history","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get NFT Lifecycle History"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get NFT Lifecycle History through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get nft lifecycle history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-make-offer","method":"POST","path":"/api/v2/nft/tokens/make-offer","title":"NFT: Make Bid for NFT","description":"NFT: Make Bid for NFT through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/make-offer","operation":"NFT: Make Bid for NFT"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-make-offer","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Make Bid for NFT"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Make Bid for NFT through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use canonical asset-listing discovery for terms. No governed offer/order creation contract is executable yet, so the legacy bid body must not be generated or sent.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-meta","method":"GET","path":"/api/v2/nft/tokens/meta","title":"NFT: Get NFT Meta Data","description":"NFT: Get NFT Meta Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/meta","operation":"NFT: Get NFT Meta Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-meta","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get NFT Meta Data"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get NFT Meta Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get nft meta data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-new","method":"POST","path":"/api/v2/nft/tokens/new","title":"NFT: Create New NFT","description":"NFT: Create New NFT through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/new","operation":"NFT: Create New NFT"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-new","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create New NFT"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Create New NFT through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use POST /api/v2/assets to create a private canonical asset draft, then publish and mint through their separate lifecycle operations when available.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-owned","method":"GET","path":"/api/v2/nft/tokens/owned","title":"NFT: Get All Owned NFTs","description":"NFT: Get All Owned NFTs through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/owned","operation":"NFT: Get All Owned NFTs"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-owned","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Owned NFTs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Owned NFTs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all owned nfts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-publish","method":"POST","path":"/api/v2/nft/tokens/publish","title":"NFT: Publish / Unpublish an NFT","description":"NFT: Publish / Unpublish an NFT through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/publish","operation":"NFT: Publish / Unpublish an NFT"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-publish","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Publish / Unpublish an NFT"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Publish / Unpublish an NFT through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Use POST /api/v2/assets/{asset_uuid}/publications for one-way reviewed publication. The legacy publish/unpublish toggle is retired.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-nft-tokens-sold","method":"GET","path":"/api/v2/nft/tokens/sold","title":"NFT: Get All Sold NFTs","description":"NFT: Get All Sold NFTs through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/nft/tokens/sold","operation":"NFT: Get All Sold NFTs"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-nft-tokens-sold","scope":"assets:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Sold NFTs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Get All Sold NFTs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all sold nfts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:read authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"post-api-v2-nft-tokens-update","method":"POST","path":"/api/v2/nft/tokens/update","title":"NFT: Update NFT Meta-Data","description":"NFT: Update NFT Meta-Data through the canonical Hybrid-Chain V2 interface.","chapter":"NFT Super Store","chapterOrder":13,"capability":"NFT Super Store","owners":["digital-asset-marketplace"],"applications":["Digital Assets"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/nft/tokens/update","operation":"NFT: Update NFT Meta-Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-nft-tokens-update","scope":"assets:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update NFT Meta-Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing assets:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"This legacy compatibility marker is non-executable. Use the canonical Digital Assets operation named in businessContext.agentGuidance and verify its availability in live OpenAPI before calling it.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NFT: Update NFT Meta-Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this route. It is a non-executable compatibility marker retained so older integrations receive an explicit migration answer instead of an invented V2 request schema.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, update, publish, mint, tag, offer, sell, transfer, pay for, or otherwise change a digital asset.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["A bearer credential with assets:write authority and the required tenant, workspace, and role context.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","No canonical asset metadata-update mutation is executable yet. Read current state and wait for a version-aware owner contract; never replay the legacy arbitrary metadata body.","Before calling any replacement, verify that the exact operation appears in GET /api/v2/openapi.json. A planned-profiled registry entry remains documentation, not runtime availability.","Do not translate legacy bodies field-for-field. Legacy owner selectors, arbitrary metadata, payment assertions, publish toggles, and unverified token-mint shapes are intentionally not accepted by canonical V2 contracts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Chain Explorer","Commerce"]}},{"id":"get-api-v2-account-activity","method":"GET","path":"/api/v2/account/activity","title":"OVERVIEW: List account activity","description":"List normalized, cursor-paginated activity from the services the account is authorized to view.","chapter":"General Data","chapterOrder":14,"capability":"Account overview","owners":["account-read-model"],"applications":["Overview","Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-account-activity","scope":"developer:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List account activity"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List normalized, cursor-paginated activity from the services the account is authorized to view.","whenToUse":"Use this operation when an integration needs to list account activity before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Trust Center","API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-account-overview","method":"GET","path":"/api/v2/account/overview","title":"OVERVIEW: Get account posture","description":"Return the authenticated account's operational posture across wallets, funding, compliance, billing, and activity.","chapter":"General Data","chapterOrder":14,"capability":"Account overview","owners":["account-read-model"],"applications":["Overview","Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-account-overview","scope":"developer:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get account posture"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated account's operational posture across wallets, funding, compliance, billing, and activity.","whenToUse":"Use this operation when an integration needs to get account posture before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Notifications","Trust Center","API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-general-countries","method":"GET","path":"/api/v2/general/countries","title":"GENERAL: Get Countries Data","description":"GENERAL: Get Countries Data through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"General Data","owners":["reference-data"],"applications":["Developers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/general/countries","operation":"GENERAL: Get Countries Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-general-countries","scope":"developer:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Countries Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"GENERAL: Get Countries Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get countries data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-general-currencies-historical","method":"GET","path":"/api/v2/general/currencies_historical","title":"GENERAL: Get Historical Rates","description":"GENERAL: Get Historical Rates through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"General Data","owners":["reference-data"],"applications":["Developers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/general/currencies_historical","operation":"GENERAL: Get Historical Rates"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-general-currencies-historical","scope":"developer:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Historical Rates"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"GENERAL: Get Historical Rates through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get historical rates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-general-info","method":"GET","path":"/api/v2/general/info","title":"GENERAL: Get Status Info","description":"GENERAL: Get Status Info through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"General Data","owners":["reference-data"],"applications":["Developers"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/general/info","operation":"GENERAL: Get Status Info"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1general~1info/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Status Info"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"GENERAL: Get Status Info through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get status info before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-general-us-states","method":"GET","path":"/api/v2/general/us_states","title":"GENERAL: Get US States Data","description":"GENERAL: Get US States Data through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"General Data","owners":["reference-data"],"applications":["Developers"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/general/us_states","operation":"GENERAL: Get US States Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-general-us-states","scope":"developer:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get US States Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"GENERAL: Get US States Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get us states data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-reference-currencies","method":"GET","path":"/api/v2/reference/currencies","title":"GENERAL: Get Currencies Data","description":"GENERAL: Get Currencies Data through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"General Data","owners":["reference-data"],"applications":["Developers"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/general/currencies","operation":"GENERAL: Get Currencies Data"}],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1reference~1currencies/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Currencies Data"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"GENERAL: Get Currencies Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get currencies data before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-identity-status","method":"GET","path":"/api/v2/identity/status","title":"IDENTITY: get status","description":"IDENTITY: get status through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"Identity · status","owners":["identity-service"],"applications":["Developers","Trust Center"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/status","source":"Identity APIHandler.py · get_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["get status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-news","method":"GET","path":"/api/v2/news","title":"news publications","description":"news publications through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"News and verification","owners":["core-evidence-read-model"],"applications":["Developers","Trust Center"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/news","source":"APIRoutes.py · view_news_publications"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1news/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["news publications"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–99","description":"Maximum published entries to return.","example":24},{"name":"category","location":"query","required":false,"type":"string · 1–64","description":"Exact public category filter.","example":"category-01"},{"name":"featured","location":"query","required":false,"type":"boolean","description":"When true, return featured publications only.","example":true}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"news publications through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to news publications before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-news-identifier","method":"GET","path":"/api/v2/news/{identifier}","title":"news publication","description":"news publication through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"News and verification","owners":["core-evidence-read-model"],"applications":["Developers","Trust Center"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/news/{identifier}","source":"APIRoutes.py · view_news_publication"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1news~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["news publication"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"news publication through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to news publication before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-news-identifier-verify","method":"GET","path":"/api/v2/news/{identifier}/verify","title":"news publication verification","description":"news publication verification through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"News and verification","owners":["core-evidence-read-model"],"applications":["Developers","Trust Center"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/news/{identifier}/verify","source":"APIRoutes.py · view_news_publication_verification"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1news~1{identifier}~1verify/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["news publication verification"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"news publication verification through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to news publication verification before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-capabilities","method":"GET","path":"/api/v2/capabilities","title":"V2 capability registry","description":"V2 capability registry through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"Platform metadata","owners":["api-gateway"],"applications":["Developers","API Reference"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"v2-native","sourceKinds":["application-expansion","v2-native"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1capabilities/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["V2 capability registry"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"V2 capability registry through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use after OpenAPI ingestion when an integration needs application mapping, ownership, legacy parity, readiness, business context, or planned-operation discovery.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","machine contract ingestion","endpoint and schema discovery","implementation-status verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Never call a registry-only planned-contract. Executable entries point back to their OpenAPI JSON Pointer through contract.reference.","Use documentationStatus, requestShapeAuthority, exampleDisclaimer, and businessContext to assess planning maturity without treating a profiled plan as deployed behavior.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Integration Guides","Access Control","Developer Portal"]}},{"id":"get-api-v2-status-info","method":"GET","path":"/api/v2/status/info","title":"main hybrid chain api","description":"main hybrid chain api through the canonical Hybrid-Chain V2 interface.","chapter":"General Data","chapterOrder":14,"capability":"Platform status","owners":["core-evidence-read-model"],"applications":["Developers","Infrastructure"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/status/info","source":"APIRoutes.py · view_main_hybrid_chain_api"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1status~1info/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["main hybrid chain api"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"main hybrid chain api through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to main hybrid chain api before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","service health review","testnet infrastructure evidence verification","account growth and readiness trending"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Admin Console","Indexer Controller","Evidence Streams"]}},{"id":"get-api-v2-identity-messaging-device-status-session-id","method":"GET","path":"/api/v2/identity/messaging/device-status/{session_id}","title":"IDENTITY: mobile messaging device status","description":"IDENTITY: mobile messaging device status through the canonical Hybrid-Chain V2 interface.","chapter":"Notifications","chapterOrder":15,"capability":"Identity · messaging","owners":["identity-service"],"applications":["Overview","Notifications","Trust Center"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/messaging/device-status/{session_id}","source":"Identity APIHandler.py · mobile_messaging_device_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1messaging~1device-status~1{session_id}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["mobile messaging device status"],"parameters":[{"name":"session_id","location":"path","required":true,"type":"identifier","description":"Canonical session id.","example":"session-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: mobile messaging device status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mobile messaging device status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Identity & Login","Access Control","Automations","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-mobile-messaging-device","method":"POST","path":"/api/v2/identity/mobile/messaging/device","title":"NOTIFICATIONS: Register messaging device keys","description":"Bind one authenticated application installation to independently generated Ed25519 signing and X25519 encryption public keys after proof of possession, then return a signed device credential.","chapter":"Notifications","chapterOrder":15,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Overview","Notifications","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/messaging/device","source":"Identity APIHandler.py · register_mobile_messaging_device"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1mobile~1messaging~1device/post","scope":"trust:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register messaging device keys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-identity-mobile-messaging-device-request-001"},{"name":"statement.deviceId","location":"body","required":true,"type":"safe device identifier · 8–128","description":"Stable identifier for this application installation. It must match the authenticated Identity session device.","example":"statement.deviceId-01"},{"name":"statement.encryptionPublicKey","location":"body","required":true,"type":"unpadded base64url X25519 public key · 43 characters","description":"Raw 32-byte public encryption key. Private encryption material must never leave the device.","example":"statement.encryptionPublicKey-01"},{"name":"statement.keyEpoch","location":"body","required":true,"type":"integer · 1–2147483647","description":"Monotonic key epoch bound into the device credential.","example":1},{"name":"statement.protocolVersion","location":"body","required":true,"type":"HybridSignedSealedEnvelope2026","description":"Exact signed-envelope protocol identifier.","example":"statement.protocolVersion-01"},{"name":"statement.signingPublicKey","location":"body","required":true,"type":"unpadded base64url Ed25519 public key · 43 characters","description":"Raw 32-byte public signing key used to verify messaging envelopes and the binding proof.","example":"statement.signingPublicKey-01"},{"name":"proofValue","location":"body","required":true,"type":"unpadded base64url Ed25519 signature · 86 characters","description":"Signature over the domain-separated canonical statement, proving possession of the submitted signing private key.","example":"proofValue-01"}],"responses":[{"status":200,"description":"Messaging public-key binding accepted and signed device credential returned.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks trust:write, the device differs from the authenticated session, or proof of possession fails.","example":null},{"status":409,"description":"The session already has a different active messaging identity.","example":null},{"status":422,"description":"Protocol, key epoch, public keys, proof, or Idempotency-Key is malformed.","example":null},{"status":503,"description":"Identity messaging registration is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Bind one authenticated application installation to independently generated Ed25519 signing and X25519 encryption public keys after proof of possession, then return a signed device credential.","whenToUse":"Use once per application installation after authentication and local generation of separate Ed25519 signing and X25519 encryption key pairs, before requesting a messaging ticket.","workflowRole":"create-or-command","sideEffects":"Creates or idempotently confirms the active Identity-owned device-key binding and returns a signed 30-day device credential. It grants messaging identity only and never grants notification preference, business-state, payment, settlement, trading, ingress, publisher, market, or traffic authority.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Construct key-sorted compact JSON of statement, prepend hybrid-chain/messaging/device-key-binding/v1 and a NUL byte, then sign those exact bytes with the submitted Ed25519 private key. Submit only the public keys and proofValue.","Keep both private keys in device secure storage. Reuse the same Idempotency-Key only for the same statement and proof. A different active binding returns 409 and requires the owner lifecycle rather than silent replacement.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Identity & Login","Access Control","Automations","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-mobile-messaging-ticket","method":"GET","path":"/api/v2/identity/mobile/messaging/ticket","title":"NOTIFICATIONS: Issue messaging ticket","description":"Issue a short-lived device- and session-bound messaging ticket for an installation with an active signed device credential.","chapter":"Notifications","chapterOrder":15,"capability":"Identity · mobile","owners":["identity-service"],"applications":["Overview","Notifications","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/messaging/ticket","source":"Identity APIHandler.py · issue_mobile_messaging_ticket"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1mobile~1messaging~1ticket/get","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Issue messaging ticket"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Short-lived device- and session-bound messaging ticket returned under no-store.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks trust:read or the session has no active messaging-device credential.","example":null},{"status":503,"description":"Identity messaging ticket issuance is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Issue a short-lived device- and session-bound messaging ticket for an installation with an active signed device credential.","whenToUse":"Request immediately before opening or refreshing the messaging transport, after the same authenticated session has an active registered messaging-device credential.","workflowRole":"discover-or-read","sideEffects":"Issues a secret hmt_v1 ticket bound to the current profile, session, and device for at most 600 seconds. It does not send a notification, change preferences, acknowledge an event, or authorize any owning business resource.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Treat ticket as a bearer secret: keep it out of URLs, prompts, logs, analytics, persistent storage, and crash reports; use it only with the messaging transport and discard it at expiry.","A ticket or delivered message is not canonical business state. Follow the message's resource reference and re-read the owning API before an agent decides or acts.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Identity & Login","Access Control","Automations","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-notifications-all","method":"GET","path":"/api/v2/notifications/all","title":"NOTIFICATIONS: List account signals","description":"List the authenticated profile and workspace's cursor-paginated operational signals, including unread count and optional archived-history inclusion, without granting authority over any referenced domain action.","chapter":"Notifications","chapterOrder":15,"capability":"Notifications","owners":["notifications"],"applications":["Overview","Notifications"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["notification-inbox-service"],"legacySources":[{"method":"GET","path":"/api/v1/notifications/all","operation":"NOTIFICATIONS: Get All Notifications"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/notifications","source":"APIRoutes.py · Handler_Notifications.handle_list · signed owner-scoped inbox projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1notifications~1all/get","scope":"profile:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List account signals"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"decimal offset cursor · 0–1000000","description":"Cursor returned by the preceding page; defaults to 0 and is valid only for the same owner and filters.","example":"0"},{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum newest notification records to return; defaults to 50.","example":50},{"name":"includeArchived","location":"query","required":false,"type":"boolean","description":"Include archived records on the complete inbox route. Defaults to false and is ignored by the unread route.","example":false}],"responses":[{"status":200,"description":"Newest owner-scoped notification page and authoritative unread aggregate returned under no-store.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks profile:read.","example":null},{"status":422,"description":"The cursor or limit is invalid.","example":null},{"status":503,"description":"The authoritative notification inbox is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated profile and workspace's cursor-paginated operational signals, including unread count and optional archived-history inclusion, without granting authority over any referenced domain action.","whenToUse":"Use for a profile or workspace notification center that needs the newest operational signals, unread aggregate, and stable presentation references before the person or agent decides whether to open the underlying domain workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Reuse nextCursor only with the same includeArchived choice. A null nextCursor means the bounded owner-scoped page is complete.","title, message, source, reference, and href are presentation and routing metadata. Re-read the referenced domain resource before acting; a notification never grants payment, settlement, governance, custody, trading, or administrative authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Trust Center","Identity & Login","Access Control","Automations"]}},{"id":"post-api-v2-notifications-mark","method":"POST","path":"/api/v2/notifications/mark","title":"NOTIFICATIONS: Mark account signals","description":"Atomically set one to 100 owner-scoped notification records to UNREAD, READ, or ARCHIVED using an idempotent acknowledgement command.","chapter":"Notifications","chapterOrder":15,"capability":"Notifications","owners":["notifications"],"applications":["Overview","Notifications"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["notification-inbox-service"],"legacySources":[{"method":"POST","path":"/api/v1/notifications/mark","operation":"NOTIFICATIONS: Mark Notification Status"}],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/notifications/mark","source":"APIRoutes.py · Handler_Notifications.handle_mark · signed idempotent owner-scoped acknowledgement"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1notifications~1mark/post","scope":"profile:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mark account signals"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-notifications-mark-request-001"},{"name":"notificationUuids","location":"body","required":true,"type":"safe notification identifier[] · 1–100 unique values","description":"Every identifier must exist in the authenticated profile and workspace inbox; mixed-owner or missing batches fail without updating any record.","example":["notice-security-review-20260901"]},{"name":"status","location":"body","required":true,"type":"UNREAD | READ | ARCHIVED","description":"Replacement inbox lifecycle state. This state changes presentation only and never authorizes the referenced domain action.","example":"READ"}],"responses":[{"status":200,"description":"Exact identifiers and resulting owner-scoped inbox state retained idempotently.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks profile:write or the RFC 9421 signature is invalid.","example":null},{"status":404,"description":"At least one identifier is not in this owner-scoped inbox; no record was changed.","example":null},{"status":409,"description":"The Idempotency-Key was previously used with a different logical request.","example":null},{"status":422,"description":"The identifier batch, lifecycle state, signature, or Idempotency-Key is malformed.","example":null},{"status":503,"description":"The authoritative notification inbox is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically set one to 100 owner-scoped notification records to UNREAD, READ, or ARCHIVED using an idempotent acknowledgement command.","whenToUse":"Use after an authenticated person or agent has intentionally acknowledged, reopened, or archived one to 100 signals from the current owner-scoped inbox.","workflowRole":"create-or-command","sideEffects":"Changes only inbox presentation state for the authenticated profile and workspace. It cannot execute, approve, cancel, settle, publish, or authorize the event referenced by a signal.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with profile:write authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Every notificationUuids member must belong to the same authenticated inbox. If any identifier is absent, foreign, malformed, or duplicated, the entire command fails before an update.","Reuse one Idempotency-Key only for an equivalent identifier set and status. Re-read the inbox after an ambiguous result rather than guessing acknowledgement state.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Trust Center","Identity & Login","Access Control","Automations"]}},{"id":"post-api-v2-notifications-push","method":"POST","path":"/api/v2/notifications/push","title":"NOTIFICATIONS: Push New Notification","description":"NOTIFICATIONS: Push New Notification through the canonical Hybrid-Chain V2 interface.","chapter":"Notifications","chapterOrder":15,"capability":"Notifications","owners":["notifications"],"applications":["Overview","Notifications"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/notifications/push","operation":"NOTIFICATIONS: Push New Notification"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-notifications-push","scope":"service:notifications:publish","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Push New Notification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing service:notifications:publish authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-notifications-push-request-001"},{"name":"event","location":"body","required":true,"type":"future authenticated service event","description":"Planning profile only. Promotion requires a service publisher identity, target-owner derivation, an allowlisted event class, typed reference, display-safe content, and deduplication metadata.","example":"event-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"NOTIFICATIONS: Push New Notification through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this planning route. It reserves an internal service-to-service publisher boundary and is intentionally unavailable to end-user bearers and public agents.","workflowRole":"create-or-command","sideEffects":"No executable public behavior exists. Promotion would create an owner-targeted signal only; it must not perform or authorize the referenced domain action.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with service:notifications:publish authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","Promotion requires a separately authenticated service publisher, an allowlisted event class, server-derived target profile and workspace, a typed resource reference, display-safe content, deduplication and idempotency, rate and abuse controls, retained provenance, and an outbox or delivery contract.","Never infer or request a notification:write user scope for publication. Domain services must publish through a narrow purpose-bound adapter after the underlying event is durably committed.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Trust Center","Identity & Login","Access Control","Automations"]}},{"id":"get-api-v2-notifications-unread","method":"GET","path":"/api/v2/notifications/unread","title":"NOTIFICATIONS: List unread account signals","description":"List only unread operational signals for the authenticated profile and workspace, with the same bounded cursor and no-authority guarantees as the complete inbox.","chapter":"Notifications","chapterOrder":15,"capability":"Notifications","owners":["notifications"],"applications":["Overview","Notifications"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["notification-inbox-service"],"legacySources":[{"method":"GET","path":"/api/v1/notifications/unread","operation":"NOTIFICATIONS: Get Unread Notifications"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/notifications/unread","source":"APIRoutes.py · Handler_Notifications.handle_list · signed unread-only owner projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1notifications~1unread/get","scope":"profile:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List unread account signals"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing profile:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"decimal offset cursor · 0–1000000","description":"Cursor returned by the preceding page; defaults to 0 and is valid only for the same owner and filters.","example":"0"},{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum newest notification records to return; defaults to 50.","example":50},{"name":"includeArchived","location":"query","required":false,"type":"boolean","description":"Include archived records on the complete inbox route. Defaults to false and is ignored by the unread route.","example":false}],"responses":[{"status":200,"description":"Unread owner-scoped notification page and authoritative unread aggregate returned under no-store.","example":null},{"status":401,"description":"The bearer credential is missing or invalid.","example":null},{"status":403,"description":"The bearer lacks profile:read.","example":null},{"status":422,"description":"The cursor or limit is invalid.","example":null},{"status":503,"description":"The authoritative notification inbox is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List only unread operational signals for the authenticated profile and workspace, with the same bounded cursor and no-authority guarantees as the complete inbox.","whenToUse":"Use for badges, attention queues, and agents that process only unacknowledged account signals without downloading read or archived history.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["daily account review","exception triage","cross-module navigation","device-bound encrypted messaging","security alerts","workflow reminders"],"prerequisites":["A bearer credential with profile:read authority and the required tenant, workspace, and role context.","an authenticated profile","access to the selected workspace"],"agentGuidance":["Treat overview data as a projection, not the authority for balances or lifecycle decisions.","Re-read the owning resource before taking a consequential action.","The route forces UNREAD. Do not send a conflicting status filter; use the complete inbox when READ or ARCHIVED records are required.","Processing a signal and acknowledging it are separate operations. Complete or reconcile the underlying business workflow before marking the signal READ when that distinction matters.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Trust Center","Identity & Login","Access Control","Automations"]}},{"id":"get-api-v2-network","method":"GET","path":"/api/v2/network","title":"NETWORK: Get Network Downline","description":"NETWORK: Get Network Downline through the canonical Hybrid-Chain V2 interface.","chapter":"Referral System","chapterOrder":16,"capability":"Referral System","owners":["identity-referrals"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/network","operation":"NETWORK: Get Network Downline"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-network","scope":"workspaces:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Network Downline"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NETWORK: Get Network Downline through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get network downline before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-network-invite","method":"POST","path":"/api/v2/network/invite","title":"NETWORK: Invite/Refer a new User","description":"NETWORK: Invite/Refer a new User through the canonical Hybrid-Chain V2 interface.","chapter":"Referral System","chapterOrder":16,"capability":"Referral System","owners":["identity-referrals"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/network/invite","operation":"NETWORK: Invite/Refer a new User"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-network-invite","scope":"workspaces:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Invite/Refer a new User"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy workspace compatibility marker; use the canonical implemented workspace lifecycle identified in guidance.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NETWORK: Invite/Refer a new User through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless 501 compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. It cannot select a workspace, invite or refer a user, revoke membership, or change a role.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","Use implemented POST /api/v2/workspaces/{workspace_id}/invitations for a bounded workspace invitation; referral acquisition is a separate Growth workflow.","Verify the implemented replacement in live OpenAPI and do not translate the legacy body field-for-field.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-network-refkey","method":"GET","path":"/api/v2/network/refkey","title":"NETWORK: Get Referral Key","description":"NETWORK: Get Referral Key through the canonical Hybrid-Chain V2 interface.","chapter":"Referral System","chapterOrder":16,"capability":"Referral System","owners":["identity-referrals"],"applications":["Teams & Workspaces"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/network/refkey","operation":"NETWORK: Get Referral Key"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-network-refkey","scope":"workspaces:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Referral Key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"NETWORK: Get Referral Key through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get referral key before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:read authority and the required tenant, workspace, and role context.","tenant membership","owner or administrator role for team mutations","admin:tenants scopes and fresh purpose-bound step-up for tenant configuration mutations","current membership, tenant, revision, domain, and entitlement versions"],"agentGuidance":["Derive tenant and workspace context from authenticated membership; never accept caller-selected owner, role authority, actor, or cross-tenant resource identifiers.","Use optimistic versions and never silently overwrite concurrent membership, role, revision, domain, or entitlement changes.","An invitation is not membership; a draft is not reviewed or published; a registered domain is not verified or routed; an entitlement is not a bearer scope or operational authority.","Preserve last-owner, administrator access, recovery, billing, domain, and dependent-resource safety when changing or removing configuration.","Tenant configuration and entitlements cannot enable frozen trading controls, matching, prediction execution, ingress, publisher activity, market status, or traffic.","Treat legacy POST workspace mutation aliases as bodyless 501 migration markers and use their implemented PUT, DELETE, or invitation replacements from live OpenAPI.","The active roster exposes opaque membership and profile references, role, version, status, and timestamps only; it is not an email or global Identity directory and invitation state remains a separate lifecycle.","Every workspace mutation requires the live OpenAPI Idempotency-Key and HTTP Message Signature contract. Reuse a key only for the byte-equivalent logical retry and re-read canonical state after a 409 or ambiguous result.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-identity-attestations","method":"GET","path":"/api/v2/identity/attestations","title":"IDENTITY: list attestations","description":"IDENTITY: list attestations through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/attestations","source":"Identity APIHandler.py · list_attestations"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-attestations","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["list attestations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: list attestations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to list attestations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-attestations-credential-uuid","method":"GET","path":"/api/v2/identity/attestations/{credential_uuid}","title":"IDENTITY: get attestation","description":"IDENTITY: get attestation through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/attestations/{credential_uuid}","source":"Identity APIHandler.py · get_attestation"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-attestations-credential-uuid","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get attestation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get attestation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-credential-uuid-challenge","method":"POST","path":"/api/v2/identity/attestations/{credential_uuid}/challenge","title":"IDENTITY: create attestation challenge","description":"IDENTITY: create attestation challenge through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/{credential_uuid}/challenge","source":"Identity APIHandler.py · create_attestation_challenge"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-credential-uuid-challenge","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["create attestation challenge"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: create attestation challenge through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public selective-disclosure challenge mutation is executable yet. Read GET /api/v2/trust/attestations and wait for a purpose-, audience-, nonce-, expiry-, and credential-bound challenge contract in live OpenAPI.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-credential-uuid-presentation","method":"POST","path":"/api/v2/identity/attestations/{credential_uuid}/presentation","title":"IDENTITY: create attestation presentation","description":"IDENTITY: create attestation presentation through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/{credential_uuid}/presentation","source":"Identity APIHandler.py · create_attestation_presentation"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-credential-uuid-presentation","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["create attestation presentation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: create attestation presentation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public presentation creation mutation is executable yet. A future contract must bind one challenge, audience, disclosed claim commitments, holder proof, expiry, and replay prevention.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-credential-uuid-status","method":"POST","path":"/api/v2/identity/attestations/{credential_uuid}/status","title":"IDENTITY: update attestation status","description":"IDENTITY: update attestation status through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/{credential_uuid}/status","source":"Identity APIHandler.py · update_attestation_status"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-credential-uuid-status","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["update attestation status"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: update attestation status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use subject-visible GET /api/v2/trust/attestations or GET /api/v2/trust/credentials for lifecycle reads. Issuer status changes require a separately authorized canonical lifecycle.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-credential-uuid-verify","method":"POST","path":"/api/v2/identity/attestations/{credential_uuid}/verify","title":"IDENTITY: verify attestation presentation","description":"IDENTITY: verify attestation presentation through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/{credential_uuid}/verify","source":"Identity APIHandler.py · verify_attestation_presentation"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-credential-uuid-verify","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["verify attestation presentation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: verify attestation presentation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public presentation-verification mutation is executable yet. Relying parties must not post an opaque legacy presentation until a bounded verifier contract appears in live OpenAPI.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-issue-identity-uuid","method":"POST","path":"/api/v2/identity/attestations/issue/{identity_uuid}","title":"IDENTITY: issue attestation","description":"IDENTITY: issue attestation through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/issue/{identity_uuid}","source":"Identity APIHandler.py · issue_attestation"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-issue-identity-uuid","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["issue attestation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"identity_uuid","location":"path","required":true,"type":"identifier","description":"Canonical identity uuid.","example":"identity-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: issue attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use POST /api/v2/trust/credentials only after its issuer-controlled contract appears in live OpenAPI. Subject identity, completed verification, consent, claim selection, validity, proof, and revocation registration must be owner-resolved.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-attestations-issuer","method":"GET","path":"/api/v2/identity/attestations/issuer","title":"IDENTITY: get attestation issuer","description":"IDENTITY: get attestation issuer through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/attestations/issuer","source":"Identity APIHandler.py · get_attestation_issuer"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-attestations-issuer","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get attestation issuer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get attestation issuer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get attestation issuer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-attestations-subject-profile-profile-uuid","method":"GET","path":"/api/v2/identity/attestations/subject/profile/{profile_uuid}","title":"IDENTITY: get subject attestations","description":"IDENTITY: get subject attestations through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/attestations/subject/profile/{profile_uuid}","source":"Identity APIHandler.py · get_subject_attestations"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-attestations-subject-profile-profile-uuid","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["get subject attestations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: get subject attestations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get subject attestations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-subject-profile-profile-uuid-credential-uuid-status","method":"POST","path":"/api/v2/identity/attestations/subject/profile/{profile_uuid}/{credential_uuid}/status","title":"IDENTITY: update subject attestation status","description":"IDENTITY: update subject attestation status through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/subject/profile/{profile_uuid}/{credential_uuid}/status","source":"Identity APIHandler.py · update_subject_attestation_status"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-subject-profile-profile-uuid-credential-uuid-status","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["update subject attestation status"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: update subject attestation status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use the canonical credential lifecycle only after the exact issuer-authorized revocation or suspension operation appears in live OpenAPI; callers cannot author subject or credential status.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-attestations-subject-profile-profile-uuid-claims","method":"GET","path":"/api/v2/identity/attestations/subject/profile/{profile_uuid}/claims","title":"IDENTITY: manage subject claims","description":"IDENTITY: manage subject claims through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/attestations/subject/profile/{profile_uuid}/claims","source":"Identity APIHandler.py · manage_subject_claims"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-attestations-subject-profile-profile-uuid-claims","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject claims"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage subject claims through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to manage subject claims before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-subject-profile-profile-uuid-claims","method":"POST","path":"/api/v2/identity/attestations/subject/profile/{profile_uuid}/claims","title":"IDENTITY: manage subject claims","description":"IDENTITY: manage subject claims through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/subject/profile/{profile_uuid}/claims","source":"Identity APIHandler.py · manage_subject_claims"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-subject-profile-profile-uuid-claims","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject claims"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage subject claims through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use implemented POST /api/v2/trust/claims to create or update one allowlisted subject-owned self-asserted claim, or DELETE /api/v2/trust/claims/{claim_uuid} for eligible deletion.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-attestations-subject-profile-profile-uuid-issue","method":"POST","path":"/api/v2/identity/attestations/subject/profile/{profile_uuid}/issue","title":"IDENTITY: issue subject attestation","description":"IDENTITY: issue subject attestation through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · attestations","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/attestations/subject/profile/{profile_uuid}/issue","source":"Identity APIHandler.py · issue_subject_attestation"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-attestations-subject-profile-profile-uuid-issue","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["issue subject attestation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: issue subject attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use POST /api/v2/trust/credentials only after it appears in live OpenAPI with issuer authority, completed verification, consent, minimized claims, validity, proof, and revocation controls.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-verification-policies","method":"GET","path":"/api/v2/identity/verification/policies","title":"TRUST: List verification policies","description":"List the versioned identity-verification policies available to the authenticated subject, including assurance levels, retention periods, required checks, and freshness windows so a person or agent can select a policy before starting verification.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["service-expansion","identity-trust-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/trust/verification-policies","source":"APIHandler.py · list_mobile_identity_verification_policies · authenticated policy catalog projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1verification~1policies/get","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List verification policies"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the versioned identity-verification policies available to the authenticated subject, including assurance levels, retention periods, required checks, and freshness windows so a person or agent can select a policy before starting verification.","whenToUse":"Start a subject verification workflow here to select the least intrusive current policy and disclose its required checks, assurance, freshness, and retention before obtaining consent.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Bind automation to policy id plus immutable version, not the display name. A listed policy is available; it is not evidence that this subject started, completed, or passed it.","freshness_days constrains reuse of prior evidence for one check. Zero does not mean evidence is permanent or exempt from the selected policy.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-verification-review","method":"GET","path":"/api/v2/identity/verification/review","title":"IDENTITY: manage verification review queue","description":"IDENTITY: manage verification review queue through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/verification/review","source":"Identity APIHandler.py · manage_verification_review_queue"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-verification-review","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage verification review queue"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage verification review queue through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to manage verification review queue before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-review","method":"POST","path":"/api/v2/identity/verification/review","title":"IDENTITY: manage verification review queue","description":"IDENTITY: manage verification review queue through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/review","source":"Identity APIHandler.py · manage_verification_review_queue"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-review","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage verification review queue"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage verification review queue through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public generic reviewer command is executable. Reviewer inventory and case actions require explicit case-bound read, assignment, screening, and decision resources under Identity Review authority.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-review-assign","method":"POST","path":"/api/v2/identity/verification/review/assign","title":"IDENTITY: assign verification reviewer","description":"IDENTITY: assign verification reviewer through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/review/assign","source":"Identity APIHandler.py · assign_verification_reviewer"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-review-assign","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["assign verification reviewer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: assign verification reviewer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No canonical reviewer-assignment mutation is executable yet. A future contract must bind one case version, eligible reviewer, separation-of-duties policy, reason, step-up, and immutable assignment evidence.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-verification-review-evidence-evidence-uuid","method":"GET","path":"/api/v2/identity/verification/review/evidence/{evidence_uuid}","title":"IDENTITY: verification evidence","description":"IDENTITY: verification evidence through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/verification/review/evidence/{evidence_uuid}","source":"Identity APIHandler.py · view_verification_evidence"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-verification-review-evidence-evidence-uuid","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["verification evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"evidence_uuid","location":"path","required":true,"type":"identifier","description":"Canonical evidence uuid.","example":"evidence-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: verification evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to verification evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-review-finalize","method":"POST","path":"/api/v2/identity/verification/review/finalize","title":"IDENTITY: finalize verification case","description":"IDENTITY: finalize verification case through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/review/finalize","source":"Identity APIHandler.py · finalize_verification_case"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-review-finalize","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["finalize verification case"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: finalize verification case through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No canonical reviewer-decision mutation is executable yet. A future contract must separate check findings from the final decision and bind case version, reviewer authority, structured reason, evidence commitments, and appeal posture.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-review-screen","method":"POST","path":"/api/v2/identity/verification/review/screen","title":"IDENTITY: request verification screening","description":"IDENTITY: request verification screening through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/review/screen","source":"Identity APIHandler.py · request_verification_screening"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-review-screen","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["request verification screening"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: request verification screening through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public ad hoc screening mutation is executable. Screening must be policy-selected, purpose-limited, provider-owned, evidence-minimized, and attached to one verification case.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-verification-sanctions-sources","method":"GET","path":"/api/v2/identity/verification/sanctions/sources","title":"TRUST: List sanctions source posture","description":"List the purpose-limited coverage and freshness posture of first-party sanctions sources without exposing source URLs, downloaded-content hashes, error messages, or screening evidence.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["service-expansion","identity-trust-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/trust/sanctions-sources","source":"APIHandler.py · list_mobile_identity_sanctions_sources · authenticated minimized source-health projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1identity~1verification~1sanctions~1sources/get","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List sanctions source posture"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the purpose-limited coverage and freshness posture of first-party sanctions sources without exposing source URLs, downloaded-content hashes, error messages, or screening evidence.","whenToUse":"Reconcile configured sanctions-source coverage and freshness immediately before a policy or compliance workflow that depends on screening posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","CURRENT describes ingestion freshness under Identity policy; it never means a subject was screened, cleared, or approved.","Raw lists, matches, source URLs, hashes, provider credentials, and diagnostics are deliberately excluded. Do not infer them from record_count or timestamps.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-identity-verification-subject-profile-profile-uuid","method":"GET","path":"/api/v2/identity/verification/subject/profile/{profile_uuid}","title":"IDENTITY: manage subject verification","description":"IDENTITY: manage subject verification through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/verification/subject/profile/{profile_uuid}","source":"Identity APIHandler.py · manage_subject_verification"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-identity-verification-subject-profile-profile-uuid","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject verification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage subject verification through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to manage subject verification before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-subject-profile-profile-uuid","method":"POST","path":"/api/v2/identity/verification/subject/profile/{profile_uuid}","title":"IDENTITY: manage subject verification","description":"IDENTITY: manage subject verification through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/subject/profile/{profile_uuid}","source":"Identity APIHandler.py · manage_subject_verification"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-subject-profile-profile-uuid","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["manage subject verification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: manage subject verification through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use implemented POST /api/v2/trust/verifications to start one subject-owned workflow and GET /api/v2/trust/verifications/{verification_uuid} to monitor it. Generic action dispatch is retired.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-identity-verification-subject-profile-profile-uuid-session-uuid-evidence","method":"POST","path":"/api/v2/identity/verification/subject/profile/{profile_uuid}/{session_uuid}/evidence","title":"IDENTITY: capture subject verification evidence","description":"IDENTITY: capture subject verification evidence through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"Identity · verification","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"service-expansion","sourceKinds":["service-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/verification/subject/profile/{profile_uuid}/{session_uuid}/evidence","source":"Identity APIHandler.py · capture_subject_verification_evidence"}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-identity-verification-subject-profile-profile-uuid-session-uuid-evidence","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["capture subject verification evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"session_uuid","location":"path","required":true,"type":"identifier","description":"Canonical session uuid.","example":"session-uuid-01"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"IDENTITY: capture subject verification evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","No public regulated-evidence upload is executable. A future owner-issued upload session must constrain evidence class, media type, bytes, digest, retention, consent, malware scanning, encryption, and one verification step.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-kyc-aristaflow-widget","method":"POST","path":"/api/v2/kyc/aristaflow/widget","title":"KYC-AML: Load AristaFlow Widget","description":"KYC-AML: Load AristaFlow Widget through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"KYC / AML Functions","owners":["identity-compliance"],"applications":["Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/kyc/aristaflow/widget","operation":"KYC-AML: Load AristaFlow Widget"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-kyc-aristaflow-widget","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Load AristaFlow Widget"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"KYC-AML: Load AristaFlow Widget through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use GET /api/v2/identity/verification/policies followed by POST /api/v2/trust/verifications. Provider widget selection and session material are Identity-owned and must not be treated as portable authority.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-kycaml-addressdata","method":"POST","path":"/api/v2/kycaml/addressdata","title":"KYC-AML: 2. Submit Address KYC Data","description":"KYC-AML: 2. Submit Address KYC Data through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"KYC / AML Functions","owners":["identity-compliance"],"applications":["Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/kycaml/addressdata","operation":"KYC-AML: 2. Submit Address KYC Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-kycaml-addressdata","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["2. Submit Address KYC Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"KYC-AML: 2. Submit Address KYC Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use the selected verification policy and subject-owned verification lifecycle. Direct legacy address payload submission is retired and must not be translated into V2.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-kycaml-identificationdata","method":"POST","path":"/api/v2/kycaml/identificationdata","title":"KYC-AML: 3. Submit KYC Identification Data","description":"KYC-AML: 3. Submit KYC Identification Data through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"KYC / AML Functions","owners":["identity-compliance"],"applications":["Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/kycaml/identificationdata","operation":"KYC-AML: 3. Submit KYC Identification Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-kycaml-identificationdata","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["3. Submit KYC Identification Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"KYC-AML: 3. Submit KYC Identification Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use the selected verification policy and subject-owned verification lifecycle. Direct identity-document payload submission is retired and must not be translated into V2.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-kycaml-personaldata","method":"POST","path":"/api/v2/kycaml/personaldata","title":"KYC-AML: 1. Submit Profile KYC Data","description":"KYC-AML: 1. Submit Profile KYC Data through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"KYC / AML Functions","owners":["identity-compliance"],"applications":["Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/kycaml/personaldata","operation":"KYC-AML: 1. Submit Profile KYC Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-kycaml-personaldata","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["1. Submit Profile KYC Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"KYC-AML: 1. Submit Profile KYC Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use the selected verification policy and subject-owned verification lifecycle. Direct personal-data payload submission is retired and must not be translated into V2.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-kycaml-selfiedata","method":"POST","path":"/api/v2/kycaml/selfiedata","title":"KYC-AML: 4. Submit KYC Selfie Data","description":"KYC-AML: 4. Submit KYC Selfie Data through the canonical Hybrid-Chain V2 interface.","chapter":"KYC / AML Functions","chapterOrder":17,"capability":"KYC / AML Functions","owners":["identity-compliance"],"applications":["Trust Center"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/kycaml/selfiedata","operation":"KYC-AML: 4. Submit KYC Selfie Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-kycaml-selfiedata","scope":"trust:compatibility","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["4. Submit KYC Selfie Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:compatibility authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Trust Center compatibility marker; use only the canonical subject-owned verification, claim, credential, or attestation lifecycle identified in guidance, and never send regulated evidence to this marker.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"KYC-AML: 4. Submit KYC Selfie Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable Trust Center compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot collect regulated evidence, start or decide a review, screen a subject, synchronize sanctions data, issue or change a credential, create or verify a presentation, or alter verification state.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:compatibility authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Use the selected verification policy and subject-owned verification lifecycle. Direct selfie or biometric payload submission is retired and must not be translated into V2.","Do not translate the legacy body field-for-field or submit personal data, address data, identity documents, selfies, biometric material, screening matches, provider payloads, reviewer selectors, credential proofs, claim cleartext, secrets, or generic action objects to this marker.","Fetch live production OpenAPI and call only the exact canonical subject-, issuer-, reviewer-, or provider-owned operation. Those authority boundaries are intentionally separate and cannot substitute for one another.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-admin-access-audit-events","method":"GET","path":"/api/v2/admin/access/audit-events","title":"ACCESS: List audit events","description":"List cursor-paginated security and access-control events.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Infrastructure","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-access-audit-events","scope":"admin:access:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List audit events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List cursor-paginated security and access-control events.","whenToUse":"Use this operation when an integration needs to list audit events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["User Intel & Risk","Indexer Controller","Evidence Streams","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-admin-access-role-assignments","method":"POST","path":"/api/v2/admin/access/role-assignments","title":"ACCESS: Assign role","description":"Create a restricted role assignment with audit evidence.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-access-role-assignments","scope":"admin:access:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Assign role"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-access-role-assignments-request-001"},{"name":"tenant_uuid","location":"body","required":true,"type":"identifier","description":"Tenant boundary in which the assignment is authorized.","example":"tenant-uuid-01"},{"name":"profile_uuid","location":"body","required":true,"type":"identifier","description":"Managed identity receiving the role.","example":"profile-uuid-01"},{"name":"role_id","location":"body","required":true,"type":"restricted role identifier","description":"Exact role returned by the role catalog; arbitrary scope arrays are not accepted.","example":"role-id-01"},{"name":"expires_at","location":"body","required":false,"type":"RFC 3339 timestamp | null","description":"Optional assignment expiry; null requests the role-policy default, not permanence.","example":"2026-09-30T20:00:00Z"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed audit rationale.","example":"reason-01"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ROLE_ASSIGNMENT authorization for the exact administrator session.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a restricted role assignment with audit evidence.","whenToUse":"Do not call this planning mutation. It reserves one tenant-scoped assignment of a predefined restricted role after fresh purpose-bound step-up.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Promotion requires least-privilege role policy, administrator eligibility, subject and tenant binding, assignment expiry, conflict handling, lockout prevention, notification, and immutable audit evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Infrastructure","User Intel & Risk","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"delete-api-v2-admin-access-role-assignments-assignment-uuid","method":"DELETE","path":"/api/v2/admin/access/role-assignments/{assignment_uuid}","title":"ACCESS: Revoke role","description":"Revoke a role assignment with audit evidence.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-admin-access-role-assignments-assignment-uuid","scope":"admin:access:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke role"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-admin-access-role-assignments-assignment-uuid-request-001"},{"name":"assignment_uuid","location":"path","required":true,"type":"identifier","description":"Canonical assignment uuid.","example":"assignment-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current assignment version for optimistic concurrency.","example":1},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed revocation rationale.","example":"reason-01"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh ROLE_ASSIGNMENT_REVOCATION authorization.","example":"step-up-token-01"}],"responses":[{"status":204,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke a role assignment with audit evidence.","whenToUse":"Do not call this planning mutation. It reserves version-checked revocation of one exact role assignment.","workflowRole":"revoke-or-delete","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Promotion requires last-owner and lockout prevention, fresh step-up, expected-version conflicts, already-revoked retry semantics, token/session impact policy, and retained rationale.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Infrastructure","User Intel & Risk","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-admin-access-roles","method":"GET","path":"/api/v2/admin/access/roles","title":"ACCESS: List roles","description":"List restricted roles, scopes, and assignments.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-access-roles","scope":"admin:access:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List roles"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List restricted roles, scopes, and assignments.","whenToUse":"Use this operation when an integration needs to list roles before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"post-api-v2-admin-access-session-revocations","method":"POST","path":"/api/v2/admin/access/session-revocations","title":"ACCESS: Revoke sessions","description":"Revoke selected sessions or all sessions for an authorized subject.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-access-session-revocations","scope":"admin:access:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke sessions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-access-session-revocations-request-001"},{"name":"tenant_uuid","location":"body","required":true,"type":"identifier","description":"Tenant boundary containing the managed identity.","example":"tenant-uuid-01"},{"name":"profile_uuid","location":"body","required":true,"type":"identifier","description":"Identity whose sessions are eligible for revocation.","example":"profile-uuid-01"},{"name":"session_ids","location":"body","required":false,"type":"identifier[] · unique","description":"Specific active sessions to revoke; omit only when all_sessions is true.","example":[]},{"name":"all_sessions","location":"body","required":true,"type":"boolean","description":"When true, revoke every active session for the subject; cannot be combined with session_ids.","example":true},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed security rationale.","example":"reason-01"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh SESSION_ADMINISTRATION authorization.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke selected sessions or all sessions for an authorized subject.","whenToUse":"Do not call this planning mutation. It reserves targeted or all-session revocation for one tenant-bound managed identity.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Promotion requires an exclusive session_ids versus all_sessions rule, fresh administrator step-up, self-lockout policy, immediate credential invalidation, partial-failure semantics, and audit evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Infrastructure","User Intel & Risk","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-admin-access-sessions","method":"GET","path":"/api/v2/admin/access/sessions","title":"ACCESS: List sessions","description":"List restricted active sessions and security posture.","chapter":"Admin Functions","chapterOrder":18,"capability":"Access control","owners":["identity-service"],"applications":["Admin Console","Access Control"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-access-sessions","scope":"admin:access:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List sessions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:access:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List restricted active sessions and security posture.","whenToUse":"Use this operation when an integration needs to list sessions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:access:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Identity & Login","Teams & Workspaces","Developers"]}},{"id":"get-api-v2-admin-approved-kycs","method":"GET","path":"/api/v2/admin/approved_kycs","title":"ADMIN: Get All Approved KYC Submissions","description":"ADMIN: Get All Approved KYC Submissions through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["identity-compliance"],"applications":["Trust Center","Admin Console","Identity Review"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/admin/approved_kycs","operation":"ADMIN: Get All Approved KYC Submissions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-approved-kycs","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Approved KYC Submissions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ADMIN: Get All Approved KYC Submissions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all approved kyc submissions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"post-api-v2-admin-kyc-status-update","method":"POST","path":"/api/v2/admin/kyc_status_update","title":"ADMIN: Set KYC Stage Status","description":"ADMIN: Set KYC Stage Status through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["identity-compliance"],"applications":["Trust Center","Admin Console","Identity Review"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/admin/kyc_status_update","operation":"ADMIN: Set KYC Stage Status"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-kyc-status-update","scope":"trust:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set KYC Stage Status"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-kyc-status-update-request-001"},{"name":"tenant_uuid","location":"body","required":true,"type":"identifier","description":"Tenant policy boundary for the review.","example":"tenant-uuid-01"},{"name":"profile_uuid","location":"body","required":true,"type":"identifier","description":"Subject whose review record is being decided.","example":"profile-uuid-01"},{"name":"verification_uuid","location":"body","required":true,"type":"identifier","description":"Current subject verification selected from the review queue.","example":"verification-uuid-01"},{"name":"decision","location":"body","required":true,"type":"APPROVE | REJECT | REQUEST_INFORMATION","description":"Exact reviewer decision; it does not authorize another business domain.","example":"decision-01"},{"name":"reason_code","location":"body","required":true,"type":"allowlisted identifier","description":"Structured retained rationale.","example":"reason-code-01"},{"name":"evidence_commitment","location":"body","required":false,"type":"SHA-256 digest","description":"Commitment to separately retained review evidence; raw KYC material is forbidden.","example":"evidence-commitment-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current verification version for optimistic concurrency.","example":1},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh IDENTITY_REVIEW authorization.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"ADMIN: Set KYC Stage Status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy-shaped planning mutation. It reserves an attributed, version-bound decision on one current verification review without exposing regulated evidence.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Promotion requires minimized reviewer queues, strict reviewer authority, reason codes, commitment-only evidence references, separation from credential issuance and transfer approval, subject notification policy, and immutable audit history.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-pending-kycs","method":"GET","path":"/api/v2/admin/pending_kycs","title":"ADMIN: Get All Pending KYC Submissions","description":"ADMIN: Get All Pending KYC Submissions through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["identity-compliance"],"applications":["Trust Center","Admin Console","Identity Review"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/admin/pending_kycs","operation":"ADMIN: Get All Pending KYC Submissions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-pending-kycs","scope":"trust:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All Pending KYC Submissions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ADMIN: Get All Pending KYC Submissions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all pending kyc submissions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"post-api-v2-admin-set-custom-meta-data","method":"POST","path":"/api/v2/admin/set_custom_meta_data","title":"ADMIN: Set Custom Meta-Data","description":"ADMIN: Set Custom Meta-Data through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["admin-domain-owner"],"applications":["Admin Console"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/admin/set_custom_meta_data","operation":"ADMIN: Set Custom Meta-Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-set-custom-meta-data","scope":"admin:write","idempotency":true,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Set Custom Meta-Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-set-custom-meta-data-request-001"},{"name":"tenant_uuid","location":"body","required":true,"type":"identifier","description":"Tenant boundary owning the target resource.","example":"tenant-uuid-01"},{"name":"resource_type","location":"body","required":true,"type":"PROFILE | TENANT | WORKSPACE","description":"Allowlisted administrative resource class.","example":"resource-type-01"},{"name":"resource_uuid","location":"body","required":true,"type":"identifier","description":"Tenant-owned target resource.","example":"resource-uuid-01"},{"name":"namespace","location":"body","required":true,"type":"allowlisted metadata namespace","description":"Schema-governed namespace; callers cannot create arbitrary namespaces.","example":"namespace-01"},{"name":"fields","location":"body","required":true,"type":"allowlisted scalar object","description":"Schema-validated non-secret metadata fields; credentials, regulated evidence, and free-form executable content are rejected.","example":{}},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current metadata version for optimistic concurrency.","example":1},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed audit rationale.","example":"reason-01"},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh CUSTOM_METADATA_UPDATE authorization.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"ADMIN: Set Custom Meta-Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy-shaped planning mutation. It reserves schema-governed non-secret administrative metadata updates for one tenant-owned resource.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Promotion must replace arbitrary metadata with allowlisted namespaces and typed fields, reject credentials and regulated evidence, enforce optimistic concurrency and size limits, and retain reason, actor, and before/after commitments.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-transaction-list","method":"GET","path":"/api/v2/admin/transaction_list","title":"ADMIN: Get All White-Label Transactions","description":"ADMIN: Get All White-Label Transactions through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["ledger-read-model"],"applications":["Admin Console"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/admin/transaction_list","operation":"ADMIN: Get All White-Label Transactions"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-transaction-list","scope":"admin:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All White-Label Transactions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ADMIN: Get All White-Label Transactions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all white-label transactions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-user-list","method":"GET","path":"/api/v2/admin/user_list","title":"ADMIN: Get All White-Label Users","description":"ADMIN: Get All White-Label Users through the canonical Hybrid-Chain V2 interface.","chapter":"Admin Functions","chapterOrder":18,"capability":"Admin Functions","owners":["identity-profile"],"applications":["Admin Console"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/admin/user_list","operation":"ADMIN: Get All White-Label Users"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-user-list","scope":"admin:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get All White-Label Users"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ADMIN: Get All White-Label Users through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all white-label users before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-overview","method":"GET","path":"/api/v2/admin/overview","title":"ADMIN: Get identity readiness overview","description":"Return aggregate-only account growth, activation, onboarding, and wallet-readiness posture across 52 weekly cohorts.","chapter":"Admin Functions","chapterOrder":18,"capability":"Administration overview","owners":["identity-service"],"applications":["Trust Center","Admin Console","Infrastructure","Indexer Controller","Trading & Matching Ops"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["identity-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/admin/cohorts","source":"APIHandler.py · get_admin_cohorts · signed gateway-only aggregate"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1overview/get","scope":"admin:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get identity readiness overview"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return aggregate-only account growth, activation, onboarding, and wallet-readiness posture across 52 weekly cohorts.","whenToUse":"Use this restricted aggregate when an administrator needs a 52-week account-acquisition and readiness trend before drilling into separately authorized identity workflows.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["service health review","testnet infrastructure evidence verification","account growth and readiness trending","incident coordination"],"prerequisites":["A bearer credential with admin:read authority and the required tenant, workspace, and role context.","no credential for public status and Explorer evidence","an admin:read bearer for the aggregate administration overview","an exact evidence identifier for historical verification"],"agentGuidance":["Health and readiness projections are observations, not permission to restart, reconfigure, route traffic, or change market state.","Treat status/info as service identity rather than dependency readiness; use the evidence timestamp, commitment, network, and component identity for operational correlation.","The administration overview contains 52 aggregate weekly cohorts and no account rows. Never infer individual account state or request broader identity data from it.","Access audit events remain a planning contract until Identity and other owners publish a unified cursor, retention policy, event taxonomy, and tenant-safe read model.","The response is produced by Identity, contains aggregate counts only, and deliberately omits latest-user rows, names, email addresses, profile identifiers, wallet identifiers, and mutation links.","registered is the cohort denominator; activated, wallet_ready, and onboarded are independent readiness signals and must not be added together. Re-fetch before reporting and do not infer individual account state from an aggregate.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Evidence Streams"]}},{"id":"get-api-v2-admin-arena-events","method":"GET","path":"/api/v2/admin/arena/events","title":"ARENA ADMIN: List live evidence events","description":"Page through tenant-scoped read-only Arena evidence events using an opaque resumable cursor without exposing the private engine or forwarding the user's bearer credential.","chapter":"Admin Functions","chapterOrder":18,"capability":"Arena administration","owners":["arena-engine"],"applications":["Arena Monitor"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1arena~1events/get","scope":"arena:admin:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List live evidence events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing arena:admin:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Page through tenant-scoped read-only Arena evidence events using an opaque resumable cursor without exposing the private engine or forwarding the user's bearer credential.","whenToUse":"Use this operation when an integration needs to list live evidence events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["live match oversight","wager and escrow observation","evidence-feed audit","referee and payout-assurance review"],"prerequisites":["A bearer credential with arena:admin:read authority and the required tenant, workspace, and role context.","an authenticated tenant administrator","both admin:read and arena:admin:read authority","an available private Arena engine configured at the Gateway"],"agentGuidance":["This surface is observation-only and grants no match, wager, wallet, escrow, payout, settlement, referee, or game-server authority.","Treat D0 simulation data as synthetic and never describe its projected payouts, proofs, or escrow state as real value movement or chain finality.","Never forward the user's bearer to Arena; the Gateway authenticates Identity and narrows the call to a short-lived signed internal capability.","Treat cursors as opaque, tenant-bound values and fail closed on authority mismatch or malformed engine responses.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Evidence Streams","Indexer Controller","Access Control"]}},{"id":"get-api-v2-admin-arena-overview","method":"GET","path":"/api/v2/admin/arena/overview","title":"ARENA ADMIN: Get live overview","description":"Return a tenant-scoped read-only projection of live match, viewer, market, wager, payout, escrow, evidence, proof, and referee-assurance posture without granting game, wallet, market, or settlement authority.","chapter":"Admin Functions","chapterOrder":18,"capability":"Arena administration","owners":["arena-engine"],"applications":["Arena Monitor"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1arena~1overview/get","scope":"arena:admin:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get live overview"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing arena:admin:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return a tenant-scoped read-only projection of live match, viewer, market, wager, payout, escrow, evidence, proof, and referee-assurance posture without granting game, wallet, market, or settlement authority.","whenToUse":"Use this operation when an integration needs to get live overview before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["live match oversight","wager and escrow observation","evidence-feed audit","referee and payout-assurance review"],"prerequisites":["A bearer credential with arena:admin:read authority and the required tenant, workspace, and role context.","an authenticated tenant administrator","both admin:read and arena:admin:read authority","an available private Arena engine configured at the Gateway"],"agentGuidance":["This surface is observation-only and grants no match, wager, wallet, escrow, payout, settlement, referee, or game-server authority.","Treat D0 simulation data as synthetic and never describe its projected payouts, proofs, or escrow state as real value movement or chain finality.","Never forward the user's bearer to Arena; the Gateway authenticates Identity and narrows the call to a short-lived signed internal capability.","Treat cursors as opaque, tenant-bound values and fail closed on authority mismatch or malformed engine responses.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Evidence Streams","Indexer Controller","Access Control"]}},{"id":"get-api-v2-admin-billing-accounts","method":"GET","path":"/api/v2/admin/billing/accounts","title":"ADMIN BILLING: List accounts","description":"List restricted customer billing accounts and reconciliation posture.","chapter":"Admin Functions","chapterOrder":18,"capability":"Billing operations","owners":["billing-service"],"applications":["Admin Console","Billing Operations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-billing-accounts","scope":"admin:billing:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List accounts"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:billing:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List restricted customer billing accounts and reconciliation posture.","whenToUse":"Use this operation when an integration needs to list accounts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:billing:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control","Billing","Funding"]}},{"id":"get-api-v2-admin-billing-events","method":"GET","path":"/api/v2/admin/billing/events","title":"ADMIN BILLING: List events","description":"List restricted billing, credit, invoice, and webhook events.","chapter":"Admin Functions","chapterOrder":18,"capability":"Billing operations","owners":["billing-service"],"applications":["Admin Console","Billing Operations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-billing-events","scope":"admin:billing:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:billing:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List restricted billing, credit, invoice, and webhook events.","whenToUse":"Use this operation when an integration needs to list events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:billing:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control","Billing","Funding"]}},{"id":"post-api-v2-admin-billing-reconciliations","method":"POST","path":"/api/v2/admin/billing/reconciliations","title":"ADMIN BILLING: Run reconciliation","description":"Request an idempotent restricted billing reconciliation.","chapter":"Admin Functions","chapterOrder":18,"capability":"Billing operations","owners":["billing-service"],"applications":["Funding","Admin Console","Billing Operations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-billing-reconciliations","scope":"admin:billing:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Run reconciliation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:billing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-billing-reconciliations-request-001"},{"name":"tenant_uuid","location":"body","required":true,"type":"identifier","description":"Tenant whose billing records are reconciled.","example":"tenant-uuid-01"},{"name":"account_uuid","location":"body","required":true,"type":"identifier","description":"Billing account returned by the restricted account collection.","example":"account-uuid-01"},{"name":"period_start","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Inclusive reconciliation window start.","example":"2026-09-30T20:00:00Z"},{"name":"period_end","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Exclusive reconciliation window end after period_start.","example":"2026-09-30T20:00:00Z"},{"name":"mode","location":"body","required":true,"type":"DRY_RUN | APPLY","description":"DRY_RUN calculates differences; APPLY requires stronger policy and records governed adjustments.","example":"mode-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–1000","description":"Attributed accounting rationale.","example":"reason-01"},{"name":"evidence_references","location":"body","required":false,"type":"identifier[]","description":"References to retained invoices, usage, credit, or processor evidence; secrets are forbidden.","example":[]},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current account reconciliation version.","example":1},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh BILLING_RECONCILIATION authorization.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request an idempotent restricted billing reconciliation.","whenToUse":"Do not call this planning mutation. It reserves a bounded dry-run or governed apply reconciliation for one billing account and period.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with admin:billing:write authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Promotion requires exact period and account isolation, processor and ledger evidence linkage, decimal and minor-unit rules, duplicate prevention, approval thresholds, adjustment limits, dry-run/apply separation, and immutable accounting evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-identity-workload-clients","method":"GET","path":"/api/v2/admin/identity/workload-clients","title":"IDENTITY ADMIN: List workload clients","description":"List tenant-scoped machine identities, public keys, delegated scopes, and lifecycle state.","chapter":"Admin Functions","chapterOrder":18,"capability":"Identity login policy","owners":["identity-service"],"applications":["Trust Center","Admin Console","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1workload-clients/get","scope":"admin:identity:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List workload clients"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List tenant-scoped machine identities, public keys, delegated scopes, and lifecycle state.","whenToUse":"Use this operation when an integration needs to list workload clients before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Infrastructure","User Intel & Risk","Access Control","Teams & Workspaces"]}},{"id":"post-api-v2-admin-identity-workload-clients","method":"POST","path":"/api/v2/admin/identity/workload-clients","title":"IDENTITY ADMIN: Register workload client","description":"Register an Ed25519 workload identity using proof of possession and purpose-bound administrator step-up.","chapter":"Admin Functions","chapterOrder":18,"capability":"Identity login policy","owners":["identity-service"],"applications":["Trust Center","Admin Console","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1workload-clients/post","scope":"admin:identity:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register workload client"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"},{"name":"tenant_uuid","location":"body","required":true,"type":"tenant identifier","description":"Tenant that owns the machine identity.","example":"tenant-uuid-01"},{"name":"label","location":"body","required":true,"type":"string · max 160","description":"Operational name.","example":"label-01"},{"name":"allowed_scopes","location":"body","required":true,"type":"business scope[]","description":"Explicit least-privilege grant; administrative scopes are rejected.","example":[]},{"name":"public_key_jwk","location":"body","required":true,"type":"OKP Ed25519 public JWK","description":"Client public key; private material is forbidden.","example":"public-key-jwk-01"},{"name":"proof","location":"body","required":true,"type":"base64url Ed25519 signature","description":"Proof over the canonical registration statement.","example":"proof-01"},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh WORKLOAD_CLIENT_REGISTRATION authorization.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Register an Ed25519 workload identity using proof of possession and purpose-bound administrator step-up.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to register workload client.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Infrastructure","User Intel & Risk","Access Control","Teams & Workspaces"]}},{"id":"post-api-v2-admin-identity-workload-clients-client-id-revocations","method":"POST","path":"/api/v2/admin/identity/workload-clients/{client_id}/revocations","title":"IDENTITY ADMIN: Revoke workload client","description":"Revoke a workload client and immediately invalidate all of its outstanding access tokens.","chapter":"Admin Functions","chapterOrder":18,"capability":"Identity login policy","owners":["identity-service"],"applications":["Trust Center","Admin Console","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1workload-clients~1{client_id}~1revocations/post","scope":"admin:identity:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke workload client"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"},{"name":"client_id","location":"path","required":true,"type":"identifier","description":"Canonical client id.","example":"client-id-01"},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh WORKLOAD_CLIENT_REVOCATION authorization.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Revoke a workload client and immediately invalidate all of its outstanding access tokens.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke workload client.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Infrastructure","User Intel & Risk","Access Control","Teams & Workspaces"]}},{"id":"post-api-v2-admin-identity-workload-clients-client-id-rotations","method":"POST","path":"/api/v2/admin/identity/workload-clients/{client_id}/rotations","title":"IDENTITY ADMIN: Rotate workload client","description":"Rotate a workload client's public request-signing key using old-key authorization and new-key proof of possession.","chapter":"Admin Functions","chapterOrder":18,"capability":"Identity login policy","owners":["identity-service"],"applications":["Trust Center","Admin Console","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1identity~1workload-clients~1{client_id}~1rotations/post","scope":"admin:identity:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Rotate workload client"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"},{"name":"client_id","location":"path","required":true,"type":"identifier","description":"Canonical client id.","example":"client-id-01"},{"name":"public_key_jwk","location":"body","required":true,"type":"replacement OKP Ed25519 public JWK","description":"Replacement public request-signing key.","example":"public-key-jwk-01"},{"name":"proof","location":"body","required":true,"type":"base64url Ed25519 signature","description":"Replacement-key proof over the canonical rotation statement.","example":"proof-01"},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh WORKLOAD_CLIENT_KEY_ROTATION authorization.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Replacement public key activated, rotation commitment returned, and prior access tokens revoked.","example":null},{"status":400,"description":"The replacement Ed25519 JWK or proof is malformed.","example":null},{"status":401,"description":"The administrator bearer is missing or invalid.","example":null},{"status":403,"description":"Tenant authority, replacement-key possession, or WORKLOAD_CLIENT_KEY_ROTATION step-up is missing.","example":null},{"status":404,"description":"The active workload client was not found.","example":null},{"status":503,"description":"Identity workload administration is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Rotate a workload client's public request-signing key using old-key authorization and new-key proof of possession.","whenToUse":"Rotate a workload request-signing key when planned key hygiene, suspected exposure, or custody migration requires a replacement without changing client identity or allowed scopes.","workflowRole":"create-or-command","sideEffects":"Activates the replacement public key, changes the derived request-signing key ID, records a rotation commitment, and immediately revokes every active workload bearer.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Obtain a fresh WORKLOAD_CLIENT_KEY_ROTATION step-up and sign the canonical rotation statement with the replacement private key. The old private key is never submitted.","After success, discard old bearers and key identifiers, verify the returned rotation commitment, and exchange a fresh assertion under the new key.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Identity Review","Infrastructure","User Intel & Risk","Access Control","Teams & Workspaces"]}},{"id":"get-api-v2-admin-news-articles","method":"GET","path":"/api/v2/admin/news/articles","title":"NEWSROOM: List articles","description":"List restricted draft, scheduled, and published newsroom records.","chapter":"Admin Functions","chapterOrder":18,"capability":"Newsroom operations","owners":["newsroom-service"],"applications":["Admin Console","Newsroom Operations"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["newsroom-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/admin/news/articles","source":"APIRoutes.py · view_v2_admin_news_articles · signed restricted newsroom ledger projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1news~1articles/get","scope":"admin:news:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List articles"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:news:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List restricted draft, scheduled, and published newsroom records.","whenToUse":"Use when an authorized editor or agent needs to discover private drafts and lifecycle posture before reading public verification or applying a revision.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:news:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Reuse next_cursor only with the same status and q filters. List items omit article bodies; select the retained article through the publisher workflow before changing it.","DRAFT, SCHEDULED, PUBLISHED, and ARCHIVED describe editorial visibility—not public proof integrity or delivery status.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control","Chain Explorer","Evidence Streams"]}},{"id":"post-api-v2-admin-news-articles","method":"POST","path":"/api/v2/admin/news/articles","title":"NEWSROOM: Create article","description":"Create a newsroom article draft.","chapter":"Admin Functions","chapterOrder":18,"capability":"Newsroom operations","owners":["newsroom-service"],"applications":["Admin Console","Newsroom Operations"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["newsroom-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/admin/news/articles","source":"APIRoutes.py · view_v2_admin_news_articles · signed idempotent private-draft creation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1news~1articles/post","scope":"admin:news:write","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create article"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:news:write authority.","example":"Bearer hc_live_…"},{"name":"slug","location":"body","required":true,"type":"lowercase URL slug · 3–160","description":"Unique permanent public slug.","example":"slug-01"},{"name":"title","location":"body","required":true,"type":"string · 3–200","description":"Public headline.","example":"title-01"},{"name":"category","location":"body","required":true,"type":"string · 1–64","description":"Exact newsroom collection.","example":"category-01"},{"name":"excerpt","location":"body","required":true,"type":"string · 1–1600","description":"Public card, search, and social summary.","example":"excerpt-01"},{"name":"body","location":"body","required":true,"type":"structured content block[] · 1–120","description":"Safe paragraph, heading, quote, list, or callout blocks; executable markup is not accepted.","example":[]},{"name":"author_name","location":"body","required":true,"type":"string · 1–160","description":"Public byline; the authenticated profile remains the audit actor.","example":"author-name-01"},{"name":"eyebrow","location":"body","required":false,"type":"string · max 80","description":"Short editorial label.","example":"eyebrow-01"},{"name":"featured","location":"body","required":false,"type":"boolean","description":"Whether the article is highlighted.","example":true},{"name":"tags","location":"body","required":false,"type":"string[] · max 16","description":"Search and classification tags.","example":[]},{"name":"products","location":"body","required":false,"type":"slug[] · max 16","description":"Related product slugs.","example":[]},{"name":"social_links","location":"body","required":false,"type":"string map · max 16","description":"Public presentation links.","example":"social-links-01"},{"name":"seo_title","location":"body","required":false,"type":"string · max 220","description":"Search title; defaults to title.","example":"seo-title-01"},{"name":"seo_description","location":"body","required":false,"type":"string · max 320","description":"Search description; defaults to excerpt.","example":"seo-description-01"},{"name":"editorial_date","location":"body","required":false,"type":"RFC 3339 timestamp | null","description":"Private proposed publication date; creation always remains DRAFT.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Create a newsroom article draft.","whenToUse":"Create a private, attributed structured-content draft after resolving a unique permanent slug and public presentation metadata.","workflowRole":"create-or-command","sideEffects":"Creates revision 1, its content commitment, and an ARTICLE_CREATED proof event. It never publishes.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:news:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Use only paragraph, heading, quote, list, and callout blocks; scripts, credentials, and arbitrary executable markup do not belong in content.","Reuse the same Idempotency-Key and byte-equivalent semantic body only for a retry of the same logical draft.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control","Chain Explorer","Evidence Streams"]}},{"id":"patch-api-v2-admin-news-articles-article-uuid","method":"PATCH","path":"/api/v2/admin/news/articles/{article_uuid}","title":"NEWSROOM: Update article","description":"Update, schedule, publish, or archive an authorized article.","chapter":"Admin Functions","chapterOrder":18,"capability":"Newsroom operations","owners":["newsroom-service"],"applications":["Admin Console","Newsroom Operations"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["newsroom-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"PATCH","path":"/v2/admin/news/articles/{article_uuid}","source":"APIRoutes.py · view_v2_admin_news_article · signed idempotent version-bound editorial transition"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1news~1articles~1{article_uuid}/patch","scope":"admin:news:write","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update article"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:news:write authority.","example":"Bearer hc_live_…"},{"name":"article_uuid","location":"path","required":true,"type":"identifier","description":"Canonical article uuid.","example":"article-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current article revision for optimistic concurrency.","example":1},{"name":"action","location":"body","required":true,"type":"SAVE_DRAFT | SCHEDULE | PUBLISH | ARCHIVE","description":"Governed editorial transition.","example":"action-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed revision or lifecycle rationale retained in evidence.","example":"reason-01"},{"name":"step_up_token","location":"body","required":false,"type":"purpose-bound token","description":"Required by publication or archive policy when configured.","example":"step-up-token-01"},{"name":"slug","location":"body","required":false,"type":"lowercase URL slug · 3–160","description":"Replacement permanent slug.","example":"slug-01"},{"name":"title","location":"body","required":false,"type":"string · 3–200","description":"Replacement headline.","example":"title-01"},{"name":"category","location":"body","required":false,"type":"string · 1–64","description":"Replacement collection.","example":"category-01"},{"name":"excerpt","location":"body","required":false,"type":"string · 1–1600","description":"Replacement public summary.","example":"excerpt-01"},{"name":"body","location":"body","required":false,"type":"structured content block[] · 1–120","description":"Replacement safe content blocks.","example":[]},{"name":"author_name","location":"body","required":false,"type":"string · 1–160","description":"Replacement public byline.","example":"author-name-01"},{"name":"featured","location":"body","required":false,"type":"boolean","description":"Replacement feature posture.","example":true},{"name":"tags","location":"body","required":false,"type":"string[] · max 16","description":"Replacement tags.","example":[]},{"name":"products","location":"body","required":false,"type":"slug[] · max 16","description":"Replacement related products.","example":[]},{"name":"social_links","location":"body","required":false,"type":"string map · max 16","description":"Replacement public presentation links.","example":"social-links-01"},{"name":"seo_title","location":"body","required":false,"type":"string · max 220","description":"Replacement search title.","example":"seo-title-01"},{"name":"seo_description","location":"body","required":false,"type":"string · max 320","description":"Replacement search description.","example":"seo-description-01"},{"name":"editorial_date","location":"body","required":false,"type":"RFC 3339 timestamp | null","description":"Required for SCHEDULE; becomes public only after PUBLISH.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Update, schedule, publish, or archive an authorized article.","whenToUse":"Use after re-reading the exact article revision to save a draft, schedule it, publish it, or archive it with an attributed reason.","workflowRole":"revise","sideEffects":"Creates a new immutable revision and lifecycle proof event; PUBLISH exposes that canonical snapshot through the public Newsroom.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:news:write authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Send the current revision as expected_version. On 409, re-read and reconcile rather than overwriting another editor.","SCHEDULE requires editorial_date. Treat PUBLISH and ARCHIVE as consequential transitions and satisfy any configured step-up policy.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Infrastructure","User Intel & Risk","Access Control","Chain Explorer","Evidence Streams"]}},{"id":"get-api-v2-admin-prediction-markets","method":"GET","path":"/api/v2/admin/prediction-markets","title":"PREDICTION OPS: List contracts","description":"List prediction contracts with lifecycle, oracle, exposure, dispute, and resolution-review posture.","chapter":"Admin Functions","chapterOrder":18,"capability":"Prediction market operations","owners":["prediction-market-service"],"applications":["Trading","Admin Console","Prediction Market Ops"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-prediction-markets","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List contracts"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List prediction contracts with lifecycle, oracle, exposure, dispute, and resolution-review posture.","whenToUse":"Use this operation when an integration needs to list contracts before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","operational posture review","exception and incident triage","administrative workflow routing"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-prediction-markets-prediction-id","method":"GET","path":"/api/v2/admin/prediction-markets/{prediction_id}","title":"PREDICTION OPS: Get control record","description":"Read one prediction contract's governed rules, oracle policy, exposure, disputes, and retained review evidence.","chapter":"Admin Functions","chapterOrder":18,"capability":"Prediction market operations","owners":["prediction-market-service"],"applications":["Trading","Admin Console","Prediction Market Ops"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-prediction-markets-prediction-id","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get control record"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"prediction_id","location":"path","required":true,"type":"identifier","description":"Canonical prediction id.","example":"prediction-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Read one prediction contract's governed rules, oracle policy, exposure, disputes, and retained review evidence.","whenToUse":"Use this operation when an integration needs to get control record before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","operational posture review","exception and incident triage","administrative workflow routing"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-prediction-markets-prediction-id-evidence","method":"GET","path":"/api/v2/admin/prediction-markets/{prediction_id}/evidence","title":"PREDICTION OPS: Get evidence","description":"Return immutable rule, oracle, review, dispute, lifecycle, and resolution evidence for one prediction contract.","chapter":"Admin Functions","chapterOrder":18,"capability":"Prediction market operations","owners":["prediction-market-service"],"applications":["Trading","Admin Console","Prediction Market Ops"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-admin-prediction-markets-prediction-id-evidence","scope":"trading:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:read authority.","example":"Bearer hc_live_…"},{"name":"prediction_id","location":"path","required":true,"type":"identifier","description":"Canonical prediction id.","example":"prediction-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return immutable rule, oracle, review, dispute, lifecycle, and resolution evidence for one prediction contract.","whenToUse":"Use this operation when an integration needs to get evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","operational posture review","exception and incident triage","administrative workflow routing"],"prerequisites":["A bearer credential with trading:read authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"post-api-v2-admin-prediction-markets-prediction-id-lifecycle-decisions","method":"POST","path":"/api/v2/admin/prediction-markets/{prediction_id}/lifecycle-decisions","title":"PREDICTION OPS: Record lifecycle decision","description":"Record a version-bound, attributed lifecycle decision without changing trading authority or traffic.","chapter":"Admin Functions","chapterOrder":18,"capability":"Prediction market operations","owners":["prediction-market-service"],"applications":["Trading","Admin Console","Prediction Market Ops"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-prediction-markets-prediction-id-lifecycle-decisions","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Record lifecycle decision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-prediction-markets-prediction-id-lifecycle-decisions-request-001"},{"name":"prediction_id","location":"path","required":true,"type":"identifier","description":"Canonical prediction id.","example":"prediction-id-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current contract version for optimistic concurrency.","example":1},{"name":"decision","location":"body","required":true,"type":"SUBMIT_FOR_REVIEW | RETURN_TO_DRAFT | ARCHIVE","description":"Non-trading administrative workflow decision.","example":"decision-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–1000","description":"Attributed operator rationale retained with the decision.","example":"reason-01"},{"name":"evidence_references","location":"body","required":false,"type":"identifier[]","description":"Retained review or policy evidence supporting the decision.","example":[]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record a version-bound, attributed lifecycle decision without changing trading authority or traffic.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record lifecycle decision.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","operational posture review","exception and incident triage","administrative workflow routing"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"post-api-v2-admin-prediction-markets-prediction-id-resolutions","method":"POST","path":"/api/v2/admin/prediction-markets/{prediction_id}/resolutions","title":"PREDICTION OPS: Record resolution","description":"Record a governed outcome resolution bound to authoritative oracle and independent-review evidence.","chapter":"Admin Functions","chapterOrder":18,"capability":"Prediction market operations","owners":["prediction-market-service"],"applications":["Trading","Admin Console","Prediction Market Ops"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-admin-prediction-markets-prediction-id-resolutions","scope":"trading:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Record resolution"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trading:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-prediction-markets-prediction-id-resolutions-request-001"},{"name":"prediction_id","location":"path","required":true,"type":"identifier","description":"Canonical prediction id.","example":"prediction-id-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current contract version for optimistic concurrency.","example":1},{"name":"outcome","location":"body","required":true,"type":"declared outcome identifier","description":"Exact outcome defined by the immutable prediction rules.","example":"outcome-01"},{"name":"oracle_evidence_references","location":"body","required":true,"type":"identifier[] · at least 1","description":"Authoritative oracle observations supporting the outcome.","example":[]},{"name":"review_evidence_references","location":"body","required":true,"type":"identifier[] · at least 1","description":"Independent-review evidence required by resolution policy.","example":[]},{"name":"reason","location":"body","required":true,"type":"string · 8–2000","description":"Attributed resolution rationale.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record a governed outcome resolution bound to authoritative oracle and independent-review evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record resolution.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","operational posture review","exception and incident triage","administrative workflow routing"],"prerequisites":["A bearer credential with trading:write authority and the required tenant, workspace, and role context.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Infrastructure","User Intel & Risk","Access Control"]}},{"id":"get-api-v2-admin-users","method":"GET","path":"/api/v2/admin/users","title":"RISK: Search managed identities","description":"Search tenant-scoped identities and return lifecycle, deterministic risk, rating, and open-alert posture.","chapter":"Admin Functions","chapterOrder":18,"capability":"User intelligence and risk","owners":["identity-service"],"applications":["Admin Console","User Intel & Risk"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["identity-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/admin/users","source":"UserRiskAPI.py · mobile_admin_user_directory · signed gateway-only tenant-scoped projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1users/get","scope":"admin:identity:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Search managed identities"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:read authority.","example":"Bearer hc_live_…"},{"name":"q","location":"query","required":false,"type":"exact email, username, profile UUID, or identity UUID · 1–120","description":"Exact identifier. Omit it to receive aggregate posture only; partial directory enumeration is intentionally unavailable.","example":"treasury"},{"name":"cursor","location":"query","required":false,"type":"opaque offset cursor","description":"Cursor returned by the previous page and valid only with the same q and filters.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum exact-match records to return; defaults to 50.","example":50},{"name":"lifecycle_status","location":"query","required":false,"type":"ACTIVE | REVIEW_REQUIRED | SUSPENDED | DEACTIVATED","description":"Exact lifecycle filter applied after the identifier boundary.","example":"lifecycle-status-01"},{"name":"risk_tier","location":"query","required":false,"type":"LOW | MODERATE | HIGH | CRITICAL","description":"Exact deterministic risk-tier filter.","example":"risk-tier-01"},{"name":"alert_status","location":"query","required":false,"type":"OPEN | ACKNOWLEDGED | RESOLVED | DISMISSED","description":"Exact alert workflow-state filter.","example":"alert-status-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Search tenant-scoped identities and return lifecycle, deterministic risk, rating, and open-alert posture.","whenToUse":"Use for a tenant-authorized risk or support workflow that already has an exact email, username, profile UUID, or identity UUID and needs the current lifecycle, deterministic risk, reviewer-rating, and open-alert posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["operational posture review","exception and incident triage","administrative workflow routing","workload-identity administration","least-privilege access review","attributed reconciliation and editorial governance"],"prerequisites":["A bearer credential with admin:identity:read authority and the required tenant, workspace, and role context.","restricted least-privilege administrative scopes","explicit tenant and role eligibility","fresh purpose-bound step-up for sensitive changes","an authoritative owner adapter and retained audit policy"],"agentGuidance":["The aggregate administration overview is executable through exact admin:read authority and intentionally contains no account-level rows or personal data.","The overview, four workload-client operations, three governed Newsroom Operations, and three tenant-scoped User Intel & Risk operations are currently executable. Every other listed administrative contract remains non-callable until it appears in live OpenAPI.","Preserve tenant boundaries, use stable resource identifiers and expected versions, retain attributed reasons, and reauthorize at the owning endpoint.","Newsroom creation is always a private draft; publishing is an explicit version-bound action and never grants website deployment or traffic authority.","Risk lookup requires an exact identifier, and interventions derive tenant and actor from the bearer session, require fresh step-up and signed idempotent requests, and cannot change TRADING capability.","Never place passwords, tokens, private keys, regulated KYC evidence, payment-processor secrets, or unrestricted free-form metadata in administrative payloads or logs.","Trading, matching, prediction-market authority, market status, and traffic remain frozen and cannot be changed through these records.","Omitting q deliberately returns metrics with an empty users array. Do not probe partial names, ranges, or generated identifiers to enumerate the directory.","The tenant and administrator role are derived from the bearer session. Reuse next_cursor only with the identical q and filters, and treat metrics as operational posture rather than an automated adverse-decision signal.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Infrastructure","Access Control","Identity Review","Trust Center"]}},{"id":"get-api-v2-admin-users-profile-uuid","method":"GET","path":"/api/v2/admin/users/{profile_uuid}","title":"RISK: Get identity control record","description":"Return one identity's lifecycle, capability controls, alerts, evidence signals, sessions, and audit events.","chapter":"Admin Functions","chapterOrder":18,"capability":"User intelligence and risk","owners":["identity-service"],"applications":["Trust Center","Admin Console","User Intel & Risk"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["identity-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/mobile/admin/users/{profile_uuid}","source":"UserRiskAPI.py · mobile_admin_user_detail · signed gateway-only tenant-scoped control record"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1users~1{profile_uuid}/get","scope":"admin:identity:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get identity control record"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:read authority.","example":"Bearer hc_live_…"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one identity's lifecycle, capability controls, alerts, evidence signals, sessions, and audit events.","whenToUse":"Use after an authorized exact lookup when an investigator needs the subject's current control version, capability controls, alerts, deterministic evidence commitments, session posture, and retained intervention history.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Signals are review inputs with evidence commitments, not facts about protected attributes and not standalone authority for an adverse decision.","The projection excludes passwords, tokens, raw KYC media, secret keys, and credential material. Lifecycle, rating, and alerts do not grant trading, settlement, payment, or traffic authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Infrastructure","Access Control"]}},{"id":"post-api-v2-admin-users-profile-uuid-interventions","method":"POST","path":"/api/v2/admin/users/{profile_uuid}/interventions","title":"RISK: Apply identity intervention","description":"Apply a version-bound lifecycle, capability, reviewer-rating, or alert decision with an attributed reason.","chapter":"Admin Functions","chapterOrder":18,"capability":"User intelligence and risk","owners":["identity-service"],"applications":["Trust Center","Admin Console","User Intel & Risk"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["identity-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/mobile/admin/users/{profile_uuid}/interventions","source":"UserRiskAPI.py · mobile_admin_user_intervention · signed, idempotent, step-up-authorized intervention"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1admin~1users~1{profile_uuid}~1interventions/post","scope":"admin:identity:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Apply identity intervention"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing admin:identity:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-admin-users-profile-uuid-interventions-request-001"},{"name":"profile_uuid","location":"path","required":true,"type":"identifier","description":"Canonical profile uuid.","example":"profile-uuid-01"},{"name":"action","location":"body","required":true,"type":"lifecycle | capability | rating | alert","description":"Exact intervention class; determines which conditional fields are admitted.","example":"action-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–1200","description":"Substantive operator rationale retained in the attributed hash-chained audit record.","example":"reason-01"},{"name":"expected_version","location":"body","required":false,"type":"integer · ≥0","description":"Latest version returned by the detail record; required for lifecycle, capability, and rating actions.","example":1},{"name":"status","location":"body","required":false,"type":"conditional lifecycle, capability, or alert state","description":"Required for lifecycle, capability, and alert actions. Allowed values depend on action.","example":"ACTIVE"},{"name":"capability","location":"body","required":false,"type":"safe capability identifier","description":"Required only for capability actions. TRADING is rejected while the trading freeze remains in force.","example":"capability-01"},{"name":"rating","location":"body","required":false,"type":"UNRATED | TRUSTED | STANDARD | WATCH | RESTRICTED","description":"Required only for a reviewer-rating action.","example":"rating-01"},{"name":"alert_uuid","location":"body","required":false,"type":"canonical alert identifier","description":"Required only for an alert workflow action.","example":"alert-uuid-01"},{"name":"assigned_to","location":"body","required":false,"type":"safe operator reference","description":"Optional alert assignee. It is attribution metadata and grants no authority.","example":"assigned-to-01"},{"name":"step_up_token","location":"body","required":true,"type":"single-use hcsu_ token","description":"Fresh USER_RISK_INTERVENTION authorization bound to the authenticated administrator session.","example":"step-up-token-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Apply a version-bound lifecycle, capability, reviewer-rating, or alert decision with an attributed reason.","whenToUse":"Use only after re-reading the exact tenant-bound detail record and obtaining a fresh USER_RISK_INTERVENTION step-up to record one reasoned lifecycle, non-trading capability, reviewer-rating, or alert workflow transition.","workflowRole":"create-or-command","sideEffects":"May change the managed identity's lifecycle, one non-trading capability control, reviewer rating, or alert workflow state and appends attributed hash-chained evidence. It never changes tenant, trading authority, matching, market status, ingress, publisher, allowlist, settlement, payment, or traffic.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with admin:identity:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Send only the fields admitted by action. Lifecycle, capability, and rating require the latest expected_version; on 409, re-read and reconcile rather than overwriting concurrent work.","Identity derives tenant and actor from the authenticated session. Never send or synthesize tenant_uuid or actor_ref. TRADING capability is hard rejected while the trading freeze is active.","Use RFC 9421 request signing and reuse the same Idempotency-Key with an equivalent body only when retrying the same logical intervention. The step-up token is single-use and cannot replace bearer or role authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Infrastructure","Access Control"]}},{"id":"get-api-v2-entropy","method":"GET","path":"/api/v2/entropy","title":"ENTROPY: Get service catalog","description":"Return supported physical sample classes, byte limits, source-signature assurance, and the current generation and source-key discovery paths.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1entropy/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get service catalog"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return supported physical sample classes, byte limits, source-signature assurance, and the current generation and source-key discovery paths.","whenToUse":"Start every Entropy Lab integration here to discover the current generation path, source-key path, supported assurance, and byte ceilings instead of hard-coding them.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","This public no-store catalog describes one physical-source sample contract. It does not generate bytes or publish beacon, Transit-key, lottery, oracle, trading, settlement, or wallet authority.","Request the minimum bytes required by the downstream protocol; published maxima are safety ceilings rather than recommendations.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-entropy-beacons","method":"GET","path":"/api/v2/entropy/beacons","title":"ENTROPY: List beacon rounds","description":"List public entropy beacon rounds and verification material.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-entropy-beacons","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List beacon rounds"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque round cursor","description":"Cursor returned by the preceding finalized-round page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum finalized beacon rounds to return; defaults to 50.","example":50}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List public entropy beacon rounds and verification material.","whenToUse":"Do not call this planning read. Source record continuity is not an implemented public-beacon round catalog.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Promotion requires contributor enrollment, commit/reveal timing, omission and abort rules, aggregation, finalization, public verification keys, stable pagination, and immutable retention.","Never synthesize rounds from sample sequence values or claim omission resistance from a source-local chain.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-entropy-beacons-round-uuid","method":"GET","path":"/api/v2/entropy/beacons/{round_uuid}","title":"ENTROPY: Get beacon round","description":"Return one public beacon output, commitments, contributors, and verification result.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-entropy-beacons-round-uuid","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get beacon round"],"parameters":[{"name":"round_uuid","location":"path","required":true,"type":"identifier","description":"Canonical round uuid.","example":"round-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one public beacon output, commitments, contributors, and verification result.","whenToUse":"Do not call this planning read. No authoritative finalized-round owner or verification schema exists.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Promotion must define round ordering, contributor commitments and reveals, final output derivation, signatures, finality, failure state, and historical-key verification.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-entropy-samples","method":"POST","path":"/api/v2/entropy/samples","title":"ENTROPY: Request protected sample","description":"Request a bearer-authorized entropy or noise sample carrying an Ed25519 proof from the physical entropy source.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1entropy~1samples/post","scope":"entropy:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request protected sample"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing entropy:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-entropy-samples-request-001"},{"name":"kind","location":"body","required":true,"type":"entropy | noise","description":"Conditioned entropy output or validation noise sample.","example":"kind-01"},{"name":"bytes","location":"body","required":true,"type":"integer · entropy 1–65536; noise 1–4096","description":"Exact number of bytes requested from the physical source.","example":1},{"name":"encoding","location":"body","required":true,"type":"base64 | hex","description":"Encoding of the returned sample value.","example":"encoding-01"},{"name":"assurance","location":"body","required":true,"type":"source_signed","description":"Require a physical-source Ed25519 proof.","example":"assurance-01"},{"name":"client_nonce","location":"body","required":true,"type":"URL-safe string · 16–128","description":"Caller nonce bound into the signed source envelope.","example":"client-nonce-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request a bearer-authorized entropy or noise sample carrying an Ed25519 proof from the physical entropy source.","whenToUse":"Use after current-key discovery with a fresh 16–128 character caller nonce and the minimum exact byte count needed by an application-specific randomness model.","workflowRole":"create-or-command","sideEffects":"Consumes one idempotent source request and returns bounded physical material plus a source-signed evidence envelope. It creates no key, beacon round, lottery result, oracle decision, transaction, or business authority.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["A bearer credential with entropy:write authority and the required tenant, workspace, and role context.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Before use, match request and nonce, source and key identities, decode the exact representation, verify byte count and sample digest, canonicalize data, verify Ed25519, and recompute the record commitment.","Never use returned bytes directly as a private key. Apply the consuming protocol's KDF, domain separation, health tests, contributor model, secrecy handling, and failure behavior.","Keep values, nonces, idempotency material, and application decisions out of URLs, prompts, logs, analytics, and shared caches.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-entropy-source-key","method":"GET","path":"/api/v2/entropy/source-key","title":"ENTROPY: Get source verification key","description":"Return the gateway-pinned Ed25519 public JWK used to verify physical-source sample envelopes without exposing source credentials or private key material.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["entropy-service"],"legacySources":[],"runtimeSources":[{"catalog":"entropy","method":"GET","path":"/entropy/source-keys/current/v2","source":"gateway-pinned EntropyAdapterConfig derived from the physical source's current Ed25519 key"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1entropy~1source-key/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get source verification key"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the gateway-pinned Ed25519 public JWK used to verify physical-source sample envelopes without exposing source credentials or private key material.","whenToUse":"Fetch before verifying a source-signed sample and again whenever the catalog, source ID, or key ID changes.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Pin source_id, key.kid, and key.x, then require both response key identifiers to match. key.x is an unpadded base64url Ed25519 public key, never a secret, encryption key, Transit RSA key, wallet key, or credential.","The endpoint publishes only the current gateway-pinned key. Do not infer historical rotation, revocation, or trust policy.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-entropy-transit-keys","method":"GET","path":"/api/v2/entropy/transit-keys","title":"ENTROPY: List transit keys","description":"List the authenticated account's active Transit RSA public-key identifiers and fingerprints without exposing private keys.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Public entropy","owners":["entropy-service"],"applications":["Entropy Lab"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-entropy-transit-keys","scope":"entropy:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List transit keys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing entropy:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque account-key cursor","description":"Cursor returned by the preceding subject-scoped key page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public-key records to return; defaults to 50.","example":50},{"name":"status","location":"query","required":false,"type":"ACTIVE | ROTATING | REVOKED","description":"Exact future account-key lifecycle filter.","example":"ACTIVE"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated account's active Transit RSA public-key identifiers and fingerprints without exposing private keys.","whenToUse":"Do not call this planning read. Account Transit RSA public keys belong to a separate key-management authority and are not the Ed25519 entropy source key.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["A bearer credential with entropy:read authority and the required tenant, workspace, and role context.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Promotion requires subject isolation, algorithm and usage profiles, lifecycle and rotation, fingerprints and public material only, pagination, and proof that private keys cannot cross the gateway.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-quantum-entropy-random-1k","method":"GET","path":"/api/v2/quantum/entropy/random/1k","title":"ENTROPY: Get Quantum Resilient Entropy Bytes","description":"ENTROPY: Get Quantum Resilient Entropy Bytes through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Quantum Entropy","owners":["quantum-service"],"applications":["Entropy Lab"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/quantum/entropy/random/1k","operation":"ENTROPY: Get Quantum Resilient Entropy Bytes"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-quantum-entropy-random-1k","scope":"entropy:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Quantum Resilient Entropy Bytes"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing entropy:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ENTROPY: Get Quantum Resilient Entropy Bytes through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy compatibility marker. Random generation is state-changing and will not be hidden behind a replayable GET.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["A bearer credential with entropy:read authority and the required tenant, workspace, and role context.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Use the implemented bounded POST /api/v2/entropy/samples contract with kind=entropy, an explicit byte count, caller nonce, bearer scope, and idempotency key.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-quantum-noise-proof-1k","method":"GET","path":"/api/v2/quantum/noise/proof/1k","title":"ENTROPY: Get Quantum Resilient Noise Proof","description":"ENTROPY: Get Quantum Resilient Noise Proof through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Entropy","chapterOrder":19,"capability":"Quantum Entropy","owners":["quantum-service"],"applications":["Entropy Lab"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/quantum/noise/proof/1k","operation":"ENTROPY: Get Quantum Resilient Noise Proof"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-quantum-noise-proof-1k","scope":"entropy:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get Quantum Resilient Noise Proof"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing entropy:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"ENTROPY: Get Quantum Resilient Noise Proof through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this legacy compatibility marker. A noise sample is not a proof object, and generation will not bypass the bounded signed POST contract.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["bounded entropy acquisition","validation-noise sampling","independent source-signature verification","source-record continuity checks","application-specific derivation input"],"prerequisites":["A bearer credential with entropy:read authority and the required tenant, workspace, and role context.","an exact required byte count and supported encoding","entropy:write authority for generation","an implementation of hybrid-json-v1 canonicalization and Ed25519 verification","an application-specific threat, derivation, health-test, and failure model"],"agentGuidance":["Never use sample bytes directly as a private key and never represent source_signed as proof of suitability, uniqueness, secrecy, unbiased downstream use, lottery fairness, or oracle truth.","Match request ID and caller nonce, source ID and both key IDs, decoded byte count, sample SHA-256, canonical data signature, and record SHA-256 before accepting a sample.","sequence and previous_record_sha256 support continuity checks only; they are not public-beacon rounds and do not prove that records were not withheld.","Fetch the current source-key document on key-ID or catalog change; the current-key endpoint does not publish historical rotation or revocation policy.","Keep sample values, idempotency keys, caller nonces, and application decisions out of URLs, prompts, logs, analytics, and shared caches; responses are no-store.","Beacon rounds, account Transit keys, and legacy 1k compatibility reads remain non-executable until their independent owner models and live OpenAPI contracts exist.","Use kind=noise only for a defined validation or research workflow, within 4,096 bytes, and retain the test method and result separately from source signature evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-data-vault-objects","method":"GET","path":"/api/v2/data-vault/objects","title":"DATA: List protected objects","description":"List the authenticated workspace's top-level encrypted objects with minimized owner-use metadata, storage readiness, opaque content roots, and commitment-only evidence. Keys, shard topology, raw storage metadata, and download authority are excluded.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["data-vault-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/data-vault/objects","source":"APIRoutes.py · view_get_v2_data_vault_objects · signed owner-scoped purpose-limited projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1data-vault~1objects/get","scope":"vault:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List protected objects"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated workspace's top-level encrypted objects with minimized owner-use metadata, storage readiness, opaque content roots, and commitment-only evidence. Keys, shard topology, raw storage metadata, and download authority are excluded.","whenToUse":"Start private Data Vault navigation here to discover the authenticated workspace's top-level protected objects before selecting a stable object identifier.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","The bearer-derived workspace is the vault boundary; no owner, vault, directory, filter, pagination, or recursive selector is accepted.","Treat names and encrypted_content_root values as private correlation data. A readable object grants no download, decryption, sharing, retention change, or erasure authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"delete-api-v2-data-vault-objects-object-uuid","method":"DELETE","path":"/api/v2/data-vault/objects/{object_uuid}","title":"DATA: Delete protected object","description":"Request policy-governed deletion or cryptographic erasure of an eligible object.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-data-vault-objects-object-uuid","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Delete protected object"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-data-vault-objects-object-uuid-request-001"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current object version used for optimistic concurrency.","example":1},{"name":"mode","location":"body","required":true,"type":"RECYCLE | CRYPTOGRAPHIC_ERASURE","description":"Requested lifecycle action. Erasure must pass retention, legal-hold, grant, and storage-proof gates.","example":"mode-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed deletion rationale retained with the evidence chain.","example":"reason-01"}],"responses":[{"status":204,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request policy-governed deletion or cryptographic erasure of an eligible object.","whenToUse":"Do not call this planning route yet. It reserves recycle or cryptographic-erasure requests only after current object, version, grant, retention, legal-hold, and storage evidence are reconciled.","workflowRole":"revoke-or-delete","sideEffects":"No executable V2 deletion exists. The legacy handler marks a record deleted and attempts to unpin one content root, which is insufficient proof of distributed erasure or key destruction.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Promotion requires optimistic concurrency, explicit recycle versus erasure semantics, active-grant handling, legal-hold and retention gates, recoverability rules, key-destruction evidence, replica cleanup, and partial-failure reconciliation.","A successful database flag or IPFS unpin is not cryptographic-erasure proof.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"get-api-v2-data-vault-objects-object-uuid","method":"GET","path":"/api/v2/data-vault/objects/{object_uuid}","title":"DATA: Get protected object","description":"Return minimized metadata and integrity evidence for one object after enforcing ownership at the authoritative storage query. Versions, retention policy, grants, keys, and download authority are not yet published by this contract.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["data-vault-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/data-vault/objects/{object_uuid}","source":"APIRoutes.py · view_get_v2_data_vault_object · owner check enforced at the storage query"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1data-vault~1objects~1{object_uuid}/get","scope":"vault:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get protected object"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return minimized metadata and integrity evidence for one object after enforcing ownership at the authoritative storage query. Versions, retention policy, grants, keys, and download authority are not yet published by this contract.","whenToUse":"Refresh one selected object's minimized metadata, readiness, presentation flags, and latest commitment-only evidence before a dependent workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Core combines the stable object identifier with the bearer-derived workspace in the authoritative query; an object owned elsewhere is indistinguishable from a missing object.","Evidence and anchor posture do not independently prove decryptability, possession, public finality, sharing consent, or permission to disclose cleartext.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"get-api-v2-data-vault-objects-object-uuid-children","method":"GET","path":"/api/v2/data-vault/objects/{object_uuid}/children","title":"DATA: List directory children","description":"List one owner-scoped directory's immediate children using the same minimized object projection. This is single-level navigation, not a recursive tree, sharing grant, or download capability.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["data-vault-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/data-vault/objects/{object_uuid}/children","source":"APIRoutes.py · view_get_v2_data_vault_object_children · directory ownership checked before a minimized immediate-child query"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1data-vault~1objects~1{object_uuid}~1children/get","scope":"vault:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List directory children"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List one owner-scoped directory's immediate children using the same minimized object projection. This is single-level navigation, not a recursive tree, sharing grant, or download capability.","whenToUse":"Use after an object detail identifies a directory and the integration needs its immediate children without loading or inferring a recursive tree.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","The parent directory is owner-checked before the child query. A file, missing directory, malformed identifier, or directory in another workspace fails closed.","Traverse deliberately one level at a time and preserve stable object identifiers; names are mutable presentation values and never authorization keys.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-data-vault-objects-object-uuid-download-tickets","method":"POST","path":"/api/v2/data-vault/objects/{object_uuid}/download-tickets","title":"DATA: Create download ticket","description":"Issue a short-lived, subject-bound download ticket for an authorized object version.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-data-vault-objects-object-uuid-download-tickets","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create download ticket"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-data-vault-objects-object-uuid-download-tickets-request-001"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"},{"name":"purpose","location":"body","required":true,"type":"string · 1–160","description":"Purpose limitation retained with ticket issuance and access evidence.","example":"purpose-01"},{"name":"version_uuid","location":"body","required":false,"type":"32-character identifier","description":"Exact immutable version; omission requests the current eligible version.","example":"version-uuid-01"},{"name":"expires_in_seconds","location":"body","required":false,"type":"integer · 60–900","description":"Requested short lifetime; policy may shorten it.","example":1},{"name":"content_disposition","location":"body","required":false,"type":"inline | attachment","description":"Presentation hint; defaults to attachment and grants no access by itself.","example":"content-disposition-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Issue a short-lived, subject-bound download ticket for an authorized object version.","whenToUse":"Do not call this planning route yet. It reserves a short-lived ticket after owner or active-grant authorization, purpose, version, retention, and object readiness are re-evaluated.","workflowRole":"create-or-command","sideEffects":"No executable public ticket issuer exists. The legacy direct download returns content through Core and lacks the required subject-, purpose-, version-, and expiry-bound capability model.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","A future ticket must be single-purpose, short-lived, revocable, audience-bound, non-loggable, and useless without the approved encrypted-object delivery path.","Never treat encrypted_content_root as a ticket or derive a storage-node URL from it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"get-api-v2-data-vault-objects-object-uuid-grants","method":"GET","path":"/api/v2/data-vault/objects/{object_uuid}/grants","title":"DATA: List sharing grants","description":"List active and historical access grants for a protected object.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-data-vault-objects-object-uuid-grants","scope":"vault:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List sharing grants"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:read authority.","example":"Bearer hc_live_…"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List active and historical access grants for a protected object.","whenToUse":"Do not call this planning read yet. It reserves an owner-visible list of active, expired, and revoked access grants for one protected object.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:read authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Promotion requires an authoritative private grant store, owner check, recipient minimization, lifecycle pagination, purpose and permission projection, and no invitation tokens or recipient secrets.","The object's shared boolean and public evidence counts cannot reconstruct recipient identity, current permission, or grant validity.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-data-vault-objects-object-uuid-grants","method":"POST","path":"/api/v2/data-vault/objects/{object_uuid}/grants","title":"DATA: Create sharing grant","description":"Grant a subject time- and purpose-bounded access to a protected object.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-data-vault-objects-object-uuid-grants","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create sharing grant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-data-vault-objects-object-uuid-grants-request-001"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"},{"name":"subject","location":"body","required":true,"type":"identity or workspace identifier","description":"Grant recipient.","example":"subject-01"},{"name":"permissions","location":"body","required":true,"type":"READ | DOWNLOAD[]","description":"Allowed operations.","example":[]},{"name":"purpose","location":"body","required":true,"type":"string","description":"Purpose limitation.","example":"purpose-01"},{"name":"expires_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Grant expiry.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Grant a subject time- and purpose-bounded access to a protected object.","whenToUse":"Do not call this planning route yet. It reserves creation of a purpose- and expiry-bound permission for a resolved identity or workspace after recipient and object policy checks.","workflowRole":"create-or-command","sideEffects":"No authoritative public grant mutation exists. Evidence schemas can retain commitments and counts, but evidence alone is not an access-control store.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Promotion requires recipient resolution, allowed permission combinations, maximum expiry, owner or delegated-grant authority, version concurrency, invitation delivery separation, idempotency, and private audit evidence.","Never infer grant success from an invitation email or an ACCESS_GRANTED public commitment; resolve canonical private state.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-data-vault-objects-object-uuid-grants-grant-uuid-revocations","method":"POST","path":"/api/v2/data-vault/objects/{object_uuid}/grants/{grant_uuid}/revocations","title":"DATA: Revoke sharing grant","description":"Revoke an active access grant while retaining its audit record.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-data-vault-objects-object-uuid-grants-grant-uuid-revocations","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke sharing grant"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-data-vault-objects-object-uuid-grants-grant-uuid-revocations-request-001"},{"name":"object_uuid","location":"path","required":true,"type":"identifier","description":"Canonical object uuid.","example":"object-uuid-01"},{"name":"grant_uuid","location":"path","required":true,"type":"identifier","description":"Canonical grant uuid.","example":"grant-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current grant version used for optimistic concurrency.","example":1},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed revocation rationale retained in private audit evidence.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke an active access grant while retaining its audit record.","whenToUse":"Do not call this planning route yet. It reserves an idempotent revocation of a current owner-scoped grant while preserving its private audit history.","workflowRole":"create-or-command","sideEffects":"No executable public revocation exists. A future transition must invalidate delivery capabilities and prevent later ticket issuance without deleting historical evidence.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Promotion requires current-version concurrency, owner or delegated revocation authority, already-revoked retry behavior, dependent-ticket invalidation, and a retained reason.","Revocation cannot claw back cleartext already obtained by a recipient; business policy must account for that limitation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-data-vault-upload-sessions","method":"POST","path":"/api/v2/data-vault/upload-sessions","title":"DATA: Create upload session","description":"Create a bounded multipart upload session with content, retention, encryption, and integrity policy.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-data-vault-upload-sessions","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create upload session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-data-vault-upload-sessions-request-001"},{"name":"file_name","location":"body","required":true,"type":"string","description":"Display filename.","example":"file-name-01"},{"name":"content_type","location":"body","required":true,"type":"media type","description":"Declared content type.","example":"content-type-01"},{"name":"size_bytes","location":"body","required":true,"type":"integer","description":"Exact plaintext size.","example":1},{"name":"content_hash","location":"body","required":true,"type":"sha256 digest","description":"Plaintext integrity commitment.","example":"content-hash-01"},{"name":"retention_policy","location":"body","required":true,"type":"object","description":"Retention and deletion policy.","example":{}},{"name":"encryption","location":"body","required":true,"type":"object","description":"Client-side encryption envelope metadata.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a bounded multipart upload session with content, retention, encryption, and integrity policy.","whenToUse":"Do not call this planning route yet. It reserves creation of a bounded client-encrypted multipart upload after classification, retention, integrity, and encryption policy are known.","workflowRole":"create-or-command","sideEffects":"No executable public behavior exists. The legacy storage handler accepts one base64 payload and therefore is not a safe substitute for a bounded resumable session.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Promotion requires content-size and part-count limits, MIME and filename validation, client-side encryption metadata validation, retention and legal-hold policy, quota reservation, expiry, idempotency, and orphan cleanup.","Never place cleartext content, encryption keys, recipient secrets, or a caller-selected vault identifier in this planning request.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-data-vault-upload-sessions-session-uuid-completion","method":"POST","path":"/api/v2/data-vault/upload-sessions/{session_uuid}/completion","title":"DATA: Complete upload","description":"Verify uploaded parts and commit one immutable encrypted object version.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Protected data vault","owners":["vault-service"],"applications":["Data Vault"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-data-vault-upload-sessions-session-uuid-completion","scope":"vault:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Complete upload"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-data-vault-upload-sessions-session-uuid-completion-request-001"},{"name":"session_uuid","location":"path","required":true,"type":"identifier","description":"Canonical session uuid.","example":"session-uuid-01"},{"name":"parts","location":"body","required":true,"type":"object[] · 1–10000","description":"Ordered uploaded-part receipts containing part_number, encrypted_size_bytes, and ciphertext_sha256; no cleartext bytes.","example":[]},{"name":"encrypted_content_root","location":"body","required":true,"type":"opaque content-addressed root · max 255","description":"Root returned by the approved storage transport after every part is durable.","example":"encrypted-content-root-01"},{"name":"ciphertext_sha256","location":"body","required":true,"type":"SHA-256 digest","description":"Digest of the complete encrypted object assembled in canonical part order.","example":"ciphertext-sha256-01"},{"name":"manifest_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the final ordered part manifest, encryption envelope metadata, and retained object policy.","example":"manifest-commitment-01"},{"name":"size_bytes","location":"body","required":true,"type":"integer · ≥0","description":"Exact plaintext size declared at session creation; a mismatch fails closed.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Verify uploaded parts and commit one immutable encrypted object version.","whenToUse":"Do not call this planning route yet. It will finalize only a live owner-scoped upload session after every encrypted part and its digest are durably verified.","workflowRole":"create-or-command","sideEffects":"When implemented, completion will create one immutable object version and storage evidence exactly once. The current legacy upload is atomic and has no separately addressable session to complete.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Completion must compare the original size, content commitment, encryption envelope, ordered part receipts, ciphertext digest, and final manifest commitment before registering an object.","An accepted storage transport receipt is not sufficient; failure to produce verifiable storage evidence must leave the session incomplete and recoverable.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-datatree","method":"POST","path":"/api/v2/quantum/storage/datatree","title":"STORAGE: Generate Data Structure Tree","description":"STORAGE: Generate Data Structure Tree through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/datatree","operation":"STORAGE: Generate Data Structure Tree"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-datatree","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Generate Data Structure Tree"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Generate Data Structure Tree through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use GET /api/v2/data-vault/objects and GET /api/v2/data-vault/objects/{object_uuid}/children for bounded owner-scoped navigation; recursive caller-shaped trees are retired.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-delete","method":"POST","path":"/api/v2/quantum/storage/delete","title":"STORAGE: Delete File From Data Vault","description":"STORAGE: Delete File From Data Vault through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/delete","operation":"STORAGE: Delete File From Data Vault"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-delete","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Delete File From Data Vault"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Delete File From Data Vault through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use DELETE /api/v2/data-vault/objects/{object_uuid} only after it appears in live OpenAPI with retention, legal-hold, active-grant, replica-cleanup, and key-destruction evidence controls.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-download","method":"POST","path":"/api/v2/quantum/storage/download","title":"STORAGE: Create File Download Link from DataVault","description":"STORAGE: Create File Download Link from DataVault through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/download","operation":"STORAGE: Create File Download Link from DataVault"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-download","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create File Download Link from DataVault"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Create File Download Link from DataVault through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use POST /api/v2/data-vault/objects/{object_uuid}/download-tickets only after it appears in live OpenAPI; direct content responses and caller-derived storage URLs are retired.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-favorite","method":"POST","path":"/api/v2/quantum/storage/favorite","title":"STORAGE: Toggle Favorites for File or Folder","description":"STORAGE: Toggle Favorites for File or Folder through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/favorite","operation":"STORAGE: Toggle Favorites for File or Folder"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-favorite","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Toggle Favorites for File or Folder"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Toggle Favorites for File or Folder through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","No canonical presentation-preference mutation is executable yet. Favorite state must be workspace-bound, versioned, and explicitly separate from content authority.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-metadata","method":"POST","path":"/api/v2/quantum/storage/metadata","title":"STORAGE: Request File Meta Data","description":"STORAGE: Request File Meta Data through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/metadata","operation":"STORAGE: Request File Meta Data"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-metadata","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Request File Meta Data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Request File Meta Data through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use implemented GET /api/v2/data-vault/objects/{object_uuid}; raw upload, shard, storage-node, and encryption metadata are intentionally excluded.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-newfolder","method":"POST","path":"/api/v2/quantum/storage/newfolder","title":"STORAGE: Create New Folder","description":"STORAGE: Create New Folder through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/newfolder","operation":"STORAGE: Create New Folder"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-newfolder","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create New Folder"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Create New Folder through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","No canonical directory-creation mutation is executable yet. Wait for an owner-scoped, parent-bound, versioned, idempotent contract with name, collision, quota, and retention policy.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-recycle","method":"POST","path":"/api/v2/quantum/storage/recycle","title":"STORAGE: Recycle File in DataVault","description":"STORAGE: Recycle File in DataVault through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/recycle","operation":"STORAGE: Recycle File in DataVault"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-recycle","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Recycle File in DataVault"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Recycle File in DataVault through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use the governed Data Vault object lifecycle only after an explicit recycle operation appears in live OpenAPI; a caller-authored deleted flag is not authoritative.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-rename","method":"POST","path":"/api/v2/quantum/storage/rename","title":"STORAGE: Rename Items in DataVault","description":"STORAGE: Rename Items in DataVault through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/rename","operation":"STORAGE: Rename Items in DataVault"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-rename","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Rename Items in DataVault"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Rename Items in DataVault through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","No canonical rename mutation is executable yet. Wait for a parent-bound, collision-safe, expected-version contract; names are never stable identifiers or authority keys.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-restore","method":"POST","path":"/api/v2/quantum/storage/restore","title":"STORAGE: Restore File from Recycle Bin","description":"STORAGE: Restore File from Recycle Bin through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/restore","operation":"STORAGE: Restore File from Recycle Bin"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-restore","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Restore File from Recycle Bin"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Restore File from Recycle Bin through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use the governed Data Vault object lifecycle only after an explicit restore operation appears in live OpenAPI and revalidates retention, storage readiness, grants, and object version.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"post-api-v2-quantum-storage-upload","method":"POST","path":"/api/v2/quantum/storage/upload","title":"STORAGE: Upload File to Data Vault","description":"STORAGE: Upload File to Data Vault through the canonical Hybrid-Chain V2 interface.","chapter":"Quantum Storage","chapterOrder":20,"capability":"Quantum Storage","owners":["protected-storage"],"applications":["Data Vault"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/quantum/storage/upload","operation":"STORAGE: Upload File to Data Vault"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-quantum-storage-upload","scope":"vault:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Upload File to Data Vault"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing vault:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Data Vault compatibility marker; follow the documented modern object lifecycle and verify live OpenAPI before calling a replacement.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"STORAGE: Upload File to Data Vault through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot read, upload, download, rename, favorite, recycle, restore, delete, share, decrypt, or change a protected object.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["A bearer credential with vault:write authority and the required tenant, workspace, and role context.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Use the multipart upload-session and completion lifecycle only after both operations appear in live OpenAPI; the legacy caller-selected vault plus base64 payload shape is retired.","Do not translate legacy bodies field-for-field or submit vault selectors, base64 or cleartext content, raw storage metadata, keys, secrets, direct-download assumptions, or caller-authored lifecycle state.","Verify the exact replacement in live production OpenAPI before calling it; a planned modern Data Vault profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network"]}},{"id":"get-api-v2-context-agent-actions","method":"GET","path":"/api/v2/context/agent-actions","title":"CONTEXT: List agent action evidence","description":"List only commitment evidence for this workload's Context Mesh actions.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1agent-actions/get","scope":"context:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List agent action evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List only commitment evidence for this workload's Context Mesh actions.","whenToUse":"Use this operation when an integration needs to list agent action evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-delivery-jobs","method":"GET","path":"/api/v2/context/delivery/jobs","title":"CONTEXT: List delivery jobs","description":"List commitment-only durable delivery state for the workload workspace.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1delivery~1jobs/get","scope":"context:subscribe","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List delivery jobs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:subscribe authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List commitment-only durable delivery state for the workload workspace.","whenToUse":"Use this operation when an integration needs to list delivery jobs before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:subscribe authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-delivery-subscriptions","method":"GET","path":"/api/v2/context/delivery/subscriptions","title":"CONTEXT: List delivery subscriptions","description":"List workspace-owned Context Exchange delivery subscriptions.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1delivery~1subscriptions/get","scope":"context:subscribe","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List delivery subscriptions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:subscribe authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List workspace-owned Context Exchange delivery subscriptions.","whenToUse":"Use this operation when an integration needs to list delivery subscriptions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:subscribe authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"put-api-v2-context-delivery-subscriptions","method":"PUT","path":"/api/v2/context/delivery/subscriptions","title":"CONTEXT: Revise delivery subscription","description":"Create an idempotent immutable revision of a workspace-owned delivery subscription.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1delivery~1subscriptions/put","scope":"context:subscribe","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revise delivery subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:subscribe authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"put-api-v2-context-delivery-subscriptions-request-001"},{"name":"channel","location":"body","required":true,"type":"string","description":"Delivery channel allowed by workspace policy.","example":"channel-01"},{"name":"destination_reference","location":"body","required":true,"type":"string","description":"Opaque workspace-owned destination reference; secrets are not accepted.","example":"destination-reference-01"},{"name":"event_types","location":"body","required":true,"type":"string[]","description":"Exact Context Mesh event types to deliver.","example":[]},{"name":"max_attempts","location":"body","required":false,"type":"integer · 0–255","description":"Optional bounded delivery-attempt limit.","example":1},{"name":"agent_action_rationale_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 commitment","description":"Commitment to the local agent rationale for the immutable subscription revision.","example":"10.00"}],"responses":[{"status":200,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Create an idempotent immutable revision of a workspace-owned delivery subscription.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revise delivery subscription.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:subscribe authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-delivery-subscriptions-subscription-id-revocations","method":"POST","path":"/api/v2/context/delivery/subscriptions/{subscription_id}/revocations","title":"CONTEXT: Revoke delivery subscription","description":"Revoke one workspace-owned delivery subscription with idempotent evidence.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1delivery~1subscriptions~1{subscription_id}~1revocations/post","scope":"context:subscribe","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke delivery subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:subscribe authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-delivery-subscriptions-subscription-id-revocations-request-001"},{"name":"subscription_id","location":"path","required":true,"type":"identifier","description":"Canonical subscription id.","example":"subscription-id-01"},{"name":"agent_action_rationale_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 commitment","description":"Commitment to the local agent rationale for revocation.","example":"10.00"}],"responses":[{"status":200,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Revoke one workspace-owned delivery subscription with idempotent evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke delivery subscription.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:subscribe authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-exchanges","method":"GET","path":"/api/v2/context/exchanges","title":"CONTEXT: List exchanges","description":"List active and pending private Context Exchanges visible to the authenticated workload.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1exchanges/get","scope":"exchanges:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List exchanges"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing exchanges:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List active and pending private Context Exchanges visible to the authenticated workload.","whenToUse":"Use this operation when an integration needs to list exchanges before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with exchanges:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-exchanges-exchange-id-clarifications","method":"POST","path":"/api/v2/context/exchanges/{exchange_id}/clarifications","title":"CONTEXT: Create clarification","description":"Submit an explicit structured clarification without forwarding private prompt history.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1exchanges~1{exchange_id}~1clarifications/post","scope":"context:feedback","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create clarification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:feedback authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-exchanges-exchange-id-clarifications-request-001"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"object_uuid","location":"body","required":true,"type":"32-character hexadecimal identifier","description":"Context object requiring clarification.","example":"10.00"},{"name":"question","location":"body","required":true,"type":"string","description":"Explicit structured clarification question.","example":"question-01"},{"name":"priority","location":"body","required":false,"type":"string","description":"Optional partner-visible priority.","example":"priority-01"},{"name":"agent_action_rationale_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 commitment","description":"Commitment to the local agent rationale; raw rationale and prompt history are forbidden.","example":"10.00"}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Submit an explicit structured clarification without forwarding private prompt history.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create clarification.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:feedback authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-exchanges-exchange-id-feed","method":"GET","path":"/api/v2/context/exchanges/{exchange_id}/feed","title":"CONTEXT: Read partner feed","description":"Read relationship- and topic-filtered partner context before any ranking or model processing.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1exchanges~1{exchange_id}~1feed/get","scope":"context:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read partner feed"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"topic","location":"query","required":false,"type":"string","description":"Optional topic constrained by the exchange's directional grant.","example":"topic-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous permission-filtered page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"page_size","location":"query","required":false,"type":"integer · 0–65535","description":"Requested bounded page size; downstream policy may apply a stricter limit.","example":1}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Read relationship- and topic-filtered partner context before any ranking or model processing.","whenToUse":"Use this operation when an integration needs to read partner feed before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-exchanges-exchange-id-proposals","method":"POST","path":"/api/v2/context/exchanges/{exchange_id}/proposals","title":"CONTEXT: Create proposal","description":"Submit a non-publishing structured partner proposal with retained provenance.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1exchanges~1{exchange_id}~1proposals/post","scope":"context:propose","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create proposal"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:propose authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-exchanges-exchange-id-proposals-request-001"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"topic","location":"body","required":true,"type":"string","description":"Topic admitted by the exchange's directional grant.","example":"topic-01"},{"name":"object_type","location":"body","required":true,"type":"string","description":"Typed proposal object class.","example":"object-type-01"},{"name":"title","location":"body","required":true,"type":"string","description":"Partner-visible proposal title.","example":"title-01"},{"name":"summary","location":"body","required":true,"type":"string","description":"Structured partner proposal summary.","example":"summary-01"},{"name":"agent_action_rationale_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 commitment","description":"Commitment to the local agent rationale; raw rationale and prompt history are forbidden.","example":"10.00"}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Submit a non-publishing structured partner proposal with retained provenance.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create proposal.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:propose authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-exchanges-exchange-id-query","method":"GET","path":"/api/v2/context/exchanges/{exchange_id}/query","title":"CONTEXT: Query partner context","description":"Query only context admitted by the exchange's directional topic grant.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1exchanges~1{exchange_id}~1query/get","scope":"context:query","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Query partner context"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:query authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"topic","location":"query","required":false,"type":"string","description":"Optional topic constrained by the exchange's directional grant.","example":"topic-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous permission-filtered page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"page_size","location":"query","required":false,"type":"integer · 0–65535","description":"Requested bounded page size; downstream policy may apply a stricter limit.","example":1}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Query only context admitted by the exchange's directional topic grant.","whenToUse":"Use this operation when an integration needs to query partner context before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:query authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-federation-exchanges","method":"GET","path":"/api/v2/context/federation/exchanges","title":"FEDERATION: List exchanges","description":"List independently operated federated exchanges visible to the authenticated workload.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1exchanges/get","scope":"federation:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List exchanges"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List independently operated federated exchanges visible to the authenticated workload.","whenToUse":"Use this operation when an integration needs to list exchanges before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-federation-exchanges-exchange-id","method":"GET","path":"/api/v2/context/federation/exchanges/{exchange_id}","title":"FEDERATION: Get exchange","description":"Read one relationship-scoped federation projection with schema, manifest, and receipt evidence.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1exchanges~1{exchange_id}/get","scope":"federation:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get exchange"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Read one relationship-scoped federation projection with schema, manifest, and receipt evidence.","whenToUse":"Use this operation when an integration needs to get exchange before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-federation-exchanges-exchange-id-imports","method":"POST","path":"/api/v2/context/federation/exchanges/{exchange_id}/imports","title":"FEDERATION: Import manifest","description":"Verify and record a signed inbound manifest after schema, direction, topic, and chain validation.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1exchanges~1{exchange_id}~1imports/post","scope":"federation:receive","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Import manifest"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:receive authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-federation-exchanges-exchange-id-imports-request-001"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for import manifest. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Verify and record a signed inbound manifest after schema, direction, topic, and chain validation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to import manifest.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:receive authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-federation-exchanges-exchange-id-manifests","method":"POST","path":"/api/v2/context/federation/exchanges/{exchange_id}/manifests","title":"FEDERATION: Publish manifest","description":"Publish an approved, signed, hash-linked outbound manifest under directional topic and residency policy.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1exchanges~1{exchange_id}~1manifests/post","scope":"federation:publish","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Publish manifest"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:publish authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-federation-exchanges-exchange-id-manifests-request-001"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for publish manifest. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Publish an approved, signed, hash-linked outbound manifest under directional topic and residency policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to publish manifest.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:publish authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-federation-exchanges-exchange-id-receipts","method":"POST","path":"/api/v2/context/federation/exchanges/{exchange_id}/receipts","title":"FEDERATION: Record receipt","description":"Verify and record a signed, residency-bound delivery receipt for a retained manifest.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1exchanges~1{exchange_id}~1receipts/post","scope":"federation:receipt","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record receipt"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:receipt authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-federation-exchanges-exchange-id-receipts-request-001"},{"name":"exchange_id","location":"path","required":true,"type":"identifier","description":"Canonical exchange id.","example":"exchange-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for record receipt. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Verify and record a signed, residency-bound delivery receipt for a retained manifest.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record receipt.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:receipt authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-federation-nodes","method":"GET","path":"/api/v2/context/federation/nodes","title":"FEDERATION: List nodes","description":"List public verification and commitment projections for this workspace's Context Mesh federation nodes.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1federation~1nodes/get","scope":"federation:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List nodes"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing federation:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List public verification and commitment projections for this workspace's Context Mesh federation nodes.","whenToUse":"Use this operation when an integration needs to list nodes before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with federation:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-memory-collection-requests-request-id","method":"GET","path":"/api/v2/context/memory-collection-requests/{request_id}","title":"MEMORY: Retrieve reviewed answer","description":"Retrieve your durable request using context:read plus the original action scope and permission. Current audience, publication and binding remain mandatory. Back off while OPEN; stop on ANSWERED, DISMISSED or access denial.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1memory-collection-requests~1{request_id}/get","scope":"context:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Retrieve reviewed answer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"request_id","location":"path","required":true,"type":"identifier","description":"Canonical request id.","example":"request-id-01"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Retrieve your durable request using context:read plus the original action scope and permission. Current audience, publication and binding remain mandatory. Back off while OPEN; stop on ANSWERED, DISMISSED or access denial.","whenToUse":"Use this operation when an integration needs to retrieve reviewed answer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-memory-collections-collection-id","method":"GET","path":"/api/v2/context/memory-collections/{collection_id}","title":"MEMORY: Read approved collection","description":"Read reviewed knowledge after current publication, audience, workload scope and collection binding checks.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1memory-collections~1{collection_id}/get","scope":"context:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read approved collection"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"collection_id","location":"path","required":true,"type":"identifier","description":"Canonical collection id.","example":"collection-id-01"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Read reviewed knowledge after current publication, audience, workload scope and collection binding checks.","whenToUse":"Use this operation when an integration needs to read approved collection before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-memory-collections-collection-id-manifest","method":"GET","path":"/api/v2/context/memory-collections/{collection_id}/manifest","title":"MEMORY: Read signed manifest","description":"Discover the authenticated V2 asynchronous protocol and effective capabilities. Verify the commitment and signature against a trusted publisher key.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1memory-collections~1{collection_id}~1manifest/get","scope":"context:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read signed manifest"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"collection_id","location":"path","required":true,"type":"identifier","description":"Canonical collection id.","example":"collection-id-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Discover the authenticated V2 asynchronous protocol and effective capabilities. Verify the commitment and signature against a trusted publisher key.","whenToUse":"Use this operation when an integration needs to read signed manifest before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-memory-collections-collection-id-requests","method":"POST","path":"/api/v2/context/memory-collections/{collection_id}/requests","title":"MEMORY: Submit durable question or proposal","description":"Submit QUERY or CLARIFY with context:query, or PROPOSE with context:propose. Requires a matching collection binding and audience capability. Reuse Idempotency-Key only with the same body. No immediate model response or financial authority.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1memory-collections~1{collection_id}~1requests/post","scope":"context:query","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Submit durable question or proposal"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:query authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-memory-collections-collection-id-requests-request-001"},{"name":"collection_id","location":"path","required":true,"type":"identifier","description":"Canonical collection id.","example":"collection-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for submit durable question or proposal. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Submit QUERY or CLARIFY with context:query, or PROPOSE with context:propose. Requires a matching collection binding and audience capability. Reuse Idempotency-Key only with the same body. No immediate model response or financial authority.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to submit durable question or proposal.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:query authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-platform-isolation-evidence","method":"GET","path":"/api/v2/context/platform/isolation-evidence","title":"GA: List isolation evidence","description":"List tenant-isolation suite results and commitments for the workload workspace.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1isolation-evidence/get","scope":"platform:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List isolation evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List tenant-isolation suite results and commitments for the workload workspace.","whenToUse":"Use this operation when an integration needs to list isolation evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-platform-isolation-evidence","method":"POST","path":"/api/v2/context/platform/isolation-evidence","title":"GA: Record isolation evidence","description":"Record signed, idempotent, commitment-only tenant-isolation test evidence.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1isolation-evidence/post","scope":"platform:evidence","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record isolation evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:evidence authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-platform-isolation-evidence-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for record isolation evidence. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Record signed, idempotent, commitment-only tenant-isolation test evidence.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record isolation evidence.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:evidence authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-platform-objectives","method":"GET","path":"/api/v2/context/platform/objectives","title":"GA: List service evidence","description":"List configured service objectives separately from observed evidence windows.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1objectives/get","scope":"platform:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List service evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List configured service objectives separately from observed evidence windows.","whenToUse":"Use this operation when an integration needs to list service evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-platform-objectives-objective-id-evidence","method":"POST","path":"/api/v2/context/platform/objectives/{objective_id}/evidence","title":"GA: Record service evidence","description":"Record signed, idempotent observations for one active service objective without inferring attainment.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1objectives~1{objective_id}~1evidence/post","scope":"platform:evidence","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record service evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:evidence authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-platform-objectives-objective-id-evidence-request-001"},{"name":"objective_id","location":"path","required":true,"type":"identifier","description":"Canonical objective id.","example":"objective-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for record service evidence. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Record signed, idempotent observations for one active service objective without inferring attainment.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record service evidence.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:evidence authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-platform-schemas","method":"GET","path":"/api/v2/context/platform/schemas","title":"GA: List schemas","description":"List workspace-scoped immutable Context Mesh schema commitments and lifecycle state.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1schemas/get","scope":"platform:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List schemas"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"List workspace-scoped immutable Context Mesh schema commitments and lifecycle state.","whenToUse":"Use this operation when an integration needs to list schemas before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-platform-summary","method":"GET","path":"/api/v2/context/platform/summary","title":"GA: Read readiness summary","description":"Read workspace onboarding, plan, region, retention, schema, hold, objective, and isolation readiness without implying certification.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1summary/get","scope":"platform:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read readiness summary"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Read workspace onboarding, plan, region, retention, schema, hold, objective, and isolation readiness without implying certification.","whenToUse":"Use this operation when an integration needs to read readiness summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"get-api-v2-context-platform-usage","method":"GET","path":"/api/v2/context/platform/usage","title":"GA: Read usage","description":"Read content-free workspace usage totals produced by idempotent meter evidence.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1usage/get","scope":"platform:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Read usage"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:read authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Permission-filtered canonical Context Mesh projection.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Read content-free workspace usage totals produced by idempotent meter evidence.","whenToUse":"Use this operation when an integration needs to read usage before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:read authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-platform-usage","method":"POST","path":"/api/v2/context/platform/usage","title":"GA: Record usage","description":"Record one signed, idempotent, content-free usage event under metering scope.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1platform~1usage/post","scope":"platform:meter","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record usage"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing platform:meter authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-platform-usage-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for record usage. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Record one signed, idempotent, content-free usage event under metering scope.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record usage.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with platform:meter authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-context-repositories-repository-id-commits","method":"POST","path":"/api/v2/context/repositories/{repository_id}/commits","title":"CONTEXT: Publish commit","description":"Publish an explicitly approved immutable context commit under repository, topic, review, and budget policy.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1context~1repositories~1{repository_id}~1commits/post","scope":"context:publish","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Publish commit"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing context:publish authority.","example":"Bearer hc_live_…"},{"name":"X-Hybrid-Agent-Timestamp","location":"header","required":true,"type":"Unix timestamp string","description":"Timestamp covered by the Ed25519 canonical-request signature and checked for freshness.","example":"1786582800"},{"name":"X-Hybrid-Agent-Nonce","location":"header","required":true,"type":"single-use opaque string","description":"Nonce atomically reserved by Identity; replayed nonce and digest pairs fail closed.","example":"01JAGENTNONCE001"},{"name":"X-Hybrid-Agent-Signature","location":"header","required":true,"type":"base64url Ed25519 signature","description":"Signature over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","example":"base64url-ed25519-signature"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-context-repositories-repository-id-commits-request-001"},{"name":"repository_id","location":"path","required":true,"type":"identifier","description":"Canonical repository id.","example":"repository-id-01"},{"name":"publication_approved","location":"body","required":true,"type":"true","description":"Explicit human or policy approval. False is rejected before publication.","example":true},{"name":"agent_action_rationale_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 commitment","description":"Domain-separated commitment to the agent's local rationale; prompt history never crosses the workspace boundary.","example":"10.00"},{"name":"message","location":"body","required":true,"type":"string","description":"Commit message retained with the immutable publication.","example":"message-01"},{"name":"source_revision","location":"body","required":false,"type":"string","description":"Optional source revision bound to the publication.","example":"source-revision-01"},{"name":"human_approval_commitment","location":"body","required":false,"type":"string","description":"Optional commitment to the human approval evidence.","example":"human-approval-commitment-01"},{"name":"objects","location":"body","required":true,"type":"ContextObject[]","description":"Approved context objects containing type, topic, title, summary, content, source references, classification, and optional confidence metadata.","example":[]}],"responses":[{"status":201,"description":"Signed Context Mesh mutation accepted and canonical evidence returned.","example":null},{"status":400,"description":"The signed-request headers, JSON body, or idempotency key are missing or malformed.","example":null},{"status":401,"description":"The workload bearer, signing key, timestamp, nonce, signature, or body digest is invalid, expired, revoked, or replayed.","example":null},{"status":403,"description":"The workload lacks the required scope or the workspace, exchange, directional topic grant, publication approval, or policy denies the operation.","example":null},{"status":409,"description":"The request conflicts with retained Context Mesh or idempotency state.","example":null},{"status":422,"description":"A path, query, typed body, rationale commitment, or downstream Context Mesh rule rejected the request.","example":null},{"status":503,"description":"Workload Identity or the authoritative Context Mesh service is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused.","Every request is signed by the registered workload Ed25519 key over timestamp, nonce, method, exact path and query, and the SHA-256 digest of the exact body bytes.","Context is permission-filtered before ranking or model processing. Cross-workspace access and topics outside the directional exchange grant fail closed.","Mutations transmit only a domain-separated rationale commitment. Raw rationale, private prompts, memory content, and signing material never cross this API boundary.","Context Mesh ingress is disabled unless all authoritative Identity and Core adapters are configured; partial configuration stops startup."]},"businessContext":{"purpose":"Publish an explicitly approved immutable context commit under repository, topic, review, and budget policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to publish commit.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals"],"prerequisites":["A bearer credential with context:publish authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center"]}},{"id":"post-api-v2-workspaces-workspace-id-knowledge-agents","method":"POST","path":"/api/v2/workspaces/{workspace_id}/knowledge-agents","title":"MEMORY: Enroll workspace knowledge agent","description":"Current human workspace OWNER enrolls an Ed25519 agent using fresh WORKLOAD_CLIENT_REGISTRATION approval and proof of key possession. Only context:read/query/feedback/propose/subscribe; no financial authority. tenant_uuid must match workspace_id.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1knowledge-agents/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Enroll workspace knowledge agent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-workspace-id-knowledge-agents-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for enroll workspace knowledge agent. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Knowledge credential operation completed.","example":null},{"status":400,"description":"Malformed body, signature, or identifier.","example":null},{"status":401,"description":"Human bearer is missing or invalid.","example":null},{"status":403,"description":"Current ownership, signing authority, scope ceiling, or fresh authenticator approval failed.","example":null},{"status":404,"description":"Workspace knowledge credential not found.","example":null},{"status":503,"description":"Authoritative Identity service unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Current human workspace OWNER enrolls an Ed25519 agent using fresh WORKLOAD_CLIENT_REGISTRATION approval and proof of key possession. Only context:read/query/feedback/propose/subscribe; no financial authority. tenant_uuid must match workspace_id.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to enroll workspace knowledge agent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center","Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"post-api-v2-workspaces-workspace-id-knowledge-agents-client-id-revocations","method":"POST","path":"/api/v2/workspaces/{workspace_id}/knowledge-agents/{client_id}/revocations","title":"MEMORY: Revoke workspace knowledge agent","description":"Current human workspace OWNER revokes a knowledge-only credential using fresh WORKLOAD_CLIENT_REVOCATION approval. Rejects credentials belonging to another workspace or carrying non-knowledge permissions.","chapter":"Data Sync Functions","chapterOrder":21,"capability":"Agent-native Context Mesh","owners":["context-mesh"],"applications":["Business Network","Teams & Workspaces"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1workspaces~1{workspace_id}~1knowledge-agents~1{client_id}~1revocations/post","scope":"workspaces:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke workspace knowledge agent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing workspaces:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-workspaces-workspace-id-knowledge-agents-client-id-revocations-request-001"},{"name":"workspace_id","location":"path","required":true,"type":"identifier","description":"Canonical workspace id.","example":"workspace-id-01"},{"name":"client_id","location":"path","required":true,"type":"identifier","description":"Canonical client id.","example":"client-id-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for revoke workspace knowledge agent. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":200,"description":"Knowledge credential operation completed.","example":null},{"status":400,"description":"Malformed body, signature, or identifier.","example":null},{"status":401,"description":"Human bearer is missing or invalid.","example":null},{"status":403,"description":"Current ownership, signing authority, scope ceiling, or fresh authenticator approval failed.","example":null},{"status":404,"description":"Workspace knowledge credential not found.","example":null},{"status":503,"description":"Authoritative Identity service unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Current human workspace OWNER revokes a knowledge-only credential using fresh WORKLOAD_CLIENT_REVOCATION approval. Rejects credentials belonging to another workspace or carrying non-knowledge permissions.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke workspace knowledge agent.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["partner-safe context sharing","federated context delivery","clarifications and structured proposals","workspace onboarding","team membership lifecycle","active workspace selection"],"prerequisites":["A bearer credential with workspaces:write authority and the required tenant, workspace, and role context.","a registered workload signing key","workspace, exchange, topic, and residency permission"],"agentGuidance":["Sign the exact request bytes and never forward raw private prompt history.","Context is filtered before ranking or model processing; do not infer access beyond returned grants.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Data Vault","Evidence Streams","Trust Center","Access Control","Tenant & Brand Manager","Identity & Login"]}},{"id":"get-api-v2-streams-all-streams","method":"GET","path":"/api/v2/streams/all_streams","title":"List all DataStreams","description":"List all DataStreams through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"GET","path":"/api/v1/streams/all_streams","operation":"List all DataStreams"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-streams-all-streams","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List all DataStreams"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List all DataStreams through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to list all datastreams before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-create","method":"POST","path":"/api/v2/streams/create","title":"Create new Data Stream","description":"Create new Data Stream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/create","operation":"Create new Data Stream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-create","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create new Data Stream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Create new Data Stream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Use POST /api/v2/evidence-streams only after it appears in live OpenAPI with a versioned schema, retention, visibility, quota, and evidence policy.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-publisher-blacklist","method":"POST","path":"/api/v2/streams/publisher_blacklist","title":"Blacklist Publisher Permissions for DataStream","description":"Blacklist Publisher Permissions for DataStream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/publisher_blacklist","operation":"Blacklist Publisher Permissions for DataStream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-publisher-blacklist","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Blacklist Publisher Permissions for DataStream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Blacklist Publisher Permissions for DataStream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","No canonical publisher-revocation mutation is executable yet. A future source lifecycle must revoke one enrolled source by stable identifier, expected version, reason, key impact, and retained evidence.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-publisher-whitelist","method":"POST","path":"/api/v2/streams/publisher_whitelist","title":"Whitelist Publisher Permissions for DataStream","description":"Whitelist Publisher Permissions for DataStream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/publisher_whitelist","operation":"Whitelist Publisher Permissions for DataStream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-publisher-whitelist","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Whitelist Publisher Permissions for DataStream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Whitelist Publisher Permissions for DataStream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Use POST /api/v2/evidence-devices only after it appears in live OpenAPI for proof-of-possession source enrollment; a free-form publisher whitelist is retired.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-subscriber-blacklist","method":"POST","path":"/api/v2/streams/subscriber_blacklist","title":"Blacklist Vault from Private DataStream","description":"Blacklist Vault from Private DataStream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/subscriber_blacklist","operation":"Blacklist Vault from Private DataStream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-subscriber-blacklist","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Blacklist Vault from Private DataStream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Blacklist Vault from Private DataStream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","No canonical subscriber-grant revocation is executable yet. Wait for a subject-resolved, purpose-bound, versioned stream-access lifecycle with delivery-capability invalidation.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-subscriber-whitelist","method":"POST","path":"/api/v2/streams/subscriber_whitelist","title":"Whitelist Vault for Private DataStream","description":"Whitelist Vault for Private DataStream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/subscriber_whitelist","operation":"Whitelist Vault for Private DataStream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-subscriber-whitelist","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Whitelist Vault for Private DataStream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Whitelist Vault for Private DataStream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","No canonical subscriber-grant creation is executable yet. Wait for an explicit purpose-, permission-, expiry-, and subject-bound stream-access contract.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-streams-toggle-activity","method":"POST","path":"/api/v2/streams/toggle_activity","title":"Toggle Active State of DataStream","description":"Toggle Active State of DataStream through the canonical Hybrid-Chain V2 interface.","chapter":"DataStreams Functions","chapterOrder":22,"capability":"DataStreams Functions","owners":["evidence-streams"],"applications":["Evidence Streams"],"authentication":"bearer","exposure":"public","status":"planned-contract","parity":"equivalent","sourceKinds":["v1-parity"],"legacySources":[{"method":"POST","path":"/api/v1/streams/toggle_activity","operation":"Toggle Active State of DataStream"}],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-streams-toggle-activity","scope":"evidence:write","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Toggle Active State of DataStream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"}],"responses":[{"status":501,"description":"Non-executable legacy Evidence Streams compatibility marker; follow the typed stream, source, grant, and lifecycle contracts only when their exact operations appear in live OpenAPI.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Toggle Active State of DataStream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Do not call this bodyless, non-executable compatibility marker.","workflowRole":"create-or-command","sideEffects":"None. The marker returns 501 and cannot create, pause, resume, archive, publish to, subscribe to, grant, revoke, ingest into, or otherwise change an evidence stream.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Use PATCH /api/v2/evidence-streams/{stream_uuid} only after it appears in live OpenAPI with explicit PAUSE, RESUME, or ARCHIVE action, expected version, and reason.","Do not translate legacy bodies field-for-field or submit owner or vault selectors, generic whitelist or blacklist state, caller-authored publisher trust, secrets, replay material, or downstream authority assertions.","Verify the exact replacement in live production OpenAPI before calling it; a planned Evidence Streams profile remains documentation only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-governance-authorities","method":"GET","path":"/api/v2/governance/authorities","title":"GOVERNANCE: List authorities","description":"List governance authorities and their active policy boundaries.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-governance-authorities","scope":"governance:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List authorities"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List governance authorities and their active policy boundaries.","whenToUse":"Use this operation when an integration needs to list authorities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"post-api-v2-governance-mpc-ceremonies","method":"POST","path":"/api/v2/governance/mpc-ceremonies","title":"GOVERNANCE: Request MPC ceremony","description":"Request a policy-authorized MPC ceremony from the custody boundary.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Wallets","Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1mpc-ceremonies/post","scope":"governance:request_mpc","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request MPC ceremony"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:request_mpc authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-governance-mpc-ceremonies-request-001"},{"name":"proposalId","location":"body","required":true,"type":"identifier","description":"Policy-approved proposal.","example":"proposalId-01"},{"name":"intentCommitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Exact retained governance-intent commitment.","example":"intentCommitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request a policy-authorized MPC ceremony from the custody boundary.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request mpc ceremony.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","multi-party approvals","authority lifecycle management"],"prerequisites":["A bearer credential with governance:request_mpc authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","AI Wallet Control","Contract Studio","Access Control"]}},{"id":"get-api-v2-governance-proposals","method":"GET","path":"/api/v2/governance/proposals","title":"GOVERNANCE: List proposals","description":"List governance proposals visible to the caller.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1proposals/get","scope":"governance:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List proposals"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List governance proposals visible to the caller.","whenToUse":"Use this operation when an integration needs to list proposals before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"post-api-v2-governance-proposals","method":"POST","path":"/api/v2/governance/proposals","title":"GOVERNANCE: Create proposal","description":"Create a policy-bound governance proposal without executing it.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1proposals/post","scope":"governance:propose","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create proposal"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:propose authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-governance-proposals-request-001"},{"name":"type","location":"body","required":true,"type":"SAFE_DEPLOYMENT | OWNER_CHANGE | THRESHOLD_CHANGE | CONTRACT_CALL","description":"Governed proposal type.","example":"type-01"},{"name":"title","location":"body","required":true,"type":"string · 1–160","description":"Proposal title.","example":"title-01"},{"name":"summary","location":"body","required":true,"type":"string · 1–1000","description":"Auditable proposal rationale.","example":"summary-01"},{"name":"risk","location":"body","required":true,"type":"STANDARD | ELEVATED","description":"Declared policy risk.","example":"risk-01"},{"name":"safeId","location":"body","required":true,"type":"identifier","description":"Governed safe or application boundary.","example":"safeId-01"},{"name":"safeName","location":"body","required":true,"type":"string · max 160","description":"Human-readable authority name.","example":"safeName-01"},{"name":"walletBindings","location":"body","required":true,"type":"MPC wallet identifier[] · 1–10","description":"Activated workspace MPC authorities.","example":[]},{"name":"chainTransaction","location":"body","required":false,"type":"object","description":"Exact unsigned transaction; signing material is forbidden.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a policy-bound governance proposal without executing it.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create proposal.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:propose authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"get-api-v2-governance-proposals-proposal-uuid","method":"GET","path":"/api/v2/governance/proposals/{proposal_uuid}","title":"GOVERNANCE: Get proposal","description":"Return proposal state, authority, approvals, and retained evidence.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1proposals~1{proposal_uuid}/get","scope":"governance:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get proposal"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:read authority.","example":"Bearer hc_live_…"},{"name":"proposal_uuid","location":"path","required":true,"type":"identifier","description":"Canonical proposal uuid.","example":"proposal-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return proposal state, authority, approvals, and retained evidence.","whenToUse":"Use this operation when an integration needs to get proposal before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"post-api-v2-governance-proposals-proposal-uuid-decisions","method":"POST","path":"/api/v2/governance/proposals/{proposal_uuid}/decisions","title":"GOVERNANCE: Record decision","description":"Record an authorized approval or rejection against a proposal.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1proposals~1{proposal_uuid}~1decisions/post","scope":"governance:decide","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record decision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:decide authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-governance-proposals-proposal-uuid-decisions-request-001"},{"name":"proposal_uuid","location":"path","required":true,"type":"identifier","description":"Canonical proposal uuid.","example":"proposal-uuid-01"},{"name":"decision","location":"body","required":true,"type":"APPROVE | REJECT","description":"Immutable policy decision.","example":"decision-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Required for rejection and retained for audit.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record an authorized approval or rejection against a proposal.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to record decision.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:decide authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"post-api-v2-governance-proposals-proposal-uuid-mpc-ceremonies-request-uuid-signing-sessions","method":"POST","path":"/api/v2/governance/proposals/{proposal_uuid}/mpc-ceremonies/{request_uuid}/signing-sessions","title":"GOVERNANCE: Start MPC signing","description":"Start commitment-bound threshold signing only after the pinned participant-readiness threshold is final.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Wallets","Governance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1governance~1proposals~1{proposal_uuid}~1mpc-ceremonies~1{request_uuid}~1signing-sessions/post","scope":"governance:request_mpc","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Start MPC signing"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:request_mpc authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-governance-proposals-proposal-uuid-mpc-ceremonies-request-uuid-signing-sessions-request-001"},{"name":"proposal_uuid","location":"path","required":true,"type":"identifier","description":"Canonical proposal uuid.","example":"proposal-uuid-01"},{"name":"request_uuid","location":"path","required":true,"type":"identifier","description":"Canonical request uuid.","example":"request-uuid-01"},{"name":"requestCommitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Exact participant-ready MPC ceremony commitment.","example":"requestCommitment-01"},{"name":"intentCommitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Exact retained governance-intent commitment.","example":"intentCommitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Start commitment-bound threshold signing only after the pinned participant-readiness threshold is final.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to start mpc signing.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","multi-party approvals","authority lifecycle management"],"prerequisites":["A bearer credential with governance:request_mpc authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Funding","AI Wallet Control","Contract Studio","Access Control"]}},{"id":"get-api-v2-governance-safes","method":"GET","path":"/api/v2/governance/safes","title":"GOVERNANCE: List safes","description":"List governed safes available to the caller.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-governance-safes","scope":"governance:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List safes"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List governed safes available to the caller.","whenToUse":"Use this operation when an integration needs to list safes before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"post-api-v2-governance-safes","method":"POST","path":"/api/v2/governance/safes","title":"GOVERNANCE: Create safe","description":"Create a governed safe with explicit owners and signature threshold.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-governance-safes","scope":"governance:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create safe"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-governance-safes-request-001"},{"name":"name","location":"body","required":true,"type":"string · 2–120","description":"Owner-visible safe name; it grants no authority by itself.","example":"Treasury policy council"},{"name":"purpose","location":"body","required":true,"type":"string · 8–500","description":"Substantive purpose limitation retained with creation and later policy-change evidence.","example":"Approve governed treasury policy changes"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Single network boundary for the safe and every future binding.","example":"hybrid-testnet"},{"name":"members","location":"body","required":true,"type":"member object[] · 2–32 unique","description":"Complete initial member set. Each object requires member_id and active signing_key_id; optional label is display-only. Private keys, seeds, passwords, and bearer secrets are forbidden.","example":[{"label":"Treasury lead","member_id":"profile-01JMEMBER01","signing_key_id":"hck_member_01"},{"label":"Risk reviewer","member_id":"profile-01JMEMBER02","signing_key_id":"hck_member_02"}]},{"name":"threshold","location":"body","required":true,"type":"integer · 1–member count","description":"Distinct eligible member approvals required by a future governed proposal. It cannot exceed the unique member count.","example":2},{"name":"proposal_ttl_seconds","location":"body","required":false,"type":"integer · 300–604800","description":"Future proposal approval window; defaults to 86400 seconds.","example":86400},{"name":"execution_delay_seconds","location":"body","required":false,"type":"integer · 0–604800","description":"Delay after approval before a separately authorized owning-domain action could become eligible; defaults to 0.","example":3600},{"name":"step_up_token","location":"body","required":true,"type":"one-use purpose-bound token","description":"Fresh GOVERNANCE_SAFE_CREATE authorization bound to the administrator session and canonical request.","example":"hcsu_…"}],"responses":[{"status":201,"description":"When promoted, a versioned PENDING_MEMBER_ACCEPTANCE safe policy and evidence identifiers are returned under no-store; no owning-domain authority is bound.","example":null},{"status":400,"description":"A name, purpose, network, member, threshold, timing field, signature, step-up token, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks governance:write, cannot enroll one or more members, or lacks the required GOVERNANCE_SAFE_CREATE step-up.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another request or an equivalent active or pending safe already exists.","example":null},{"status":422,"description":"A member or signing key is ineligible, the threshold is unsatisfiable, or a timing or network boundary violates owner policy.","example":null},{"status":503,"description":"No authoritative safe owner, membership verifier, evidence ledger, or step-up verifier is available; creation must fail closed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a governed safe with explicit owners and signature threshold.","whenToUse":"Do not call this planning route. Use the profile to design a future workspace- and network-bound approval policy only after reconciling eligible principals and their active registered signing keys.","workflowRole":"create-or-command","sideEffects":"No executable public safe owner exists. A future promotion would create one versioned PENDING_MEMBER_ACCEPTANCE policy and evidence record without binding wallet, contract, access, settlement, trading, publisher, ingress, market-status, or traffic authority.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:write authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Supply the complete initial member set and a satisfiable threshold. Each member references an existing principal and active public signing-key identifier; private keys, seeds, passwords, recovery material, and bearer secrets are forbidden.","Treat labels as display metadata. The future owner must verify uniqueness, workspace and network eligibility, key possession, step-up purpose, threshold bounds, and member acceptance before the safe can become ACTIVE.","Creation does not execute a transaction, move value, modify a wallet, bind a contract authority, or approve a proposal. Any future binding requires a separate typed owning-domain ceremony and fresh policy checks.","Retain the safe identifier, version, policy commitment, member-acceptance posture, and evidence identifiers. Promotion requires an identified authoritative owner, immutable proposal evidence, replay-safe signatures, recovery and lockout policy, and conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"patch-api-v2-governance-safes-safe-uuid","method":"PATCH","path":"/api/v2/governance/safes/{safe_uuid}","title":"GOVERNANCE: Update safe policy","description":"Propose an owner or threshold change through the governed safe workflow.","chapter":"Governance","chapterOrder":23,"capability":"Governance","owners":["governance-service"],"applications":["Governance"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-governance-safes-safe-uuid","scope":"governance:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update safe policy"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing governance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-governance-safes-safe-uuid-request-001"},{"name":"safe_uuid","location":"path","required":true,"type":"identifier","description":"Canonical safe uuid.","example":"safe-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current safe-policy version used for optimistic concurrency.","example":3},{"name":"members","location":"body","required":false,"type":"member object[] · 2–32 unique","description":"Optional complete replacement member set using active member_id and signing_key_id values. Omission retains the existing set.","example":[{"label":"Treasury lead","member_id":"profile-01JMEMBER01","signing_key_id":"hck_member_01"},{"label":"Compliance reviewer","member_id":"profile-01JMEMBER03","signing_key_id":"hck_member_03"}]},{"name":"threshold","location":"body","required":false,"type":"integer · 1–replacement or current member count","description":"Optional replacement approval threshold. The resulting policy must remain satisfiable.","example":2},{"name":"proposal_ttl_seconds","location":"body","required":false,"type":"integer · 300–604800","description":"Optional replacement proposal approval window.","example":172800},{"name":"execution_delay_seconds","location":"body","required":false,"type":"integer · 0–604800","description":"Optional replacement delay applied only after a policy-change proposal becomes approved.","example":7200},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed policy-change rationale retained with the proposal and evidence chain.","example":"Replace a departing signer and extend the review window"},{"name":"step_up_token","location":"body","required":true,"type":"one-use purpose-bound token","description":"Fresh GOVERNANCE_SAFE_POLICY_CHANGE authorization bound to the administrator session, safe, and expected version.","example":"hcsu_…"}],"responses":[{"status":202,"description":"When promoted, a version-bound safe-policy-change proposal is retained for member approval; the active policy remains unchanged.","example":null},{"status":400,"description":"The update contains no policy change or a member, threshold, timing, reason, signature, step-up token, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal cannot propose changes for this safe or lacks the required GOVERNANCE_SAFE_POLICY_CHANGE step-up.","example":null},{"status":404,"description":"The safe does not exist in the authenticated workspace and network boundary.","example":null},{"status":409,"description":"The expected version is stale, an incompatible policy proposal is already open, or the Idempotency-Key conflicts with another request.","example":null},{"status":422,"description":"The resulting member set or threshold is unsatisfiable, a member key is ineligible, or a timing boundary violates owner policy.","example":null},{"status":503,"description":"The authoritative safe owner, proposal ledger, membership verifier, or step-up verifier is unavailable; the active policy must remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Propose an owner or threshold change through the governed safe workflow.","whenToUse":"Do not call this planning route. Use the profile to design a future version-aware proposal that replaces safe membership, threshold, approval window, or execution delay after reading the current policy.","workflowRole":"revise","sideEffects":"No executable public policy update exists. A future promotion would retain a POLICY_CHANGE proposal for current-member approval while leaving the active policy unchanged until every configured threshold, delay, acceptance, and owner gate passes.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance"],"prerequisites":["A bearer credential with governance:write authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Send expected_version, a substantive reason, step-up authorization, and at least one replacement policy field. members and event timing are replacements, not patches; never silently merge a stale local set.","On 409, re-read the safe and open proposals before forming a new intent. A 202 response would mean proposal retention only, not approval, activation, execution, or authority transfer.","A changed member must prove control of an eligible registered public signing key. Removing a member cannot erase prior approvals or evidence, and the resulting threshold must remain satisfiable through the complete transition.","Policy changes cannot alter trading, matching, settlement, publisher, ingress, market status, or traffic. Any future owning-domain binding remains separate and must reference the active safe policy version and commitment.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Contract Studio","Access Control"]}},{"id":"get-api-v2-funding-bindings","method":"GET","path":"/api/v2/funding/bindings","title":"FUNDING: List network bindings","description":"Return owner-scoped funding route bindings and their preparation or activation posture without exposing wallet addresses, keys, or custody material.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/bindings","source":"APIRoutes.py · Handler_FundingV2.handle_bindings · signed owner-scoped network binding projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1bindings/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List network bindings"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return owner-scoped funding route bindings and their preparation or activation posture without exposing wallet addresses, keys, or custody material.","whenToUse":"Use this operation when an integration needs to list network bindings before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"post-api-v2-funding-bindings","method":"POST","path":"/api/v2/funding/bindings","title":"FUNDING: Prepare binding","description":"Prepare an owner-scoped wallet activation binding for one network, chain, and currency; the resulting PREPARED route cannot receive credit or activate value movement.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/funding/bindings","source":"APIRoutes.py · Handler_FundingV2.handle_bindings · signed idempotent non-value-bearing binding preparation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1bindings/post","scope":"funding:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Prepare binding"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-funding-bindings-request-001"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Network of the already activated owner wallet. It must equal the authenticated network context.","example":"hybrid-testnet"},{"name":"activation_identifier","location":"body","required":true,"type":"identifier","description":"Owner-scoped active MPC wallet activation used to derive wallet, address, and activation commitment. Wallet UUIDs and native addresses are not accepted.","example":"activation-01"},{"name":"chain_code","location":"body","required":false,"type":"uppercase chain code · default HYBRID","description":"Deposit rail. HYBRID selects the network's canonical native-asset boundary.","example":"HYBRID"},{"name":"currency","location":"body","required":false,"type":"uppercase asset code · max 16","description":"Funding asset. For HYBRID, omission selects the configured native asset for the selected network.","example":"THYB"}],"responses":[{"status":201,"description":"A PREPARED owner-scoped route and its policy commitment are returned; value_bearing_enabled remains false.","example":null},{"status":200,"description":"An equivalent owner, activation, network, chain, and currency binding already exists and is returned idempotently.","example":null},{"status":400,"description":"The network, activation identifier, chain, currency, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks funding:write or does not own the selected activation.","example":null},{"status":404,"description":"The active owner-scoped wallet activation was not found.","example":null},{"status":409,"description":"Network, native-asset, activation, or existing-route policy conflicts with the request.","example":null},{"status":422,"description":"The chain or currency is unsupported for this network's funding policy.","example":null},{"status":503,"description":"The wallet activation, funding owner, or evidence ledger is unavailable; no route is prepared.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Prepare an owner-scoped wallet activation binding for one network, chain, and currency; the resulting PREPARED route cannot receive credit or activate value movement.","whenToUse":"Use after an MPC wallet activation exists to prepare one owner-scoped funding route for a specific network, chain, and currency. Preparation makes the route discoverable to later funding workflows without making it value-bearing.","workflowRole":"create-or-command","sideEffects":"Creates or returns only a PREPARED binding and route-policy commitment. It assigns no deposit coordinate, credits no balance, enables no withdrawal, and moves no value.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:write authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","The bearer and network context determine the owner. Submit an activation identifier, never a profile UUID, vault UUID, wallet UUID, native address, private key, seed, MPC share, or signing nonce.","For HYBRID, currency must match the selected network's canonical native asset. Omission may select that configured asset; never guess it from another network.","PREPARED is not ACTIVE. Continue only through separately authorized route assignment, reserve attestation, activation, and later settlement controls exposed by their owning services.","The executable contract enforces funding:write, active owner-scoped wallet resolution, network and native-asset isolation, canonical uniqueness, idempotency, route-policy commitments, immutable events, and an explicit no-value invariant.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-api-v2-funding-deposits","method":"GET","path":"/api/v2/funding/deposits","title":"FUNDING: List deposits","description":"List the authenticated owner's newest observed deposits, confirmation progress, reserve commitments, exact decimal amounts, retained first-observed valuation, and credit-availability lifecycle without exposing owner IDs, wallet IDs, or native addresses.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding","Indexer Controller"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/deposits","source":"APIRoutes.py · view_get_v2_funding_deposits · signed owner-scoped minimized deposit projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1deposits/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List deposits"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque 32-character hexadecimal cursor","description":"Cursor returned by the preceding owner-scoped page; valid only with the same state filter.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum newest deposits to return; defaults to 50.","example":50},{"name":"state","location":"query","required":false,"type":"DETECTED | CONFIRMING | RESERVE_ATTESTED | CREDIT_PENDING | AVAILABLE | REJECTED | REORGED","description":"Exact uppercase deposit lifecycle-state filter.","example":"AVAILABLE"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated owner's newest observed deposits, confirmation progress, reserve commitments, exact decimal amounts, retained first-observed valuation, and credit-availability lifecycle without exposing owner IDs, wallet IDs, or native addresses.","whenToUse":"Use after funding coordinates are configured to reconcile the authenticated owner's observed chain deposits, confirmation progress, reserve evidence, and credit-availability posture without exposing wallet addresses or widening the owner boundary.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Preserve amount, price_usd, and value_usd as exact decimal strings. A first-observed valuation is retained evidence, not a current market quote.","AVAILABLE is the funding lifecycle state recorded by Core; it does not independently authorize withdrawal, transfer, settlement, trading, or operational control.","Continue only with next_cursor and the same state filter. Re-fetch after additional confirmations or a possible reorganization.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Infrastructure","Chain Explorer"]}},{"id":"get-api-v2-funding-positions","method":"GET","path":"/api/v2/funding/positions","title":"FUNDING: Get positions","description":"Return balances, bindings, deposits, and settlement posture for the active network.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/positions","source":"APIRoutes.py · Handler_FundingV2.handle_positions · signed projection-only funding positions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1positions/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get positions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return balances, bindings, deposits, and settlement posture for the active network.","whenToUse":"Use this operation when an integration needs to get positions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-api-v2-funding-readiness","method":"GET","path":"/api/v2/funding/readiness","title":"FUNDING: Get operational readiness","description":"Return fail-closed funding readiness evidence without authorizing activation.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/readiness","source":"APIRoutes.py · Handler_FundingV2.handle_readiness · signed fail-closed readiness projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1readiness/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get operational readiness"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return fail-closed funding readiness evidence without authorizing activation.","whenToUse":"Use this operation when an integration needs to get operational readiness before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-api-v2-funding-reconciliation-incidents","method":"GET","path":"/api/v2/funding/reconciliation-incidents","title":"FUNDING: List reconciliation incidents","description":"List the authenticated owner's newest funding reconciliation exceptions, reason and resolution codes, event identifiers, and evidence commitments through a read-only projection that never changes balances.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding","Indexer Controller"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/reconciliation-incidents","source":"APIRoutes.py · view_get_v2_funding_reconciliation_incidents · signed owner-scoped evidence-only incident projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1reconciliation-incidents/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List reconciliation incidents"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque 32-character hexadecimal cursor","description":"Cursor returned by the preceding owner-scoped page; valid only with the same state filter.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum newest incidents to return; defaults to 50.","example":50},{"name":"state","location":"query","required":false,"type":"OPEN | RESOLVED | DISMISSED","description":"Exact uppercase incident lifecycle-state filter.","example":"OPEN"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated owner's newest funding reconciliation exceptions, reason and resolution codes, event identifiers, and evidence commitments through a read-only projection that never changes balances.","whenToUse":"Use when funding operations or an agent must investigate owner-scoped exceptions between chain observations, reserve evidence, and the retained deposit projection.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Treat reason_code, source_observation_commitment, event identifiers, and resolution commitments as an evidence trail; retrieve the related deposit before presenting a conclusion.","RESOLVED reports recorded workflow resolution. balance_changed_by_resolution is always false because this endpoint cannot post, reverse, or repair a balance.","Do not infer chain finality, customer liability, settlement authorization, or remediation authority from incident state alone.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Infrastructure","Chain Explorer"]}},{"id":"get-api-v2-funding-settlement-intents","method":"GET","path":"/api/v2/funding/settlement-intents","title":"FUNDING: List settlement intents","description":"List owner-scoped settlement intents and their current authorization, reservation, signing, broadcast, and finality posture without granting authority to advance them.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/settlement-intents","source":"APIRoutes.py · Handler_FundingV2.handle_settlement_intents · signed owner-scoped intent projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1settlement-intents/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List settlement intents"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List owner-scoped settlement intents and their current authorization, reservation, signing, broadcast, and finality posture without granting authority to advance them.","whenToUse":"Use this operation when an integration needs to list settlement intents before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"post-api-v2-funding-settlement-intents","method":"POST","path":"/api/v2/funding/settlement-intents","title":"FUNDING: Create settlement intent","description":"Create an owner-scoped withdrawal or internal-transfer intent in AUTHORIZATION_REQUIRED state; creation neither reserves collateral nor signs, broadcasts, or moves funds.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/funding/settlement-intents","source":"APIRoutes.py · Handler_FundingV2.handle_settlement_intents · signed idempotent prepared intent creation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1settlement-intents/post","scope":"funding:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create settlement intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-funding-settlement-intents-request-001"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Network of the source activation and destination. It must equal the authenticated network context.","example":"hybrid-testnet"},{"name":"intent_type","location":"body","required":true,"type":"WITHDRAWAL | INTERNAL_TRANSFER","description":"WITHDRAWAL targets an eligible external destination; INTERNAL_TRANSFER resolves another active wallet in the same Hybrid network.","example":"INTERNAL_TRANSFER"},{"name":"activation_identifier","location":"body","required":true,"type":"identifier","description":"Owner-scoped active MPC wallet activation. The gateway and Core derive the source wallet and native address.","example":"activation-01"},{"name":"amount","location":"body","required":true,"type":"non-negative exact decimal string · max 18 fractional digits","description":"Requested amount without floating-point conversion. Production non-zero value remains fail closed until the owning policy explicitly enables it.","example":"0"},{"name":"chain_code","location":"body","required":false,"type":"uppercase chain code · default HYBRID","description":"Settlement rail. INTERNAL_TRANSFER requires HYBRID.","example":"HYBRID"},{"name":"currency","location":"body","required":true,"type":"uppercase asset code · max 16","description":"Exact settlement asset for the selected network and rail.","example":"THYB"},{"name":"destination_reference","location":"body","required":true,"type":"network-valid destination identifier","description":"External rail destination or same-network native destination, interpreted by intent_type. It is never used as an owner selector.","example":"thyb1destination…"},{"name":"sender_sequence","location":"body","required":false,"type":"integer · ≥1","description":"Latest source-wallet sequence returned by the owner projection. A stale value fails with 409; omission asks Core to use its locked current sequence.","example":12}],"responses":[{"status":201,"description":"An AUTHORIZATION_REQUIRED intent, request and policy commitments, locked sender sequence, and next consent action are returned; funds_moved is false.","example":null},{"status":200,"description":"The same Idempotency-Key and byte-equivalent logical intent are replayed without creating another intent.","example":null},{"status":400,"description":"The intent type, activation, amount, rail, currency, destination, sequence, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks funding:write or does not own the source activation.","example":null},{"status":404,"description":"The source activation or same-network destination does not exist in the owner-visible boundary.","example":null},{"status":409,"description":"The sender sequence changed, destination is ineligible, production value movement remains disabled, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Network, native-asset, exact-decimal, destination, or settlement policy validation failed.","example":null},{"status":503,"description":"Funding, wallet activation, collateral, or evidence ownership is unavailable; no intent is created.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an owner-scoped withdrawal or internal-transfer intent in AUTHORIZATION_REQUIRED state; creation neither reserves collateral nor signs, broadcasts, or moves funds.","whenToUse":"Use to record an exact withdrawal or same-network internal-transfer proposal before customer consent and every custody, collateral, and finality gate.","workflowRole":"create-or-command","sideEffects":"Records AUTHORIZATION_REQUIRED state and commitments only; it does not reserve collateral, collect consent, produce an MPC signature, broadcast a transaction, credit a recipient, or move funds.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:write authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Preserve amount as an exact decimal string and destination_reference exactly as the selected rail requires. INTERNAL_TRANSFER requires the canonical HYBRID rail and an active destination on the same network.","Use sender_sequence from the latest source projection when supplied. A stale sequence must fail with 409 rather than silently targeting newer wallet state.","Production non-zero value movement remains fail closed. Zero-value and isolated test-asset evidence do not authorize production value, traffic, trading, matching, or market-state changes.","A created intent must next complete exact customer consent, authorization, collateral reservation, MPC signing, broadcast, and validator finality as separate observable lifecycle steps.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-api-v2-funding-settlement-intents-intent-uuid","method":"GET","path":"/api/v2/funding/settlement-intents/{intent_uuid}","title":"FUNDING: Get settlement intent","description":"Return the complete state and evidence for one settlement intent.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/funding/settlement-intents/{intent_uuid}","source":"APIRoutes.py · Handler_FundingV2.handle_settlement_intent · signed owner-visible intent detail"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1settlement-intents~1{intent_uuid}/get","scope":"funding:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get settlement intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:read authority.","example":"Bearer hc_live_…"},{"name":"intent_uuid","location":"path","required":true,"type":"identifier","description":"Canonical intent uuid.","example":"intent-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the complete state and evidence for one settlement intent.","whenToUse":"Use this operation when an integration needs to get settlement intent before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:read authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"post-api-v2-funding-settlement-intents-intent-uuid-cancellations","method":"POST","path":"/api/v2/funding/settlement-intents/{intent_uuid}/cancellations","title":"FUNDING: Cancel settlement intent","description":"Atomically cancel an owner-scoped pre-broadcast settlement intent and release any held collateral; signing, broadcast, and terminal states remain outside customer cancellation authority.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/funding/settlement-intents/{intent_uuid}/cancellations","source":"APIRoutes.py · Handler_FundingV2.handle_settlement_intent_cancellation · signed idempotent pre-broadcast cancellation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1settlement-intents~1{intent_uuid}~1cancellations/post","scope":"funding:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel settlement intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-funding-settlement-intents-intent-uuid-cancellations-request-001"},{"name":"intent_uuid","location":"path","required":true,"type":"identifier","description":"Canonical intent uuid.","example":"intent-uuid-01"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Must match the authenticated owner and settlement intent.","example":"hybrid-testnet"},{"name":"expected_request_commitment","location":"body","required":true,"type":"64-character hexadecimal SHA-256 digest","description":"Commitment from the latest intent projection. It prevents an agent from cancelling a refreshed or different intent after stale UI state.","example":"dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"},{"name":"reason_code","location":"body","required":true,"type":"OWNER_CANCELLED","description":"Exact customer-controlled cancellation reason. Broader administrative or machine failure transitions require separately governed endpoints.","example":"OWNER_CANCELLED"}],"responses":[{"status":200,"description":"The eligible intent is CANCELLED and any held collateral is released atomically; repeating the exact completed cancellation is idempotent.","example":null},{"status":400,"description":"The network, expected commitment, reason, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks funding:write or does not own the settlement intent.","example":null},{"status":404,"description":"The settlement intent does not exist in the authenticated owner and network boundary.","example":null},{"status":409,"description":"The request commitment is stale, the intent entered signing, broadcast, or another terminal state, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"The cancellation reason, current lifecycle, or collateral-release policy rejects the request.","example":null},{"status":503,"description":"Funding or collateral ownership is unavailable; intent and collateral state remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Atomically cancel an owner-scoped pre-broadcast settlement intent and release any held collateral; signing, broadcast, and terminal states remain outside customer cancellation authority.","whenToUse":"Use to cancel an owner-scoped intent only while it is still pre-broadcast and therefore recoverable without contradicting an external transaction.","workflowRole":"create-or-command","sideEffects":"Atomically changes an eligible intent to CANCELLED, releases its collateral reservation if present, and appends evidence; it never reverses a broadcast transaction or changes another balance.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:write authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Refresh the intent first and bind expected_request_commitment. Customer cancellation is eligible only from AUTHORIZATION_REQUIRED, AUTHORIZED, or FUNDS_RESERVED; signing, broadcasting, confirming, completed, failed, and other terminal states fail with 409.","An already CANCELLED exact intent is an idempotent success. An ambiguous response must be reconciled by re-reading the intent and collateral posture before retrying the same body and Idempotency-Key.","Cancellation does not revoke a credential, wallet, funding binding, deposit, or external rail instruction. Later compensating action, if any, requires a separately named owner and authority.","The executable contract enforces funding:write, owner and network isolation, expected-commitment concurrency, row locking, atomic collateral release, retained cancellation evidence, idempotent replay, and fail-closed behavior when either owner is unavailable.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"post-api-v2-funding-settlement-intents-intent-uuid-consent","method":"POST","path":"/api/v2/funding/settlement-intents/{intent_uuid}/consent","title":"FUNDING: Complete settlement consent","description":"Advance the exact-intent customer-consent ceremony through challenge, native-plus-passkey preauthorization, and OPAQUE receipt completion without accepting a password or authorizing broadcast.","chapter":"Funding & Settlement","chapterOrder":24,"capability":"Funding & settlement","owners":["funding-service"],"applications":["Funding"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["funding-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/funding/settlement-intents/{intent_uuid}/consent","source":"APIRoutes.py · Handler_FundingV2.handle_settlement_intent_consent · signed challenge, preauthorization, and completion lifecycle"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1funding~1settlement-intents~1{intent_uuid}~1consent/post","scope":"funding:consent","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Complete settlement consent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing funding:consent authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-funding-settlement-intents-intent-uuid-consent-request-001"},{"name":"intent_uuid","location":"path","required":true,"type":"identifier","description":"Canonical intent uuid.","example":"intent-uuid-01"},{"name":"phase","location":"body","required":true,"type":"CHALLENGE | PREAUTHORIZE | COMPLETE","description":"Explicit ceremony phase. Each phase accepts only its conditional fields and returns the material required by the next phase.","example":"CHALLENGE"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Must match the authenticated owner, intent, source activation, credentials, and proof material.","example":"hybrid-testnet"},{"name":"challenge_uuid","location":"body","required":false,"type":"32-character hexadecimal identifier","description":"Required for PREAUTHORIZE and COMPLETE. It must be the fresh, open, unconsumed challenge returned for this exact intent.","example":"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"},{"name":"canonical_intent","location":"body","required":false,"type":"canonical key-sorted JSON string","description":"Required only for PREAUTHORIZE and must byte-match the canonical intent returned by CHALLENGE.","example":"{\"challenge_uuid\":\"…\",\"intent_uuid\":\"…\"}"},{"name":"signature_hex","location":"body","required":false,"type":"128-character hexadecimal Ed25519 signature","description":"Required only for PREAUTHORIZE. Native-wallet proof over canonical_intent; a private key is never accepted.","example":"cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"},{"name":"passkey_assertion","location":"body","required":false,"type":"WebAuthn assertion object","description":"Required only for PREAUTHORIZE. Must prove user presence and verification against the challenge's RP ID and origin policy.","example":{"authenticator_data":"base64url…","client_data_json":"base64url…","credential_id":"base64url…","signature":"base64url…"}},{"name":"receipt","location":"body","required":false,"type":"OPAQUE authorization receipt object","description":"Required only for COMPLETE. Short-lived receipt returned by the password-authentication broker; the password and password file are never transmitted here.","example":{"authorization_uuid":"consent-01","credential_uuid":"opaque-credential-01","receipt":"signed-opaque-receipt…"}}],"responses":[{"status":201,"description":"The requested ceremony phase completes and returns only the fresh challenge, preauthorization ticket, or retained proof commitments required by the next step.","example":null},{"status":200,"description":"An already completed equivalent phase or final exact-intent consent is returned idempotently.","example":null},{"status":400,"description":"The phase or its conditional challenge, canonical intent, signature, passkey assertion, receipt, signed headers, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks funding:consent, the credential subject differs, or native, passkey, OPAQUE, RP, origin, presence, or verification proof fails.","example":null},{"status":404,"description":"The owner-scoped intent, challenge, enrollment, credential, or pinned authority was not found.","example":null},{"status":409,"description":"Intent state is ineligible, the challenge expired or was consumed, proof targets another intent, credential epoch changed, or the Idempotency-Key conflicts.","example":null},{"status":422,"description":"Canonicalization, proof binding, receipt freshness, exact-intent commitment, or network policy validation failed.","example":null},{"status":503,"description":"Funding consent, WebAuthn, OPAQUE authorization, Identity, or evidence retention is unavailable; consent is not inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Advance the exact-intent customer-consent ceremony through challenge, native-plus-passkey preauthorization, and OPAQUE receipt completion without accepting a password or authorizing broadcast.","whenToUse":"Use after creating an intent to run the three-phase proof ceremony that binds the customer physically and cryptographically to that one unchanged settlement intent.","workflowRole":"create-or-command","sideEffects":"CHALLENGE issues short-lived material; PREAUTHORIZE verifies native and WebAuthn proofs and returns an OPAQUE broker ticket; COMPLETE retains commitments and wakes later authorization. None signs, broadcasts, or moves value.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["A bearer credential with funding:consent authority and the required tenant, workspace, and role context.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Call phases in order: CHALLENGE with network_id; PREAUTHORIZE with that fresh challenge, byte-identical canonical_intent, native signature, and passkey assertion; COMPLETE with the same challenge and its short-lived OPAQUE receipt.","Never send a password, password file, private native key, passkey private key, biometric data, seed, MPC share, signing nonce, or reusable authentication secret. The OPAQUE broker returns only a purpose-bound receipt.","Every proof must bind intent UUID, request commitment, wallet and key epoch, participant-set and policy commitments, credential subject, network, challenge, issuance, and expiry. Any drift requires a new challenge.","Consent means the customer approved the exact intent. It is not custody authorization, collateral availability, MPC completion, broadcast permission, validator finality, settlement completion, or production-value enablement.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Payments","Indexer Controller"]}},{"id":"get-api-v2-strategy-pools","method":"GET","path":"/api/v2/strategy-pools","title":"STRATEGY: List pools","description":"List strategy pools visible to the caller.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-strategy-pools","scope":"strategies:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List pools"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List strategy pools visible to the caller.","whenToUse":"Use this operation when an integration needs to list pools before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:read authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"post-api-v2-strategy-pools","method":"POST","path":"/api/v2/strategy-pools","title":"STRATEGY: Create pool","description":"Create a governed strategy pool definition.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-strategy-pools","scope":"strategies:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Create pool"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-strategy-pools-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for create pool. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a governed strategy pool definition.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create pool.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:write authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"get-api-v2-strategy-pools-pool-uuid","method":"GET","path":"/api/v2/strategy-pools/{pool_uuid}","title":"STRATEGY: Get pool","description":"Return pool policy, composition, performance, and evidence.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-strategy-pools-pool-uuid","scope":"strategies:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get pool"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:read authority.","example":"Bearer hc_live_…"},{"name":"pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical pool uuid.","example":"pool-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return pool policy, composition, performance, and evidence.","whenToUse":"Use this operation when an integration needs to get pool before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:read authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"patch-api-v2-strategy-pools-pool-uuid","method":"PATCH","path":"/api/v2/strategy-pools/{pool_uuid}","title":"STRATEGY: Update pool","description":"Update an eligible pool through its governance policy.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-strategy-pools-pool-uuid","scope":"strategies:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Update pool"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-strategy-pools-pool-uuid-request-001"},{"name":"pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical pool uuid.","example":"pool-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for update pool. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update an eligible pool through its governance policy.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update pool.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:write authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"post-api-v2-strategy-pools-pool-uuid-allocations","method":"POST","path":"/api/v2/strategy-pools/{pool_uuid}/allocations","title":"STRATEGY: Create allocation","description":"Allocate an eligible funding position to a strategy pool.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-strategy-pools-pool-uuid-allocations","scope":"strategies:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Create allocation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-strategy-pools-pool-uuid-allocations-request-001"},{"name":"pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical pool uuid.","example":"pool-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for create allocation. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Allocate an eligible funding position to a strategy pool.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create allocation.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:write authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"get-api-v2-strategy-pools-pool-uuid-positions","method":"GET","path":"/api/v2/strategy-pools/{pool_uuid}/positions","title":"STRATEGY: List positions","description":"List current and historical positions for a strategy pool.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-strategy-pools-pool-uuid-positions","scope":"strategies:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List positions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:read authority.","example":"Bearer hc_live_…"},{"name":"pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical pool uuid.","example":"pool-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List current and historical positions for a strategy pool.","whenToUse":"Use this operation when an integration needs to list positions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:read authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"post-api-v2-strategy-pools-pool-uuid-redemptions","method":"POST","path":"/api/v2/strategy-pools/{pool_uuid}/redemptions","title":"STRATEGY: Create redemption","description":"Request redemption of an eligible strategy allocation.","chapter":"Strategy Pools","chapterOrder":25,"capability":"Strategy pools","owners":["strategy-service"],"applications":["Strategy Pools","Liquidity Management"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-strategy-pools-pool-uuid-redemptions","scope":"strategies:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-outline","requestShapeAuthority":"not-yet-specified","exampleDisclaimer":"The request body is intentionally an outline; no client should generate or send it until an owner schema is published in OpenAPI.","uxActions":["Create redemption"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing strategies:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-strategy-pools-pool-uuid-redemptions-request-001"},{"name":"pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical pool uuid.","example":"pool-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for create redemption. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request redemption of an eligible strategy allocation.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create redemption.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["A bearer credential with strategies:write authority and the required tenant, workspace, and role context.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trading","Trust Center","Wallets"]}},{"id":"get-api-v2-billing-account","method":"GET","path":"/api/v2/billing/account","title":"BILLING: Get billing account","description":"Return the authenticated workspace's credit balance, allowance, current-period consumption, credit-pool expiry behavior, active subscriptions, and settlement posture.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Billing"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["billing-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/billing/overview","source":"APIRoutes.py · view_billing_overview"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1billing~1account/get","scope":"billing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get billing account"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the authenticated workspace's credit balance, allowance, current-period consumption, credit-pool expiry behavior, active subscriptions, and settlement posture.","whenToUse":"Use this operation when an integration needs to get billing account before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"prerequisites":["A bearer credential with billing:read authority and the required tenant, workspace, and role context.","a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing Operations","Business Network","Admin Console"]}},{"id":"post-api-v2-billing-checkouts","method":"POST","path":"/api/v2/billing/checkouts","title":"BILLING: Create checkout","description":"Create a hosted checkout session for an eligible product.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Billing"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-billing-checkouts","scope":"billing:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create checkout"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-billing-checkouts-request-001"},{"name":"product_code","location":"body","required":true,"type":"active billing product code · 1–32","description":"Exact server-owned code freshly resolved from GET /api/v2/billing/products. Display names, processor price identifiers, and caller-supplied amounts are rejected.","example":"PRO"}],"responses":[{"status":201,"description":"When promoted, a short-lived hosted checkout URL, canonical billing intent identifier, processor mode, and expiry are returned under no-store.","example":null},{"status":400,"description":"The product code, empty-field policy, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, invalid, or outside the expected workspace.","example":null},{"status":403,"description":"The principal lacks billing:write or workspace policy forbids hosted checkout.","example":null},{"status":404,"description":"The product code is not in the current active catalog.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another request or an equivalent checkout intent is already active.","example":null},{"status":422,"description":"The product is not eligible for this workspace, processor mode, currency, subscription state, or settlement posture.","example":null},{"status":503,"description":"The authoritative intent owner, processor adapter, attachment step, or protected checkout configuration is unavailable; no usable URL may be returned.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a hosted checkout session for an eligible product.","whenToUse":"Do not call this planning route. After reconciling the current billing account and active product catalog, use the profile only to design a future hosted purchase handoff for one exact server-owned product code.","workflowRole":"create-or-command","sideEffects":"No executable Rust gateway behavior exists. A future promotion would create a Core billing intent, create a processor-hosted checkout, and attach the opaque processor checkout identifier to the canonical intent as one fail-closed orchestration.","businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"prerequisites":["A bearer credential with billing:write authority and the required tenant, workspace, and role context.","a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries.","The body contains only product_code. The future gateway must derive workspace, account, contact, currency, amount, credit grant, processor mode, success path, cancel path, and metadata from authoritative state; callers cannot override them.","Resolve product_code immediately before submission. Never send an amount, currency, credit quantity, processor price ID, processor customer ID, success URL, cancel URL, owner ID, or workspace ID.","Treat checkout_url as a short-lived bearer capability returned once under no-store. Keep it out of prompts, logs, analytics, referrers, persistent agent memory, and third-party redirect parameters.","HTTP 201 would mean only that the hosted handoff was created. Reconcile GET /api/v2/billing/account after processor completion; a redirect, intent, or checkout session is not payment, subscription, credit-posting, invoice, or settlement proof.","Promotion requires one authoritative orchestration owner, processor test/live isolation, fixed allowlisted redirects, signed webhook reconciliation, atomic intent attachment, duplicate prevention, expiry, and end-to-end conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing Operations","Business Network","Admin Console"]}},{"id":"get-api-v2-billing-invoices","method":"GET","path":"/api/v2/billing/invoices","title":"BILLING: List invoices","description":"List cursor-paginated billing invoices for the caller.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Commerce","Billing"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-billing-invoices","scope":"billing:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List invoices"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List cursor-paginated billing invoices for the caller.","whenToUse":"Use this operation when an integration needs to list invoices before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["merchant onboarding and policy review","catalog and structured invoice creation","checkout capability issuance","invoice cancellation before payment","rotational-wallet observation and reconciliation","merchant settlement handoff"],"prerequisites":["A bearer credential with billing:read authority and the required tenant, workspace, and role context.","commerce:write and merchant administration authority in the authenticated workspace","eligible merchant operational wallet, settlement currency, checkout rails, compliance posture, and customer-data policy","fresh purpose-bound step-up and RFC 9421 signature for consequential planned mutations"],"agentGuidance":["Keep merchant, product, invoice, checkout, payment, rotational wallet, settlement, order, fulfillment, and refund identifiers and states distinct.","An invoice or detected deposit is not payment finality, settlement, fulfillment, asset delivery, or refund authority.","Never expose passwords, password hashes, seeds, private keys, MPC shares, banking credentials, processor customer IDs, or raw custody selectors in Commerce requests or metadata.","VERIFY_ONLY synchronization changes nothing; APPLY_OBSERVATIONS may retain verified observations but cannot settle balances or mark an invoice paid without owning evidence.","Treat legacy /api/v2/merchant/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Funding","Digital Assets","Billing Operations","Business Network","Admin Console"]}},{"id":"post-api-v2-billing-portal-sessions","method":"POST","path":"/api/v2/billing/portal-sessions","title":"BILLING: Create portal session","description":"Create a short-lived customer billing portal session.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Billing"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-billing-portal-sessions","scope":"billing:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create portal session"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-billing-portal-sessions-request-001"}],"responses":[{"status":201,"description":"When promoted, one short-lived hosted billing-portal URL and its expiry are returned under no-store.","example":null},{"status":400,"description":"The request is not empty or its signature or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, invalid, or outside the expected workspace.","example":null},{"status":403,"description":"The principal lacks billing:write or workspace policy forbids portal access.","example":null},{"status":409,"description":"No processor customer profile exists yet or the Idempotency-Key conflicts with another request.","example":null},{"status":422,"description":"The current billing account, processor mode, customer lifecycle, or return policy is not eligible for a hosted portal.","example":null},{"status":503,"description":"The authoritative billing context, processor adapter, or protected portal configuration is unavailable; no usable URL may be returned.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a short-lived customer billing portal session.","whenToUse":"Do not call this planning route. Use the profile only to design a future short-lived handoff into the authenticated workspace's existing processor-managed billing profile.","workflowRole":"create-or-command","sideEffects":"No executable Rust gateway behavior exists. A future promotion would read the workspace's private processor customer context and create one hosted portal session without exposing the customer identifier.","businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"prerequisites":["A bearer credential with billing:write authority and the required tenant, workspace, and role context.","a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries.","The future request body is exactly empty. Workspace, customer, processor mode, return path, locale, and portal configuration must be derived by the owner; caller-selected URLs and processor identifiers are forbidden.","Treat portal_url as a short-lived bearer capability returned under no-store and keep it out of prompts, logs, analytics, referrers, browser persistence, and agent memory.","A 409 for missing processor profile is expected before a successful subscription checkout. Do not fabricate a customer ID or retry against a different workspace.","Actions completed in the hosted portal become canonical only after signed processor-event reconciliation. Re-read GET /api/v2/billing/account instead of trusting the return redirect or browser state.","Promotion requires a protected processor adapter, fixed allowlisted return path, customer isolation, test/live separation, short expiry, webhook reconciliation, idempotency, and conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing Operations","Business Network","Admin Console"]}},{"id":"get-api-v2-billing-products","method":"GET","path":"/api/v2/billing/products","title":"BILLING: List products","description":"List active plans and non-expiring credit top-ups with exact minor-unit prices, currency, interval, and granted credit units.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Billing"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["billing-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/billing/catalog","source":"APIRoutes.py · view_billing_catalog"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1billing~1products/get","scope":"billing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List products"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List active plans and non-expiring credit top-ups with exact minor-unit prices, currency, interval, and granted credit units.","whenToUse":"Use this operation when an integration needs to list products before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"prerequisites":["A bearer credential with billing:read authority and the required tenant, workspace, and role context.","a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing Operations","Business Network","Admin Console"]}},{"id":"get-api-v2-billing-usage","method":"GET","path":"/api/v2/billing/usage","title":"BILLING: Get usage","description":"Return aggregate metered credit usage, pending events, and reconciliation counters for the authenticated workspace's active billing period.","chapter":"Billing","chapterOrder":26,"capability":"Customer billing","owners":["billing-service"],"applications":["Billing"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["billing-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/billing/summary","source":"APIRoutes.py · view_billing_summary"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1billing~1usage/get","scope":"billing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get usage"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing billing:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return aggregate metered credit usage, pending events, and reconciliation counters for the authenticated workspace's active billing period.","whenToUse":"Use this operation when an integration needs to get usage before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["credit and allowance monitoring","subscription and expiry review","period usage reconciliation","plan and top-up discovery"],"prerequisites":["A bearer credential with billing:read authority and the required tenant, workspace, and role context.","a bearer credential with billing:read","an active authenticated workspace whose identifier is bound by Identity"],"agentGuidance":["Never send a workspace or owner identifier; the gateway derives billing ownership from the authenticated principal.","Do not infer payment settlement from account, subscription, or usage status alone.","Use monetary values in minor units and preserve credit quantities as decimal strings.","Purchased top-up pools do not expire; allowance and subscription pools can expire at their returned boundaries.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing Operations","Business Network","Admin Console"]}},{"id":"get-api-v2-developer-api-keys","method":"GET","path":"/api/v2/developer/api-keys","title":"DEVELOPERS: List API keys","description":"List API-key metadata without returning secret material.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-developer-api-keys","scope":"developer:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List API keys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List API-key metadata without returning secret material.","whenToUse":"Use this operation when an integration needs to list api keys before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"post-api-v2-developer-api-keys","method":"POST","path":"/api/v2/developer/api-keys","title":"DEVELOPERS: Create API key","description":"Create a scoped API key and return its secret exactly once.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-developer-api-keys","scope":"developer:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create API key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-developer-api-keys-request-001"},{"name":"label","location":"body","required":true,"type":"string · 2–120","description":"Human-readable key purpose shown in owner inventory and audit evidence; it grants no authority.","example":"Production reporting agent"},{"name":"purpose","location":"body","required":true,"type":"string · 8–320","description":"Substantive purpose limitation retained with issuance and revocation evidence.","example":"Read billing and price evidence for daily treasury reporting"},{"name":"network_id","location":"body","required":true,"type":"hybrid-devnet | hybrid-testnet | hybrid-mainnet","description":"Single network boundary. A future key must never authenticate on another network.","example":"hybrid-testnet"},{"name":"scopes","location":"body","required":true,"type":"non-administrative scope[] · 1–32 unique","description":"Explicit least-privilege subset of the caller's delegable scopes. Administrative, step-up, publisher, ingress, matching, settlement, and frozen trading scopes fail closed.","example":["billing:read","pricing:read"]},{"name":"expires_in_days","location":"body","required":false,"type":"integer · 1–365","description":"Requested lifetime; defaults to 90 days and owner policy may shorten it.","example":90},{"name":"ip_allowlist","location":"body","required":false,"type":"IPv4 or IPv6 CIDR[] · 0–32 unique","description":"Optional source-network restriction. Empty means no IP restriction and must be surfaced explicitly in the returned metadata.","example":["203.0.113.0/24"]}],"responses":[{"status":201,"description":"When promoted, public key metadata plus the API-key bearer secret are returned exactly once under no-store.","example":null},{"status":400,"description":"The label, purpose, network, scope set, lifetime, IP allowlist, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal cannot delegate one or more requested scopes or policy forbids API-key issuance.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another request or an equivalent active key exceeds owner policy.","example":null},{"status":422,"description":"A requested scope, network, lifetime, or IP range violates the future least-privilege policy.","example":null},{"status":503,"description":"The authoritative credential owner, hashing service, audit ledger, or one-time secret delivery is unavailable; issuance must fail closed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a scoped API key and return its secret exactly once.","whenToUse":"Do not call this planning route. Prefer a registered Ed25519 workload identity and short-lived refreshless token; use this profile only where a future integration demonstrably requires a bounded bearer API key.","workflowRole":"create-or-command","sideEffects":"No executable public API-key issuer exists. A future promotion would create one owner- and network-bound credential record, retain only a slow hash and display-safe fingerprint, and return the bearer secret exactly once.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Request only the smallest non-administrative scope set needed by one workload. The future issuer must reject scopes the caller cannot delegate plus all step-up, publisher, ingress, matching, settlement, administrative, and frozen trading authority.","Treat the returned secret as single-view: place it directly into approved secret storage and keep it out of URLs, source control, environment dumps, prompts, logs, analytics, tickets, chat, crash reports, and persistent agent memory.","Bind every key to one network, owner, expiry, purpose, and optional IP allowlist. A key is not a user session, request-signing key, refresh token, payment credential, wallet key, or authority to widen its own scopes.","Promotion requires an authoritative credential owner, cryptographically random prefix-bearing secrets, slow one-way hashing, constant-time verification, last-used evidence, rate controls, explicit expiry, atomic revocation, owner notification, and conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"delete-api-v2-developer-api-keys-key-uuid","method":"DELETE","path":"/api/v2/developer/api-keys/{key_uuid}","title":"DEVELOPERS: Revoke API key","description":"Revoke an API key owned by the active account or workspace.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-developer-api-keys-key-uuid","scope":"developer:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke API key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-developer-api-keys-key-uuid-request-001"},{"name":"key_uuid","location":"path","required":true,"type":"identifier","description":"Canonical key uuid.","example":"key-uuid-01"}],"responses":[{"status":204,"description":"When promoted, the owner-scoped key is irreversibly revoked; repeating revocation is an idempotent no-content success.","example":null},{"status":400,"description":"The key identifier, empty-body digest, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal cannot administer the owner-scoped key.","example":null},{"status":404,"description":"The key does not exist in the authenticated owner boundary.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another revocation request.","example":null},{"status":503,"description":"The authoritative credential owner, revocation store, or audit ledger is unavailable; revocation state must not be guessed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke an API key owned by the active account or workspace.","whenToUse":"Do not call this planning route. Use the profile to design owner-initiated immediate revocation after key inventory reconciliation, rotation, expiry, suspected exposure, or workload retirement.","workflowRole":"revoke-or-delete","sideEffects":"No executable public revocation exists. A future promotion would irreversibly invalidate the selected key and retain attributed revocation evidence without deleting historical use records.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","The future request has an empty body and covers the exact path, empty-body digest, and Idempotency-Key with the V2 request signature. Never transmit the API-key secret to identify or revoke it.","Treat repeated revocation as a 204 idempotent success. After an ambiguous response, list key metadata and require REVOKED before assuming the secret is unusable.","Revocation cannot recover an exposed secret, cancel actions already committed by owning domains, or revoke another credential. Rotate dependent configuration and investigate retained last-used evidence separately.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-developer-webhooks","method":"GET","path":"/api/v2/developer/webhooks","title":"DEVELOPERS: List webhooks","description":"List webhook registrations and delivery posture.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-developer-webhooks","scope":"developer:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List webhooks"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List webhook registrations and delivery posture.","whenToUse":"Use this operation when an integration needs to list webhooks before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"post-api-v2-developer-webhooks","method":"POST","path":"/api/v2/developer/webhooks","title":"DEVELOPERS: Create webhook","description":"Register a signed webhook destination and subscribed event types.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-developer-webhooks","scope":"developer:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create webhook"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-developer-webhooks-request-001"},{"name":"name","location":"body","required":true,"type":"string · 2–120","description":"Owner-visible callback registration name.","example":"Treasury evidence updates"},{"name":"url","location":"body","required":true,"type":"public HTTPS URL · max 500","description":"Exact callback destination. Private, loopback, link-local, credential-bearing, redirected, or non-HTTPS targets must fail SSRF policy.","example":"https://integrator.example.com/hybrid-chain/events"},{"name":"event_types","location":"body","required":true,"type":"allowlisted event identifier[] · 1–100 unique","description":"Exact public-safe event classes. Wildcards and owner-selected internal event names are forbidden.","example":["billing.usage.updated","price_feed.health.changed"]},{"name":"description","location":"body","required":false,"type":"string · max 320","description":"Operator context retained with the registration; secrets are forbidden.","example":"Updates for the production reporting pipeline"}],"responses":[{"status":201,"description":"When promoted, callback metadata, verification posture, and the signing secret are returned exactly once under no-store.","example":null},{"status":400,"description":"The name, URL, event set, description, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks developer:write or cannot subscribe to one or more event classes.","example":null},{"status":409,"description":"The Idempotency-Key conflicts with another request or an equivalent callback already exists.","example":null},{"status":422,"description":"The destination fails SSRF policy or an event class, owner boundary, or delivery policy is unavailable.","example":null},{"status":503,"description":"The authoritative webhook owner, DNS and network verifier, secret store, outbox, or audit ledger is unavailable; registration must fail closed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register a signed webhook destination and subscribed event types.","whenToUse":"Do not call this planning route. Use the profile only to design a future owner-scoped HTTPS callback after selecting exact public-safe event classes and an internet-reachable destination controlled by the integrator.","workflowRole":"create-or-command","sideEffects":"No executable public webhook registry or delivery owner exists. A future promotion would register one callback, create one signing secret, verify destination safety, and return the secret exactly once without delivering historical events.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","The owner must resolve DNS and validate every connection against private, loopback, link-local, multicast, metadata-service, credential-bearing, non-HTTPS, redirected, and rebinding targets before each delivery.","Treat the returned signing secret as single-view and store it in an approved secret manager. Never send a caller-selected secret or place the returned value in prompts, logs, source control, URLs, analytics, or agent memory.","Verify the exact raw request bytes, timestamp, delivery ID, event ID, signature version, and HMAC before parsing; reject stale timestamps and atomically deduplicate event IDs while returning a bounded 2xx only after durable acceptance.","A callback is a notification of committed domain state, not the authority itself. Re-read the referenced owning resource before consequential action, and never treat delivery order as global business ordering.","Promotion requires an authoritative registry and outbox, event allowlist and schemas, SSRF-safe delivery, encrypted secret custody, rotation, retries with jitter, dead-letter evidence, observability without payload leakage, and conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"patch-api-v2-developer-webhooks-webhook-uuid","method":"PATCH","path":"/api/v2/developer/webhooks/{webhook_uuid}","title":"DEVELOPERS: Update webhook","description":"Update webhook state, destination, or event subscriptions.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-developer-webhooks-webhook-uuid","scope":"developer:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update webhook"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing developer:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-developer-webhooks-webhook-uuid-request-001"},{"name":"webhook_uuid","location":"path","required":true,"type":"identifier","description":"Canonical webhook uuid.","example":"webhook-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current registration version used for optimistic concurrency.","example":3},{"name":"name","location":"body","required":false,"type":"string · 2–120","description":"Replacement owner-visible name.","example":"Treasury and audit evidence updates"},{"name":"url","location":"body","required":false,"type":"public HTTPS URL · max 500","description":"Replacement callback destination subject to complete SSRF validation and re-verification.","example":"https://integrator.example.com/hybrid-chain/events-v2"},{"name":"event_types","location":"body","required":false,"type":"allowlisted event identifier[] · 1–100 unique","description":"Complete replacement event set; wildcards and internal events are forbidden.","example":["billing.usage.updated"]},{"name":"status","location":"body","required":false,"type":"ACTIVE | PAUSED","description":"Replacement delivery lifecycle. PAUSED retains evidence and configuration but stops new deliveries.","example":"PAUSED"}],"responses":[{"status":200,"description":"When promoted, canonical versioned callback configuration and verification posture are returned under no-store.","example":null},{"status":400,"description":"The update is empty or a field, signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal cannot administer the owner-scoped callback or subscribe to an event class.","example":null},{"status":404,"description":"The callback does not exist in the authenticated owner boundary.","example":null},{"status":409,"description":"The expected version is stale or the Idempotency-Key conflicts with another update.","example":null},{"status":422,"description":"The replacement destination fails SSRF policy or the requested state or event set violates delivery policy.","example":null},{"status":503,"description":"The authoritative webhook owner, destination verifier, outbox, or audit ledger is unavailable; existing configuration must remain unchanged.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update webhook state, destination, or event subscriptions.","whenToUse":"Do not call this planning route. Use the profile to design a version-aware replacement of callback name, destination, event set, or ACTIVE/PAUSED lifecycle after reading the current owner-scoped registration.","workflowRole":"revise","sideEffects":"No executable public update exists. A future promotion would atomically replace allowed fields, increment version, re-verify a changed destination, and retain configuration evidence without rotating the signing secret.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration"],"prerequisites":["A bearer credential with developer:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Send expected_version plus at least one changed field. On 409, re-read and reconcile; never overwrite a concurrent owner update or silently merge event sets.","Changing url must pause delivery until the complete SSRF and ownership-verification policy passes. PAUSED stops new attempts but retains registration and delivery evidence.","This route cannot set, reveal, or rotate the signing secret. Production promotion also requires a separate one-time secret-rotation ceremony with overlap, cutover, and revocation semantics.","After success, use the returned canonical version and verification state. Do not infer that in-flight retries used the new destination or event set without delivery evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-openapi-json","method":"GET","path":"/api/v2/openapi.json","title":"DEVELOPERS: Get OpenAPI specification","description":"Return the machine-readable OpenAPI specification for implemented V2 contracts.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["api-gateway","developer-platform"],"applications":["Developers","API Reference"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1openapi.json/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get OpenAPI specification"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the machine-readable OpenAPI specification for implemented V2 contracts.","whenToUse":"Fetch before generating tools, SDKs, requests, validators, or conformance tests, and re-fetch before release validation or when deployment may have changed.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","machine contract ingestion","endpoint and schema discovery","implementation-status verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Only operations present here are executable Rust gateway contracts. Read parameters, requestBody, responses, component schemas, security, operationId, and x-hybrid-chain metadata rather than scraping website prose.","A route can still fail closed for scope, tenant, feature, owner-adapter, domain, or downstream readiness; OpenAPI presence never bypasses runtime policy.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Integration Guides","Access Control","Developer Portal"]}},{"id":"get-api-v2-security-signing-keys","method":"GET","path":"/api/v2/security/signing-keys","title":"SECURITY: List request-signing keys","description":"List public request-signing key metadata for the authenticated client.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1security~1signing-keys/get","scope":"security:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List request-signing keys"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List public request-signing key metadata for the authenticated client.","whenToUse":"Use this operation when an integration needs to list request-signing keys before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change"],"prerequisites":["A bearer credential with security:read authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Trust Center","Teams & Workspaces"]}},{"id":"post-api-v2-security-signing-keys-key-id-revocations","method":"POST","path":"/api/v2/security/signing-keys/{key_id}/revocations","title":"SECURITY: Revoke request-signing key","description":"Revoke an active request-signing key after purpose-bound step-up authorization.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1security~1signing-keys~1{key_id}~1revocations/post","scope":"security:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Revoke request-signing key"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"key_id","location":"path","required":true,"type":"identifier","description":"Canonical key id.","example":"key-id-01"},{"name":"step_up_token","location":"body","required":true,"type":"one-time hcsu_ token","description":"Fresh API_SIGNING_KEY_REVOCATION authorization.","example":"step-up-token-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Revoke an active request-signing key after purpose-bound step-up authorization.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to revoke request-signing key.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Trust Center","Teams & Workspaces"]}},{"id":"post-api-v2-security-step-up","method":"POST","path":"/api/v2/security/step-up","title":"SECURITY: Create step-up authorization","description":"Verify a fresh authenticator code and issue a five-minute purpose-bound authorization.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer access","owners":["developer-platform"],"applications":["Developers","Identity & Login"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1security~1step-up/post","scope":"security:write","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create step-up authorization"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing security:write authority.","example":"Bearer hc_live_…"},{"name":"purpose","location":"body","required":true,"type":"supported step-up purpose","description":"Exact sensitive action this five-minute one-use authorization may approve.","example":"purpose-01"},{"name":"authenticator_code","location":"body","required":true,"type":"6-digit TOTP","description":"Fresh authenticator code; never retained by the gateway.","example":"authenticator-code-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Verify a fresh authenticator code and issue a five-minute purpose-bound authorization.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create step-up authorization.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","personal and corporate account onboarding","session issuance, refresh, inventory, and revocation","password recovery and authenticated password change"],"prerequisites":["A bearer credential with security:write authority and the required tenant, workspace, and role context.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control","Trust Center","Teams & Workspaces"]}},{"id":"get-api-v2-developer-portal","method":"GET","path":"/api/v2/developer-portal","title":"DEVELOPERS: Get portal catalog","description":"Return public SDK, environment, authentication, reference, and guide discovery metadata.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer documentation","owners":["developer-platform"],"applications":["Developers","Developer Portal"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1developer-portal/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get portal catalog"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return public SDK, environment, authentication, reference, and guide discovery metadata.","whenToUse":"Start every human or agent integration here to discover current machine-contract, readiness-registry, guide, Explorer, SDK, authentication, and operational-policy resources.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","integration onboarding","SDK generation and publication discovery","environment and authentication setup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","Follow resource href values rather than constructing adjacent paths. The portal is discovery metadata, not the executable operation catalog itself.","Use referencePolicy to separate executable OpenAPI truth from planned capability context, then apply agentIntegration rules for pagination, decimal strings, retries, idempotency, signing, and stable error handling.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-developer-portal-sdks","method":"GET","path":"/api/v2/developer-portal/sdks","title":"DEVELOPERS: Get SDK publication catalog","description":"Return official SDK publication status and the authoritative OpenAPI generation contract; an empty package list means no official SDK is currently published.","chapter":"Developer Platform","chapterOrder":27,"capability":"Developer documentation","owners":["developer-platform"],"applications":["Developers","Developer Portal"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1developer-portal~1sdks/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get SDK publication catalog"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return official SDK publication status and the authoritative OpenAPI generation contract; an empty package list means no official SDK is currently published.","whenToUse":"Use before selecting a generated or official client package so automation can distinguish a published, checksummed SDK from a client it must generate from OpenAPI.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","integration onboarding","SDK generation and publication discovery","environment and authentication setup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","An empty officialSdks array is authoritative unavailability, not an incomplete response or permission to invent a package name.","When no official package is listed, generate from generationContract.href and retain the observed OpenAPI digest, generator identity, settings, and generated artifact digest for reproducibility.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-integration-guides","method":"GET","path":"/api/v2/integration-guides","title":"GUIDES: List integration guides","description":"List published implementation blueprints by product, industry, use case, and maturity.","chapter":"Developer Platform","chapterOrder":27,"capability":"Integration guides","owners":["developer-platform"],"applications":["Developers","Integration Guides"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1integration-guides/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List integration guides"],"parameters":[{"name":"category","location":"query","required":false,"type":"category slug","description":"Exact guide category filter.","example":"financial-infrastructure"},{"name":"q","location":"query","required":false,"type":"string","description":"Case-insensitive title, category, and content search.","example":"payroll"},{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum guides to return.","example":50},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the preceding page.","example":"eyJvZmZzZXQiOjUwfQ"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List published implementation blueprints by product, industry, use case, and maturity.","whenToUse":"Search task-oriented business blueprints after selecting a business outcome and before composing several module contracts into one workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","workflow implementation","security-profile adoption","cross-module orchestration"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","category is an exact slug; q is a case-insensitive title, category, and content search; limit defaults to 50 and must be 1 through 100.","Treat nextCursor as opaque and reuse it only with the same category and q. Preserve sourceSha256 when pinning the narrative version used by an implementation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Access Control","Developer Portal"]}},{"id":"get-api-v2-integration-guides-guide-slug","method":"GET","path":"/api/v2/integration-guides/{guide_slug}","title":"GUIDES: Get integration guide","description":"Return one versioned integration blueprint and its linked endpoint contracts.","chapter":"Developer Platform","chapterOrder":27,"capability":"Integration guides","owners":["developer-platform"],"applications":["Developers","Integration Guides"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1integration-guides~1{guide_slug}/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get integration guide"],"parameters":[{"name":"guide_slug","location":"path","required":true,"type":"identifier","description":"Canonical guide slug.","example":"guide-slug-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one versioned integration blueprint and its linked endpoint contracts.","whenToUse":"Fetch a selected guide's full Markdown narrative and linked capability candidates before implementing its end-to-end controls, reconciliation, and failure handling.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["API credential lifecycle","agent authentication","webhook and SDK integration","workflow implementation","security-profile adoption","cross-module orchestration"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated administrator for credential changes","secure local key custody"],"agentGuidance":["Ingest the live OpenAPI document before generating calls.","Treat capability-registry-only routes as non-executable plans.","relatedEndpoints can contain both implemented-contract and planned-contract entries. Resolve each entry against live OpenAPI and use only those present there.","The guide explains composition and business intent; it never overrides an endpoint schema, authorization boundary, runtime policy, or deployment status.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["API Reference","Access Control","Developer Portal"]}},{"id":"get-api-v2-contracts","method":"GET","path":"/api/v2/contracts","title":"CONTRACTS: List launches","description":"List smart-contract launch records visible to the caller.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts/get","scope":"contracts:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List launches"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List smart-contract launch records visible to the caller.","whenToUse":"Use this operation when an integration needs to list launches before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-contracts","method":"POST","path":"/api/v2/contracts","title":"CONTRACTS: Create launch","description":"Create an immutable smart-contract launch intent from source, artifact, constructor, state, and runtime policy digests.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts/post","scope":"contracts:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create launch"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-contracts-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for create launch. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an immutable smart-contract launch intent from source, artifact, constructor, state, and runtime policy digests.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to create launch.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:write authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-contracts-launch-uuid","method":"GET","path":"/api/v2/contracts/{launch_uuid}","title":"CONTRACTS: Get launch","description":"Return one contract launch and its authority analysis.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}/get","scope":"contracts:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get launch"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one contract launch and its authority analysis.","whenToUse":"Use this operation when an integration needs to get launch before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"patch-api-v2-contracts-launch-uuid","method":"PATCH","path":"/api/v2/contracts/{launch_uuid}","title":"CONTRACTS: Update draft","description":"Update a contract launch while it remains in an editable draft state.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}/patch","scope":"contracts:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update draft"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-contracts-launch-uuid-request-001"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for update draft. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update a contract launch while it remains in an editable draft state.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to update draft.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:write authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-contracts-launch-uuid-analysis","method":"POST","path":"/api/v2/contracts/{launch_uuid}/analysis","title":"CONTRACTS: Analyze authority","description":"Analyze contract authority, runtime policy, and deployment prerequisites.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Governance","Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1analysis/post","scope":"contracts:read","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Analyze authority"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-contracts-launch-uuid-analysis-request-001"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for analyze authority. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Analyze contract authority, runtime policy, and deployment prerequisites.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to analyze authority.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Access Control","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-contracts-launch-uuid-authorities","method":"GET","path":"/api/v2/contracts/{launch_uuid}/authorities","title":"CONTRACTS: Get launch authorities","description":"Return authority assignments and threshold status for a launch.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Governance","Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1authorities/get","scope":"contracts:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get launch authorities"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return authority assignments and threshold status for a launch.","whenToUse":"Use this operation when an integration needs to get launch authorities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Access Control","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-contracts-launch-uuid-deployment-preparations","method":"POST","path":"/api/v2/contracts/{launch_uuid}/deployment-preparations","title":"CONTRACTS: Prepare deployment","description":"Prepare an unsigned deterministic deployment transaction without broadcasting it.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1deployment-preparations/post","scope":"contracts:deploy","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Prepare deployment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:deploy authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-contracts-launch-uuid-deployment-preparations-request-001"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for prepare deployment. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Prepare an unsigned deterministic deployment transaction without broadcasting it.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to prepare deployment.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:deploy authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-contracts-launch-uuid-evidence","method":"GET","path":"/api/v2/contracts/{launch_uuid}/evidence","title":"CONTRACTS: Get launch evidence","description":"Return retained source, build, authority, approval, and deployment evidence.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1evidence/get","scope":"contracts:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get launch evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return retained source, build, authority, approval, and deployment evidence.","whenToUse":"Use this operation when an integration needs to get launch evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-contracts-launch-uuid-freeze","method":"POST","path":"/api/v2/contracts/{launch_uuid}/freeze","title":"CONTRACTS: Freeze launch","description":"Freeze the launch intent so its governed digests can no longer change.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1freeze/post","scope":"contracts:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Freeze launch"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-contracts-launch-uuid-freeze-request-001"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for freeze launch. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Freeze the launch intent so its governed digests can no longer change.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to freeze launch.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:govern authority and the required tenant, workspace, and role context.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Execution Studio","Chain Explorer"]}},{"id":"post-api-v2-contracts-launch-uuid-governance-bindings","method":"POST","path":"/api/v2/contracts/{launch_uuid}/governance-bindings","title":"CONTRACTS: Bind governance","description":"Bind an approved governance authority to a frozen contract launch.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Governance","Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1{launch_uuid}~1governance-bindings/post","scope":"contracts:govern","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Bind governance"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:govern authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-contracts-launch-uuid-governance-bindings-request-001"},{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for bind governance. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Bind an approved governance authority to a frozen contract launch.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to bind governance.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","contract launch planning","authority analysis","governed deployment preparation"],"prerequisites":["A bearer credential with contracts:govern authority and the required tenant, workspace, and role context.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Wallets","Access Control","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-contracts-authority-wallets","method":"GET","path":"/api/v2/contracts/authority-wallets","title":"CONTRACTS: List authority wallets","description":"List activated MPC wallets eligible for smart-contract authority roles.","chapter":"Smart Contracts","chapterOrder":28,"capability":"Smart-contract lifecycle","owners":["contract-authority-service"],"applications":["Wallets","Governance","Contract Studio"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1contracts~1authority-wallets/get","scope":"contracts:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List authority wallets"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing contracts:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List activated MPC wallets eligible for smart-contract authority roles.","whenToUse":"Use this operation when an integration needs to list authority wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","multi-party approvals","authority lifecycle management"],"prerequisites":["A bearer credential with contracts:read authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Funding","AI Wallet Control","Access Control","Execution Studio","Chain Explorer"]}},{"id":"get-api-v2-execution-deployments","method":"GET","path":"/api/v2/execution/deployments","title":"EXECUTION: List deployments","description":"List package deployments and their current state.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-deployments","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List deployments"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List package deployments and their current state.","whenToUse":"Use this operation when an integration needs to list deployments before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-deployments","method":"POST","path":"/api/v2/execution/deployments","title":"EXECUTION: Create deployment","description":"Create a policy-bound package deployment.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-deployments","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create deployment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-deployments-request-001"},{"name":"package_uuid","location":"body","required":true,"type":"32-character identifier","description":"Visible immutable published package.","example":"5f1e2d3c4b5a69788796a5b4c3d2e1f0"},{"name":"package_version","location":"body","required":true,"type":"integer · ≥1","description":"Exact published package version.","example":3},{"name":"expected_package_commitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Published source, manifest, validation, and policy commitment.","example":"3d9b…64hex"},{"name":"environment","location":"body","required":true,"type":"TEST | PRODUCTION","description":"Isolation boundary. TEST credentials, artifacts, nodes, and receipts cannot be promoted by assertion into PRODUCTION.","example":"TEST"},{"name":"runtime_profile_id","location":"body","required":true,"type":"approved immutable runtime profile identifier","description":"Must match the package publication and eligible node pool.","example":"wasm-wasi-deterministic-v1"},{"name":"resource_limits","location":"body","required":true,"type":"bounded resource object","description":"Deployment ceilings no wider than package and platform policy.","example":{"concurrent_invocations":2,"cpu_millis":500,"memory_mib":128,"wall_time_ms":5000}},{"name":"network_policy_id","location":"body","required":true,"type":"approved deny-by-default policy identifier","description":"Server-owned egress and service-access policy; callers cannot submit hostnames, IP ranges, or firewall rules.","example":"network-none-v1"},{"name":"secret_binding_references","location":"body","required":false,"type":"opaque binding identifier[] · max 16","description":"Pre-authorized purpose-bound secret bindings resolved only inside the isolated runtime; secret values never enter this API.","example":[]},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_DEPLOYMENT_CREATION authorization bound to package, environment, policies, and limits.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A PREPARED deployment with immutable package, environment, runtime, resource, network, and secret-binding policy commitments returned; it is not active.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a policy-bound package deployment.","whenToUse":"Do not call this planning route yet. It reserves a PREPARED deployment of one immutable published package into an isolated TEST or PRODUCTION environment.","workflowRole":"create-or-command","sideEffects":"When promoted, allocates configuration and policy only. It does not activate a deployment, invoke code, admit triggers, widen package capabilities, reveal secrets, or promote TEST state into PRODUCTION.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Runtime profile must match publication. Resource limits can only narrow policy, egress is deny-by-default, and secret values remain inside their owning secret service behind purpose-bound references.","Promotion requires package and validation freshness, environment isolation, eligible attested nodes, secret-binding review, network and data policy, quotas, step-up, idempotency, rollout and rollback policy, and evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-deployments-deployment-uuid-invocations","method":"POST","path":"/api/v2/execution/deployments/{deployment_uuid}/invocations","title":"EXECUTION: Invoke deployment","description":"Invoke an active deployment with validated inputs and idempotency.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-deployments-deployment-uuid-invocations","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Invoke deployment"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-deployments-deployment-uuid-invocations-request-001"},{"name":"deployment_uuid","location":"path","required":true,"type":"identifier","description":"Canonical deployment uuid.","example":"deployment-uuid-01"},{"name":"expected_deployment_version","location":"body","required":true,"type":"integer · ≥1","description":"Current ACTIVE deployment version and policy snapshot.","example":2},{"name":"mode","location":"body","required":true,"type":"VALIDATE_ONLY | EXECUTE","description":"VALIDATE_ONLY checks schema, bindings, policy, and resource admission without executing package code.","example":"VALIDATE_ONLY"},{"name":"input","location":"body","required":true,"type":"schema-bound JSON value","description":"Input validated against the immutable published package schema; credentials and prohibited cleartext fail closed.","example":{"evidence_commitment":"ab12…","invoice_total":"125.00"}},{"name":"expected_input_schema_commitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Published input schema commitment used for validation.","example":"a1b2…64hex"},{"name":"execution_authorization_reference","location":"body","required":false,"type":"opaque purpose-bound reference","description":"Required when the invocation may perform an external domain action; absent for pure deterministic compute.","example":"authz_01K4…"},{"name":"client_reference","location":"body","required":true,"type":"string · 1–120","description":"Caller-stable idempotent business reference.","example":"invoice-classify-2026-09-01-0001"},{"name":"requested_timeout_ms","location":"body","required":false,"type":"integer · 100–60000","description":"Requested wall-clock ceiling; policy may shorten it.","example":5000}],"responses":[{"status":202,"description":"A VALIDATING or QUEUED invocation accepted with exact deployment, input-schema, input, authorization, and idempotency commitments; acceptance is not execution success.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Invoke an active deployment with validated inputs and idempotency.","whenToUse":"Do not call this planning route yet. It reserves VALIDATE_ONLY input admission or one idempotent EXECUTE invocation against the exact current deployment version.","workflowRole":"create-or-command","sideEffects":"VALIDATE_ONLY runs no package code. EXECUTE may queue isolated deterministic computation; any external domain effect still requires a fresh owner-issued authorization and is recorded separately. Acceptance is not completion or finality.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Input must match the published schema and commitment. Never use input fields to override package, deployment, owner, runtime, node, network, secret, capability, or authority policy.","Verify execution receipt, package and input commitments, node/runtime attestation, outputs, resource use, and any separate domain receipt together. Logs are diagnostic and not authoritative outputs.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-executions","method":"GET","path":"/api/v2/execution/executions","title":"EXECUTION: List executions","description":"List execution records and deterministic receipts.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-executions","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List executions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List execution records and deterministic receipts.","whenToUse":"Use this operation when an integration needs to list executions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-executions-execution-uuid","method":"GET","path":"/api/v2/execution/executions/{execution_uuid}","title":"EXECUTION: Get execution","description":"Return one execution, its logs, outputs, attestations, and receipt.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-executions-execution-uuid","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get execution"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"execution_uuid","location":"path","required":true,"type":"identifier","description":"Canonical execution uuid.","example":"execution-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one execution, its logs, outputs, attestations, and receipt.","whenToUse":"Use this operation when an integration needs to get execution before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-nodes","method":"GET","path":"/api/v2/execution/nodes","title":"EXECUTION: List nodes","description":"List execution nodes and their attested health.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-nodes","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List nodes"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List execution nodes and their attested health.","whenToUse":"Use this operation when an integration needs to list nodes before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-operators","method":"GET","path":"/api/v2/execution/operators","title":"EXECUTION: List operators","description":"List execution operators and authority statements.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-operators","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List operators"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List execution operators and authority statements.","whenToUse":"Use this operation when an integration needs to list operators before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-packages","method":"GET","path":"/api/v2/execution/packages","title":"EXECUTION: List packages","description":"List deterministic execution packages visible to the caller.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-packages","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List packages"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List deterministic execution packages visible to the caller.","whenToUse":"Use this operation when an integration needs to list packages before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-packages","method":"POST","path":"/api/v2/execution/packages","title":"EXECUTION: Create package","description":"Create a versioned deterministic execution package.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-packages","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-packages-request-001"},{"name":"name","location":"body","required":true,"type":"string · 2–120","description":"Workspace-visible package name; presentation metadata only.","example":"Invoice evidence classifier"},{"name":"description","location":"body","required":false,"type":"string · max 1000","description":"Non-secret package purpose, expected inputs, and output meaning.","example":"Deterministically classifies minimized invoice evidence commitments."},{"name":"runtime_profile_id","location":"body","required":true,"type":"approved immutable runtime profile identifier","description":"Server-owned compiler, runtime, ABI, sandbox, and determinism profile.","example":"wasm-wasi-deterministic-v1"},{"name":"source_bundle_reference","location":"body","required":true,"type":"opaque owner-scoped artifact reference","description":"Immutable client-uploaded source bundle in the approved artifact owner; URLs and inline source are rejected.","example":"artifact_01K4…"},{"name":"source_bundle_sha256","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Digest of the exact canonical source archive bytes.","example":"8f5d…64hex"},{"name":"manifest","location":"body","required":true,"type":"closed package manifest object","description":"Entrypoint, input/output schema commitments, dependency lock commitment, build command profile, and declared artifact layout.","example":{"dependency_lock_sha256":"e5f6…","entrypoint":"classify","input_schema_sha256":"a1b2…","output_schema_sha256":"c3d4…"}},{"name":"declared_capabilities","location":"body","required":true,"type":"allowlisted capability identifier[] · unique","description":"Capabilities requested from the execution profile. Empty means pure compute; arbitrary network, filesystem, secret, or domain authority is rejected.","example":["deterministic:compute"]},{"name":"resource_policy","location":"body","required":true,"type":"bounded resource object","description":"CPU, memory, output, log, and wall-clock ceilings within platform policy.","example":{"cpu_millis":500,"log_bytes":16384,"memory_mib":128,"output_bytes":65536,"wall_time_ms":5000}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_PACKAGE_CREATION authorization bound to the source, manifest, capabilities, and resource commitments.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A private DRAFT package with canonical source, manifest, capability, runtime, and resource commitments returned; it is neither validated nor executable.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a versioned deterministic execution package.","whenToUse":"Do not call this planning route yet. It reserves one private DRAFT from an immutable owner-scoped source artifact, closed manifest, approved runtime profile, declared capabilities, and bounded resources.","workflowRole":"create-or-command","sideEffects":"When promoted, creates package configuration and commitments only. It does not validate, build, publish, deploy, execute, schedule, access secrets, or invoke a business domain.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Promotion requires canonical archive rules, digest verification, manifest and schema validation, dependency-lock policy, source and license scanning, capability allowlists, deny-by-default runtime policy, quotas, step-up, idempotency, and immutable evidence.","Never submit inline code, external artifact URLs, credentials, private keys, arbitrary hosts, shell commands, or undeclared dependencies.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-packages-package-uuid","method":"GET","path":"/api/v2/execution/packages/{package_uuid}","title":"EXECUTION: Get package","description":"Return package source, manifest, policy, and verification state.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-packages-package-uuid","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"package_uuid","location":"path","required":true,"type":"identifier","description":"Canonical package uuid.","example":"package-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return package source, manifest, policy, and verification state.","whenToUse":"Use this operation when an integration needs to get package before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"patch-api-v2-execution-packages-package-uuid","method":"PATCH","path":"/api/v2/execution/packages/{package_uuid}","title":"EXECUTION: Update package","description":"Update an editable execution package draft.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-execution-packages-package-uuid","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-execution-packages-package-uuid-request-001"},{"name":"package_uuid","location":"path","required":true,"type":"identifier","description":"Canonical package uuid.","example":"package-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current editable DRAFT version for optimistic concurrency.","example":2},{"name":"name","location":"body","required":false,"type":"string · 2–120","description":"Replacement private package name.","example":"Invoice evidence classifier"},{"name":"description","location":"body","required":false,"type":"string · max 1000","description":"Replacement non-secret purpose and semantics.","example":"Adds a bounded unknown-category result."},{"name":"runtime_profile_id","location":"body","required":false,"type":"approved immutable runtime profile identifier","description":"Replacement build and sandbox profile; changing it invalidates prior validation.","example":"wasm-wasi-deterministic-v1"},{"name":"source_bundle_reference","location":"body","required":false,"type":"opaque owner-scoped artifact reference","description":"Replacement immutable source artifact.","example":"artifact_01K5…"},{"name":"source_bundle_sha256","location":"body","required":false,"type":"lowercase SHA-256 digest","description":"Digest of the replacement canonical archive.","example":"9e6c…64hex"},{"name":"manifest","location":"body","required":false,"type":"closed package manifest object","description":"Replacement manifest; any change invalidates prior validation.","example":{"dependency_lock_sha256":"f7a8…","entrypoint":"classify","input_schema_sha256":"a1b2…","output_schema_sha256":"d5e6…"}},{"name":"declared_capabilities","location":"body","required":false,"type":"allowlisted capability identifier[] · unique","description":"Replacement capability request.","example":["deterministic:compute"]},{"name":"resource_policy","location":"body","required":false,"type":"bounded resource object","description":"Replacement execution ceilings.","example":{"cpu_millis":500,"log_bytes":16384,"memory_mib":128,"output_bytes":65536,"wall_time_ms":5000}},{"name":"change_summary","location":"body","required":true,"type":"string · 8–500","description":"Attributed revision rationale retained with before/after commitments.","example":"Clarify output schema and lock dependencies."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_PACKAGE_UPDATE authorization bound to the current version and replacement commitment.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Editable DRAFT revised with a new version and commitments; any prior validation is invalidated and no published version changes.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update an editable execution package draft.","whenToUse":"Do not call this planning route yet. It reserves expected-version edits to an owner-scoped DRAFT before validation or publication.","workflowRole":"revise","sideEffects":"When promoted, creates a new DRAFT revision and invalidates validation derived from prior source, manifest, runtime, capability, or resource commitments. Published versions remain immutable.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Send at least one admitted replacement and a substantive change summary. A published or validating version cannot be edited in place.","Promotion requires version locking, artifact ownership and digest checks, dependency and schema diff policy, step-up, idempotency, and retained before/after commitments.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-packages-package-uuid-publications","method":"POST","path":"/api/v2/execution/packages/{package_uuid}/publications","title":"EXECUTION: Publish package","description":"Publish a validated immutable package version.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-packages-package-uuid-publications","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Publish package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-packages-package-uuid-publications-request-001"},{"name":"package_uuid","location":"path","required":true,"type":"identifier","description":"Canonical package uuid.","example":"package-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Exact validated DRAFT version selected for immutable publication.","example":3},{"name":"validation_uuid","location":"body","required":true,"type":"32-character identifier","description":"Successful current validation for the same package version and commitments.","example":"7a1f2b3c4d5e67890123456789abcdef"},{"name":"expected_validation_commitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Commitment to the validation profile, inputs, findings, reproducible build, and result.","example":"2c8a…64hex"},{"name":"visibility","location":"body","required":true,"type":"PRIVATE | WORKSPACE | PUBLIC","description":"Publication audience. PUBLIC requires separately configured review and disclosure policy.","example":"WORKSPACE"},{"name":"release_notes","location":"body","required":true,"type":"string · 8–2000","description":"Non-secret immutable release context.","example":"Initial validated workspace release."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_PACKAGE_PUBLICATION authorization bound to version, validation, visibility, and commitment.","example":"hcsu_…"}],"responses":[{"status":201,"description":"Validated package version published immutably at the admitted visibility with source, build, manifest, validation, and policy commitments.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Publish a validated immutable package version.","whenToUse":"Do not call this planning route yet. It reserves one-way immutable publication of an exact current validation result and package version.","workflowRole":"create-or-command","sideEffects":"When promoted, freezes source, manifest, build artifact, validation, visibility, and policy commitments for one version. Publication does not create or activate a deployment.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","PUBLIC visibility requires explicit disclosure, license, provenance, malware, secret-scan, export, and content review; PRIVATE and WORKSPACE remain owner-scoped.","Promotion requires validation freshness, exact commitment binding, step-up, idempotency, immutable version identity, conflict handling, and public index coordination.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-packages-package-uuid-validations","method":"POST","path":"/api/v2/execution/packages/{package_uuid}/validations","title":"EXECUTION: Validate package","description":"Validate package source, manifest, declared capabilities, and signed policy.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-packages-package-uuid-validations","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Validate package"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-packages-package-uuid-validations-request-001"},{"name":"package_uuid","location":"path","required":true,"type":"identifier","description":"Canonical package uuid.","example":"package-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Exact DRAFT package version to validate.","example":3},{"name":"validation_profile_id","location":"body","required":true,"type":"approved validation profile identifier","description":"Server-owned static-analysis, dependency, reproducibility, sandbox, signature, and policy suite.","example":"wasm-production-validation-v2"},{"name":"expected_source_sha256","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Last-read canonical source archive digest.","example":"9e6c…64hex"},{"name":"expected_manifest_commitment","location":"body","required":true,"type":"lowercase SHA-256 digest","description":"Last-read canonical manifest commitment.","example":"4a7d…64hex"},{"name":"evidence_references","location":"body","required":false,"type":"opaque identifier[] · max 32","description":"Optional owner-scoped provenance, review, license, or attestation references; raw evidence and secrets are forbidden.","example":["evidence_01K4…"]},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_PACKAGE_VALIDATION authorization for the exact version and profile.","example":"hcsu_…"}],"responses":[{"status":202,"description":"Validation accepted for the exact draft version and commitments; acceptance is not validation success or publication.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Validate package source, manifest, declared capabilities, and signed policy.","whenToUse":"Do not call this planning route yet. It reserves validation of one exact DRAFT version under a server-owned reproducibility and safety profile.","workflowRole":"create-or-command","sideEffects":"When promoted, queues static analysis, dependency checks, reproducible builds, capability-policy evaluation, sandbox tests, signature checks, and evidence; acceptance is not PASS and never publishes or runs code.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Validation must bind source digest, manifest commitment, runtime and compiler images, dependency lock, declared capabilities, resource policy, test vectors, findings, and output artifact digest.","A PASS is scoped to those exact inputs and expires or becomes stale when any dependency, policy, runtime, key, or draft commitment changes.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-execution-triggers","method":"GET","path":"/api/v2/execution/triggers","title":"EXECUTION: List triggers","description":"List schedule, event, and API triggers.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-execution-triggers","scope":"execution:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List triggers"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List schedule, event, and API triggers.","whenToUse":"Use this operation when an integration needs to list triggers before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:read authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-execution-triggers","method":"POST","path":"/api/v2/execution/triggers","title":"EXECUTION: Create trigger","description":"Create a policy-bound trigger for a deployment.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-execution-triggers","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create trigger"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-execution-triggers-request-001"},{"name":"deployment_uuid","location":"body","required":true,"type":"32-character identifier","description":"ACTIVE owner-scoped deployment selected after current-state reconciliation.","example":"8a7b6c5d4e3f2109876543210fedcba9"},{"name":"expected_deployment_version","location":"body","required":true,"type":"integer · ≥1","description":"Exact deployment policy version bound to the trigger.","example":2},{"name":"trigger","location":"body","required":true,"type":"discriminated SCHEDULE | EVENT | API object","description":"Typed trigger with bounded cadence or allowlisted event/topic and filters. Arbitrary webhooks and expressions are rejected.","example":{"filters":{"status":"ACCEPTED"},"topic":"invoice.evidence.received","type":"EVENT"}},{"name":"input_template","location":"body","required":true,"type":"allowlisted binding object","description":"Typed mappings into the package input schema without secrets or executable expressions.","example":{"evidence_commitment":"$.event.commitment","invoice_total":"$.event.total"}},{"name":"execution_policy","location":"body","required":true,"type":"bounded trigger policy object","description":"Concurrency, deduplication, timeout, retry, and failure posture no wider than deployment policy.","example":{"deduplication_window_seconds":3600,"max_attempts":2,"max_concurrency":1}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_TRIGGER_CREATION authorization bound to deployment, trigger, template, and policy.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A DRAFT trigger bound to one deployment version, typed configuration, input template, and execution policy returned; it admits no events yet.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a policy-bound trigger for a deployment.","whenToUse":"Do not call this planning route yet. It reserves a DRAFT schedule, event, or API trigger bound to one active deployment version and schema-checked input template.","workflowRole":"create-or-command","sideEffects":"When promoted, creates trigger configuration only. It admits no schedule, event, API call, execution, or business action until separately activated under current policy.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Promotion requires cadence and timezone limits, allowlisted topics and filters, authenticated API admission, schema-safe bindings, deduplication, concurrency and retry budgets, deployment-version binding, step-up, idempotency, and evidence.","Trigger configuration cannot contain secrets, arbitrary code, expressions, URLs, owner selectors, or authority assertions.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"patch-api-v2-execution-triggers-trigger-uuid","method":"PATCH","path":"/api/v2/execution/triggers/{trigger_uuid}","title":"EXECUTION: Update trigger","description":"Pause, resume, or revise an eligible trigger.","chapter":"Execution","chapterOrder":29,"capability":"Deterministic execution","owners":["execution-service"],"applications":["Execution Studio"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-execution-triggers-trigger-uuid","scope":"execution:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update trigger"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing execution:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-execution-triggers-trigger-uuid-request-001"},{"name":"trigger_uuid","location":"path","required":true,"type":"identifier","description":"Canonical trigger uuid.","example":"trigger-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current trigger version for optimistic concurrency.","example":3},{"name":"lifecycle_action","location":"body","required":true,"type":"UPDATE_CONFIGURATION | PAUSE | RESUME | ARCHIVE","description":"Explicit transition; ARCHIVE is terminal and history remains retained.","example":"PAUSE"},{"name":"trigger","location":"body","required":false,"type":"discriminated SCHEDULE | EVENT | API object","description":"Replacement typed trigger for UPDATE_CONFIGURATION.","example":{"cadence":"PT1H","timezone":"UTC","type":"SCHEDULE"}},{"name":"input_template","location":"body","required":false,"type":"allowlisted binding object","description":"Replacement schema-checked mappings without secrets or expressions.","example":{"evidence_commitment":"$.event.commitment"}},{"name":"execution_policy","location":"body","required":false,"type":"bounded trigger policy object","description":"Replacement concurrency, deduplication, timeout, retry, and failure posture.","example":{"deduplication_window_seconds":3600,"max_attempts":1,"max_concurrency":1}},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed configuration or lifecycle rationale.","example":"Pause while the input schema is revised."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh EXECUTION_TRIGGER_UPDATE authorization bound to the current version and transition.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Eligible trigger configuration or lifecycle transition retained with a new version; historical admissions and executions remain immutable.","example":null},{"status":400,"description":"A typed field, identifier, digest, expected version, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks execution:write, workspace ownership, package/deployment/trigger authority, required review, or a fresh purpose-bound authorization.","example":null},{"status":404,"description":"The package, artifact, validation, deployment, trigger, runtime profile, action authority, or referenced owner-scoped resource does not exist in the authenticated boundary.","example":null},{"status":409,"description":"The version, lifecycle, artifact digest, validation, publication, deployment, trigger, environment, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Source, manifest, schema, dependency, capability, reproducibility, visibility, sandbox, resource, egress, secret-binding, input, trigger, or downstream domain policy rejected the request.","example":null},{"status":503,"description":"Artifact storage, validator, builder, execution scheduler, isolated runtime, Identity, policy, evidence, node attestation, or owning domain is unavailable; no unverified state is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Pause, resume, or revise an eligible trigger.","whenToUse":"Do not call this planning route yet. It reserves version-bound configuration changes or explicit PAUSE, RESUME, or terminal ARCHIVE transitions.","workflowRole":"revise","sideEffects":"When promoted, creates a new trigger revision or lifecycle event. PAUSE blocks new admissions, RESUME revalidates deployment and policy, and ARCHIVE is terminal; none deletes executions or evidence.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["A bearer credential with execution:write authority and the required tenant, workspace, and role context.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Only UPDATE_CONFIGURATION admits replacement trigger, template, or policy. A deployment change requires a separately created trigger unless the future contract explicitly profiles rebinding.","Promotion requires state-machine tests, expected-version conflicts, pending-admission behavior, schedule reconciliation, deduplication continuity, step-up, idempotency, and immutable history.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams"]}},{"id":"post-api-v2-automation-deliveries-delivery-uuid-retries","method":"POST","path":"/api/v2/automation-deliveries/{delivery_uuid}/retries","title":"AUTOMATIONS: Retry callback delivery","description":"Request an idempotent retry of an eligible failed delivery.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automation-deliveries-delivery-uuid-retries","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Retry callback delivery"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automation-deliveries-delivery-uuid-retries-request-001"},{"name":"delivery_uuid","location":"path","required":true,"type":"identifier","description":"Canonical delivery uuid.","example":"delivery-uuid-01"},{"name":"expected_delivery_version","location":"body","required":true,"type":"integer · ≥1","description":"Current failed-delivery version used to prevent duplicate or stale requeue decisions.","example":2},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed retry rationale retained with the new attempt.","example":"Receiver recovered after a maintenance window."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh AUTOMATION_DELIVERY_RETRY authorization for the selected delivery and active endpoint.","example":"hcsu_…"}],"responses":[{"status":202,"description":"One eligible failed delivery requeued against the current active endpoint policy; the original attempt remains immutable.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request an idempotent retry of an eligible failed delivery.","whenToUse":"Do not call this planning route yet. It reserves a new attempt for one eligible failed delivery after the current endpoint, key epoch, retry budget, payload commitment, and retention window are revalidated.","workflowRole":"create-or-command","sideEffects":"When promoted, appends a new immutable attempt; it never rewrites the original result, re-runs the automation, or invokes the underlying domain action again.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","The retry must use the original minimized payload commitment and current delivery policy. A changed business payload requires a new domain event and delivery, not a retry.","Promotion requires expected-version locking, endpoint activity and ownership checks, maximum age and attempt budgets, backoff, deduplication, step-up, idempotency, SSRF revalidation, and signed receipts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-automation-endpoints","method":"GET","path":"/api/v2/automation-endpoints","title":"AUTOMATIONS: List callback endpoints","description":"List signed callback destinations, key fingerprints, and delivery posture.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-automation-endpoints","scope":"automations:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List callback endpoints"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List signed callback destinations, key fingerprints, and delivery posture.","whenToUse":"Inventory owner-scoped callback destinations, admitted event types, lifecycle, key fingerprint and epoch, and delivery posture before selecting an endpoint.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:read authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","URLs and fingerprints are private integration configuration. Never expose signing secrets, DNS resolution details, response bodies, or internal network diagnostics.","An ACTIVE endpoint is eligible for delivery only; it grants no domain action, trigger, or subscriber authority.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"post-api-v2-automation-endpoints","method":"POST","path":"/api/v2/automation-endpoints","title":"AUTOMATIONS: Create callback endpoint","description":"Register an HTTPS callback destination and return its signing secret exactly once.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automation-endpoints","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create callback endpoint"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automation-endpoints-request-001"},{"name":"name","location":"body","required":true,"type":"string","description":"Endpoint label.","example":"name-01"},{"name":"url","location":"body","required":true,"type":"HTTPS URL","description":"Callback destination.","example":"url-01"},{"name":"event_types","location":"body","required":true,"type":"identifier[]","description":"Subscribed event types.","example":[]},{"name":"timeout_ms","location":"body","required":false,"type":"integer","description":"Delivery timeout.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register an HTTPS callback destination and return its signing secret exactly once.","whenToUse":"Do not call this planning route until live OpenAPI advertises it. It reserves one HTTPS callback after ownership and SSRF-safe destination validation.","workflowRole":"create-or-command","sideEffects":"When promoted, returns one signing secret exactly once and stores only its protected verifier or encrypted form; endpoint creation does not create an automation or send a production event.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Promotion requires HTTPS, DNS rebinding and private-address defenses, redirect prohibition, hostname and certificate policy, event-type allowlists, bounded timeouts, quota, secret single-view handling, idempotency, and evidence.","Keep the secret out of URLs, prompts, logs, analytics, support tickets, browser storage, and agent memory. Losing it requires rotation, not retrieval.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"delete-api-v2-automation-endpoints-endpoint-uuid","method":"DELETE","path":"/api/v2/automation-endpoints/{endpoint_uuid}","title":"AUTOMATIONS: Delete callback endpoint","description":"Disable and remove a callback endpoint while retaining delivery evidence.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#delete-api-v2-automation-endpoints-endpoint-uuid","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Delete callback endpoint"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-automation-endpoints-endpoint-uuid-request-001"},{"name":"endpoint_uuid","location":"path","required":true,"type":"identifier","description":"Canonical endpoint uuid.","example":"endpoint-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current endpoint version used for optimistic concurrency.","example":3},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed removal rationale retained with endpoint and delivery history.","example":"Destination retired after integration migration."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh AUTOMATION_ENDPOINT_REMOVAL authorization bound to the endpoint and current version.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Endpoint disabled for future delivery and removal evidence returned; secrets and historical delivery evidence remain governed by retention policy.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Disable and remove a callback endpoint while retaining delivery evidence.","whenToUse":"Do not call this planning route yet. It reserves version-bound endpoint removal after dependent automations and queued deliveries are reconciled.","workflowRole":"revoke-or-delete","sideEffects":"When promoted, blocks future delivery and retains configuration, key-epoch, attempt, and removal evidence. It does not delete automations, runs, domain outcomes, or previously delivered envelopes.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Promotion requires dependency checks, queued-attempt disposition, version locking, step-up, reason retention, signing-key destruction policy, already-removed retry semantics, and no silent reassignment.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"post-api-v2-automation-endpoints-endpoint-uuid-secret-rotations","method":"POST","path":"/api/v2/automation-endpoints/{endpoint_uuid}/secret-rotations","title":"AUTOMATIONS: Rotate callback secret","description":"Rotate an endpoint signing secret with an explicit overlap window.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automation-endpoints-endpoint-uuid-secret-rotations","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Rotate callback secret"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automation-endpoints-endpoint-uuid-secret-rotations-request-001"},{"name":"endpoint_uuid","location":"path","required":true,"type":"identifier","description":"Canonical endpoint uuid.","example":"endpoint-uuid-01"},{"name":"overlap_seconds","location":"body","required":true,"type":"integer · 0–86400","description":"Old/new signing-secret overlap window.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Rotate an endpoint signing secret with an explicit overlap window.","whenToUse":"Do not call this planning route until present in live OpenAPI. It reserves a new signing epoch with a bounded old/new verification overlap.","workflowRole":"create-or-command","sideEffects":"When promoted, returns the new secret once, preserves the old key only for the admitted overlap, and never changes endpoint ownership, URL, event types, or automation authority.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Consumers must select verification keys by epoch and retire the prior secret after overlap. A retry remains signed under the policy recorded for its new attempt.","Promotion requires fresh step-up, version binding, overlap limits, single-view delivery, old-key destruction evidence, idempotency, and retained rotation history.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"post-api-v2-automation-endpoints-endpoint-uuid-tests","method":"POST","path":"/api/v2/automation-endpoints/{endpoint_uuid}/tests","title":"AUTOMATIONS: Test callback endpoint","description":"Send a signed non-production test event to an active callback endpoint.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automation-endpoints-endpoint-uuid-tests","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Test callback endpoint"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automation-endpoints-endpoint-uuid-tests-request-001"},{"name":"endpoint_uuid","location":"path","required":true,"type":"identifier","description":"Canonical endpoint uuid.","example":"endpoint-uuid-01"},{"name":"expected_endpoint_version","location":"body","required":true,"type":"integer · ≥1","description":"Current endpoint version and signing-key epoch used for the test.","example":3},{"name":"test_event_code","location":"body","required":true,"type":"allowlisted test event code","description":"Non-production payload profile selected from the endpoint's admitted event types.","example":"AUTOMATION_ENDPOINT_TEST"},{"name":"challenge_nonce","location":"body","required":true,"type":"single-use URL-safe string · 16–128","description":"Caller-generated nonce echoed inside the signed test envelope for correlation and replay detection.","example":"test-01K43J7F9T2YQ8M6"},{"name":"timeout_ms","location":"body","required":false,"type":"integer · 100–10000","description":"Per-attempt timeout bounded by platform and endpoint policy.","example":3000},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh AUTOMATION_ENDPOINT_TEST authorization for this endpoint and key epoch.","example":"hcsu_…"}],"responses":[{"status":202,"description":"A signed non-production test attempt queued with the selected endpoint version and key epoch; acceptance does not prove delivery.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Send a signed non-production test event to an active callback endpoint.","whenToUse":"Do not call this planning route yet. It reserves one signed, non-production challenge event against the current endpoint version and key epoch.","workflowRole":"create-or-command","sideEffects":"Queues only an allowlisted test envelope. It cannot trigger an automation, invoke a domain action, replay a production payload, or prove receiver processing.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Promotion requires single-use challenge nonces, explicit test markers, strict payload minimization, current DNS and SSRF checks, bounded timeout, rate limits, signature evidence, and no automatic activation based solely on HTTP success.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-automations","method":"GET","path":"/api/v2/automations","title":"AUTOMATIONS: List automations","description":"List signed automation rules visible to the caller.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-automations","scope":"automations:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List automations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List signed automation rules visible to the caller.","whenToUse":"Inventory owner-scoped automation definitions, lifecycle posture, action profiles, trigger classes, current versions, and recent run state before selecting one for inspection or administration.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:read authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","A listed ACTIVE automation is configured to admit triggers; it does not prove its next trigger will pass current domain policy or that any prior run succeeded.","Reuse pagination and filters without widening the bearer-derived workspace. Names, descriptions, and callback labels are private presentation metadata.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"post-api-v2-automations","method":"POST","path":"/api/v2/automations","title":"AUTOMATIONS: Create automation","description":"Create an automation with explicit trigger, action, callback, and policy boundaries.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automations","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create automation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automations-request-001"},{"name":"name","location":"body","required":true,"type":"string · 2–120","description":"Workspace-visible automation name; it is presentation metadata, not an authority key.","example":"Invoice evidence follow-up"},{"name":"description","location":"body","required":false,"type":"string · max 500","description":"Non-secret business purpose and operator context.","example":"Request document review after an invoice evidence event."},{"name":"trigger","location":"body","required":true,"type":"discriminated object","description":"Exactly one MANUAL, SCHEDULE, or EVENT trigger. Schedule triggers require a bounded cadence and timezone; event triggers require an allowlisted topic and typed filters.","example":{"filters":{"status":"ACCEPTED"},"topic":"invoice.evidence.received","type":"EVENT"}},{"name":"action_profile_id","location":"body","required":true,"type":"server-owned action profile identifier","description":"Approved action class resolved from the automation catalog. Arbitrary URLs, code, API paths, scopes, or shell commands are rejected.","example":"request-document-review"},{"name":"input_bindings","location":"body","required":false,"type":"allowlisted binding object","description":"Typed mappings from trigger fields or constants into the approved action profile; secrets and executable expressions are forbidden.","example":{"evidence_reference":"$.event.reference"}},{"name":"callback_endpoint_uuid","location":"body","required":false,"type":"32-character identifier | null","description":"Optional active workspace-owned callback endpoint for signed outcome delivery. Null means no callback.","example":"9128ab9dc2d64d85a0123613fce29afd"},{"name":"execution_policy","location":"body","required":true,"type":"bounded policy object","description":"Concurrency, timeout, retry, deduplication, and failure posture within platform limits; it cannot weaken the underlying domain policy.","example":{"deduplication_window_seconds":3600,"max_attempts":3,"max_concurrency":1,"timeout_seconds":30}},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh AUTOMATION_CONFIGURATION authorization bound to the workspace and configuration commitment.","example":"hcsu_…"}],"responses":[{"status":201,"description":"A DRAFT automation revision and immutable configuration commitment returned; no trigger is active and no domain action is authorized.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an automation with explicit trigger, action, callback, and policy boundaries.","whenToUse":"Do not call this planning route yet. It reserves creation of one DRAFT automation from a typed trigger, server-owned action profile, safe bindings, optional callback, and bounded execution policy.","workflowRole":"create-or-command","sideEffects":"When promoted, creates configuration and evidence only. The automation remains DRAFT, admits no trigger, stores no reusable domain credential, and authorizes no underlying action.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Promotion requires action-profile ownership, trigger schema and schedule bounds, SSRF-safe callback ownership, secret-free input bindings, concurrency and retry budgets, step-up, idempotency, immutable configuration commitments, and an explicit later activation transition.","Never submit arbitrary API paths, URLs, code, shell commands, bearer tokens, signing keys, passwords, private keys, regulated cleartext, or credentials in the trigger, action, or bindings.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-automations-automation-uuid","method":"GET","path":"/api/v2/automations/{automation_uuid}","title":"AUTOMATIONS: Get automation","description":"Return an automation and its retained configuration history.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-automations-automation-uuid","scope":"automations:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Get automation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:read authority.","example":"Bearer hc_live_…"},{"name":"automation_uuid","location":"path","required":true,"type":"identifier","description":"Canonical automation uuid.","example":"automation-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return an automation and its retained configuration history.","whenToUse":"Refresh one automation's current version, typed configuration, lifecycle, authority posture, and retained revision history before updating or running it.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:read authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Configuration history explains intent; it is not a reusable authorization. Resolve the current action profile and domain policy independently.","A callback endpoint reference identifies signed outcome delivery only and never becomes the target of the underlying business action.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"patch-api-v2-automations-automation-uuid","method":"PATCH","path":"/api/v2/automations/{automation_uuid}","title":"AUTOMATIONS: Update automation","description":"Update or change the lifecycle state of an automation.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-automations-automation-uuid","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update automation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-automations-automation-uuid-request-001"},{"name":"automation_uuid","location":"path","required":true,"type":"identifier","description":"Canonical automation uuid.","example":"automation-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current automation version used for optimistic concurrency.","example":4},{"name":"lifecycle_action","location":"body","required":true,"type":"UPDATE_CONFIGURATION | PAUSE | RESUME | ARCHIVE","description":"Explicit transition. ARCHIVE is terminal; PAUSE blocks future trigger admission but does not delete retained runs or deliveries.","example":"PAUSE"},{"name":"name","location":"body","required":false,"type":"string · 2–120","description":"Replacement presentation name for UPDATE_CONFIGURATION.","example":"Invoice evidence follow-up"},{"name":"description","location":"body","required":false,"type":"string · max 500","description":"Replacement non-secret purpose context.","example":"Pause during policy maintenance."},{"name":"trigger","location":"body","required":false,"type":"discriminated object","description":"Replacement MANUAL, SCHEDULE, or EVENT trigger for UPDATE_CONFIGURATION.","example":{"cadence":"PT1H","timezone":"UTC","type":"SCHEDULE"}},{"name":"action_profile_id","location":"body","required":false,"type":"server-owned action profile identifier","description":"Replacement approved action class; changing it requires full policy and authority revalidation.","example":"request-document-review"},{"name":"input_bindings","location":"body","required":false,"type":"allowlisted binding object","description":"Replacement typed bindings without secrets or executable expressions.","example":{"evidence_reference":"$.event.reference"}},{"name":"callback_endpoint_uuid","location":"body","required":false,"type":"32-character identifier | null","description":"Replacement active workspace-owned endpoint or null to remove callback delivery.","example":"callback-endpoint-uuid-01"},{"name":"execution_policy","location":"body","required":false,"type":"bounded policy object","description":"Replacement concurrency, timeout, retry, deduplication, and failure posture.","example":{"deduplication_window_seconds":3600,"max_attempts":2,"max_concurrency":1,"timeout_seconds":30}},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed lifecycle or configuration rationale retained with the revision.","example":"Pause while the downstream review policy is revised."},{"name":"step_up_token","location":"body","required":true,"type":"purpose-bound token","description":"Fresh AUTOMATION_CONFIGURATION authorization bound to the current version and requested transition.","example":"hcsu_…"}],"responses":[{"status":200,"description":"Eligible configuration or lifecycle transition retained with a new version; historical runs and deliveries remain immutable.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Update or change the lifecycle state of an automation.","whenToUse":"Do not call this planning route yet. It reserves an expected-version configuration update or explicit PAUSE, RESUME, or terminal ARCHIVE transition.","workflowRole":"revise","sideEffects":"When promoted, creates a new immutable revision or lifecycle event. PAUSE stops future trigger admission, RESUME re-enables admission after revalidation, and ARCHIVE is terminal; none deletes historical runs or evidence.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Only UPDATE_CONFIGURATION admits replacement fields. RESUME must revalidate the action profile, trigger, callback, and workspace policy; it cannot reactivate revoked domain authority.","Promotion requires version locking, state-machine tests, pending-run behavior, schedule reconciliation, callback ownership, step-up, idempotency, and retained before/after commitments.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-automations-automation-uuid-deliveries","method":"GET","path":"/api/v2/automations/{automation_uuid}/deliveries","title":"AUTOMATIONS: List callback deliveries","description":"List signed callback attempts and delivery outcomes.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-automations-automation-uuid-deliveries","scope":"automations:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List callback deliveries"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:read authority.","example":"Bearer hc_live_…"},{"name":"automation_uuid","location":"path","required":true,"type":"identifier","description":"Canonical automation uuid.","example":"automation-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List signed callback attempts and delivery outcomes.","whenToUse":"Inspect signed callback attempts for one automation after resolving a run, without using delivery state as proof of the underlying action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:read authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","DELIVERED means the receiver acknowledged the signed envelope under callback policy. It does not prove the receiver processed it or that the domain action succeeded.","Preserve attempt number, endpoint key epoch, payload commitment, signature metadata, HTTP class, and next retry posture for reconciliation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-automations-automation-uuid-runs","method":"GET","path":"/api/v2/automations/{automation_uuid}/runs","title":"AUTOMATIONS: List runs","description":"List automation run outcomes and signed callback receipts.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-automations-automation-uuid-runs","scope":"automations:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List runs"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:read authority.","example":"Bearer hc_live_…"},{"name":"automation_uuid","location":"path","required":true,"type":"identifier","description":"Canonical automation uuid.","example":"automation-uuid-01"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List automation run outcomes and signed callback receipts.","whenToUse":"List bounded run records and deterministic receipts to distinguish admission, validation, domain invocation, completion, failure, cancellation, and callback posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:read authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","QUEUED or STARTED is not domain success; COMPLETED must be evaluated with the owning domain receipt and current business state.","Run inputs, outputs, credentials, and regulated payload cleartext must remain minimized or commitment-only.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"post-api-v2-automations-automation-uuid-runs","method":"POST","path":"/api/v2/automations/{automation_uuid}/runs","title":"AUTOMATIONS: Run automation","description":"Request an idempotent manual automation run.","chapter":"Automations","chapterOrder":30,"capability":"Automations","owners":["automation-service"],"applications":["Automations"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-automations-automation-uuid-runs","scope":"automations:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Run automation"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing automations:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-automations-automation-uuid-runs-request-001"},{"name":"automation_uuid","location":"path","required":true,"type":"identifier","description":"Canonical automation uuid.","example":"automation-uuid-01"},{"name":"expected_automation_version","location":"body","required":true,"type":"integer · ≥1","description":"Current version whose trigger, action profile, bindings, and execution policy must be used.","example":4},{"name":"mode","location":"body","required":true,"type":"VALIDATE_ONLY | EXECUTE","description":"VALIDATE_ONLY evaluates bindings and policy without invoking the domain action. EXECUTE requires fresh action-specific authority.","example":"VALIDATE_ONLY"},{"name":"input_overrides","location":"body","required":false,"type":"allowlisted scalar object","description":"Manual-trigger values admitted by the action profile; they cannot replace owner, tenant, workspace, scope, endpoint, or authority context.","example":{"evidence_reference":"evt_01K4…"}},{"name":"execution_authorization_reference","location":"body","required":false,"type":"opaque purpose-bound reference","description":"Required for EXECUTE when the owning domain issues a fresh single-purpose authorization. It is not a bearer token and cannot be stored in the automation definition.","example":"authz_01K4…"},{"name":"client_reference","location":"body","required":true,"type":"string · 1–120","description":"Caller-stable business reference retained with the idempotent run request.","example":"manual-validation-2026-09-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Non-secret operator reason for the manual request.","example":"Validate the revised evidence mapping before resuming."}],"responses":[{"status":202,"description":"A VALIDATING or QUEUED manual run accepted with exact automation-version, input, authorization, and idempotency commitments; acceptance is not domain-action success.","example":null},{"status":400,"description":"A typed field, version, reason, step-up token, request signature, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks automations:write, workspace ownership, fresh configuration authority, or the underlying action-specific authority required for execution.","example":null},{"status":404,"description":"The automation, endpoint, delivery, action profile, or referenced owner-scoped resource does not exist in the authenticated workspace.","example":null},{"status":409,"description":"The expected version, lifecycle, endpoint key epoch, delivery eligibility, deduplication state, or Idempotency-Key conflicts.","example":null},{"status":422,"description":"Trigger, action profile, input binding, callback, retry, SSRF, secret-safety, concurrency, schedule, event, or domain policy rejected the request.","example":null},{"status":503,"description":"Automation orchestration, endpoint delivery, Identity, policy, evidence, or the owning domain is unavailable; no unverified transition is inferred.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Request an idempotent manual automation run.","whenToUse":"Do not call this planning route yet. It reserves a manual VALIDATE_ONLY or EXECUTE request bound to one exact automation version and caller-stable reference.","workflowRole":"create-or-command","sideEffects":"VALIDATE_ONLY evaluates configuration and policy without invoking a domain action. EXECUTE may queue one run only after the owning domain validates a fresh purpose-bound authorization reference; acceptance is not action success.","businessCases":["scheduled operational checks","event-triggered evidence and notification workflows","manual validate-only or authorized runs","signed webhook delivery","callback secret rotation","failed-delivery reconciliation"],"prerequisites":["A bearer credential with automations:write authority and the required tenant, workspace, and role context.","automations:read or automations:write in the bearer-derived workspace","a server-owned approved action profile and typed trigger schema","separate current authority from the owning domain for every consequential execution","an SSRF-safe active callback endpoint and receiver-side signature verification when callbacks are used","caller-owned policies for idempotency, concurrency, retry, deduplication, failure handling, evidence retention, and receiver processing"],"agentGuidance":["Automation never creates, stores, widens, or substitutes authority absent from the triggering principal and the current owning-domain policy. Configuration approval is not execution approval.","Never submit arbitrary API paths, internal URLs, code, shell commands, executable expressions, bearer tokens, passwords, private keys, signing secrets, regulated cleartext, or reusable domain credentials in triggers, actions, bindings, inputs, or callback metadata.","DRAFT is not active, ACTIVE only admits eligible triggers, QUEUED is not started, STARTED is not domain success, COMPLETED requires the owning-domain receipt, DELIVERED only means callback acknowledgement, and alert or callback success does not prove receiver processing.","Use VALIDATE_ONLY before EXECUTE. Bind every manual run to the current automation version, one client reference, stable idempotency key, typed inputs, and a fresh single-purpose authorization when the action owner requires it.","Verify callback signatures over the exact raw body, timestamp, delivery ID, attempt, and key epoch; enforce freshness and replay protection and retain only commitments and safe response diagnostics.","A delivery retry appends a new attempt for the original minimized payload; it never reruns the automation or underlying business action. A changed payload requires a new domain event.","Endpoint deletion blocks future delivery but does not delete automations, runs, domain results, or historical receipts. Secret rotation returns a new secret once and does not change endpoint or automation authority.","No automation contract may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Automation operation until its exact contract appears in the live production OpenAPI document.","Input overrides are allowlisted values, not a way to replace owner, workspace, scope, action, endpoint, or policy. Never persist the execution authorization in the automation definition.","On an ambiguous response, re-read runs by client reference and idempotency receipt. Do not submit a second logical run with the same reference.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Developers","Notifications","AI Wallet Control"]}},{"id":"get-api-v2-price-feed-plans","method":"GET","path":"/api/v2/price-feed-plans","title":"PRICING: List delivery plans","description":"List active price-delivery plans and the feed, connection, cadence, replay-window, and retention limits agents must evaluate before planning a subscription.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/subscription-plans","source":"APIRoutes.py · view_price_feed_subscription_plans"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feed-plans/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List delivery plans"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":50},{"name":"status","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"ACTIVE"},{"name":"q","location":"query","required":false,"type":"string · max 200","description":"Optional application search term.","example":"treasury"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List active price-delivery plans and the feed, connection, cadence, replay-window, and retention limits agents must evaluate before planning a subscription.","whenToUse":"Use before planning a delivery subscription so the integration can select an active plan from authoritative limits instead of hard-coding DEVELOPER or guessing entitlements.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Treat plan codes as server-owned identifiers and re-fetch them before presenting or validating a subscription request.","Compare max_feeds, max_connections, min_cadence_ms, replay_window_minutes, and retained_history_days against the workload's actual delivery and audit requirements.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feed-subscriptions","method":"GET","path":"/api/v2/price-feed-subscriptions","title":"PRICING: List subscriptions","description":"List the authenticated workspace's delivery entitlements, replay limits, lifecycle posture, billing posture, and current-month transport usage.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/subscriptions","source":"APIRoutes.py · view_price_feed_subscriptions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feed-subscriptions/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List subscriptions"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List the authenticated workspace's delivery entitlements, replay limits, lifecycle posture, billing posture, and current-month transport usage.","whenToUse":"Use this operation when an integration needs to list subscriptions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"post-api-v2-price-feed-subscriptions","method":"POST","path":"/api/v2/price-feed-subscriptions","title":"PRICING: Create subscription","description":"Create an ACTIVE owner-scoped delivery contract with exact feed entitlements, plan limits, metered-service posture, and retained retry semantics.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/pricing/subscriptions","source":"APIRoutes.py · create_v2_price_feed_subscription · gateway-authenticated and idempotent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feed-subscriptions/post","scope":"pricing:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-price-feed-subscriptions-request-001"},{"name":"name","location":"body","required":false,"type":"string · 1–120","description":"Delivery contract name; defaults to My price delivery.","example":"name-01"},{"name":"client_id","location":"body","required":false,"type":"string · max 64","description":"Optional caller-owned attribution identifier retained on the contract; it grants no scope or ownership.","example":"client-id-01"},{"name":"plan_code","location":"body","required":false,"type":"string · max 32","description":"Active delivery-plan code returned by GET /api/v2/price-feed-plans; defaults to DEVELOPER.","example":"plan-code-01"},{"name":"feed_uuids","location":"body","required":true,"type":"32-character identifier[] · unique, at least 1","description":"Active public or workspace-owned feeds. The plan constrains the maximum and raises each delivered cadence to at least its min_cadence_ms.","example":[]}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create an ACTIVE owner-scoped delivery contract with exact feed entitlements, plan limits, metered-service posture, and retained retry semantics.","whenToUse":"After listing plans and feeds, use this planning contract to bind a workspace to an explicit set of active public or workspace-owned feeds under one delivery plan.","workflowRole":"create-or-command","sideEffects":"When promoted, creates an ACTIVE metered delivery contract, entitled feed items, retained contract evidence, and a workspace-owned subscription. It does not grant trading, publisher, ingress, or settlement authority.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:write authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Resolve plan_code from GET /api/v2/price-feed-plans and every feed_uuids member from GET /api/v2/price-feeds immediately before submission.","The selected plan caps feed count and raises delivery cadence to at least the plan minimum; requested feeds outside the authenticated workspace visibility boundary fail closed.","client_id is attribution only and cannot select another owner or widen scope.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feed-subscriptions-subscription-uuid","method":"GET","path":"/api/v2/price-feed-subscriptions/{subscription_uuid}","title":"PRICING: Get subscription","description":"Return one workspace-owned delivery contract with lifecycle timestamps, plan limits, entitled feeds, current-month usage, and commercial contract posture.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/subscriptions/{subscription_uuid}","source":"APIRoutes.py · view_price_feed_subscription · workspace-owned detail projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feed-subscriptions~1{subscription_uuid}/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"},{"name":"subscription_uuid","location":"path","required":true,"type":"identifier","description":"Canonical subscription uuid.","example":"subscription-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one workspace-owned delivery contract with lifecycle timestamps, plan limits, entitled feeds, current-month usage, and commercial contract posture.","whenToUse":"Use after list discovery or after a lifecycle operation to reconcile the exact plan, entitled feeds, timestamps, metering, and commercial posture of one workspace-owned delivery contract.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Do not infer delivery availability from status alone; verify the requested feed is enabled and that plan cadence, replay, and retention limits satisfy the consuming workflow.","Billing and usage fields describe metering posture, not payment or settlement finality.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"patch-api-v2-price-feed-subscriptions-subscription-uuid","method":"PATCH","path":"/api/v2/price-feed-subscriptions/{subscription_uuid}","title":"PRICING: Update subscription","description":"Pause, resume, or terminally cancel one owner-scoped delivery contract and retain the resulting lifecycle evidence.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"PATCH","path":"/v2/pricing/subscriptions/{subscription_uuid}","source":"APIRoutes.py · update_v2_price_feed_subscription · gateway-authenticated and idempotent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feed-subscriptions~1{subscription_uuid}/patch","scope":"pricing:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Update subscription"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-price-feed-subscriptions-subscription-uuid-request-001"},{"name":"subscription_uuid","location":"path","required":true,"type":"identifier","description":"Canonical subscription uuid.","example":"subscription-uuid-01"},{"name":"action","location":"body","required":true,"type":"PAUSE | RESUME | CANCEL","description":"Lifecycle transition for the workspace-owned contract. Repeating the current target state is a no-op; CANCEL is terminal and cannot be resumed.","example":"action-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Pause, resume, or terminally cancel one owner-scoped delivery contract and retain the resulting lifecycle evidence.","whenToUse":"Use the planning contract to pause delivery temporarily, resume a paused contract, or cancel it permanently after reconciling the latest subscription detail.","workflowRole":"revise","sideEffects":"When promoted, updates both domain and metered-contract lifecycle state and records transition evidence. CANCEL also marks billing posture cancelled and is irreversible.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:write authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","PAUSE targets PAUSED, RESUME targets ACTIVE, and CANCEL targets CANCELLED. Repeating the current target is idempotent; any transition from CANCELLED is rejected.","Re-read the subscription after a successful transition and use its returned timestamps and state rather than predicting them client-side.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"post-api-v2-price-feed-tickets","method":"POST","path":"/api/v2/price-feed-tickets","title":"PRICING: Create access ticket","description":"Plan short-lived scoped ticket issuance. No public ticket issuer exists in the authoritative owner yet.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-price-feed-tickets","scope":"pricing:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create access ticket"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-price-feed-tickets-request-001"},{"name":"subscription_uuid","location":"body","required":true,"type":"32-character identifier","description":"ACTIVE workspace-owned delivery subscription freshly reconciled through GET /api/v2/price-feed-subscriptions/{subscription_uuid}.","example":"6d9dc70b29364bfb9415f05d96df2c75"},{"name":"feed_uuids","location":"body","required":true,"type":"32-character identifier[] · 1–100 unique","description":"Exact subset of currently enabled subscription feeds the future ticket may read. The issuer must reject foreign, disabled, or unsubscribed feeds.","example":["83185058266a46c4a31870d1c9f7b445"]},{"name":"transport","location":"body","required":true,"type":"WEBSOCKET | SSE","description":"Delivery transport the future ticket is audience-bound to. The ticket must not be reusable across transports.","example":"WEBSOCKET"},{"name":"audience","location":"body","required":true,"type":"allowlisted service audience · 1–255","description":"Exact owner-configured delivery-service audience. Arbitrary URLs, browser redirect targets, and caller-selected internal hosts must fail closed.","example":"wss://prices.hybrid-chain.com/v2/delivery"},{"name":"purpose","location":"body","required":true,"type":"string · 8–160","description":"Human- and agent-readable purpose limitation retained with issuance evidence; it grants no extra feed, workspace, or business authority.","example":"Treasury valuation evidence stream"},{"name":"requested_expires_in_seconds","location":"body","required":false,"type":"integer · 30–300","description":"Requested ticket lifetime. Owner policy may shorten it and must never extend it beyond the subscription or bearer lifetime.","example":120},{"name":"client_nonce","location":"body","required":true,"type":"single-use URL-safe string · 16–128","description":"Caller-generated nonce bound into the future signed ticket and atomically reserved to prevent replay.","example":"price-ticket-01K43J7F9T2YQ8M6"}],"responses":[{"status":201,"description":"When promoted, a single-view short-lived ticket, public issuance metadata, exact feed entitlements, audience, transport, and expiry are returned under no-store.","example":null},{"status":400,"description":"The future ticket request, delivery audience, transport, purpose, lifetime, nonce, or idempotency key is malformed.","example":null},{"status":401,"description":"The bearer credential is missing, expired, invalid, or not bound to the expected workspace and network.","example":null},{"status":403,"description":"The principal lacks pricing:write, the subscription is not ACTIVE and owner-scoped, or a requested feed is not enabled by the subscription.","example":null},{"status":404,"description":"The workspace-visible subscription or a requested feed cannot be resolved.","example":null},{"status":409,"description":"The nonce was already consumed or the Idempotency-Key was reused with a different canonical request.","example":null},{"status":422,"description":"The requested lifetime, feed subset, audience, transport, or purpose violates the future owner policy.","example":null},{"status":503,"description":"The authoritative ticket issuer, replay store, signing key, or delivery service is unavailable; issuance must fail closed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Plan short-lived scoped ticket issuance. No public ticket issuer exists in the authoritative owner yet.","whenToUse":"Do not call this route. Use the profile only to plan a future short-lived, single-view, subscription-bound connection credential after reconciling the active subscription and exact enabled feed subset.","workflowRole":"create-or-command","sideEffects":"No executable public behavior exists. Core can only record that an already-issued ticket was observed for an ACTIVE subscription; it cannot mint, sign, scope, expire, or return one.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:write authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","The profiled request is a design contract, not an available credential endpoint. Never synthesize a ticket, guess a signing key, or send this request until it appears in production OpenAPI.","A future issuer must derive workspace and network from the bearer, require an ACTIVE owner-scoped subscription, constrain feed_uuids to its enabled entitlements, and allow only configured audience and transport pairs.","Treat the returned ticket secret as single-view and short-lived: keep it out of URLs, prompts, logs, analytics, browser storage, crash reports, and persistent agent memory.","Bind ticket redemption to the signed client_nonce, audience, transport, subscription, exact feeds, subject, workspace, network, issuance time, and expiry; reserve nonce and ticket replay state atomically.","A delivery ticket can only read entitled price evidence. It cannot publish observations, enable ingress, trade, match, settle, move value, widen a subscription, change market status, or route unrelated traffic.","Promotion requires an authoritative issuer, protected signing key, one-time secret delivery, revocation and replay stores, delivery-side verification, retained public-safe evidence, and executable contract tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feeds","method":"GET","path":"/api/v2/price-feeds","title":"PRICING: List feeds","description":"List public feeds plus workspace-owned composites with canonical instruments, provider composition, cadence, aggregation policy, and failover posture.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/feeds","source":"APIRoutes.py · view_get_price_feeds"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feeds/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List feeds"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List public feeds plus workspace-owned composites with canonical instruments, provider composition, cadence, aggregation policy, and failover posture.","whenToUse":"Use this operation when an integration needs to list feeds before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feeds-feed-uuid","method":"GET","path":"/api/v2/price-feeds/{feed_uuid}","title":"PRICING: Get feed","description":"Return one workspace-visible feed and the exact source and policy context needed to interpret its normalized observations.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/feeds","source":"Gateway purpose-limited detail projection over APIRoutes.py · view_get_price_feeds"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feeds~1{feed_uuid}/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get feed"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"},{"name":"feed_uuid","location":"path","required":true,"type":"identifier","description":"Canonical feed uuid.","example":"feed-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one workspace-visible feed and the exact source and policy context needed to interpret its normalized observations.","whenToUse":"Use this operation when an integration needs to get feed before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feeds-feed-uuid-history","method":"GET","path":"/api/v2/price-feeds/{feed_uuid}/history","title":"PRICING: Replay signed feed evidence","description":"Replay subscription-entitled signed observations in feed-local sequence order with explicit cursor and retention-window diagnostics.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/replay","source":"APIRoutes.py · view_get_price_feed_replay"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feeds~1{feed_uuid}~1history/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Replay signed feed evidence"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"},{"name":"feed_uuid","location":"path","required":true,"type":"identifier","description":"Canonical feed uuid.","example":"feed-uuid-01"},{"name":"subscription_uuid","location":"query","required":true,"type":"identifier","description":"Active or paused delivery contract that grants replay access to this feed.","example":"subscription-uuid-01"},{"name":"after_sequence","location":"query","required":false,"type":"integer · ≥0","description":"Return signed observations strictly after this feed-local sequence; defaults to 0.","example":0},{"name":"limit","location":"query","required":false,"type":"integer · 1–500","description":"Maximum signed observations to return; defaults to 100.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Replay subscription-entitled signed observations in feed-local sequence order with explicit cursor and retention-window diagnostics.","whenToUse":"Use this operation when an integration needs to replay signed feed evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-price-feeds-feed-uuid-snapshot","method":"GET","path":"/api/v2/price-feeds/{feed_uuid}/snapshot","title":"PRICING: Get latest signed snapshot","description":"Return the latest signed observation together with health, age, cadence, quality, and hash-chain evidence.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/pricing/operations + /explorer/prices/{evidence_uuid}","source":"Gateway latest-evidence projection over Core feed operations and signed public evidence"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feeds~1{feed_uuid}~1snapshot/get","scope":"pricing:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get latest signed snapshot"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:read authority.","example":"Bearer hc_live_…"},{"name":"feed_uuid","location":"path","required":true,"type":"identifier","description":"Canonical feed uuid.","example":"feed-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return the latest signed observation together with health, age, cadence, quality, and hash-chain evidence.","whenToUse":"Use this operation when an integration needs to get latest signed snapshot before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:read authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"post-api-v2-price-feeds-composites","method":"POST","path":"/api/v2/price-feeds/composites","title":"PRICING: Create composite","description":"Register an owner-scoped, DataStream-backed composite from two through eight verified direct provider mappings without granting publication or trading authority.","chapter":"Price Feeds","chapterOrder":31,"capability":"Price feeds","owners":["market-data-service"],"applications":["Price Feeds"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["price-feed-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/pricing/composites","source":"APIRoutes.py · create_v2_price_feed_composite · gateway-authenticated and idempotent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1price-feeds~1composites/post","scope":"pricing:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create composite"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing pricing:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-price-feeds-composites-request-001"},{"name":"name","location":"body","required":true,"type":"string · 1–120","description":"Workspace-visible composite feed name.","example":"name-01"},{"name":"instrument_uuid","location":"body","required":true,"type":"32-character identifier","description":"Active canonical instrument already covered by every selected provider mapping.","example":"instrument-uuid-01"},{"name":"sources","location":"body","required":true,"type":"object[] · 2–8 distinct live provider mappings","description":"Ordered sources. Each object requires provider_uuid and provider_symbol; optional weight is a positive decimal bounded to 0.000001–100 and defaults to 1. Duplicate providers and unsupported instrument mappings are rejected.","example":[]},{"name":"method","location":"body","required":false,"type":"WEIGHTED_MEDIAN | MEDIAN | WEIGHTED_MEAN","description":"Aggregation method; defaults to WEIGHTED_MEDIAN.","example":"method-01"},{"name":"staleness_threshold_ms","location":"body","required":false,"type":"integer · 500–120000","description":"Maximum source age admitted by Core; defaults to 5000.","example":1},{"name":"min_sources","location":"body","required":false,"type":"integer · 1–source count","description":"Minimum healthy sources; defaults to 2 and cannot exceed the number of selected sources.","example":1},{"name":"max_deviation_bps","location":"body","required":false,"type":"decimal · 1–5000","description":"Outlier threshold; defaults to 100 basis points.","example":"10.00"},{"name":"failover_mode","location":"body","required":false,"type":"STRICT | ALLOW_SINGLE","description":"Degradation policy; defaults to ALLOW_SINGLE. Consumers still apply their own fitness policy.","example":"failover-mode-01"},{"name":"cadence_ms","location":"body","required":false,"type":"integer · 100–60000","description":"Target publication cadence; defaults to 1000 milliseconds.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register an owner-scoped, DataStream-backed composite from two through eight verified direct provider mappings without granting publication or trading authority.","whenToUse":"After discovering canonical instruments and live provider coverage, use this planning contract to define a private workspace-owned aggregate with explicit source, freshness, outlier, quorum, and failover policy.","workflowRole":"create-or-command","sideEffects":"When promoted, creates a private DataStream-backed aggregate feed, aggregation policy, ordered provider mappings, and metered custom-feed usage evidence. It does not enable publication or trading ingress.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review"],"prerequisites":["A bearer credential with pricing:write authority and the required tenant, workspace, and role context.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","All selected providers must currently publish the same active canonical instrument; provider order becomes source priority and provider UUIDs must be distinct.","ALLOW_SINGLE describes feed degradation behavior, not consumer acceptance. Consequential consumers should impose their own minimum source and maximum-age policy.","Preserve source weights as decimals and do not derive provider symbols from the canonical instrument symbol.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading"]}},{"id":"get-api-v2-transfer-compliance-counterparties","method":"GET","path":"/api/v2/transfer-compliance/counterparties","title":"COMPLIANCE: List counterparties","description":"List VASP counterparties and interoperability posture.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/transfer-compliance/counterparties","source":"APIRoutes.py · view_handle_transfer_compliance_counterparties · purpose-limited gateway projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1counterparties/get","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List counterparties"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List VASP counterparties and interoperability posture.","whenToUse":"Use this operation when an integration needs to list counterparties before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-counterparties","method":"POST","path":"/api/v2/transfer-compliance/counterparties","title":"COMPLIANCE: Register counterparty","description":"Register a VASP counterparty for review.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/counterparties","source":"APIRoutes.py · create_v2_transfer_compliance_counterparty · private owner-scoped registration"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1counterparties/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register counterparty"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-counterparties-request-001"},{"name":"code","location":"body","required":true,"type":"identifier · 2–64","description":"Globally unique counterparty code.","example":"code-01"},{"name":"display_name","location":"body","required":true,"type":"string · 1–160","description":"Operator-readable counterparty name.","example":"display-name-01"},{"name":"did","location":"body","required":true,"type":"DID · max 255","description":"Counterparty DID.","example":"did-01"},{"name":"jurisdiction","location":"body","required":false,"type":"jurisdiction code · max 32","description":"Operating jurisdiction; defaults to GLOBAL.","example":"jurisdiction-01"},{"name":"regulatory_status","location":"body","required":false,"type":"identifier · max 64","description":"Declared regulatory posture; defaults to UNVERIFIED.","example":"regulatory-status-01"},{"name":"risk_rating","location":"body","required":false,"type":"identifier · max 64","description":"Initial risk posture; defaults to UNRATED.","example":"risk-rating-01"},{"name":"supported_protocols","location":"body","required":false,"type":"identifier[]","description":"Supported interoperability protocols; defaults to HYBRID_TRANSFER_V1.","example":[]},{"name":"networks","location":"body","required":false,"type":"identifier[]","description":"Supported settlement networks; defaults to HYBRID.","example":[]},{"name":"signing_key","location":"body","required":true,"type":"public JWK object","description":"Counterparty public verification key required before approval.","example":{}},{"name":"encryption_key","location":"body","required":true,"type":"public JWK object","description":"Counterparty public envelope-encryption key required before approval.","example":{}},{"name":"compliance_endpoint","location":"body","required":false,"type":"HTTPS URL · max 500","description":"Private delivery endpoint retained by Core and never returned by the public V2 projection.","example":"compliance-endpoint-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register a VASP counterparty for review.","whenToUse":"Register a VASP or institutional counterparty before due-diligence review, using its DID, current public verification and encryption keys, supported protocols, networks, and private delivery endpoint.","workflowRole":"create-or-command","sideEffects":"Creates a private owner-scoped PENDING directory record and commitment. Registration is not approval, publication, disclosure authority, or transfer authority.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Submit public JWK members only. Private key members are rejected and must never enter prompts, logs, or API payloads.","Reconcile the current key and validity posture immediately before encrypting or screening a transfer.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-transfer-compliance-counterparties-counterparty-uuid","method":"GET","path":"/api/v2/transfer-compliance/counterparties/{counterparty_uuid}","title":"COMPLIANCE: Get counterparty","description":"Reconcile one owner-registered VASP counterparty's interoperability, public-key, risk, due-diligence, validity, and lifecycle posture without exposing its private delivery endpoint.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/transfer-compliance/counterparties/{counterparty_uuid}","source":"APIRoutes.py · view_handle_transfer_compliance_counterparty · owner-scoped purpose-limited gateway projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1counterparties~1{counterparty_uuid}/get","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get counterparty"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"},{"name":"counterparty_uuid","location":"path","required":true,"type":"identifier","description":"Canonical counterparty uuid.","example":"counterparty-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Reconcile one owner-registered VASP counterparty's interoperability, public-key, risk, due-diligence, validity, and lifecycle posture without exposing its private delivery endpoint.","whenToUse":"Use after counterparty collection discovery and immediately before a disclosure or transfer review to reconcile public keys, protocol and network compatibility, due-diligence status, validity, risk, and lifecycle state.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Treat ACTIVE plus APPROVED plus an unexpired valid_until as counterparty fitness evidence, not as transfer authorization or settlement approval.","Resolve key identifiers from the current record and never retain the private compliance endpoint, which the public projection intentionally excludes.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-counterparties-counterparty-uuid-decisions","method":"POST","path":"/api/v2/transfer-compliance/counterparties/{counterparty_uuid}/decisions","title":"COMPLIANCE: Review counterparty","description":"Approve, reject, request information for, or suspend a counterparty directory record.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/counterparties/{counterparty_uuid}/decide","source":"APIRoutes.py · decide_v2_transfer_compliance_counterparty · signed reviewer-only due diligence"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1counterparties~1{counterparty_uuid}~1decisions/post","scope":"compliance:review","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Review counterparty"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:review authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-counterparties-counterparty-uuid-decisions-request-001"},{"name":"counterparty_uuid","location":"path","required":true,"type":"identifier","description":"Canonical counterparty uuid.","example":"counterparty-uuid-01"},{"name":"action","location":"body","required":true,"type":"APPROVE | REJECT | REQUEST_INFORMATION | SUSPEND","description":"Authorized due-diligence decision.","example":"action-01"},{"name":"reason_code","location":"body","required":false,"type":"identifier · max 96","description":"Structured rationale; defaults to DUE_DILIGENCE_REVIEW.","example":"reason-code-01"},{"name":"evidence_commitment","location":"body","required":false,"type":"SHA-256 digest","description":"Commitment to retained review evidence.","example":"evidence-commitment-01"},{"name":"validity_days","location":"body","required":false,"type":"integer · 1–730","description":"Approval validity; defaults to 365 days and applies only to APPROVE.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Approve, reject, request information for, or suspend a counterparty directory record.","whenToUse":"Use from an independently authorized compliance-review workflow after the underlying due-diligence evidence has been retained and committed.","workflowRole":"create-or-command","sideEffects":"Signs a due-diligence decision and changes the directory record to ACTIVE/APPROVED, REJECTED, INFORMATION_REQUIRED/PENDING, or SUSPENDED. It grants no transfer or settlement authority.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:review authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Approval requires a DID and current public signing and encryption keys; validity is bounded to 1–730 days.","ACTIVE plus APPROVED plus unexpired validity is fitness evidence only; each transfer still requires its own policy and lifecycle decisions.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-transfer-compliance-credentials","method":"GET","path":"/api/v2/transfer-compliance/credentials","title":"COMPLIANCE: List credentials","description":"List transfer credentials and selective-disclosure manifests.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"GET","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"APIHandler.py · manage_subject_transfer_credentials · commitment-only gateway projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1credentials/get","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List credentials"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List transfer credentials and selective-disclosure manifests.","whenToUse":"Use this operation when an integration needs to list credentials before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","identity onboarding"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Data Vault","Business Network","Evidence Streams","Wallets","Identity & Login"]}},{"id":"post-api-v2-transfer-compliance-credentials","method":"POST","path":"/api/v2/transfer-compliance/credentials","title":"COMPLIANCE: Issue credential","description":"Issue a scoped transfer credential from an authorized trust boundary.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-transfer-compliance-credentials","scope":"compliance:issue","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Issue credential"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:issue authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-credentials-request-001"},{"name":"subject_profile_uuid","location":"body","required":true,"type":"32-character subject identifier","description":"Exact tenant-visible subject selected by an independently authorized issuer.","example":"f8317aef81764e1f923037c1b76df8de"},{"name":"credential_schema_id","location":"body","required":true,"type":"versioned allowlisted schema identifier · max 96","description":"Exact issuer-owned claim schema and semantic version.","example":"hybrid-transfer-person-v1"},{"name":"verification_uuid","location":"body","required":true,"type":"32-character identifier","description":"Completed subject verification that supplies the issuance evidence boundary.","example":"c61d80befec6449ab7260c5cd11d42f8"},{"name":"verification_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the exact completed verification version and minimized issuance evidence.","example":"cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"},{"name":"claim_commitments","location":"body","required":true,"type":"claim-key to SHA-256 digest map · 1–64 entries","description":"Commitments to the smallest schema-allowed claim set. Claim cleartext, identity documents, biometrics, and screening matches are forbidden.","example":{"country_of_residence":"eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee","legal_name":"dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"}},{"name":"jurisdiction","location":"body","required":true,"type":"jurisdiction code · max 16","description":"Issuer jurisdiction and policy context retained with the credential.","example":"CH"},{"name":"purpose","location":"body","required":true,"type":"identifier · 3–96","description":"Purpose limitation applied to later disclosure and relying-party evaluation.","example":"REGULATED_TRANSFER"},{"name":"valid_until","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Credential expiry bounded by policy and underlying evidence freshness.","example":"2027-09-01T00:00:00Z"},{"name":"revocation_registry_id","location":"body","required":true,"type":"issuer-controlled registry identifier · max 96","description":"Registry in which the issuer can publish lifecycle revocation without disclosing claims.","example":"transfer-credentials-2026"},{"name":"evidence_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to retained issuer review and approval evidence.","example":"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"},{"name":"step_up_token","location":"body","required":true,"type":"one-use purpose-bound token","description":"Fresh TRANSFER_CREDENTIAL_ISSUANCE authorization bound to the issuer, subject, schema, and evidence commitments.","example":"hcsu_…"}],"responses":[{"status":201,"description":"When promoted, minimized issuer-signed credential metadata, claim commitments, lifecycle status, validity, revocation registry, and evidence identifiers are returned under no-store.","example":null},{"status":400,"description":"A subject, schema, verification, commitment, jurisdiction, purpose, validity, revocation registry, signature, step-up token, or idempotency key is malformed.","example":null},{"status":401,"description":"The issuer bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks compliance:issue, tenant issuer authority, schema authority, or TRANSFER_CREDENTIAL_ISSUANCE step-up.","example":null},{"status":404,"description":"The tenant-visible subject, completed verification, schema, or revocation registry cannot be resolved.","example":null},{"status":409,"description":"The verification version is stale, an equivalent current credential exists, or the Idempotency-Key conflicts with another request.","example":null},{"status":422,"description":"The evidence is incomplete, a claim is outside the schema or purpose, consent is unavailable, or validity exceeds verification or policy freshness.","example":null},{"status":503,"description":"The authoritative issuer, verification owner, signing key, revocation registry, or evidence ledger is unavailable; issuance must fail closed.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Issue a scoped transfer credential from an authorized trust boundary.","whenToUse":"Do not call this planning route. Use the profile only to design future formal credential issuance by a separately authenticated tenant issuer after current verification, subject consent, schema, evidence, revocation, and signing authority are reconciled.","workflowRole":"create-or-command","sideEffects":"No executable public issuer exists. A future promotion would create one minimized issuer-signed credential and immutable issuance evidence without returning claim cleartext or authorizing a transfer.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","identity onboarding"],"prerequisites":["A bearer credential with compliance:issue authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Require exact subject, versioned allowlisted schema, completed verification and commitment, minimal schema-valid claim commitments, jurisdiction, purpose, bounded validity, revocation registry, issuer evidence commitment, and purpose-bound step-up.","Never submit claim cleartext, identity documents, biometric media, screening matches, wallet secrets, private signing keys, or raw verification evidence. Issuance signs commitments and minimized metadata only.","A 201 would mean credential issuance, not subject consent for a particular counterparty, selective disclosure, transfer approval, broadcast, settlement, or value movement. Later relying parties must verify issuer key, signature, schema, purpose, status, validity, revocation, evidence freshness, and their own policy.","Promotion requires a named authoritative issuer, compliance:issue distinct from subject and reviewer authority, tenant and schema isolation, protected signing keys, consent evidence, verification-version binding, revocation and suspension lifecycle, expiry, audit evidence, and conformance tests.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Data Vault","Business Network","Evidence Streams","Wallets","Identity & Login"]}},{"id":"post-api-v2-transfer-compliance-disclosure-envelopes","method":"POST","path":"/api/v2/transfer-compliance/disclosure-envelopes","title":"COMPLIANCE: Authorize disclosure envelope","description":"Encrypt and queue an authorized disclosure envelope for an approved counterparty key.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"TransferCredentialService.py · authorize_envelope · executable signed, owner-scoped, idempotent authorization command; encryption and delivery remain separate"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1disclosure-envelopes/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Authorize disclosure envelope"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-disclosure-envelopes-request-001"},{"name":"manifest_uuid","location":"body","required":true,"type":"32-character identifier","description":"Current consent-bound disclosure manifest owned by the subject.","example":"manifest-uuid-01"},{"name":"manifest_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment that must match the selected valid manifest.","example":"manifest-commitment-01"},{"name":"ciphertext_sha256","location":"body","required":true,"type":"SHA-256 digest","description":"Digest of client-side ciphertext. Identity never receives or stores the ciphertext.","example":"ciphertext-sha256-01"},{"name":"payload_schema","location":"body","required":false,"type":"identifier · max 64","description":"Canonical payload schema; defaults to IVMS101_2023.","example":"payload-schema-01"},{"name":"payload_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the canonical cleartext payload before encryption.","example":"payload-commitment-01"},{"name":"encryption_algorithm","location":"body","required":false,"type":"identifier · max 64","description":"Client-side envelope algorithm; defaults to X25519-XCHACHA20-POLY1305.","example":"encryption-algorithm-01"},{"name":"recipient_key_id","location":"body","required":true,"type":"string · max 96","description":"Approved recipient public encryption-key identifier.","example":"recipient-key-id-01"},{"name":"associated_data_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the associated-data binding. Authorization validity is capped at 24 hours and never exceeds the manifest expiry.","example":"associated-data-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Encrypt and queue an authorized disclosure envelope for an approved counterparty key.","whenToUse":"Use only after client-side encryption of a canonical payload for the currently approved counterparty key and after a matching consent-bound manifest exists.","workflowRole":"create-or-command","sideEffects":"When promoted, Identity authorizes a recipient-, manifest-, ciphertext-digest-, schema-, payload-, algorithm-, key-, associated-data-, and expiry-bound envelope commitment. Identity never receives ciphertext; Core delivery remains a separate unpublished operation.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Hash the exact ciphertext bytes and canonical cleartext payload independently; do not confuse ciphertext_sha256 with payload_commitment.","Reconcile the counterparty key immediately before encryption because due diligence and keys can expire, rotate, or be suspended.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-disclosure-manifests","method":"POST","path":"/api/v2/transfer-compliance/disclosure-manifests","title":"COMPLIANCE: Create disclosure manifest","description":"Create a purpose-, counterparty-, claim-, and expiry-bound selective-disclosure manifest.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"TransferCredentialService.py · create_manifest · executable signed, owner-scoped, idempotent commitment command"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1disclosure-manifests/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create disclosure manifest"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-disclosure-manifests-request-001"},{"name":"credential_uuid","location":"body","required":true,"type":"32-character identifier","description":"Valid formal credential owned by the authenticated subject.","example":"credential-uuid-01"},{"name":"counterparty_did","location":"body","required":true,"type":"DID · max 255","description":"Recipient DID bound into the disclosure context.","example":"counterparty-did-01"},{"name":"purpose","location":"body","required":false,"type":"identifier · max 96","description":"Disclosure purpose; defaults to REGULATED_TRANSFER.","example":"purpose-01"},{"name":"claim_keys","location":"body","required":true,"type":"string[] · unique, each max 96","description":"One or more minimal claims that exist on the selected credential; only their commitments are retained.","example":[]},{"name":"validity_hours","location":"body","required":false,"type":"integer · 1–720","description":"Manifest lifetime; defaults to 24 hours.","example":1},{"name":"consent","location":"body","required":true,"type":"true","description":"Explicit subject consent. Any value other than true is rejected.","example":true}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a purpose-, counterparty-, claim-, and expiry-bound selective-disclosure manifest.","whenToUse":"Use after selecting the smallest claim set from a current formal credential and an approved counterparty DID, with explicit subject consent for one stated purpose.","workflowRole":"create-or-command","sideEffects":"When promoted, creates a short-lived identity-owned manifest containing claim commitments, consent commitment, recipient DID, purpose, and expiry. It exposes no credential cleartext.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Select only claim keys required by policy; IVMS101 readiness identifies missing claim groups but does not authorize disclosure.","Recreate rather than reuse a manifest when recipient, purpose, claims, credential, or expiry context changes.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-transfer-compliance-reviews","method":"GET","path":"/api/v2/transfer-compliance/reviews","title":"COMPLIANCE: List reviews","description":"List transfers and counterparties awaiting authorized review.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-transfer-compliance-reviews","scope":"compliance:review","idempotency":false,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["List reviews"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:review authority.","example":"Bearer hc_live_…"},{"name":"resource_type","location":"query","required":false,"type":"TRANSFER | COUNTERPARTY","description":"Restrict the future authorized review queue to one resource class.","example":"resource-type-01"},{"name":"status","location":"query","required":false,"type":"PENDING | INFORMATION_REQUIRED | REVIEW","description":"Restrict results to an exact review posture.","example":"ACTIVE"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List transfers and counterparties awaiting authorized review.","whenToUse":"Do not call this route yet. It reserves a minimized, authority-filtered review queue, but Core currently exposes only an internal administrative overview rather than a safe public reviewer projection.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:review authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Do not substitute transfer or counterparty collection reads for reviewer authority; those reads report state but do not grant review capability.","Promotion requires explicit compliance:review authorization, tenant and assignment filtering, pagination, resource-safe summaries, and no KYC or screening cleartext.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-transfer-compliance-transfers","method":"GET","path":"/api/v2/transfer-compliance/transfers","title":"COMPLIANCE: List transfers","description":"List transfers with their travel-rule and credential posture.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/transfer-compliance/intents","source":"APIRoutes.py · view_handle_transfer_compliance_intents"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers/get","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List transfers"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List transfers with their travel-rule and credential posture.","whenToUse":"Use this operation when an integration needs to list transfers before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-transfers","method":"POST","path":"/api/v2/transfer-compliance/transfers","title":"COMPLIANCE: Create transfer intent","description":"Record an inbound or outbound regulated transfer intent without broadcasting value.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/intents","source":"APIRoutes.py · create_v2_transfer_compliance_intent · gateway-authenticated and idempotent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Create transfer intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-transfers-request-001"},{"name":"direction","location":"body","required":false,"type":"OUTBOUND | INBOUND","description":"Transfer direction; defaults to OUTBOUND.","example":"direction-01"},{"name":"asset","location":"body","required":true,"type":"asset code · 2–24","description":"Canonical transfer asset code.","example":"asset-01"},{"name":"network","location":"body","required":false,"type":"network code · 2–32","description":"Settlement network; defaults to HYBRID.","example":"network-01"},{"name":"amount","location":"body","required":true,"type":"positive decimal string","description":"Transfer amount represented without binary floating-point conversion.","example":"10.00"},{"name":"destination_reference","location":"body","required":false,"type":"string · max 256","description":"Public destination or account reference. Never place KYC cleartext here.","example":"destination-reference-01"},{"name":"counterparty_uuid","location":"body","required":false,"type":"32-character identifier","description":"Owner-registered counterparty selected from the counterparty collection.","example":"counterparty-uuid-01"},{"name":"origin_jurisdiction","location":"body","required":false,"type":"jurisdiction code · max 64","description":"Origin jurisdiction; defaults to GLOBAL.","example":"origin-jurisdiction-01"},{"name":"destination_jurisdiction","location":"body","required":false,"type":"jurisdiction code · max 64","description":"Destination jurisdiction; defaults to GLOBAL.","example":"destination-jurisdiction-01"},{"name":"expires_in_minutes","location":"body","required":false,"type":"integer · 5–1440","description":"Intent lifetime; defaults to 60 minutes.","example":1},{"name":"policy","location":"body","required":false,"type":"object","description":"Optional version, required_claims, and screening policy snapshot. Core defaults version to 2026-07-v1 and sanctions/counterparty screening to true.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record an inbound or outbound regulated transfer intent without broadcasting value.","whenToUse":"After credential readiness and counterparty discovery, create a DRAFT compliance intent before any regulated transfer is prepared or screened.","workflowRole":"create-or-command","sideEffects":"Records an owner-scoped DRAFT, immutable policy snapshot and commitment, participant row, expiry, idempotency state, and first signed hash-chain event. It does not move value, authorize settlement, or broadcast a transaction.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Use decimal strings for amount, choose counterparty_uuid from the owner-scoped directory, and keep identity cleartext out of destination_reference and policy fields.","The intent lifecycle is DRAFT → DATA_REQUIRED → SCREENING → REVIEW → APPROVED → AUTHORIZED → BROADCAST → CONFIRMED, with explicit rejection, cancellation, failure, and expiry branches.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-transfer-compliance-transfers-transfer-uuid","method":"GET","path":"/api/v2/transfer-compliance/transfers/{transfer_uuid}","title":"COMPLIANCE: Get transfer","description":"Return one transfer's compliance decision and retained evidence.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/transfer-compliance/intents/{transfer_uuid}","source":"APIRoutes.py · view_handle_transfer_compliance_intent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers~1{transfer_uuid}/get","scope":"compliance:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get transfer"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:read authority.","example":"Bearer hc_live_…"},{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return one transfer's compliance decision and retained evidence.","whenToUse":"Use this operation when an integration needs to get transfer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:read authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-transfers-transfer-uuid-cancellations","method":"POST","path":"/api/v2/transfer-compliance/transfers/{transfer_uuid}/cancellations","title":"COMPLIANCE: Cancel transfer intent","description":"Cancel an eligible transfer intent before authorization and broadcast.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/intents/{transfer_uuid}/cancel","source":"APIRoutes.py · cancel_v2_transfer_compliance_intent · subject-owned pre-authorization cancellation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers~1{transfer_uuid}~1cancellations/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Cancel transfer intent"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-transfers-transfer-uuid-cancellations-request-001"},{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"},{"name":"reason_code","location":"body","required":false,"type":"identifier · max 96","description":"Structured subject cancellation reason.","example":"reason-code-01"},{"name":"evidence","location":"body","required":false,"type":"object","description":"Optional public-safe codes and commitments. Cancellation is permitted only from DRAFT, DATA_REQUIRED, or APPROVED.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Cancel an eligible transfer intent before authorization and broadcast.","whenToUse":"Use only while a subject-owned intent is DRAFT, DATA_REQUIRED, or APPROVED and before system authorization or broadcast.","workflowRole":"create-or-command","sideEffects":"Moves the eligible intent to terminal CANCELLED and appends signed evidence. It cannot unwind any external transaction or settlement activity.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Treat cancellation as terminal and create a new intent if the business request resumes.","A 409 means the current state is not cancellable; re-read the intent instead of retrying with a different body.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-transfers-transfer-uuid-decisions","method":"POST","path":"/api/v2/transfer-compliance/transfers/{transfer_uuid}/decisions","title":"COMPLIANCE: Record transfer decision","description":"Record an authorized compliance decision for a held transfer.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/intents/{transfer_uuid}/policy","source":"APIRoutes.py · decide_v2_transfer_compliance_policy · signed reviewer-only public-safe evaluation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers~1{transfer_uuid}~1decisions/post","scope":"compliance:review","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Record transfer decision"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:review authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-transfers-transfer-uuid-decisions-request-001"},{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"},{"name":"sanctions_status","location":"body","required":false,"type":"CLEAR | MATCH | REJECTED | BLOCKED | UNKNOWN","description":"Public-safe screening outcome; defaults to UNKNOWN.","example":"sanctions-status-01"},{"name":"wallet_risk_status","location":"body","required":false,"type":"CLEAR | LOW | ACCEPTABLE | REJECTED | BLOCKED | PROHIBITED | UNKNOWN","description":"Public-safe wallet-risk outcome; defaults to UNKNOWN.","example":"wallet-risk-status-01"},{"name":"screening_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the underlying screening evidence; raw match data is never accepted.","example":"screening-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Record an authorized compliance decision for a held transfer.","whenToUse":"Use only from SCREENING within a separately authorized reviewer or evaluator workflow after screening systems have retained the underlying evidence elsewhere.","workflowRole":"create-or-command","sideEffects":"Derives CLEAR, REVIEW, or REJECT from public-safe outcomes and counterparty fitness; signs and retains the decision and event commitments; and may advance to REVIEW or REJECTED. It never stores raw screening matches.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:review authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","screening_commitment is mandatory provenance for the underlying screening work; status labels alone are insufficient.","A CLEAR policy result is still not final approval, transfer authorization, broadcast authority, or evidence that value moved.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-transfers-transfer-uuid-disclosures","method":"POST","path":"/api/v2/transfer-compliance/transfers/{transfer_uuid}/disclosures","title":"COMPLIANCE: Submit disclosure","description":"Submit a consent-bound minimized disclosure package for screening.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/intents/{transfer_uuid}/disclose","source":"APIRoutes.py · disclose_v2_transfer_compliance_intent · commitment-only DATA_REQUIRED to SCREENING"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers~1{transfer_uuid}~1disclosures/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Submit disclosure"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-transfers-transfer-uuid-disclosures-request-001"},{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"},{"name":"credential_reference","location":"body","required":true,"type":"identifier · max 96","description":"Valid formal credential owned by the authenticated subject.","example":"credential-reference-01"},{"name":"disclosure_manifest_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Current consent-, purpose-, counterparty-, claim-, and expiry-bound manifest commitment.","example":"disclosure-manifest-commitment-01"},{"name":"wallet_proof_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Current primary-vault wallet-control proof commitment.","example":"wallet-proof-commitment-01"},{"name":"evidence","location":"body","required":false,"type":"object","description":"Optional public-safe codes and commitments; cleartext evidence is reduced to a private commitment before event retention.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Submit a consent-bound minimized disclosure package for screening.","whenToUse":"Use only when a subject-owned intent is DATA_REQUIRED and the credential portfolio shows a current formal credential, primary-vault wallet proof, and consent-bound disclosure manifest.","workflowRole":"create-or-command","sideEffects":"Validates all three subject-owned commitments, marks the originator participant READY, advances the intent to SCREENING, and appends signed evidence. It sends no ciphertext and moves no value.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Create and verify the disclosure manifest and wallet proof before submitting their commitments; stale, revoked, foreign, or mismatched records fail closed.","Do not send claim cleartext, KYC documents, private keys, seed material, or screening-match details.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-transfers-transfer-uuid-preparations","method":"POST","path":"/api/v2/transfer-compliance/transfers/{transfer_uuid}/preparations","title":"COMPLIANCE: Prepare required data","description":"Calculate the minimum credential and counterparty evidence required for a transfer.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"POST","path":"/v2/transfer-compliance/intents/{transfer_uuid}/prepare","source":"APIRoutes.py · prepare_v2_transfer_compliance_intent · subject-owned DRAFT to DATA_REQUIRED"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1transfers~1{transfer_uuid}~1preparations/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Prepare required data"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-transfers-transfer-uuid-preparations-request-001"},{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"},{"name":"evidence","location":"body","required":false,"type":"object","description":"Optional public-safe reason, decision, transaction, block, confirmation, or SHA-256 commitment fields. Other values are reduced to one private evidence commitment.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Calculate the minimum credential and counterparty evidence required for a transfer.","whenToUse":"Use once on a subject-owned DRAFT to begin the minimized evidence workflow and make required credential, wallet-control, disclosure, and counterparty posture explicit.","workflowRole":"create-or-command","sideEffects":"Advances DRAFT to DATA_REQUIRED and appends a signed, commitment-safe event. It grants no approval, transfer, settlement, broadcast, or trading authority.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Resolve credential and counterparty readiness after preparation; do not interpret DATA_REQUIRED as a failed or approved transfer.","Keep KYC cleartext and documents outside the evidence object; unknown evidence fields are reduced to one commitment by Core.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"post-api-v2-transfer-compliance-vasp-credentials","method":"POST","path":"/api/v2/transfer-compliance/vasp-credentials","title":"COMPLIANCE: Request VASP credential","description":"Create a pending institutional credential commitment for issuer review.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Transfer Compliance","Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"TransferCredentialService.py · register_vasp · executable signed, owner-scoped, idempotent candidate-registration command; not issuer approval"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1vasp-credentials/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Request VASP credential"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-vasp-credentials-request-001"},{"name":"did","location":"body","required":true,"type":"DID · max 255","description":"Institutional DID submitted for issuer review.","example":"did-01"},{"name":"jurisdiction","location":"body","required":false,"type":"jurisdiction code · max 16","description":"Operating jurisdiction; defaults to GLOBAL.","example":"jurisdiction-01"},{"name":"legal_entity_identifier","location":"body","required":false,"type":"string · max 96","description":"Optional LEI or comparable institutional identifier.","example":"legal-entity-identifier-01"},{"name":"regulatory_status","location":"body","required":false,"type":"identifier · max 32","description":"Claimed regulatory posture; defaults to UNVERIFIED and does not become trusted merely by submission.","example":"regulatory-status-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a pending institutional credential commitment for issuer review.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to request vasp credential.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","identity onboarding"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Payments","Data Vault","Business Network","Evidence Streams","Wallets","Identity & Login"]}},{"id":"post-api-v2-transfer-compliance-wallet-control-proofs","method":"POST","path":"/api/v2/transfer-compliance/wallet-control-proofs","title":"COMPLIANCE: Register wallet proof","description":"Register externally completed signed-challenge commitments without accepting private keys.","chapter":"Transfer Compliance","chapterOrder":32,"capability":"Transfer compliance","owners":["transfer-compliance-service"],"applications":["Wallets","Transfer Compliance"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["transfer-compliance-service"],"legacySources":[],"runtimeSources":[{"catalog":"identity","method":"POST","path":"/identity/transfer-credentials/subject/profile/{profile_uuid}","source":"TransferCredentialService.py · register_wallet_proof · executable signed, owner-scoped, idempotent proof-registration command"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1transfer-compliance~1wallet-control-proofs/post","scope":"compliance:write","idempotency":true,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Register wallet proof"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing compliance:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-transfer-compliance-wallet-control-proofs-request-001"},{"name":"vault_uuid","location":"body","required":false,"type":"32-character identifier","description":"Subject primary vault; omission selects the primary vault and any other vault is rejected.","example":"vault-uuid-01"},{"name":"network","location":"body","required":false,"type":"network code · max 32","description":"Wallet network; defaults to HYBRID.","example":"network-01"},{"name":"wallet_reference","location":"body","required":true,"type":"public wallet reference · max 255","description":"Public address or account reference. Never provide a private key or seed.","example":"wallet-reference-01"},{"name":"verification_method","location":"body","required":false,"type":"identifier · max 64","description":"Externally completed proof method; defaults to SIGNED_CHALLENGE.","example":"verification-method-01"},{"name":"challenge_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the issued possession challenge.","example":"challenge-commitment-01"},{"name":"proof_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the externally verified source proof.","example":"proof-commitment-01"},{"name":"validity_days","location":"body","required":false,"type":"integer · 1–365","description":"Proof lifetime; defaults to 90 days. A new valid proof supersedes the prior proof for the same vault and network.","example":1}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register externally completed signed-challenge commitments without accepting private keys.","whenToUse":"Use this operation only after the caller has resolved the current authoritative state and is ready to register wallet proof.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","Travel Rule and IVMS101 orchestration","counterparty screening and key selection"],"prerequisites":["A bearer credential with compliance:write authority and the required tenant, workspace, and role context.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Trust Center","Data Vault"]}},{"id":"get-api-v2-evidence-alerts","method":"GET","path":"/api/v2/evidence-alerts","title":"EVIDENCE: List alerts","description":"List evidence-stream alerts and acknowledgement state.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-alerts","source":"APIRoutes.py · view_get_v2_evidence_alerts · minimized alert projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-alerts/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List alerts"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum newest alerts to return.","example":100},{"name":"status","location":"query","required":false,"type":"OPEN | ACKNOWLEDGED | RESOLVED","description":"Exact alert lifecycle-state filter.","example":"OPEN"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List evidence-stream alerts and acknowledgement state.","whenToUse":"Review newest owner-scoped evidence alerts and their acknowledgement lifecycle before inspecting the referenced stream, source, event, or rule.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Messages are operator context; arbitrary evaluated values and actor identifiers are excluded.","Acknowledged or resolved state records workflow handling and does not retroactively validate the triggering event.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-alerts-alert-uuid-acknowledgements","method":"POST","path":"/api/v2/evidence-alerts/{alert_uuid}/acknowledgements","title":"EVIDENCE: Acknowledge alert","description":"Acknowledge an evidence alert with actor and audit evidence.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-alerts-alert-uuid-acknowledgements","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Acknowledge alert"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-alerts-alert-uuid-acknowledgements-request-001"},{"name":"alert_uuid","location":"path","required":true,"type":"identifier","description":"Canonical alert uuid.","example":"alert-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current alert version for optimistic concurrency.","example":1},{"name":"decision","location":"body","required":true,"type":"ACKNOWLEDGE | RESOLVE","description":"Alert lifecycle decision.","example":"decision-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed response rationale.","example":"reason-01"},{"name":"evidence_commitment","location":"body","required":false,"type":"SHA-256 digest","description":"Optional commitment to remediation or review evidence.","example":"evidence-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Acknowledge an evidence alert with actor and audit evidence.","whenToUse":"Do not call this planning route yet. It reserves an attributed, version-checked acknowledgement or resolution without changing the underlying evidence.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires alert:manage scope, state-transition rules, actor attribution, expected-version conflicts, remediation evidence, idempotent retries, and immutable audit history.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-devices","method":"POST","path":"/api/v2/evidence-devices","title":"EVIDENCE: Register device","description":"Register a signing device for evidence ingestion.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-devices","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Register device"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-devices-request-001"},{"name":"stream_uuid","location":"body","required":true,"type":"32-character identifier","description":"Active owner-scoped stream.","example":"stream-uuid-01"},{"name":"external_reference","location":"body","required":true,"type":"string · 1–120","description":"Workspace-stable source reference.","example":"external-reference-01"},{"name":"name","location":"body","required":true,"type":"string · 1–120","description":"Operator-readable source name.","example":"name-01"},{"name":"source_type","location":"body","required":true,"type":"identifier · max 80","description":"Source class such as SENSOR, SERVICE, or ORACLE.","example":"source-type-01"},{"name":"public_key_jwk","location":"body","required":true,"type":"public JWK","description":"Source verification key; private keys and symmetric secrets are forbidden.","example":"public-key-jwk-01"},{"name":"attestation","location":"body","required":false,"type":"object","description":"Optional manufacturer, workload, or enrollment evidence commitments.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Register a signing device for evidence ingestion.","whenToUse":"Do not call this planning route yet. It reserves public-key enrollment of a source into one owned stream without accepting private keys or general-purpose credentials.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires source:enroll scope, public-key validation, proof of possession, external-reference uniqueness, optional attestation policy, lifecycle and rotation contracts, and one-time credential delivery separation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-health","method":"GET","path":"/api/v2/evidence-health","title":"EVIDENCE: Get health","description":"Summarize owner-scoped stream, source, alert, and quarantine posture for operational monitoring.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-health","source":"APIRoutes.py · view_get_v2_evidence_health · aggregate owner-scoped operational posture"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-health/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get health"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Summarize owner-scoped stream, source, alert, and quarantine posture for operational monitoring.","whenToUse":"Use for owner-scoped monitoring and alerting when an integration needs a compact pipeline posture before loading detailed streams, sources, alerts, or quarantine records.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","DEGRADED means an open alert, open quarantine record, or stale active source exists; it is not a settlement, compliance, trading, disclosure, or safety decision.","Resolve the detailed collections before diagnosing cause. Aggregate counts may change immediately after this no-store response.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-quarantine","method":"GET","path":"/api/v2/evidence-quarantine","title":"EVIDENCE: List quarantine","description":"List evidence held for validation or sequence review.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-quarantine","source":"APIRoutes.py · view_get_v2_evidence_quarantine · commitment-only quarantine projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-quarantine/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List quarantine"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum newest quarantine records to return.","example":100},{"name":"status","location":"query","required":false,"type":"OPEN | DISMISSED","description":"Exact quarantine lifecycle-state filter.","example":"OPEN"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List evidence held for validation or sequence review.","whenToUse":"Review rejected or held evidence by reason and payload commitment without retrieving rejected cleartext or replay material.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","A quarantine record grants no right to release, replay, alter, or reinterpret the payload.","Use a fresh signed nonce for any future retransmission; never resubmit retained nonce or credential material.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-quarantine-record-uuid-decisions","method":"POST","path":"/api/v2/evidence-quarantine/{record_uuid}/decisions","title":"EVIDENCE: Decide quarantine record","description":"Release, reject, or retain a quarantined evidence record with signed rationale.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-quarantine-record-uuid-decisions","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Decide quarantine record"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-quarantine-record-uuid-decisions-request-001"},{"name":"record_uuid","location":"path","required":true,"type":"identifier","description":"Canonical record uuid.","example":"record-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current quarantine-record version.","example":1},{"name":"decision","location":"body","required":true,"type":"REJECT | RETAIN | REQUEST_RETRANSMISSION","description":"Governed disposition; retransmission always requires a fresh signed nonce.","example":"decision-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed decision rationale.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Release, reject, or retain a quarantined evidence record with signed rationale.","whenToUse":"Do not call this planning route yet. It reserves governed disposition of one owner-scoped quarantine record.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires quarantine:manage scope, version concurrency, reason retention, immutable payload commitment, explicit no-release policy, fresh-nonce retransmission, and audit receipts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-rules","method":"POST","path":"/api/v2/evidence-rules","title":"EVIDENCE: Create rule","description":"Create a governed evidence-stream alert or validation rule.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-rules","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create rule"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-rules-request-001"},{"name":"stream_uuid","location":"body","required":true,"type":"32-character identifier","description":"Owned stream governed by the rule.","example":"stream-uuid-01"},{"name":"name","location":"body","required":true,"type":"string · 1–120","description":"Operator-readable rule name.","example":"name-01"},{"name":"field_path","location":"body","required":true,"type":"bounded JSON path","description":"Schema-valid field evaluated by the rule.","example":"field-path-01"},{"name":"operator","location":"body","required":true,"type":"GT | GTE | LT | LTE | EQ | NEQ | CONTAINS","description":"Typed comparison operator.","example":"operator-01"},{"name":"comparison","location":"body","required":true,"type":"JSON scalar","description":"Comparison value type-compatible with the schema field.","example":"comparison-01"},{"name":"severity","location":"body","required":false,"type":"INFO | WARNING | CRITICAL","description":"Alert severity; defaults to WARNING.","example":"severity-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a governed evidence-stream alert or validation rule.","whenToUse":"Do not call this planning route yet. It reserves a schema-checked alert rule for one owned stream.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires rule:manage scope, field-path validation against the bound schema, typed comparison checks, complexity and evaluation budgets, lifecycle/version contracts, and clear alert deduplication behavior.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-schemas","method":"GET","path":"/api/v2/evidence-schemas","title":"EVIDENCE: List schemas","description":"List evidence schemas visible to the caller.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-schemas","source":"APIRoutes.py · view_get_v2_evidence_schemas · machine-usable schema projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-schemas/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List schemas"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List evidence schemas visible to the caller.","whenToUse":"Fetch the executable JSON Schema and schema commitment before validating, interpreting, or generating an evidence payload for a selected stream.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Treat returned schemas as private workspace configuration unless separately published.","A schema validates structure and constraints; it does not establish source identity, factual accuracy, consent, or business authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-schemas","method":"POST","path":"/api/v2/evidence-schemas","title":"EVIDENCE: Create schema","description":"Create a versioned validation schema for evidence ingestion.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-schemas","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create schema"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-schemas-request-001"},{"name":"name","location":"body","required":true,"type":"string · 1–120","description":"Stable schema family name.","example":"name-01"},{"name":"schema","location":"body","required":true,"type":"JSON Schema object","description":"Executable validation contract with bounded depth and size.","example":{}},{"name":"compatibility","location":"body","required":false,"type":"BACKWARD | FORWARD | FULL | NONE","description":"Version-compatibility policy; defaults to BACKWARD.","example":"compatibility-01"},{"name":"reason","location":"body","required":false,"type":"string · max 500","description":"Version rationale retained with the schema commitment.","example":"reason-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a versioned validation schema for evidence ingestion.","whenToUse":"Do not call this planning route yet. It reserves a committed versioned JSON Schema after compatibility and safety review.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires schema:create scope, bounded schema complexity, prohibited keyword policy, compatibility checks against active streams, canonical commitment derivation, immutable versions, and audit evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-sources","method":"GET","path":"/api/v2/evidence-sources","title":"EVIDENCE: List sources","description":"List owner-scoped evidence sources and their liveness and acceptance posture without key material or precise location.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-sources","source":"APIRoutes.py · view_get_v2_evidence_sources · minimized owner-scoped source posture"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-sources/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List sources"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List owner-scoped evidence sources and their liveness and acceptance posture without key material or precise location.","whenToUse":"Inventory the authenticated workspace's enrolled evidence sources and reconcile liveness, acceptance, and rejection posture before trusting stream freshness.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Location, public-key material, credential state, owner IDs, and enrollment evidence are deliberately excluded.","An ACTIVE source or recent last_seen_at value does not prove calibration, factual accuracy, or current authorization for a downstream business decision.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-streams","method":"GET","path":"/api/v2/evidence-streams","title":"EVIDENCE: List streams","description":"List evidence streams visible to the caller.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-streams","source":"APIRoutes.py · view_get_v2_evidence_streams · owner-scoped stream projection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-streams/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List streams"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List evidence streams visible to the caller.","whenToUse":"Start a private Evidence Streams workflow here to discover owner-scoped streams, schema bindings, retention posture, activity, and current chain-head commitments.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","A chain head is a drift-detection anchor, not proof that every prior event is present, factually true, or authorized for a downstream action.","Use stable stream and schema identifiers in later reads; names and descriptions are mutable private presentation data.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-streams","method":"POST","path":"/api/v2/evidence-streams","title":"EVIDENCE: Create stream","description":"Create a schema-bound signed evidence stream.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-streams","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Create stream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-streams-request-001"},{"name":"name","location":"body","required":true,"type":"string · 1–120","description":"Workspace-visible stream name.","example":"name-01"},{"name":"schema_uuid","location":"body","required":true,"type":"32-character identifier","description":"Active versioned evidence schema selected from the schema collection.","example":"schema-uuid-01"},{"name":"visibility","location":"body","required":false,"type":"PRIVATE | PUBLIC","description":"Publication posture; defaults to PRIVATE and does not itself disclose events.","example":"visibility-01"},{"name":"retention_days","location":"body","required":false,"type":"integer · 1–3650","description":"Requested retention window; policy may require a longer period.","example":1},{"name":"description","location":"body","required":false,"type":"string · max 500","description":"Purpose and observation context. Secrets and raw evidence are forbidden.","example":"description-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create a schema-bound signed evidence stream.","whenToUse":"Do not call this planning route yet. It reserves creation of a schema-bound stream after classification, retention, publication, quota, and authority policy are approved.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires evidence:create scope, schema ownership and active-version checks, retention and legal-hold policy, visibility review, idempotency, quota reservation, billing behavior, and private audit evidence.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"patch-api-v2-evidence-streams-stream-uuid","method":"PATCH","path":"/api/v2/evidence-streams/{stream_uuid}","title":"EVIDENCE: Update stream","description":"Pause, resume, or archive an evidence stream.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#patch-api-v2-evidence-streams-stream-uuid","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Update stream"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"patch-api-v2-evidence-streams-stream-uuid-request-001"},{"name":"stream_uuid","location":"path","required":true,"type":"identifier","description":"Canonical stream uuid.","example":"stream-uuid-01"},{"name":"expected_version","location":"body","required":true,"type":"integer · ≥1","description":"Current stream version for optimistic concurrency.","example":1},{"name":"action","location":"body","required":true,"type":"PAUSE | RESUME | ARCHIVE","description":"Governed lifecycle transition.","example":"action-01"},{"name":"reason","location":"body","required":true,"type":"string · 8–500","description":"Attributed rationale retained with private audit evidence.","example":"reason-01"}],"responses":[{"status":200,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Pause, resume, or archive an evidence stream.","whenToUse":"Do not call this planning route yet. It reserves optimistic-concurrency pause, resume, or archive transitions for an owner-scoped stream.","workflowRole":"revise","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion must define ingestion behavior during pause, archive finality, active-source and pending-batch handling, reason retention, retry semantics, and version conflicts.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-streams-stream-uuid-event-batches","method":"POST","path":"/api/v2/evidence-streams/{stream_uuid}/event-batches","title":"EVIDENCE: Ingest event batch","description":"Ingest an ordered idempotent batch of evidence events.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-streams-stream-uuid-event-batches","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Ingest event batch"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-streams-stream-uuid-event-batches-request-001"},{"name":"stream_uuid","location":"path","required":true,"type":"identifier","description":"Canonical stream uuid.","example":"stream-uuid-01"},{"name":"batch_reference","location":"body","required":true,"type":"caller-stable identifier · max 160","description":"Idempotent batch identity.","example":"batch-reference-01"},{"name":"events","location":"body","required":true,"type":"evidence event[] · 1–500","description":"Ordered source-signed event envelopes; partial acceptance must be explicit.","example":[]},{"name":"batch_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the canonical ordered batch.","example":"batch-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Ingest an ordered idempotent batch of evidence events.","whenToUse":"Do not call this planning route yet. It reserves bounded ordered ingestion with explicit atomic or per-event acceptance semantics.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires maximum event and byte budgets, one canonical batch commitment, duplicate and partial-failure behavior, order preservation, lock limits, idempotent retry, quarantine receipts, and billing reconciliation.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-evidence-streams-stream-uuid-events","method":"GET","path":"/api/v2/evidence-streams/{stream_uuid}/events","title":"EVIDENCE: List events","description":"List retained events and verification state for a stream.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"source-backed-projection","sourceKinds":["evidence-stream-service"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/v2/evidence-streams/{stream_uuid}/events","source":"APIRoutes.py · view_get_v2_evidence_stream_events · owner check and commitment-only event chain"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1evidence-streams~1{stream_uuid}~1events/get","scope":"evidence:read","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List events"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:read authority.","example":"Bearer hc_live_…"},{"name":"stream_uuid","location":"path","required":true,"type":"identifier","description":"Canonical stream uuid.","example":"stream-uuid-01"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum newest retained events to return in descending sequence order.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List retained events and verification state for a stream.","whenToUse":"Load a bounded newest-first commitment chain for one owned stream after resolving its schema and source posture.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:read authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Complete verification requires payload, previous-chain, chain, and signature checks under the applicable key policy; a bounded page may omit the prior link.","ACCEPTED and source_authenticated report ingestion posture only and never authorize settlement, payment, trading, governance, disclosure, or operational control.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"post-api-v2-evidence-streams-stream-uuid-events","method":"POST","path":"/api/v2/evidence-streams/{stream_uuid}/events","title":"EVIDENCE: Ingest event","description":"Ingest and verify one idempotent evidence event.","chapter":"Evidence Streams","chapterOrder":33,"capability":"Evidence streams","owners":["evidence-stream-service"],"applications":["Evidence Streams"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-evidence-streams-stream-uuid-events","scope":"evidence:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Ingest event"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing evidence:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-evidence-streams-stream-uuid-events-request-001"},{"name":"stream_uuid","location":"path","required":true,"type":"identifier","description":"Canonical stream uuid.","example":"stream-uuid-01"},{"name":"source_id","location":"body","required":true,"type":"32-character identifier","description":"Active source enrolled to this stream.","example":"source-id-01"},{"name":"event_type","location":"body","required":true,"type":"identifier · max 120","description":"Schema-defined observation type.","example":"event-type-01"},{"name":"occurred_at","location":"body","required":true,"type":"RFC 3339 timestamp","description":"Source observation time.","example":"2026-09-30T20:00:00Z"},{"name":"nonce","location":"body","required":true,"type":"unique URL-safe string · 16–160","description":"Single-use replay-prevention nonce.","example":"nonce-01"},{"name":"payload","location":"body","required":true,"type":"JSON object","description":"Schema-valid observation payload. Business secrets require a separately approved evidence classification.","example":{}},{"name":"payload_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the canonical payload.","example":"payload-commitment-01"},{"name":"source_signature","location":"body","required":true,"type":"base64 signature","description":"Signature over the canonical source envelope.","example":"source-signature-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Ingest and verify one idempotent evidence event.","whenToUse":"Do not call this planning route yet. It reserves one schema-validated, replay-protected, source-signed event append.","workflowRole":"create-or-command","sideEffects":"May create a retained command or resource transition when the executable contract and all policy gates permit it.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["A bearer credential with evidence:write authority and the required tenant, workspace, and role context.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Promotion requires evidence:ingest scope, source enrollment and key validity, strict timestamp and nonce windows, canonicalization, schema validation, ordered locking, idempotency, quarantine rules, size limits, billing, and signed server receipts.","Never infer downstream business authority from an accepted append.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Trust Center","Data Vault","Chain Explorer"]}},{"id":"get-api-v2-trust-attestations","method":"GET","path":"/api/v2/trust/attestations","title":"TRUST: List attestations","description":"List attestations issued to or visible by the caller.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1attestations/get","scope":"trust:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List attestations"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List attestations issued to or visible by the caller.","whenToUse":"List formal issuer statements visible to the subject when a relying workflow needs commitment-level eligibility evidence without private claim values.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Evaluate status, validity window, issuer_signature_valid, proof_type, encoding, and commitment together. A commitment hash alone establishes neither cleartext nor authority.","Attestations do not authorize payment, transfer, trading, disclosure, or administration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-trust-claims","method":"GET","path":"/api/v2/trust/claims","title":"TRUST: List claims","description":"List subject claims and disclosure posture.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1claims/get","scope":"trust:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List claims"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List subject claims and disclosure posture.","whenToUse":"Read private subject-owned claim values and disclosure posture for an owner-facing editor or a consent preparation workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Claims contain cleartext subject data. Keep values out of URLs, prompts, analytics, logs, and shared caches.","SELF_ASSERTED or UNVERIFIED values are not issuer-backed facts, and include_in_credential is intent rather than proof of issuance or disclosure authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-trust-claims","method":"POST","path":"/api/v2/trust/claims","title":"TRUST: Save claim","description":"Create or update a subject-owned identity claim.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1claims/post","scope":"trust:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Save claim"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-trust-claims-request-001"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for save claim. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Create or update a subject-owned identity claim.","whenToUse":"Create a new allowlisted subject claim or update an eligible existing claim after the subject confirms its exact value, validity, and credential-inclusion preference.","workflowRole":"create-or-command","sideEffects":"Creates or updates private owner data as SELF_ASSERTED and potentially UNVERIFIED. It does not issue a credential or verify the value.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Omit claim_id to create; provide an eligible owner claim identifier to update. Unknown fields and disallowed namespaces fail closed.","Reuse the idempotency key only for the same logical save and never place identity documents or screening data in claim value.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"delete-api-v2-trust-claims-claim-uuid","method":"DELETE","path":"/api/v2/trust/claims/{claim_uuid}","title":"TRUST: Delete claim","description":"Delete an eligible subject-owned identity claim.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1claims~1{claim_uuid}/delete","scope":"trust:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Delete claim"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"delete-api-v2-trust-claims-claim-uuid-request-001"},{"name":"claim_uuid","location":"path","required":true,"type":"identifier","description":"Canonical claim uuid.","example":"claim-uuid-01"},{"name":"request","location":"body","required":true,"type":"object","description":"Planning outline only for delete claim. The exact fields are intentionally unspecified until the owner schema is implemented and published in OpenAPI.","example":{}}],"responses":[{"status":204,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Delete an eligible subject-owned identity claim.","whenToUse":"Delete an eligible subject-owned self-asserted claim after refreshing the collection and retaining an allowlisted reason.","workflowRole":"revoke-or-delete","sideEffects":"Removes the eligible private claim while retaining the deletion's idempotency and audit posture. Success returns HTTP 204 with no body.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Deletion does not revoke an already issued credential or erase evidence retained under a separate legal or policy basis.","Use the same idempotency key only to retry the same claim and reason_code request.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-trust-credentials","method":"GET","path":"/api/v2/trust/credentials","title":"TRUST: List credentials","description":"List identity and verification credentials visible to the subject.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1credentials/get","scope":"trust:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["List credentials"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the preceding page; valid only for the same subject and filter set.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum credentials to return; defaults to 50.","example":50},{"name":"status","location":"query","required":false,"type":"uppercase lifecycle state · 2–32","description":"Exact canonical credential lifecycle filter.","example":"VALID"},{"name":"q","location":"query","required":false,"type":"string · max 200, no control characters","description":"Case-insensitive credential search term.","example":"age"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"List identity and verification credentials visible to the subject.","whenToUse":"Discover the subject's credential portfolio and reconcile lifecycle, issuer proof posture, and commitments before selecting one for a relying workflow.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Continue only with next_cursor and preserve the same subject and filters; never synthesize a cursor.","VALID status alone is insufficient. Confirm validity timestamps, issuer signature posture, proof type, assurance, verification status, and the relying policy immediately before use.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-trust-credentials","method":"POST","path":"/api/v2/trust/credentials","title":"TRUST: Issue credential","description":"Issue an authorized identity credential.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-trust-credentials","scope":"trust:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Issue credential"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-trust-credentials-request-001"},{"name":"verification_uuid","location":"body","required":true,"type":"32-character identifier","description":"Completed subject-owned verification that supplies the policy and evidence provenance.","example":"verification-uuid-01"},{"name":"credential_type","location":"body","required":true,"type":"issuer allowlisted identifier","description":"Exact credential profile the authorized issuer is requested to create.","example":"credential-type-01"},{"name":"claim_keys","location":"body","required":true,"type":"string[] · unique, at least 1","description":"Smallest approved set of subject claim keys to commit into the credential.","example":[]},{"name":"valid_until","location":"body","required":false,"type":"RFC 3339 timestamp","description":"Requested expiry; issuer and policy may shorten it.","example":"2026-09-30T20:00:00Z"},{"name":"consent_commitment","location":"body","required":true,"type":"SHA-256 digest","description":"Commitment to the subject's purpose- and claim-bound issuance consent; never cleartext identity evidence.","example":"consent-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Issue an authorized identity credential.","whenToUse":"Do not call this planning route. It reserves issuer-controlled creation of a minimized subject credential only after completed verification, consent, and claim-selection provenance exist.","workflowRole":"create-or-command","sideEffects":"No executable public issuance behavior exists. Subject credential reads and verification state do not confer issuer authority.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Promotion requires issuer authentication, policy and verification binding, claim minimization, consent, validity, signature and proof profiles, duplicate handling, revocation registration, audit evidence, and failure contracts.","Never submit identity documents, biometric media, screening matches, private keys, or generic metadata to this planning contract.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-trust-credentials-credential-uuid-revocations","method":"POST","path":"/api/v2/trust/credentials/{credential_uuid}/revocations","title":"TRUST: Revoke credential","description":"Revoke a credential with a retained reason and authority.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"planned-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#post-api-v2-trust-credentials-credential-uuid-revocations","scope":"trust:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Revoke credential"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-trust-credentials-credential-uuid-revocations-request-001"},{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"},{"name":"reason_code","location":"body","required":true,"type":"issuer allowlisted identifier","description":"Structured revocation reason retained in private issuer audit evidence.","example":"reason-code-01"},{"name":"expected_status","location":"body","required":true,"type":"VALID | SUSPENDED","description":"Current lifecycle state for optimistic concurrency.","example":"expected-status-01"},{"name":"evidence_commitment","location":"body","required":false,"type":"SHA-256 digest","description":"Optional commitment to separately retained revocation evidence; raw evidence is forbidden.","example":"evidence-commitment-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Revoke a credential with a retained reason and authority.","whenToUse":"Do not call this planning route. It reserves issuer-authorized, version-aware credential revocation with a retained structured reason.","workflowRole":"create-or-command","sideEffects":"No executable public revocation exists. Deleting a claim or observing a failed verification is not a substitute for issuer lifecycle action.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Promotion requires issuer or delegated revocation authority, current-state concurrency, already-revoked retry semantics, status-list publication, relying-party freshness guidance, audit evidence, and subject notification policy.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"post-api-v2-trust-verifications","method":"POST","path":"/api/v2/trust/verifications","title":"TRUST: Start verification","description":"Start an identity verification workflow.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1verifications/post","scope":"trust:write","idempotency":true,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Start verification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:write authority.","example":"Bearer hc_live_…"},{"name":"Idempotency-Key","location":"header","required":true,"type":"ASCII string · 1–128","description":"Caller-generated stable key reused for retries of the same logical mutation.","example":"post-api-v2-trust-verifications-request-001"},{"name":"policy_id","location":"body","required":false,"type":"policy identifier","description":"Approved verification policy; Identity applies its default when omitted.","example":"policy-id-01"},{"name":"jurisdiction","location":"body","required":false,"type":"uppercase jurisdiction code","description":"Optional policy jurisdiction context.","example":"jurisdiction-01"}],"responses":[{"status":201,"description":"Mutation accepted and canonical state returned.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.","Mutations are retry-safe only when the same Idempotency-Key and canonical request body are reused."]},"businessContext":{"purpose":"Start an identity verification workflow.","whenToUse":"Use after policy selection and subject disclosure to start or idempotently resume one subject-owned verification under the exact policy and optional jurisdiction.","workflowRole":"create-or-command","sideEffects":"Creates or resumes a private Identity verification lifecycle. It does not upload evidence, complete checks, issue a credential, make an approval decision, or grant authority in another domain.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:write authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Reuse an Idempotency-Key only for a byte-equivalent retry of the same policy and jurisdiction request.","HTTP 201 means the workflow record exists. Inspect status, current_step, decision, checks, and nullable completion fields before describing the outcome.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema.","Reuse the same Idempotency-Key and canonical body only for a retry of the same logical mutation."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-trust-verifications-verification-uuid","method":"GET","path":"/api/v2/trust/verifications/{verification_uuid}","title":"TRUST: Get verification","description":"Return verification state and evidence visible to the caller.","chapter":"Trust Center","chapterOrder":34,"capability":"Trust & identity","owners":["identity-service"],"applications":["Trust Center"],"authentication":"bearer+scope","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1trust~1verifications~1{verification_uuid}/get","scope":"trust:read","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get verification"],"parameters":[{"name":"Authorization","location":"header","required":true,"type":"Bearer token","description":"Credential containing trust:read authority.","example":"Bearer hc_live_…"},{"name":"verification_uuid","location":"path","required":true,"type":"identifier","description":"Canonical verification uuid.","example":"verification-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":401,"description":"Bearer credential is missing, expired, or invalid.","example":null},{"status":403,"description":"The principal lacks the required scope, role, tenant, or step-up authority.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return verification state and evidence visible to the caller.","whenToUse":"Poll or reconcile one subject-owned verification after start, using the canonical returned identifier.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["A bearer credential with trust:read authority and the required tenant, workspace, and role context.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Evidence entries expose media metadata and SHA-256 commitments, not document or biometric bytes and not a retrieval capability.","CAPTURED evidence, a completed check, and a final verification decision are distinct states. Branch only on the exact returned lifecycle fields.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-ai-wallet-policies-identifier","method":"GET","path":"/api/v2/explorer/ai-wallet-policies/{identifier}","title":"EXPLORER: AI wallet policy","description":"EXPLORER: AI wallet policy through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · ai wallet policies","owners":["explorer-read-model"],"applications":["Wallets","AI Wallet Control","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/ai-wallet-policies/{identifier}","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1ai-wallet-policies~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["AI wallet policy"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: AI wallet policy through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to ai wallet policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","agent wallet inventory","native-asset budget and policy review"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","Access Control","Automations","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-asset-collections","method":"GET","path":"/api/v2/explorer/asset-collections","title":"EXPLORER: Asset collections","description":"EXPLORER: Asset collections through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · asset collections","owners":["explorer-read-model"],"applications":["Digital Assets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-collections","source":"APIRoutes.py · view_explorer_asset_collections"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1asset-collections/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset collections"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset collections through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset collections before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Commerce","Developer Portal","Evidence Streams"]}},{"id":"get-api-v2-explorer-asset-collections-collection-uuid","method":"GET","path":"/api/v2/explorer/asset-collections/{collection_uuid}","title":"EXPLORER: Asset collection","description":"EXPLORER: Asset collection through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · asset collections","owners":["explorer-read-model"],"applications":["Digital Assets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-collections/{collection_uuid}","source":"APIRoutes.py · view_explorer_asset_collection"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1asset-collections~1{collection_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset collection"],"parameters":[{"name":"collection_uuid","location":"path","required":true,"type":"identifier","description":"Canonical collection uuid.","example":"collection-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset collection through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset collection before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Commerce","Developer Portal","Evidence Streams"]}},{"id":"get-api-v2-explorer-asset-proofs-proof-uuid","method":"GET","path":"/api/v2/explorer/asset-proofs/{proof_uuid}","title":"EXPLORER: Asset proof","description":"EXPLORER: Asset proof through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · asset proofs","owners":["explorer-read-model"],"applications":["Digital Assets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/asset-proofs/{proof_uuid}","source":"APIRoutes.py · view_explorer_asset_proof"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1asset-proofs~1{proof_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset proof"],"parameters":[{"name":"proof_uuid","location":"path","required":true,"type":"identifier","description":"Canonical proof uuid.","example":"proof-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset proof through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset proof before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Commerce","Developer Portal","Evidence Streams"]}},{"id":"get-api-v2-explorer-assets","method":"GET","path":"/api/v2/explorer/assets","title":"EXPLORER: Assets","description":"EXPLORER: Assets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · assets","owners":["asset-registry-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets","source":"APIRoutes.py · view_explorer_assets"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/assets","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1assets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Assets"],"parameters":[{"name":"cursor","location":"query","required":false,"type":"opaque offset cursor","description":"Cursor returned by the preceding page; valid only with the same filters.","example":"offset-24"},{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public assets to return; defaults to 24.","example":24},{"name":"status","location":"query","required":false,"type":"canonical lifecycle state · max 32","description":"Case-insensitive exact lifecycle-state filter.","example":"PUBLISHED"},{"name":"asset_type","location":"query","required":false,"type":"canonical asset classification · max 64","description":"Case-insensitive exact asset-type filter.","example":"CERTIFICATE"},{"name":"q","location":"query","required":false,"type":"string · 1–200","description":"Case-insensitive search across asset UUID, name, symbol, and description.","example":"solar"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Assets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to assets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-assets-asset-uuid","method":"GET","path":"/api/v2/explorer/assets/{asset_uuid}","title":"EXPLORER: Asset","description":"EXPLORER: Asset through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · assets","owners":["asset-registry-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}","source":"APIRoutes.py · view_explorer_asset"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1assets~1{asset_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-assets-asset-uuid-history","method":"GET","path":"/api/v2/explorer/assets/{asset_uuid}/history","title":"EXPLORER: Asset history","description":"EXPLORER: Asset history through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · assets","owners":["asset-registry-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}/history","source":"APIRoutes.py · view_explorer_asset_history"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1assets~1{asset_uuid}~1history/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset history"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset history through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-assets-asset-uuid-proofs","method":"GET","path":"/api/v2/explorer/assets/{asset_uuid}/proofs","title":"EXPLORER: Asset proofs","description":"EXPLORER: Asset proofs through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · assets","owners":["asset-registry-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/assets/{asset_uuid}/proofs","source":"APIRoutes.py · view_explorer_asset_proofs"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1assets~1{asset_uuid}~1proofs/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset proofs"],"parameters":[{"name":"asset_uuid","location":"path","required":true,"type":"identifier","description":"Canonical asset uuid.","example":"asset-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset proofs through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset proofs before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-balances","method":"GET","path":"/api/v2/explorer/balances","title":"EXPLORER: Balances","description":"EXPLORER: Balances through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · balances","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/balances","source":"APIRoutes.py · view_explorer_balances"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1balances/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Balances"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Balances through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to balances before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-barriers","method":"GET","path":"/api/v2/explorer/barriers","title":"EXPLORER: Barriers","description":"EXPLORER: Barriers through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · barriers","owners":["explorer-read-model"],"applications":["Barriers","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/barriers","source":"APIRoutes.py · view_explorer_barriers"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/barriers","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1barriers/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Barriers"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Barriers through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to barriers before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-barriers-product-uuid","method":"GET","path":"/api/v2/explorer/barriers/{product_uuid}","title":"EXPLORER: Barrier","description":"EXPLORER: Barrier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · barriers","owners":["explorer-read-model"],"applications":["Barriers","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/barriers/{product_uuid}","source":"APIRoutes.py · view_explorer_barrier"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1barriers~1{product_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Barrier"],"parameters":[{"name":"product_uuid","location":"path","required":true,"type":"identifier","description":"Canonical product uuid.","example":"product-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Barrier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to barrier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["conditional transfers","risk and compliance gates","programmable execution safeguards","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an approved condition source","authority for the protected operation"],"agentGuidance":["A barrier decision cannot widen the underlying caller authority.","Pin inputs, versions, and evidence so evaluations are reproducible.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Execution Studio","Transfer Compliance","Automations","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer","method":"GET","path":"/api/v2/explorer","title":"EXPLORER: Get catalog","description":"Return explorer resource families, network head, indexing freshness, and supported filters.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · catalog","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"application-expansion","sourceKinds":["application-expansion"],"legacySources":[],"runtimeSources":[],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer/get","scope":"none","idempotency":false,"maturity":"ux-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get catalog"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Return explorer resource families, network head, indexing freshness, and supported filters.","whenToUse":"Use this operation when an integration needs to get catalog before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-contracts","method":"GET","path":"/api/v2/explorer/contracts","title":"EXPLORER: Contract explorer","description":"EXPLORER: Contract explorer through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · contracts","owners":["contract-evidence-read-model"],"applications":["Contract Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/contracts","source":"APIRoutes.py · view_contract_explorer"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1contracts/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Contract explorer"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Contract explorer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to contract explorer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-contracts-launch-uuid","method":"GET","path":"/api/v2/explorer/contracts/{launch_uuid}","title":"EXPLORER: Contract explorer detail","description":"EXPLORER: Contract explorer detail through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · contracts","owners":["contract-evidence-read-model"],"applications":["Contract Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/contracts/{identifier}","source":"APIRoutes.py · view_contract_explorer_detail"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1contracts~1{launch_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Contract explorer detail"],"parameters":[{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Contract explorer detail through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to contract explorer detail before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-contracts-launch-uuid-verify","method":"GET","path":"/api/v2/explorer/contracts/{launch_uuid}/verify","title":"EXPLORER: Contract explorer verify","description":"EXPLORER: Contract explorer verify through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · contracts","owners":["contract-evidence-read-model"],"applications":["Contract Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/contracts/{identifier}/verify","source":"APIRoutes.py · view_contract_explorer_verify"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1contracts~1{launch_uuid}~1verify/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Contract explorer verify"],"parameters":[{"name":"launch_uuid","location":"path","required":true,"type":"identifier","description":"Canonical launch uuid.","example":"launch-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Contract explorer verify through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to contract explorer verify before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["contract launch planning","authority analysis","governed deployment preparation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","immutable artifact commitments","eligible governance and authority wallets"],"agentGuidance":["Preparation never signs, broadcasts, or deploys a contract.","Use hashes and evidence endpoints to independently verify every transition.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Execution Studio","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-counterparties","method":"GET","path":"/api/v2/explorer/counterparties","title":"EXPLORER: Transfer counterparties","description":"EXPLORER: Transfer counterparties through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · counterparties","owners":["explorer-read-model"],"applications":["Transfer Compliance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/counterparties","source":"APIRoutes.py · view_explorer_transfer_counterparties"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1counterparties/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer counterparties"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Transfer counterparties through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to transfer counterparties before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-explorer-counterparties-counterparty-uuid","method":"GET","path":"/api/v2/explorer/counterparties/{counterparty_uuid}","title":"EXPLORER: Transfer counterparty","description":"EXPLORER: Transfer counterparty through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · counterparties","owners":["explorer-read-model"],"applications":["Transfer Compliance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/counterparties/{counterparty_uuid}","source":"APIRoutes.py · view_explorer_transfer_counterparty"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1counterparties~1{counterparty_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer counterparty"],"parameters":[{"name":"counterparty_uuid","location":"path","required":true,"type":"identifier","description":"Canonical counterparty uuid.","example":"counterparty-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Transfer counterparty through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to transfer counterparty before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-explorer-currencies","method":"GET","path":"/api/v2/explorer/currencies","title":"EXPLORER: Get All Currencies","description":"EXPLORER: Get All Currencies through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · currencies","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/currencies","operation":"EXPLORER: Get All Currencies"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/currencies","source":"APIRoutes.py · view_explorer_currencies_summary"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/currencies","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1currencies/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get All Currencies"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get All Currencies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all currencies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-currencies-crypto","method":"GET","path":"/api/v2/explorer/currencies/crypto","title":"EXPLORER: Get Crypto Currencies","description":"EXPLORER: Get Crypto Currencies through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · currencies","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/currencies/crypto","operation":"EXPLORER: Get Crypto Currencies"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/currencies/crypto","source":"APIRoutes.py · view_explorer_currencies_crypto_summary"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/currencies/crypto","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1currencies~1crypto/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Crypto Currencies"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Crypto Currencies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get crypto currencies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-currencies-fiat","method":"GET","path":"/api/v2/explorer/currencies/fiat","title":"EXPLORER: Get Fiat Currencies","description":"EXPLORER: Get Fiat Currencies through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · currencies","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/currencies/fiat","operation":"EXPLORER: Get Fiat Currencies"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/currencies/fiat","source":"APIRoutes.py · view_explorer_currencies_fiat_summary"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/currencies/fiat","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1currencies~1fiat/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Fiat Currencies"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Fiat Currencies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get fiat currencies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-data-vault-anchors","method":"GET","path":"/api/v2/explorer/data-vault/anchors","title":"EXPLORER: Data-vault anchors","description":"EXPLORER: Data-vault anchors through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · data vault","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/data-vault/anchors","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1data-vault~1anchors/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Data-vault anchors"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum anchor batches to return.","example":50},{"name":"offset","location":"query","required":false,"type":"integer · ≥0","description":"Zero-based result offset.","example":0}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Data-vault anchors through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to data-vault anchors before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-data-vault-anchors-identifier","method":"GET","path":"/api/v2/explorer/data-vault/anchors/{identifier}","title":"EXPLORER: Data-vault anchor","description":"EXPLORER: Data-vault anchor through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · data vault","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/data-vault/anchors/{identifier}","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1data-vault~1anchors~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Data-vault anchor"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Data-vault anchor through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to data-vault anchor before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-data-vault-evidence","method":"GET","path":"/api/v2/explorer/data-vault/evidence","title":"EXPLORER: Data-vault evidence","description":"EXPLORER: Data-vault evidence through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · data vault","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/data-vault/evidence","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1data-vault~1evidence/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Data-vault evidence"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum evidence records to return.","example":100},{"name":"offset","location":"query","required":false,"type":"integer · ≥0","description":"Zero-based result offset.","example":0},{"name":"subject","location":"query","required":false,"type":"identifier","description":"Exact public evidence subject.","example":"subject-01"},{"name":"type","location":"query","required":false,"type":"string","description":"Exact evidence event type.","example":"type-01"},{"name":"anchor_state","location":"query","required":false,"type":"string","description":"Filter by anchor lifecycle state.","example":"anchor-state-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Data-vault evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to data-vault evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-data-vault-proof-identifier","method":"GET","path":"/api/v2/explorer/data-vault/proof/{identifier}","title":"EXPLORER: Data-vault proof","description":"EXPLORER: Data-vault proof through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · data vault","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/data-vault/proof/{identifier}","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1data-vault~1proof~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Data-vault proof"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Data-vault proof through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to data-vault proof before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-data-vault-summary","method":"GET","path":"/api/v2/explorer/data-vault/summary","title":"EXPLORER: Data-vault summary","description":"EXPLORER: Data-vault summary through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · data vault","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/data-vault/summary","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1data-vault~1summary/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Data-vault summary"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Data-vault summary through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to data-vault summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-datastreams","method":"GET","path":"/api/v2/explorer/datastreams","title":"EXPLORER: Get All DataStreams","description":"EXPLORER: Get All DataStreams through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · datastreams","owners":["explorer-read-model"],"applications":["Evidence Streams","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/datastreams","operation":"EXPLORER: Get All DataStreams"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/datastreams","source":"APIRoutes.py · view_get_hybrid_chain_data_explorer_streams"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1datastreams/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get All DataStreams"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get All DataStreams through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all datastreams before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-evidence-events-event-uuid","method":"GET","path":"/api/v2/explorer/evidence-events/{event_uuid}","title":"EXPLORER: Evidence event","description":"EXPLORER: Evidence event through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · evidence events","owners":["explorer-read-model"],"applications":["Evidence Streams","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/evidence-events/{event_uuid}","source":"APIRoutes.py · view_explorer_evidence_event"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1evidence-events~1{event_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Evidence event"],"parameters":[{"name":"event_uuid","location":"path","required":true,"type":"identifier","description":"Canonical event uuid.","example":"event-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Evidence event through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to evidence event before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-evidence-streams","method":"GET","path":"/api/v2/explorer/evidence-streams","title":"EXPLORER: Evidence streams","description":"EXPLORER: Evidence streams through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · evidence streams","owners":["explorer-read-model"],"applications":["Evidence Streams","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/evidence-streams","source":"APIRoutes.py · view_explorer_evidence_streams"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1evidence-streams/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Evidence streams"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Evidence streams through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to evidence streams before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-evidence-streams-stream-uuid","method":"GET","path":"/api/v2/explorer/evidence-streams/{stream_uuid}","title":"EXPLORER: Evidence stream","description":"EXPLORER: Evidence stream through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · evidence streams","owners":["explorer-read-model"],"applications":["Evidence Streams","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/evidence-streams/{stream_uuid}","source":"APIRoutes.py · view_explorer_evidence_stream"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1evidence-streams~1{stream_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Evidence stream"],"parameters":[{"name":"stream_uuid","location":"path","required":true,"type":"identifier","description":"Canonical stream uuid.","example":"stream-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Evidence stream through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to evidence stream before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["audit and provenance event ingestion","schema-governed evidence exchange","bounded timeline and integrity verification","source enrollment and liveness monitoring","alert and quarantine triage","rule-based operational observation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","evidence:read for implemented monitoring reads and separately promoted evidence write scopes for mutations","a bearer-derived workspace and stable owner-scoped stream identifier","an active committed schema with bounded complexity and compatibility policy","an enrolled proof-of-possession source with current signing policy for ingestion","caller-owned rules for freshness, chain continuity, source assurance, factual confidence, and downstream fitness"],"agentGuidance":["Evidence records describe observations and processing outcomes; they do not authorize the actions they mention.","Resolve stable stream, schema, source, event, alert, quarantine, and rule identifiers before interpreting or changing workflow state; names and messages are presentation context.","Verify payload, previous-chain, chain, schema, source-signature, and server-signature commitments under the applicable key policy; a bounded page may not contain the prior link needed for complete continuity.","Treat ACTIVE sources, source_authenticated events, ACCEPTED ingestion, OPEN or RESOLVED alerts, quarantine decisions, and OPERATIONAL health as narrow workflow posture—not calibration, completeness, factual truth, regulatory approval, or permission for settlement, payment, trading, governance, disclosure, safety control, or custody.","Keep payload and metadata cleartext, rejected content, source private keys, credentials, precise locations, replay nonces, attachment ciphertext, arbitrary alert values, and owner identifiers out of shared prompts, URLs, logs, analytics, caches, and agent memory.","Publisher enrollment is not factual endorsement, subscriber access is not downstream business authority, stream pause is not event deletion, alert resolution does not retroactively validate evidence, and quarantine disposition does not release or replay a payload.","The six legacy /api/v2/streams/* POST routes are bodyless 501 migration markers. Their generic whitelist, blacklist, toggle, and caller-selected ownership shapes must never be translated into a modern request.","Never call a planned mutation until its exact operation appears in the live production OpenAPI contract.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trust Center","Data Vault","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-executions","method":"GET","path":"/api/v2/explorer/execution/executions","title":"EXPLORER: Hybridscript executions","description":"EXPLORER: Hybridscript executions through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/executions","source":"APIRoutes.py · explorer_hybridscript_executions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1executions/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript executions"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript executions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript executions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-executions-identifier","method":"GET","path":"/api/v2/explorer/execution/executions/{identifier}","title":"EXPLORER: Hybridscript execution","description":"EXPLORER: Hybridscript execution through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/executions/{identifier}","source":"APIRoutes.py · explorer_hybridscript_execution"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1executions~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript execution"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript execution through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript execution before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-nodes","method":"GET","path":"/api/v2/explorer/execution/nodes","title":"EXPLORER: Hybridscript nodes","description":"EXPLORER: Hybridscript nodes through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/nodes","source":"APIRoutes.py · explorer_hybridscript_nodes"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1nodes/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript nodes"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript nodes through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript nodes before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-nodes-identifier","method":"GET","path":"/api/v2/explorer/execution/nodes/{identifier}","title":"EXPLORER: Hybridscript node","description":"EXPLORER: Hybridscript node through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/nodes/{identifier}","source":"APIRoutes.py · explorer_hybridscript_node"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1nodes~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript node"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript node through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript node before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-operators","method":"GET","path":"/api/v2/explorer/execution/operators","title":"EXPLORER: Hybridscript operators","description":"EXPLORER: Hybridscript operators through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/operators","source":"APIRoutes.py · explorer_hybridscript_operators"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1operators/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript operators"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript operators through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript operators before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-operators-identifier","method":"GET","path":"/api/v2/explorer/execution/operators/{identifier}","title":"EXPLORER: Hybridscript operator","description":"EXPLORER: Hybridscript operator through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/operators/{identifier}","source":"APIRoutes.py · explorer_hybridscript_operator"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1operators~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Hybridscript operator"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Hybridscript operator through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to hybridscript operator before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-packages","method":"GET","path":"/api/v2/explorer/execution/packages","title":"EXPLORER: Execution packages","description":"EXPLORER: Execution packages through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/packages","source":"APIRoutes.py · explorer_execution_packages"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1packages/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Execution packages"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Execution packages through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to execution packages before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-packages-identifier","method":"GET","path":"/api/v2/explorer/execution/packages/{identifier}","title":"EXPLORER: Execution package","description":"EXPLORER: Execution package through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/packages/{identifier}","source":"APIRoutes.py · explorer_execution_package"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1packages~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Execution package"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Execution package through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to execution package before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication","isolated test and production deployment","schema-bound deterministic invocation","event and schedule triggers"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","execution:read or execution:write in the bearer-derived workspace","an immutable owner-scoped source artifact and canonical SHA-256 digest","approved runtime and validation profiles with pinned compiler, runtime, ABI, and dependency policy","closed input/output schemas, dependency-lock commitment, capability request, and resource limits","eligible attested nodes and isolated environment policy for deployment","fresh owning-domain authorization for any effect beyond pure deterministic compute","caller-owned acceptance rules for validation freshness, node attestation, reproducibility, outputs, logs, receipts, and finality"],"agentGuidance":["Separate DRAFT creation, validation admission, validation PASS, publication, deployment preparation, activation, invocation admission, execution completion, callback or trigger handling, external domain effects, and chain finality; no state implies another.","Never submit inline code, arbitrary artifact URLs, API paths, shell commands, executable expressions, unpinned dependencies, arbitrary network destinations, credentials, private keys, secret values, regulated cleartext, owner selectors, node selectors, or authority assertions.","Source, manifest, dependency-lock, runtime, compiler, validation, build artifact, package, deployment, input-schema, input, output, node-attestation, and receipt commitments must all refer to the same lineage before a result is trusted.","A validation PASS is scoped to exact inputs and policy and becomes stale when source, manifest, dependency, runtime, compiler, key, schema, capability, resource, or policy commitments change.","TEST and PRODUCTION artifacts, credentials, nodes, secret bindings, data, and receipts are isolated. Never promote TEST state by relabeling or caller assertion.","VALIDATE_ONLY executes no package code. EXECUTE acceptance is not completion. Logs are diagnostic, outputs must match the published schema, and any external business effect requires and returns a separately owned domain authorization and receipt.","Package publication grants no deployment or invocation authority, deployment preparation grants no activation authority, and a trigger grants no new package capability or domain permission.","No execution package, deployment, invocation, or trigger may change trading, matching, prediction-market execution, ingress, publisher, allowlist, market status, suspension, or traffic while those controls remain frozen.","Never call a planned Execution Studio operation until its exact contract appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Barriers","Evidence Streams","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-execution-publishing-authority","method":"GET","path":"/api/v2/explorer/execution/publishing-authority","title":"EXPLORER: Execution publishing authority","description":"EXPLORER: Execution publishing authority through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · execution","owners":["execution-evidence-read-model"],"applications":["Governance","Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/execution/publishing-authority","source":"APIRoutes.py · explorer_execution_publishing_authority"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1execution~1publishing-authority/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Execution publishing authority"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Execution publishing authority through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to execution publishing authority before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Barriers","Evidence Streams","Developer Portal"]}},{"id":"get-api-v2-explorer-funding","method":"GET","path":"/api/v2/explorer/funding","title":"EXPLORER: Compose the funding evidence dashboard","description":"Planning marker for the Explorer website's funding dashboard composition. It is not an aggregate API endpoint: clients assemble the view from the implemented funding operations, bindings, deposits, settlement intents, integrity audit, acceptance certificates and authorities, activation governance, escrow positions, and shadow observations reads.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"documented-composition","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding","source":null}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-explorer-funding","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Compose the funding evidence dashboard"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Planning marker for the Explorer website's funding dashboard composition. It is not an aggregate API endpoint: clients assemble the view from the implemented funding operations, bindings, deposits, settlement intents, integrity audit, acceptance certificates and authorities, activation governance, escrow positions, and shadow observations reads.","whenToUse":"Use this registry entry to discover the canonical atomic reads behind a website view. Do not issue a request to the planning path.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Do not call this path. Fetch only the atomic funding resources the user needs; this avoids coupling an integration to a large website-specific payload.","Forward the same bounded limit to bindings, deposits, settlement intents, acceptance certificates, escrow positions, and shadow observations. Operations, acceptance authorities, and activation governance are singleton reads.","Treat unavailable optional evidence as unknown, never as an empty proof set or an authorization signal.","Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-identifier","method":"GET","path":"/api/v2/explorer/funding/{identifier}","title":"EXPLORER: · funding · identifier","description":"EXPLORER: · funding · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/deposits/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-acceptance-authorities","method":"GET","path":"/api/v2/explorer/funding/acceptance-authorities","title":"EXPLORER: Funding acceptance authorities","description":"EXPLORER: Funding acceptance authorities through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Governance","Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-authorities","source":"APIRoutes.py · view_explorer_funding_acceptance_authorities"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance-authorities/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding acceptance authorities"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding acceptance authorities through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding acceptance authorities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Payments","Indexer Controller","Developer Portal"]}},{"id":"get-api-v2-explorer-funding-acceptance-authorities-authority-identifier","method":"GET","path":"/api/v2/explorer/funding/acceptance-authorities/{authority_identifier}","title":"EXPLORER: Funding acceptance authority","description":"EXPLORER: Funding acceptance authority through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Governance","Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-authorities/{authority_identifier}","source":"APIRoutes.py · view_explorer_funding_acceptance_authority"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance-authorities~1{authority_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding acceptance authority"],"parameters":[{"name":"authority_identifier","location":"path","required":true,"type":"identifier","description":"Canonical authority identifier.","example":"authority-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding acceptance authority through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding acceptance authority before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Payments","Indexer Controller","Developer Portal"]}},{"id":"get-api-v2-explorer-funding-acceptance-authorities-identifier","method":"GET","path":"/api/v2/explorer/funding/acceptance-authorities/{identifier}","title":"EXPLORER: · funding · acceptance authorities · identifier","description":"EXPLORER: · funding · acceptance authorities · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Governance","Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/acceptance-authorities/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-authorities/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance-authorities~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · acceptance authorities · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · acceptance authorities · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · acceptance authorities · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Payments","Indexer Controller","Developer Portal"]}},{"id":"get-api-v2-explorer-funding-acceptance-certificates","method":"GET","path":"/api/v2/explorer/funding/acceptance-certificates","title":"EXPLORER: Funding acceptance certificates","description":"EXPLORER: Funding acceptance certificates through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-certificates","source":"APIRoutes.py · view_explorer_funding_acceptance_certificates"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance-certificates/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding acceptance certificates"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding acceptance certificates through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding acceptance certificates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-acceptance-certificates-acceptance-identifier","method":"GET","path":"/api/v2/explorer/funding/acceptance-certificates/{acceptance_identifier}","title":"EXPLORER: Funding acceptance certificate","description":"EXPLORER: Funding acceptance certificate through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-certificates/{acceptance_identifier}","source":"APIRoutes.py · view_explorer_funding_acceptance_certificate"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance-certificates~1{acceptance_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding acceptance certificate"],"parameters":[{"name":"acceptance_identifier","location":"path","required":true,"type":"identifier","description":"Canonical acceptance identifier.","example":"acceptance-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding acceptance certificate through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding acceptance certificate before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-acceptance-identifier","method":"GET","path":"/api/v2/explorer/funding/acceptance/{identifier}","title":"EXPLORER: · funding · acceptance · identifier","description":"EXPLORER: · funding · acceptance · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/acceptance/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/acceptance-certificates/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1acceptance~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · acceptance · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · acceptance · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · acceptance · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-activation-governance","method":"GET","path":"/api/v2/explorer/funding/activation-governance","title":"EXPLORER: Funding activation governance","description":"EXPLORER: Funding activation governance through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Governance","Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/activation-governance","source":"APIRoutes.py · view_explorer_funding_activation_governance"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1activation-governance/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding activation governance"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding activation governance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding activation governance before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Payments","Indexer Controller","Developer Portal"]}},{"id":"get-api-v2-explorer-funding-activation-governance-policy-identifier","method":"GET","path":"/api/v2/explorer/funding/activation-governance/{policy_identifier}","title":"EXPLORER: Funding activation policy","description":"EXPLORER: Funding activation policy through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Governance","Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/activation-governance/{policy_identifier}","source":"APIRoutes.py · view_explorer_funding_activation_policy"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1activation-governance~1{policy_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding activation policy"],"parameters":[{"name":"policy_identifier","location":"path","required":true,"type":"identifier","description":"Canonical policy identifier.","example":"policy-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding activation policy through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding activation policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["multi-party approvals","authority lifecycle management","policy and risk acceptance","deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","governance scope and eligible role","current authority and policy versions"],"agentGuidance":["A proposal or ceremony does not itself execute a transaction.","Bind every decision to the current version and retain its evidence identifiers.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Contract Studio","Access Control","Payments","Indexer Controller","Developer Portal"]}},{"id":"get-api-v2-explorer-funding-bindings","method":"GET","path":"/api/v2/explorer/funding/bindings","title":"EXPLORER: Funding bindings","description":"EXPLORER: Funding bindings through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/bindings","source":"APIRoutes.py · view_explorer_funding_bindings"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1bindings/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding bindings"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding bindings through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding bindings before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-bindings-binding-identifier","method":"GET","path":"/api/v2/explorer/funding/bindings/{binding_identifier}","title":"EXPLORER: Funding binding","description":"EXPLORER: Funding binding through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/bindings/{binding_identifier}","source":"APIRoutes.py · view_explorer_funding_binding"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1bindings~1{binding_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding binding"],"parameters":[{"name":"binding_identifier","location":"path","required":true,"type":"identifier","description":"Canonical binding identifier.","example":"binding-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding binding through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding binding before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-deposits","method":"GET","path":"/api/v2/explorer/funding/deposits","title":"EXPLORER: Funding deposits","description":"EXPLORER: Funding deposits through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer","Indexer Controller"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/deposits","source":"APIRoutes.py · view_explorer_funding_deposits"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1deposits/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding deposits"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding deposits through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding deposits before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Developer Portal","Digital Assets","Evidence Streams","Infrastructure"]}},{"id":"get-api-v2-explorer-funding-deposits-deposit-identifier","method":"GET","path":"/api/v2/explorer/funding/deposits/{deposit_identifier}","title":"EXPLORER: Funding deposit","description":"EXPLORER: Funding deposit through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/deposits/{deposit_identifier}","source":"APIRoutes.py · view_explorer_funding_deposit"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1deposits~1{deposit_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding deposit"],"parameters":[{"name":"deposit_identifier","location":"path","required":true,"type":"identifier","description":"Canonical deposit identifier.","example":"deposit-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding deposit through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding deposit before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-escrow-positions","method":"GET","path":"/api/v2/explorer/funding/escrow-positions","title":"EXPLORER: Funding escrow positions","description":"EXPLORER: Funding escrow positions through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/escrow-positions","source":"APIRoutes.py · view_explorer_funding_escrow_positions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1escrow-positions/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding escrow positions"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding escrow positions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding escrow positions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-escrow-positions-position-identifier","method":"GET","path":"/api/v2/explorer/funding/escrow-positions/{position_identifier}","title":"EXPLORER: Funding escrow position","description":"EXPLORER: Funding escrow position through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/escrow-positions/{position_identifier}","source":"APIRoutes.py · view_explorer_funding_escrow_position"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1escrow-positions~1{position_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding escrow position"],"parameters":[{"name":"position_identifier","location":"path","required":true,"type":"identifier","description":"Canonical position identifier.","example":"position-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding escrow position through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding escrow position before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-escrow-identifier","method":"GET","path":"/api/v2/explorer/funding/escrow/{identifier}","title":"EXPLORER: · funding · escrow · identifier","description":"EXPLORER: · funding · escrow · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/escrow/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/escrow-positions/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1escrow~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · escrow · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · escrow · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · escrow · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-integrity-audit","method":"GET","path":"/api/v2/explorer/funding/integrity-audit","title":"EXPLORER: Funding integrity audit","description":"EXPLORER: Funding integrity audit through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/integrity-audit","source":"APIRoutes.py · view_explorer_funding_integrity_audit"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1integrity-audit/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding integrity audit"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum integrity records to return.","example":100},{"name":"binding_uuid","location":"query","required":false,"type":"identifier","description":"Exact funding binding to audit.","example":"binding-uuid-01"},{"name":"deposit_uuid","location":"query","required":false,"type":"identifier","description":"Exact deposit to audit.","example":"deposit-uuid-01"},{"name":"intent_uuid","location":"query","required":false,"type":"identifier","description":"Exact settlement intent to audit.","example":"intent-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding integrity audit through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding integrity audit before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-observations-identifier","method":"GET","path":"/api/v2/explorer/funding/observations/{identifier}","title":"EXPLORER: · funding · observations · identifier","description":"EXPLORER: · funding · observations · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/observations/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/shadow-observations/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1observations~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · observations · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · observations · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · observations · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-operations","method":"GET","path":"/api/v2/explorer/funding/operations","title":"EXPLORER: Funding operations","description":"EXPLORER: Funding operations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/operations","source":"APIRoutes.py · view_explorer_funding_operations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1operations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding operations"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding operations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding operations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-routes-identifier","method":"GET","path":"/api/v2/explorer/funding/routes/{identifier}","title":"EXPLORER: · funding · routes · identifier","description":"EXPLORER: · funding · routes · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/routes/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/bindings/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1routes~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · routes · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · routes · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · routes · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-settlement-intents","method":"GET","path":"/api/v2/explorer/funding/settlement-intents","title":"EXPLORER: Funding settlement intents","description":"EXPLORER: Funding settlement intents through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer","Indexer Controller"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/settlement-intents","source":"APIRoutes.py · view_explorer_funding_settlement_intents"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1settlement-intents/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding settlement intents"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding settlement intents through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding settlement intents before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Developer Portal","Digital Assets","Evidence Streams","Infrastructure"]}},{"id":"get-api-v2-explorer-funding-settlement-intents-intent-identifier","method":"GET","path":"/api/v2/explorer/funding/settlement-intents/{intent_identifier}","title":"EXPLORER: Funding settlement intent","description":"EXPLORER: Funding settlement intent through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/settlement-intents/{intent_identifier}","source":"APIRoutes.py · view_explorer_funding_settlement_intent"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1settlement-intents~1{intent_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding settlement intent"],"parameters":[{"name":"intent_identifier","location":"path","required":true,"type":"identifier","description":"Canonical intent identifier.","example":"intent-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding settlement intent through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding settlement intent before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-settlements-identifier","method":"GET","path":"/api/v2/explorer/funding/settlements/{identifier}","title":"EXPLORER: · funding · settlements · identifier","description":"EXPLORER: · funding · settlements · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/funding/settlements/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/funding/settlement-intents/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1settlements~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· funding · settlements · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · funding · settlements · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · funding · settlements · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-shadow-observations","method":"GET","path":"/api/v2/explorer/funding/shadow-observations","title":"EXPLORER: Funding shadow observations","description":"EXPLORER: Funding shadow observations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/shadow-observations","source":"APIRoutes.py · view_explorer_funding_shadow_observations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1shadow-observations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding shadow observations"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public funding records to return.","example":100}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding shadow observations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding shadow observations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-shadow-observations-shadow-observation-identifier","method":"GET","path":"/api/v2/explorer/funding/shadow-observations/{shadow_observation_identifier}","title":"EXPLORER: Funding shadow observation","description":"EXPLORER: Funding shadow observation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/shadow-observations/{shadow_observation_identifier}","source":"APIRoutes.py · view_explorer_funding_shadow_observation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1shadow-observations~1{shadow_observation_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding shadow observation"],"parameters":[{"name":"shadow_observation_identifier","location":"path","required":true,"type":"identifier","description":"Canonical shadow observation identifier.","example":"shadow-observation-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding shadow observation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding shadow observation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-funding-source-observers-observer-key-id-tip","method":"GET","path":"/api/v2/explorer/funding/source-observers/{observer_key_id}/tip","title":"EXPLORER: Funding source observer tip","description":"EXPLORER: Funding source observer tip through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · funding","owners":["funding-evidence-read-model"],"applications":["Funding","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/funding/source-observers/{observer_key_id}/tip","source":"APIRoutes.py · view_explorer_funding_source_observer_tip"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1funding~1source-observers~1{observer_key_id}~1tip/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Funding source observer tip"],"parameters":[{"name":"observer_key_id","location":"path","required":true,"type":"identifier","description":"Canonical observer key id.","example":"observer-key-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Funding source observer tip through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to funding source observer tip before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["deposit monitoring","wallet funding-route preparation","withdrawal and same-network transfer intent planning","multi-factor exact-intent customer consent","pre-broadcast cancellation and collateral release","settlement reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner and matching network context","an active owner-scoped MPC wallet activation for route or intent mutations","rail-specific compliance, native-asset, custody, collateral, and finality readiness"],"agentGuidance":["Treat PREPARED bindings, observed deposits, accepted intents, completed consent, collateral reservation, and broadcast as distinct states; none substitutes for final settlement evidence.","Preserve amounts as exact decimal strings, re-fetch network and native-asset policy, and never derive owner, wallet, or destination authority from presentation data.","Use one Idempotency-Key only for a byte-equivalent logical mutation and reconcile owner state before retrying an ambiguous response.","Never send passwords, private keys, seeds, MPC shares, signing nonces, raw bank coordinates, or credential secrets through Funding contracts.","Planned Funding mutations remain non-executable until they appear in production OpenAPI; current production non-zero value movement and all trading or matching authority remain fail closed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Wallets","Payments","Indexer Controller","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-identities","method":"GET","path":"/api/v2/explorer/identities","title":"EXPLORER: Identities","description":"EXPLORER: Identities through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · identities","owners":["identity-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/identities","source":"APIRoutes.py · view_explorer_identities"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/identities","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1identities/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Identities"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Identities through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to identities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-identities-credential-uuid","method":"GET","path":"/api/v2/explorer/identities/{credential_uuid}","title":"EXPLORER: Identity","description":"EXPLORER: Identity through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · identities","owners":["identity-evidence-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/identities/{credential_uuid}","source":"APIRoutes.py · view_explorer_identity"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1identities~1{credential_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Identity"],"parameters":[{"name":"credential_uuid","location":"path","required":true,"type":"identifier","description":"Canonical credential uuid.","example":"credential-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Identity through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to identity before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-identities-uuid","method":"GET","path":"/api/v2/explorer/identities/{uuid}","title":"EXPLORER: · identities · uuid","description":"EXPLORER: · identities · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · identities","owners":["identity-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/identities/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/identities/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1identities~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· identities · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · identities · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · identities · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-identities-issuer","method":"GET","path":"/api/v2/explorer/identities/issuer","title":"EXPLORER: Identity issuer","description":"EXPLORER: Identity issuer through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · identities","owners":["identity-evidence-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/identities/issuer","source":"APIRoutes.py · view_explorer_identity_issuer"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1identities~1issuer/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Identity issuer"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Identity issuer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to identity issuer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-liquidity-pools--z07j5s","method":"GET","path":"/api/v2/explorer/liquidity_pools","title":"EXPLORER: Get Liquidity Pools","description":"EXPLORER: Get Liquidity Pools through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · liquidity pools","owners":["explorer-read-model"],"applications":["Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/liquidity_pools","operation":"EXPLORER: Get Liquidity Pools"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/liquidity_pools","source":"APIRoutes.py · view_explorer_liquidity_pools"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1liquidity_pools/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Liquidity Pools"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Liquidity Pools through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get liquidity pools before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["pool monitoring","liquidity allocation planning","flow and performance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","eligible venue and asset pair","liquidity and treasury authority for mutations"],"agentGuidance":["Read projections do not grant market-making or transfer authority.","Use exact decimal strings and reconcile movements from the authoritative ledger.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Strategy Pools","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-liquidity-pools-events--18cdrrg","method":"GET","path":"/api/v2/explorer/liquidity_pools/events","title":"EXPLORER: Get Liquidity Pool Events","description":"EXPLORER: Get Liquidity Pool Events through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · liquidity pools","owners":["explorer-read-model"],"applications":["Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/liquidity_pools/events","operation":"EXPLORER: Get Liquidity Pool Events"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/liquidity_pools/events","source":"APIRoutes.py · view_explorer_liquidity_pools_events"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1liquidity_pools~1events/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Liquidity Pool Events"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Liquidity Pool Events through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get liquidity pool events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["pool monitoring","liquidity allocation planning","flow and performance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","eligible venue and asset pair","liquidity and treasury authority for mutations"],"agentGuidance":["Read projections do not grant market-making or transfer authority.","Use exact decimal strings and reconcile movements from the authoritative ledger.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Strategy Pools","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-liquidity-pools","method":"GET","path":"/api/v2/explorer/liquidity-pools","title":"EXPLORER: · liquidity pools","description":"EXPLORER: · liquidity pools through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · liquidity pools","owners":["explorer-read-model"],"applications":["Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/liquidity-pools","source":null},{"catalog":"core","method":"GET","path":"/explorer/liquidity_pools","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1liquidity-pools/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· liquidity pools"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · liquidity pools through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · liquidity pools before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["pool monitoring","liquidity allocation planning","flow and performance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","eligible venue and asset pair","liquidity and treasury authority for mutations"],"agentGuidance":["Read projections do not grant market-making or transfer authority.","Use exact decimal strings and reconcile movements from the authoritative ledger.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Strategy Pools","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-liquidity-pools-events","method":"GET","path":"/api/v2/explorer/liquidity-pools/events","title":"EXPLORER: · liquidity pools · events","description":"EXPLORER: · liquidity pools · events through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · liquidity pools","owners":["explorer-read-model"],"applications":["Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/liquidity-pools/events","source":null},{"catalog":"core","method":"GET","path":"/explorer/liquidity_pools/events","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1liquidity-pools~1events/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· liquidity pools · events"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · liquidity pools · events through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · liquidity pools · events before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["pool monitoring","liquidity allocation planning","flow and performance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","eligible venue and asset pair","liquidity and treasury authority for mutations"],"agentGuidance":["Read projections do not grant market-making or transfer authority.","Use exact decimal strings and reconcile movements from the authoritative ledger.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Strategy Pools","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-markets-liquidity-pool-uuid","method":"GET","path":"/api/v2/explorer/markets/{liquidity_pool_uuid}","title":"EXPLORER: Markets","description":"EXPLORER: Markets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · markets","owners":["explorer-read-model"],"applications":["Trading","Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/markets/{liquidity_pool_uuid}","source":"APIRoutes.py · view_explorer_markets"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1markets~1{liquidity_pool_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Markets"],"parameters":[{"name":"liquidity_pool_uuid","location":"path","required":true,"type":"identifier","description":"Canonical liquidity pool uuid.","example":"liquidity-pool-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Markets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to markets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Trading & Matching Ops","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mints-mint-uuid","method":"GET","path":"/api/v2/explorer/mints/{mint_uuid}","title":"EXPLORER: Asset mint","description":"EXPLORER: Asset mint through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mints","owners":["explorer-read-model"],"applications":["Digital Assets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mints/{mint_uuid}","source":"APIRoutes.py · view_explorer_asset_mint"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mints~1{mint_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Asset mint"],"parameters":[{"name":"mint_uuid","location":"path","required":true,"type":"identifier","description":"Canonical mint uuid.","example":"mint-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Asset mint through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to asset mint before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["public token and digital-asset catalog discovery","canonical token details and collection membership","mint, lifecycle, provenance, and proof reconciliation","fungible, security-token, and collectible asset issuance","collection and asset publication","governed mint, burn, and supply reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","issuer, holder, seller, or separately governed compliance authority appropriate to the exact mutation","active network, asset, collection, authority, precision, cap, metadata, and compliance policy eligibility","fresh purpose-bound step-up and RFC 9421 request signature for consequential planned mutations","authoritative Commerce confirmation when payment or order evidence participates"],"agentGuidance":["Use the implemented canonical asset, collection, history, proof, and mint-evidence reads for public token discovery; legacy /api/v2/tokens/* reads remain non-executable migration documentation.","A public asset record exposes identity, classification, exact supply projections, metadata commitments, and lifecycle timestamps—not current price, performance, buying power, holder ownership, reserve inventory, redemption eligibility, or trading authority.","Use asset_uuid and collection_uuid as stable identities. Symbols, names, category codes, media URIs, and display metadata are not globally unique and are never proof or authorization.","Differentiate draft creation, public metadata publication, supply issuance, holding ownership, market listing, payment, and delivery; no state implies another.","Preserve quantities, prices, balances, and supply as exact decimal strings and bind mutations to last-read versions and commitments.","Derive owner boundaries from the bearer and opaque owner-safe references; never send database IDs, vault selectors, private keys, seeds, MPC shares, signing nonces, or custody credentials.","Use canonical proof endpoints to verify commitments instead of trusting display fields, screenshots, caller-authored status, or legacy token and NFT payloads.","Treat /api/v2/tokens/mint and /api/v2/nft mutation paths as 501 compatibility markers. Follow their canonical migration guidance and call a replacement only when it appears in live OpenAPI.","A planned-profiled operation is reviewed documentation, not executable behavior. Re-fetch /api/v2/openapi.json before generating or releasing an integration.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Contract Studio","Commerce","Developer Portal","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallet-ceremonies","method":"GET","path":"/api/v2/explorer/mpc-wallet-ceremonies","title":"EXPLORER: Mpc wallet ceremonies","description":"EXPLORER: Mpc wallet ceremonies through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallet ceremonies","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallet-ceremonies","source":"APIRoutes.py · view_explorer_mpc_wallet_ceremonies"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/mpc-wallet-ceremonies","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallet-ceremonies/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet ceremonies"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet ceremonies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet ceremonies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallet-ceremonies-request-uuid","method":"GET","path":"/api/v2/explorer/mpc-wallet-ceremonies/{request_uuid}","title":"EXPLORER: Mpc wallet ceremony","description":"EXPLORER: Mpc wallet ceremony through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallet ceremonies","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallet-ceremonies/{request_uuid}","source":"APIRoutes.py · view_explorer_mpc_wallet_ceremony"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/mpc-wallet-ceremonies/{request_uuid}","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallet-ceremonies~1{request_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet ceremony"],"parameters":[{"name":"request_uuid","location":"path","required":true,"type":"identifier","description":"Canonical request uuid.","example":"request-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet ceremony through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet ceremony before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets","method":"GET","path":"/api/v2/explorer/mpc-wallets","title":"EXPLORER: Mpc wallets","description":"EXPLORER: Mpc wallets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets","source":"APIRoutes.py · view_explorer_mpc_wallets"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/mpc-wallets","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallets"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum public MPC wallets to return.","example":50},{"name":"offset","location":"query","required":false,"type":"integer · ≥0","description":"Zero-based result offset.","example":0},{"name":"network_id","location":"query","required":false,"type":"network identifier","description":"Exact public network filter.","example":"network-id-01"},{"name":"state","location":"query","required":false,"type":"string","description":"Optional lifecycle-state filter.","example":"state-01"},{"name":"search","location":"query","required":false,"type":"string · max 180","description":"Wallet identifier, label, or address search.","example":"search-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/{identifier}","title":"EXPLORER: · mpc wallets · identifier","description":"EXPLORER: · mpc wallets · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/mpc-wallets/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· mpc wallets · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · mpc wallets · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · mpc wallets · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-wallet-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/{wallet_identifier}","title":"EXPLORER: Mpc wallet","description":"EXPLORER: Mpc wallet through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/{wallet_identifier}","source":"APIRoutes.py · view_explorer_mpc_wallet"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1{wallet_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet"],"parameters":[{"name":"wallet_identifier","location":"path","required":true,"type":"identifier","description":"Canonical wallet identifier.","example":"wallet-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-wallet-uuid-operational-readiness","method":"GET","path":"/api/v2/explorer/mpc-wallets/{wallet_uuid}/operational-readiness","title":"EXPLORER: Mpc wallet operational readiness","description":"EXPLORER: Mpc wallet operational readiness through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/{wallet_uuid}/operational-readiness","source":"APIRoutes.py · view_explorer_mpc_wallet_operational_readiness"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1{wallet_uuid}~1operational-readiness/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet operational readiness"],"parameters":[{"name":"wallet_uuid","location":"path","required":true,"type":"identifier","description":"Canonical wallet uuid.","example":"wallet-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet operational readiness through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet operational readiness before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-beneficial-claims-domain-uuid","method":"GET","path":"/api/v2/explorer/mpc-wallets/beneficial-claims/{domain_uuid}","title":"EXPLORER: Mpc beneficial claims","description":"EXPLORER: Mpc beneficial claims through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/beneficial-claims/{domain_uuid}","source":"APIRoutes.py · view_explorer_mpc_beneficial_claims"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1beneficial-claims~1{domain_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc beneficial claims"],"parameters":[{"name":"domain_uuid","location":"path","required":true,"type":"identifier","description":"Canonical domain uuid.","example":"domain-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc beneficial claims through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc beneficial claims before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-admissions-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-admissions/{identifier}","title":"EXPLORER: Mpc custody admission","description":"EXPLORER: Mpc custody admission through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-admissions/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_admission"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-admissions~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody admission"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody admission through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody admission before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-chain-adapter-admissions","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-chain-adapter-admissions","title":"EXPLORER: Mpc custody chain adapter admissions","description":"EXPLORER: Mpc custody chain adapter admissions through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-chain-adapter-admissions","source":"APIRoutes.py · view_explorer_mpc_custody_chain_adapter_admissions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-chain-adapter-admissions/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody chain adapter admissions"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody chain adapter admissions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody chain adapter admissions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-chain-adapter-admissions-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-chain-adapter-admissions/{identifier}","title":"EXPLORER: Mpc custody chain adapter admission","description":"EXPLORER: Mpc custody chain adapter admission through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-chain-adapter-admissions/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_chain_adapter_admission"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-chain-adapter-admissions~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody chain adapter admission"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody chain adapter admission through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody chain adapter admission before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-chain-capabilities","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-chain-capabilities","title":"EXPLORER: Mpc custody chain capabilities","description":"EXPLORER: Mpc custody chain capabilities through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Developers","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-chain-capabilities","source":"APIRoutes.py · view_explorer_mpc_custody_chain_capabilities"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-chain-capabilities/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody chain capabilities"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody chain capabilities through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody chain capabilities before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","API credential lifecycle","agent authentication"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-chain-capabilities-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-chain-capabilities/{identifier}","title":"EXPLORER: Mpc custody chain capability","description":"EXPLORER: Mpc custody chain capability through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Developers","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-chain-capabilities/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_chain_capability"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-chain-capabilities~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody chain capability"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody chain capability through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody chain capability before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","API credential lifecycle","agent authentication"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","API Reference","Integration Guides","Access Control"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-chain-readiness","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-chain-readiness","title":"EXPLORER: Mpc custody chain readiness","description":"EXPLORER: Mpc custody chain readiness through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-chain-readiness","source":"APIRoutes.py · view_explorer_mpc_custody_chain_readiness"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-chain-readiness/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody chain readiness"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody chain readiness through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody chain readiness before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-domains","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-domains","title":"EXPLORER: Mpc custody domains","description":"EXPLORER: Mpc custody domains through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-domains","source":"APIRoutes.py · view_explorer_mpc_custody_domains"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-domains/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody domains"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody domains through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody domains before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-domains-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-domains/{identifier}","title":"EXPLORER: Mpc custody domain","description":"EXPLORER: Mpc custody domain through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-domains/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_domain"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-domains~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody domain"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody domain through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody domain before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-gateways","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-gateways","title":"EXPLORER: Mpc custody gateways","description":"EXPLORER: Mpc custody gateways through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-gateways","source":"APIRoutes.py · view_explorer_mpc_custody_gateways"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-gateways/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody gateways"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody gateways through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody gateways before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-gateways-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-gateways/{identifier}","title":"EXPLORER: Mpc custody gateway","description":"EXPLORER: Mpc custody gateway through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-gateways/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_gateway"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-gateways~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody gateway"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody gateway through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody gateway before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-registry-checkpoint","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-registry/checkpoint","title":"EXPLORER: Mpc custody registry checkpoint","description":"EXPLORER: Mpc custody registry checkpoint through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-registry/checkpoint","source":"APIRoutes.py · view_explorer_mpc_custody_registry_checkpoint"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-registry~1checkpoint/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody registry checkpoint"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody registry checkpoint through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody registry checkpoint before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-reserve-authorities-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-reserve-authorities/{identifier}","title":"EXPLORER: Mpc custody reserve authority","description":"EXPLORER: Mpc custody reserve authority through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Governance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-reserve-authorities/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_reserve_authority"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-reserve-authorities~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody reserve authority"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody reserve authority through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody reserve authority before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","multi-party approvals","authority lifecycle management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Funding","AI Wallet Control","Contract Studio","Access Control","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-reserve-transfers-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-reserve-transfers/{identifier}","title":"EXPLORER: Mpc custody reserve transfer","description":"EXPLORER: Mpc custody reserve transfer through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-reserve-transfers/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_reserve_transfer"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-reserve-transfers~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody reserve transfer"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody reserve transfer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody reserve transfer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-root-candidates","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-root-candidates","title":"EXPLORER: Mpc custody root candidates","description":"EXPLORER: Mpc custody root candidates through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-root-candidates","source":"APIRoutes.py · view_explorer_mpc_custody_root_candidates"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-root-candidates/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody root candidates"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody root candidates through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody root candidates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-root-candidates-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-root-candidates/{identifier}","title":"EXPLORER: Mpc custody root candidate","description":"EXPLORER: Mpc custody root candidate through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-root-candidates/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_root_candidate"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-root-candidates~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody root candidate"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody root candidate through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody root candidate before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-custody-transactions-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/custody-transactions/{identifier}","title":"EXPLORER: Mpc custody transaction","description":"EXPLORER: Mpc custody transaction through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/custody-transactions/{identifier}","source":"APIRoutes.py · view_explorer_mpc_custody_transaction"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1custody-transactions~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc custody transaction"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc custody transaction through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc custody transaction before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-devnet-faucet-claims","method":"GET","path":"/api/v2/explorer/mpc-wallets/devnet-faucet/claims","title":"EXPLORER: Mpc wallet devnet faucet claims","description":"EXPLORER: Mpc wallet devnet faucet claims through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/devnet-faucet/claims","source":"APIRoutes.py · view_explorer_mpc_wallet_devnet_faucet_claims"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1devnet-faucet~1claims/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet devnet faucet claims"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public faucet claims to return.","example":12}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet devnet faucet claims through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet devnet faucet claims before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-devnet-faucet-claims-claim-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/devnet-faucet/claims/{claim_identifier}","title":"EXPLORER: Mpc wallet devnet faucet claim","description":"EXPLORER: Mpc wallet devnet faucet claim through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/devnet-faucet/claims/{claim_identifier}","source":"APIRoutes.py · view_explorer_mpc_wallet_devnet_faucet_claim"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1devnet-faucet~1claims~1{claim_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet devnet faucet claim"],"parameters":[{"name":"claim_identifier","location":"path","required":true,"type":"identifier","description":"Canonical claim identifier.","example":"claim-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet devnet faucet claim through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet devnet faucet claim before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-devnet-faucet-independent-attestations-latest","method":"GET","path":"/api/v2/explorer/mpc-wallets/devnet-faucet/independent-attestations/latest","title":"EXPLORER: Mpc wallet devnet faucet attestation","description":"EXPLORER: Mpc wallet devnet faucet attestation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/devnet-faucet/independent-attestations/latest","source":"APIRoutes.py · view_explorer_mpc_wallet_devnet_faucet_attestation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1devnet-faucet~1independent-attestations~1latest/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet devnet faucet attestation"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet devnet faucet attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet devnet faucet attestation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-devnet-faucet-status","method":"GET","path":"/api/v2/explorer/mpc-wallets/devnet-faucet/status","title":"EXPLORER: Mpc wallet devnet faucet status","description":"EXPLORER: Mpc wallet devnet faucet status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/devnet-faucet/status","source":"APIRoutes.py · view_explorer_mpc_wallet_devnet_faucet_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1devnet-faucet~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet devnet faucet status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet devnet faucet status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet devnet faucet status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-faucets","method":"GET","path":"/api/v2/explorer/mpc-wallets/faucets","title":"EXPLORER: Mpc wallet faucets","description":"EXPLORER: Mpc wallet faucets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/faucets","source":"APIRoutes.py · view_explorer_mpc_wallet_faucets"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1faucets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet faucets"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet faucets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet faucets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-networks","method":"GET","path":"/api/v2/explorer/mpc-wallets/networks","title":"EXPLORER: Mpc wallet networks","description":"EXPLORER: Mpc wallet networks through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/networks","source":"APIRoutes.py · view_explorer_mpc_wallet_networks"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1networks/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet networks"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet networks through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet networks before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-nonmainnet-frost-evidence-evidence-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/nonmainnet/frost/evidence/{evidence_identifier}","title":"EXPLORER: Mpc nonmainnet frost evidence","description":"EXPLORER: Mpc nonmainnet frost evidence through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/nonmainnet/frost/evidence/{evidence_identifier}","source":"APIRoutes.py · view_mpc_nonmainnet_frost_evidence"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1nonmainnet~1frost~1evidence~1{evidence_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc nonmainnet frost evidence"],"parameters":[{"name":"evidence_identifier","location":"path","required":true,"type":"identifier","description":"Canonical evidence identifier.","example":"evidence-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc nonmainnet frost evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc nonmainnet frost evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-nonmainnet-frost-status-network-id","method":"GET","path":"/api/v2/explorer/mpc-wallets/nonmainnet/frost/status/{network_id}","title":"EXPLORER: Mpc nonmainnet frost status","description":"EXPLORER: Mpc nonmainnet frost status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/nonmainnet/frost/status/{network_id}","source":"APIRoutes.py · view_mpc_nonmainnet_frost_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1nonmainnet~1frost~1status~1{network_id}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc nonmainnet frost status"],"parameters":[{"name":"network_id","location":"path","required":true,"type":"identifier","description":"Canonical network id.","example":"network-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc nonmainnet frost status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc nonmainnet frost status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-security-domains","method":"GET","path":"/api/v2/explorer/mpc-wallets/security-domains","title":"EXPLORER: Mpc wallet security domains","description":"EXPLORER: Mpc wallet security domains through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/security-domains","source":"APIRoutes.py · view_explorer_mpc_wallet_security_domains"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1security-domains/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet security domains"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet security domains through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet security domains before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-security-domains-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/security-domains/{identifier}","title":"EXPLORER: Mpc wallet security domain","description":"EXPLORER: Mpc wallet security domain through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/security-domains/{identifier}","source":"APIRoutes.py · view_explorer_mpc_wallet_security_domain"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1security-domains~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet security domain"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet security domain through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet security domain before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-synthetic-assets","method":"GET","path":"/api/v2/explorer/mpc-wallets/synthetic-assets","title":"EXPLORER: Mpc synthetic assets","description":"EXPLORER: Mpc synthetic assets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-assets","source":"APIRoutes.py · view_explorer_mpc_synthetic_assets"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1synthetic-assets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc synthetic assets"],"parameters":[{"name":"network_id","location":"query","required":false,"type":"hybrid-devnet | hybrid-testnet","description":"Exact synthetic-asset network.","example":"network-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc synthetic assets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc synthetic assets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-synthetic-assets-integrity-network-id","method":"GET","path":"/api/v2/explorer/mpc-wallets/synthetic-assets/integrity/{network_id}","title":"EXPLORER: Mpc synthetic asset integrity","description":"EXPLORER: Mpc synthetic asset integrity through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-assets/integrity/{network_id}","source":"APIRoutes.py · view_explorer_mpc_synthetic_asset_integrity"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1synthetic-assets~1integrity~1{network_id}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc synthetic asset integrity"],"parameters":[{"name":"network_id","location":"path","required":true,"type":"identifier","description":"Canonical network id.","example":"network-id-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc synthetic asset integrity through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc synthetic asset integrity before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-synthetic-assets-integrity-hybrid-testnet-quorum","method":"GET","path":"/api/v2/explorer/mpc-wallets/synthetic-assets/integrity/hybrid-testnet/quorum","title":"EXPLORER: Mpc testnet synthetic asset quorum","description":"EXPLORER: Mpc testnet synthetic asset quorum through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-assets/integrity/hybrid-testnet/quorum","source":"APIRoutes.py · view_mpc_testnet_synthetic_asset_quorum"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1synthetic-assets~1integrity~1hybrid-testnet~1quorum/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet synthetic asset quorum"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet synthetic asset quorum through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet synthetic asset quorum before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-synthetic-faucet-claims-claim-uuid","method":"GET","path":"/api/v2/explorer/mpc-wallets/synthetic-faucet-claims/{claim_uuid}","title":"EXPLORER: Mpc synthetic faucet claim","description":"EXPLORER: Mpc synthetic faucet claim through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-faucet-claims/{claim_uuid}","source":"APIRoutes.py · view_explorer_mpc_synthetic_faucet_claim"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1synthetic-faucet-claims~1{claim_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc synthetic faucet claim"],"parameters":[{"name":"claim_uuid","location":"path","required":true,"type":"identifier","description":"Canonical claim uuid.","example":"claim-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc synthetic faucet claim through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc synthetic faucet claim before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-synthetic-transfers-transfer-uuid","method":"GET","path":"/api/v2/explorer/mpc-wallets/synthetic-transfers/{transfer_uuid}","title":"EXPLORER: Mpc synthetic transfer","description":"EXPLORER: Mpc synthetic transfer through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-transfers/{transfer_uuid}","source":"APIRoutes.py · view_explorer_mpc_synthetic_transfer"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1synthetic-transfers~1{transfer_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc synthetic transfer"],"parameters":[{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc synthetic transfer through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc synthetic transfer before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-faucet-claims","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet-faucet/claims","title":"EXPLORER: Mpc wallet testnet faucet claims","description":"EXPLORER: Mpc wallet testnet faucet claims through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet-faucet/claims","source":"APIRoutes.py · view_explorer_mpc_wallet_testnet_faucet_claims"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet-faucet~1claims/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet testnet faucet claims"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public faucet claims to return.","example":12}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet testnet faucet claims through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet testnet faucet claims before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-faucet-claims-claim-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet-faucet/claims/{claim_identifier}","title":"EXPLORER: Mpc wallet testnet faucet claim","description":"EXPLORER: Mpc wallet testnet faucet claim through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet-faucet/claims/{claim_identifier}","source":"APIRoutes.py · view_explorer_mpc_wallet_testnet_faucet_claim"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet-faucet~1claims~1{claim_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet testnet faucet claim"],"parameters":[{"name":"claim_identifier","location":"path","required":true,"type":"identifier","description":"Canonical claim identifier.","example":"claim-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet testnet faucet claim through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet testnet faucet claim before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-faucet-independent-attestations-latest","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet-faucet/independent-attestations/latest","title":"EXPLORER: Mpc wallet testnet faucet attestation","description":"EXPLORER: Mpc wallet testnet faucet attestation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet-faucet/independent-attestations/latest","source":"APIRoutes.py · view_explorer_mpc_wallet_testnet_faucet_attestation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet-faucet~1independent-attestations~1latest/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet testnet faucet attestation"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet testnet faucet attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet testnet faucet attestation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","identity onboarding","policy, consent, and retention disclosure"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Identity & Login","Transfer Compliance","Identity Review"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-faucet-status","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet-faucet/status","title":"EXPLORER: Mpc wallet testnet faucet status","description":"EXPLORER: Mpc wallet testnet faucet status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet-faucet/status","source":"APIRoutes.py · view_explorer_mpc_wallet_testnet_faucet_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet-faucet~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc wallet testnet faucet status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc wallet testnet faucet status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc wallet testnet faucet status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-infrastructure-evidence-evidence-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/infrastructure/evidence/{evidence_identifier}","title":"EXPLORER: Mpc testnet infrastructure evidence","description":"EXPLORER: Mpc testnet infrastructure evidence through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer","Infrastructure"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/infrastructure/evidence/{evidence_identifier}","source":"APIRoutes.py · view_mpc_testnet_infrastructure_evidence"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1infrastructure~1evidence~1{evidence_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet infrastructure evidence"],"parameters":[{"name":"evidence_identifier","location":"path","required":true,"type":"identifier","description":"Canonical evidence identifier.","example":"evidence-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet infrastructure evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet infrastructure evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-infrastructure-status","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/infrastructure/status","title":"EXPLORER: Mpc testnet infrastructure status","description":"EXPLORER: Mpc testnet infrastructure status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer","Infrastructure"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/infrastructure/status","source":"APIRoutes.py · view_mpc_testnet_infrastructure_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1infrastructure~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet infrastructure status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet infrastructure status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet infrastructure status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-lifecycle-acceptances","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/lifecycle-acceptances","title":"EXPLORER: Mpc testnet wallet lifecycle acceptances","description":"EXPLORER: Mpc testnet wallet lifecycle acceptances through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/lifecycle-acceptances","source":"APIRoutes.py · view_explorer_mpc_testnet_wallet_lifecycle_acceptances"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1lifecycle-acceptances/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet wallet lifecycle acceptances"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet wallet lifecycle acceptances through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet wallet lifecycle acceptances before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-lifecycle-acceptances-acceptance-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/lifecycle-acceptances/{acceptance_identifier}","title":"EXPLORER: Mpc testnet wallet lifecycle acceptance","description":"EXPLORER: Mpc testnet wallet lifecycle acceptance through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/lifecycle-acceptances/{acceptance_identifier}","source":"APIRoutes.py · view_explorer_mpc_testnet_wallet_lifecycle_acceptance"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1lifecycle-acceptances~1{acceptance_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet wallet lifecycle acceptance"],"parameters":[{"name":"acceptance_identifier","location":"path","required":true,"type":"identifier","description":"Canonical acceptance identifier.","example":"acceptance-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet wallet lifecycle acceptance through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet wallet lifecycle acceptance before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-settlement-integrity","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/settlement-integrity","title":"EXPLORER: Mpc testnet settlement integrity","description":"EXPLORER: Mpc testnet settlement integrity through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/settlement-integrity","source":"APIRoutes.py · view_explorer_mpc_testnet_settlement_integrity"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1settlement-integrity/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet settlement integrity"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet settlement integrity through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet settlement integrity before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-mpc-wallets-testnet-settlement-integrity-integrity-identifier","method":"GET","path":"/api/v2/explorer/mpc-wallets/testnet/settlement-integrity/{integrity_identifier}","title":"EXPLORER: Mpc testnet settlement integrity record","description":"EXPLORER: Mpc testnet settlement integrity record through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · mpc wallets","owners":["wallet-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/settlement-integrity/{integrity_identifier}","source":"APIRoutes.py · view_explorer_mpc_testnet_settlement_integrity_record"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1mpc-wallets~1testnet~1settlement-integrity~1{integrity_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mpc testnet settlement integrity record"],"parameters":[{"name":"integrity_identifier","location":"path","required":true,"type":"identifier","description":"Canonical integrity identifier.","example":"integrity-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mpc testnet settlement integrity record through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mpc testnet settlement integrity record before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-orders","method":"GET","path":"/api/v2/explorer/orders","title":"EXPLORER: Get Orders","description":"EXPLORER: Get Orders through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · orders","owners":["explorer-read-model","trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/orders","operation":"EXPLORER: Get Orders"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/orders","source":"APIRoutes.py · view_explorer_orders"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/orders","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1orders/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Orders"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Orders through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get orders before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-orders-order-reference","method":"GET","path":"/api/v2/explorer/orders/{order_reference}","title":"EXPLORER: Get Order Details","description":"EXPLORER: Get Order Details through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · orders","owners":["explorer-read-model","trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/orders/0695ca418af345d58f77498c8b8ce1e0","operation":"EXPLORER: Get Order Details"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/orders/{order_reference}","source":"APIRoutes.py · view_explorer_order"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1orders~1{order_reference}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Order Details"],"parameters":[{"name":"order_reference","location":"path","required":true,"type":"identifier","description":"Canonical order reference.","example":"order-reference-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Order Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get order details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-orders-uuid","method":"GET","path":"/api/v2/explorer/orders/{uuid}","title":"EXPLORER: · orders · uuid","description":"EXPLORER: · orders · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · orders","owners":["trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/orders/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/orders/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1orders~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· orders · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · orders · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · orders · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-prices","method":"GET","path":"/api/v2/explorer/prices","title":"EXPLORER: Prices","description":"EXPLORER: Prices through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · prices","owners":["market-data-read-model"],"applications":["Price Feeds","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/prices","source":"APIRoutes.py · view_explorer_prices"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/prices","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1prices/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Prices"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum price evidence records.","example":100},{"name":"offset","location":"query","required":false,"type":"integer · ≥0","description":"Zero-based result offset.","example":0},{"name":"instrument","location":"query","required":false,"type":"string · max 80","description":"Exact or canonical instrument filter.","example":"instrument-01"},{"name":"provider","location":"query","required":false,"type":"string · max 80","description":"Exact evidence provider filter.","example":"provider-01"},{"name":"type","location":"query","required":false,"type":"string · max 80","description":"Exact price-evidence type.","example":"type-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Prices through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to prices before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading","Developer Portal"]}},{"id":"get-api-v2-explorer-prices-evidence-uuid","method":"GET","path":"/api/v2/explorer/prices/{evidence_uuid}","title":"EXPLORER: Price","description":"EXPLORER: Price through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · prices","owners":["market-data-read-model"],"applications":["Price Feeds","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/prices/{evidence_uuid}","source":"APIRoutes.py · view_explorer_price"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1prices~1{evidence_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Price"],"parameters":[{"name":"evidence_uuid","location":"path","required":true,"type":"identifier","description":"Canonical evidence uuid.","example":"evidence-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Price through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to price before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading","Developer Portal"]}},{"id":"get-api-v2-explorer-prices-uuid","method":"GET","path":"/api/v2/explorer/prices/{uuid}","title":"EXPLORER: · prices · uuid","description":"EXPLORER: · prices · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · prices","owners":["market-data-read-model"],"applications":["Price Feeds","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/prices/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/prices/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1prices~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· prices · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · prices · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · prices · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["reference valuation","multi-source price provenance","freshness and quality monitoring","signed price-evidence replay","delivery entitlement and usage review","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a bearer credential with pricing:read","a supported canonical instrument mapping","an active or paused subscription for replay","a business-specific maximum age and acceptable quality policy"],"agentGuidance":["Never treat a returned number as usable solely because the request succeeded; require acceptable health, age, quality_state, chain_state, and quote asset.","Preserve decimal price strings exactly and never round-trip them through binary floating point.","Verify payload_hash, previous_evidence_hash, and the returned signature metadata when evidence integrity matters.","Treat next_after_sequence as an opaque feed-local progression point and keep it bound to the same feed and subscription.","A readable price feed supplies observation evidence only; it does not grant trading, matching, barrier activation, settlement, publisher, or ingress authority.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Billing","Prediction Markets","Barriers","Evidence Streams","Trading","Developer Portal"]}},{"id":"get-api-v2-explorer-search","method":"GET","path":"/api/v2/explorer/search","title":"EXPLORER: Search Chain","description":"EXPLORER: Search Chain through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · search","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/search","operation":"EXPLORER: Search Chain"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/search","source":"APIRoutes.py · view_explorer_search"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/search","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1search/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Search Chain"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Search Chain through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to search chain before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements","method":"GET","path":"/api/v2/explorer/settlements","title":"EXPLORER: Compose the settlement evidence dashboard","description":"Planning marker for the Explorer website's settlement dashboard composition. It is not an aggregate API endpoint: clients assemble the view from implemented settlement status, evidence, operations, bounded history, archive checkpoints, integrity audit, quorum canaries, authorization activations, wallet enrollments and activations, network-scoped faucet evidence, testnet infrastructure, synthetic assets, and funding settlement intents.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"documented-composition","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements","source":null}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-explorer-settlements","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Compose the settlement evidence dashboard"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Planning marker for the Explorer website's settlement dashboard composition. It is not an aggregate API endpoint: clients assemble the view from implemented settlement status, evidence, operations, bounded history, archive checkpoints, integrity audit, quorum canaries, authorization activations, wallet enrollments and activations, network-scoped faucet evidence, testnet infrastructure, synthetic assets, and funding settlement intents.","whenToUse":"Use this registry entry to discover the canonical atomic reads behind a website view. Do not issue a request to the planning path.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Do not call this path. Select atomic settlement evidence reads from the live OpenAPI contract and reconcile them using their documented identifiers and timestamps.","Apply limit, before_sequence, network_id, address, and transaction_uuid only to the settlement-evidence collection; other component reads publish their own exact parameters.","Missing optional telemetry is unknown. It does not invalidate retained settlement evidence, and it never implies network readiness or authority.","Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-record","method":"GET","path":"/api/v2/explorer/settlements/{record}","title":"EXPLORER: · settlements · record","description":"EXPLORER: · settlements · record through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/{record}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/evidence/{record}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1{record}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · record"],"parameters":[{"name":"record","location":"path","required":true,"type":"identifier","description":"Canonical record.","example":"record-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · record through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · record before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-acceptance-key","method":"GET","path":"/api/v2/explorer/settlements/acceptance-key","title":"EXPLORER: Settlement acceptance key","description":"EXPLORER: Settlement acceptance key through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/acceptance-key","source":"APIRoutes.py · view_explorer_settlement_acceptance_key"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1acceptance-key/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement acceptance key"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement acceptance key through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement acceptance key before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-acceptance-keys","method":"GET","path":"/api/v2/explorer/settlements/acceptance-keys","title":"EXPLORER: Settlement acceptance keys","description":"EXPLORER: Settlement acceptance keys through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/acceptance-keys","source":"APIRoutes.py · view_explorer_settlement_acceptance_keys"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1acceptance-keys/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement acceptance keys"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement acceptance keys through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement acceptance keys before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-archive-checkpoints","method":"GET","path":"/api/v2/explorer/settlements/archive-checkpoints","title":"EXPLORER: Settlement archive checkpoints","description":"EXPLORER: Settlement archive checkpoints through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/archive-checkpoints","source":"APIRoutes.py · view_explorer_settlement_archive_checkpoints"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1archive-checkpoints/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement archive checkpoints"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement archive checkpoints through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement archive checkpoints before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-archive-checkpoints-latest","method":"GET","path":"/api/v2/explorer/settlements/archive-checkpoints/latest","title":"EXPLORER: Settlement archive checkpoint latest","description":"EXPLORER: Settlement archive checkpoint latest through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/archive-checkpoints/latest","source":"APIRoutes.py · view_explorer_settlement_archive_checkpoint_latest"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1archive-checkpoints~1latest/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement archive checkpoint latest"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement archive checkpoint latest through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement archive checkpoint latest before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-authorization-activations","method":"GET","path":"/api/v2/explorer/settlements/authorization-activations","title":"EXPLORER: Settlement authorization activations","description":"EXPLORER: Settlement authorization activations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/authorization-activations","source":"APIRoutes.py · view_explorer_settlement_authorization_activations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1authorization-activations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement authorization activations"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement authorization activations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement authorization activations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-authorization-activations-activation-identifier","method":"GET","path":"/api/v2/explorer/settlements/authorization-activations/{activation_identifier}","title":"EXPLORER: Settlement authorization activation","description":"EXPLORER: Settlement authorization activation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/authorization-activations/{activation_identifier}","source":"APIRoutes.py · view_explorer_settlement_authorization_activation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1authorization-activations~1{activation_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement authorization activation"],"parameters":[{"name":"activation_identifier","location":"path","required":true,"type":"identifier","description":"Canonical activation identifier.","example":"activation-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement authorization activation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement authorization activation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-authorizations-identifier","method":"GET","path":"/api/v2/explorer/settlements/authorizations/{identifier}","title":"EXPLORER: · settlements · authorizations · identifier","description":"EXPLORER: · settlements · authorizations · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/authorizations/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/authorization-activations/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1authorizations~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · authorizations · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · authorizations · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · authorizations · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-canaries-commitment","method":"GET","path":"/api/v2/explorer/settlements/canaries/{commitment}","title":"EXPLORER: · settlements · canaries · commitment","description":"EXPLORER: · settlements · canaries · commitment through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/canaries/{commitment}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/quorum-canaries/{commitment}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1canaries~1{commitment}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · canaries · commitment"],"parameters":[{"name":"commitment","location":"path","required":true,"type":"identifier","description":"Canonical commitment.","example":"commitment-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · canaries · commitment through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · canaries · commitment before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-evidence","method":"GET","path":"/api/v2/explorer/settlements/evidence","title":"EXPLORER: Settlement evidence","description":"EXPLORER: Settlement evidence through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/evidence","source":"APIRoutes.py · view_explorer_settlement_evidence"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1evidence/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement evidence"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum settlement-evidence records to return.","example":50},{"name":"before_sequence","location":"query","required":false,"type":"integer","description":"Return records preceding this Core sequence.","example":1},{"name":"network_id","location":"query","required":false,"type":"network identifier","description":"Exact public network filter.","example":"network-id-01"},{"name":"address","location":"query","required":false,"type":"network address","description":"Exact public address filter.","example":"address-01"},{"name":"transaction_uuid","location":"query","required":false,"type":"identifier","description":"Exact settlement transaction filter.","example":"transaction-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-evidence-record-identifier","method":"GET","path":"/api/v2/explorer/settlements/evidence/{record_identifier}","title":"EXPLORER: Settlement evidence detail","description":"EXPLORER: Settlement evidence detail through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/evidence/{record_identifier}","source":"APIRoutes.py · view_explorer_settlement_evidence_detail"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1evidence~1{record_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement evidence detail"],"parameters":[{"name":"record_identifier","location":"path","required":true,"type":"identifier","description":"Canonical record identifier.","example":"record-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement evidence detail through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement evidence detail before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-faucet-claims-identifier","method":"GET","path":"/api/v2/explorer/settlements/faucet-claims/{identifier}","title":"EXPLORER: Resolve a network-scoped faucet claim","description":"Planning marker for a website helper that guesses whether an identifier belongs to the devnet or testnet faucet. Canonical integrations must choose the network explicitly and call either the implemented devnet-faucet or testnet-faucet claim read.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"documented-composition","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/faucet-claims/{identifier}","source":null}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-explorer-settlements-faucet-claims-identifier","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Resolve a network-scoped faucet claim"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Planning marker for a website helper that guesses whether an identifier belongs to the devnet or testnet faucet. Canonical integrations must choose the network explicitly and call either the implemented devnet-faucet or testnet-faucet claim read.","whenToUse":"Use this registry entry to discover the canonical atomic reads behind a website view. Do not issue a request to the planning path.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Do not call this ambiguous path. Use /api/v2/explorer/mpc-wallets/devnet-faucet/claims/{claim_identifier} or /api/v2/explorer/mpc-wallets/testnet-faucet/claims/{claim_identifier}.","Persist network_id with every claim identifier; do not probe both networks to infer business state.","A faucet claim is test-network evidence only and conveys no balance, settlement, production-network, or trading authority.","Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-faucets","method":"GET","path":"/api/v2/explorer/settlements/faucets","title":"EXPLORER: · settlements · faucets","description":"EXPLORER: · settlements · faucets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/faucets","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/faucets","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1faucets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · faucets"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · faucets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · faucets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-integrity-audit","method":"GET","path":"/api/v2/explorer/settlements/integrity-audit","title":"EXPLORER: Settlement integrity audit","description":"EXPLORER: Settlement integrity audit through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/integrity-audit","source":"APIRoutes.py · view_explorer_settlement_integrity_audit"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1integrity-audit/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement integrity audit"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement integrity audit through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement integrity audit before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-mainnet-readiness","method":"GET","path":"/api/v2/explorer/settlements/mainnet-readiness","title":"EXPLORER: Mainnet readiness evidence","description":"EXPLORER: Mainnet readiness evidence through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/mainnet-readiness","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1mainnet-readiness/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mainnet readiness evidence"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum retained readiness evaluations.","example":12}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mainnet readiness evidence through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mainnet readiness evidence before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-mainnet-readiness-status","method":"GET","path":"/api/v2/explorer/settlements/mainnet-readiness/status","title":"EXPLORER: Mainnet readiness status","description":"EXPLORER: Mainnet readiness status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/mainnet-readiness/status","source":"Explorer website adapter · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1mainnet-readiness~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Mainnet readiness status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Mainnet readiness status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to mainnet readiness status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-network-promotions","method":"GET","path":"/api/v2/explorer/settlements/network-promotions","title":"EXPLORER: Settlement network promotions","description":"EXPLORER: Settlement network promotions through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/network-promotions","source":"APIRoutes.py · view_explorer_settlement_network_promotions"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1network-promotions/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement network promotions"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement network promotions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement network promotions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-network-promotions-promotion-identifier","method":"GET","path":"/api/v2/explorer/settlements/network-promotions/{promotion_identifier}","title":"EXPLORER: Settlement network promotion","description":"EXPLORER: Settlement network promotion through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/network-promotions/{promotion_identifier}","source":"APIRoutes.py · view_explorer_settlement_network_promotion"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1network-promotions~1{promotion_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement network promotion"],"parameters":[{"name":"promotion_identifier","location":"path","required":true,"type":"identifier","description":"Canonical promotion identifier.","example":"promotion-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement network promotion through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement network promotion before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-operations","method":"GET","path":"/api/v2/explorer/settlements/operations","title":"EXPLORER: Settlement operations","description":"EXPLORER: Settlement operations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/operations","source":"APIRoutes.py · view_explorer_settlement_operations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1operations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement operations"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement operations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement operations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-operations-history","method":"GET","path":"/api/v2/explorer/settlements/operations/history","title":"EXPLORER: Settlement operations history","description":"EXPLORER: Settlement operations history through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/operations/history","source":"APIRoutes.py · view_explorer_settlement_operations_history"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1operations~1history/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement operations history"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement operations history through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement operations history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-promotions-identifier","method":"GET","path":"/api/v2/explorer/settlements/promotions/{identifier}","title":"EXPLORER: · settlements · promotions · identifier","description":"EXPLORER: · settlements · promotions · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/promotions/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/network-promotions/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1promotions~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · promotions · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · promotions · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · promotions · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-quorum-canaries","method":"GET","path":"/api/v2/explorer/settlements/quorum-canaries","title":"EXPLORER: Settlement quorum canaries","description":"EXPLORER: Settlement quorum canaries through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/quorum-canaries","source":"APIRoutes.py · view_explorer_settlement_quorum_canaries"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1quorum-canaries/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement quorum canaries"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement quorum canaries through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement quorum canaries before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-quorum-canaries-canary-commitment","method":"GET","path":"/api/v2/explorer/settlements/quorum-canaries/{canary_commitment}","title":"EXPLORER: Settlement quorum canary","description":"EXPLORER: Settlement quorum canary through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/quorum-canaries/{canary_commitment}","source":"APIRoutes.py · view_explorer_settlement_quorum_canary"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1quorum-canaries~1{canary_commitment}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement quorum canary"],"parameters":[{"name":"canary_commitment","location":"path","required":true,"type":"identifier","description":"Canonical canary commitment.","example":"canary-commitment-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement quorum canary through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement quorum canary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-replication-batch","method":"GET","path":"/api/v2/explorer/settlements/replication-batch","title":"EXPLORER: Settlement replication batch","description":"EXPLORER: Settlement replication batch through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/replication-batch","source":"APIRoutes.py · view_explorer_settlement_replication_batch"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1replication-batch/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement replication batch"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement replication batch through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement replication batch before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-status","method":"GET","path":"/api/v2/explorer/settlements/status","title":"EXPLORER: Settlement evidence status","description":"EXPLORER: Settlement evidence status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/status","source":"APIRoutes.py · view_explorer_settlement_evidence_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement evidence status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement evidence status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement evidence status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-supply-gate","method":"GET","path":"/api/v2/explorer/settlements/supply-gate","title":"EXPLORER: · settlements · supply gate","description":"EXPLORER: · settlements · supply gate through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/supply-gate","source":null},{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations/latest","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1supply-gate/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · supply gate"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · supply gate through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · supply gate before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-supply-gate-attestations","method":"GET","path":"/api/v2/explorer/settlements/supply-gate/attestations","title":"EXPLORER: · settlements · supply gate · attestations","description":"EXPLORER: · settlements · supply gate · attestations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/supply-gate/attestations","source":null},{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1supply-gate~1attestations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · supply gate · attestations"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · supply gate · attestations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · supply gate · attestations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-supply-gate-attestations-commitment","method":"GET","path":"/api/v2/explorer/settlements/supply-gate/attestations/{commitment}","title":"EXPLORER: · settlements · supply gate · attestations · commitment","description":"EXPLORER: · settlements · supply gate · attestations · commitment through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/supply-gate/attestations/{commitment}","source":null},{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations/{commitment}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1supply-gate~1attestations~1{commitment}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · supply gate · attestations · commitment"],"parameters":[{"name":"commitment","location":"path","required":true,"type":"identifier","description":"Canonical commitment.","example":"commitment-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · supply gate · attestations · commitment through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · supply gate · attestations · commitment before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-supply-gate-policy","method":"GET","path":"/api/v2/explorer/settlements/supply-gate/policy","title":"EXPLORER: · settlements · supply gate · policy","description":"EXPLORER: · settlements · supply gate · policy through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/supply-gate/policy","source":null},{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/policy","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1supply-gate~1policy/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · supply gate · policy"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · supply gate · policy through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · supply gate · policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-supply-gate-status","method":"GET","path":"/api/v2/explorer/settlements/supply-gate/status","title":"EXPLORER: · settlements · supply gate · status","description":"EXPLORER: · settlements · supply gate · status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/supply-gate/status","source":null},{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/status","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1supply-gate~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · supply gate · status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · supply gate · status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · supply gate · status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-synthetic-assets","method":"GET","path":"/api/v2/explorer/settlements/synthetic-assets","title":"EXPLORER: · settlements · synthetic assets","description":"EXPLORER: · settlements · synthetic assets through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/synthetic-assets","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-assets","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1synthetic-assets/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · synthetic assets"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · synthetic assets through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · synthetic assets before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-synthetic-assets-quorum","method":"GET","path":"/api/v2/explorer/settlements/synthetic-assets/quorum","title":"EXPLORER: · settlements · synthetic assets · quorum","description":"EXPLORER: · settlements · synthetic assets · quorum through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/synthetic-assets/quorum","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/synthetic-assets/integrity/hybrid-testnet/quorum","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1synthetic-assets~1quorum/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · synthetic assets · quorum"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · synthetic assets · quorum through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · synthetic assets · quorum before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-testnet-candidates","method":"GET","path":"/api/v2/explorer/settlements/testnet-candidates","title":"EXPLORER: Settlement testnet candidates","description":"EXPLORER: Settlement testnet candidates through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/testnet-candidates","source":"APIRoutes.py · view_explorer_settlement_testnet_candidates"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/testnet-candidates","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1testnet-candidates/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement testnet candidates"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement testnet candidates through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement testnet candidates before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-testnet-candidates-candidate-identifier","method":"GET","path":"/api/v2/explorer/settlements/testnet-candidates/{candidate_identifier}","title":"EXPLORER: Settlement testnet candidate","description":"EXPLORER: Settlement testnet candidate through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/testnet-candidates/{candidate_identifier}","source":"APIRoutes.py · view_explorer_settlement_testnet_candidate"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1testnet-candidates~1{candidate_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement testnet candidate"],"parameters":[{"name":"candidate_identifier","location":"path","required":true,"type":"identifier","description":"Canonical candidate identifier.","example":"candidate-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement testnet candidate through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement testnet candidate before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-testnet-candidates-identifier","method":"GET","path":"/api/v2/explorer/settlements/testnet-candidates/{identifier}","title":"EXPLORER: · settlements · testnet candidates · identifier","description":"EXPLORER: · settlements · testnet candidates · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/testnet-candidates/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/testnet-candidates/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1testnet-candidates~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · testnet candidates · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · testnet candidates · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · testnet candidates · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-testnet-infrastructure","method":"GET","path":"/api/v2/explorer/settlements/testnet-infrastructure","title":"EXPLORER: · settlements · testnet infrastructure","description":"EXPLORER: · settlements · testnet infrastructure through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer","Infrastructure"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/testnet-infrastructure","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/infrastructure/status","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1testnet-infrastructure/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · testnet infrastructure"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · testnet infrastructure through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · testnet infrastructure before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval","service health review","testnet infrastructure evidence verification","account growth and readiness trending"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams","Admin Console","Indexer Controller"]}},{"id":"get-api-v2-explorer-settlements-testnet-infrastructure-identifier","method":"GET","path":"/api/v2/explorer/settlements/testnet-infrastructure/{identifier}","title":"EXPLORER: · settlements · testnet infrastructure · identifier","description":"EXPLORER: · settlements · testnet infrastructure · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer","Infrastructure"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/testnet-infrastructure/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/testnet/infrastructure/evidence/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1testnet-infrastructure~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · testnet infrastructure · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · testnet infrastructure · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · testnet infrastructure · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval","service health review","testnet infrastructure evidence verification","account growth and readiness trending"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams","Admin Console","Indexer Controller"]}},{"id":"get-api-v2-explorer-settlements-wallet-activations","method":"GET","path":"/api/v2/explorer/settlements/wallet-activations","title":"EXPLORER: Settlement wallet activations","description":"EXPLORER: Settlement wallet activations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-activations","source":"APIRoutes.py · view_explorer_settlement_wallet_activations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-activations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement wallet activations"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement wallet activations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement wallet activations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-activations-activation-identifier","method":"GET","path":"/api/v2/explorer/settlements/wallet-activations/{activation_identifier}","title":"EXPLORER: Settlement wallet activation","description":"EXPLORER: Settlement wallet activation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-activations/{activation_identifier}","source":"APIRoutes.py · view_explorer_settlement_wallet_activation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-activations~1{activation_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement wallet activation"],"parameters":[{"name":"activation_identifier","location":"path","required":true,"type":"identifier","description":"Canonical activation identifier.","example":"activation-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement wallet activation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement wallet activation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-activations-identifier","method":"GET","path":"/api/v2/explorer/settlements/wallet-activations/{identifier}","title":"EXPLORER: · settlements · wallet activations · identifier","description":"EXPLORER: · settlements · wallet activations · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/wallet-activations/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-activations/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-activations~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · wallet activations · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · wallet activations · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · wallet activations · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-enrollments","method":"GET","path":"/api/v2/explorer/settlements/wallet-enrollments","title":"EXPLORER: Settlement wallet enrollments","description":"EXPLORER: Settlement wallet enrollments through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-enrollments","source":"APIRoutes.py · view_explorer_settlement_wallet_enrollments"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-enrollments/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement wallet enrollments"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–100","description":"Maximum public settlement records to return.","example":25}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement wallet enrollments through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement wallet enrollments before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-enrollments-enrollment-identifier","method":"GET","path":"/api/v2/explorer/settlements/wallet-enrollments/{enrollment_identifier}","title":"EXPLORER: Settlement wallet enrollment","description":"EXPLORER: Settlement wallet enrollment through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-enrollments/{enrollment_identifier}","source":"APIRoutes.py · view_explorer_settlement_wallet_enrollment"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-enrollments~1{enrollment_identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Settlement wallet enrollment"],"parameters":[{"name":"enrollment_identifier","location":"path","required":true,"type":"identifier","description":"Canonical enrollment identifier.","example":"enrollment-identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Settlement wallet enrollment through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to settlement wallet enrollment before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-enrollments-identifier","method":"GET","path":"/api/v2/explorer/settlements/wallet-enrollments/{identifier}","title":"EXPLORER: · settlements · wallet enrollments · identifier","description":"EXPLORER: · settlements · wallet enrollments · identifier through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Wallets","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/wallet-enrollments/{identifier}","source":null},{"catalog":"core","method":"GET","path":"/explorer/settlements/wallet-enrollments/{identifier}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-enrollments~1{identifier}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · wallet enrollments · identifier"],"parameters":[{"name":"identifier","location":"path","required":true,"type":"identifier","description":"Canonical identifier.","example":"identifier-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · wallet enrollments · identifier through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · wallet enrollments · identifier before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","chain and transaction lookup","asset and contract verification"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-settlements-wallet-networks","method":"GET","path":"/api/v2/explorer/settlements/wallet-networks","title":"EXPLORER: · settlements · wallet networks","description":"EXPLORER: · settlements · wallet networks through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · settlements","owners":["settlement-evidence-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/settlements/wallet-networks","source":null},{"catalog":"core","method":"GET","path":"/explorer/mpc-wallets/networks","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1settlements~1wallet-networks/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· settlements · wallet networks"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · settlements · wallet networks through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · settlements · wallet networks before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-strategies","method":"GET","path":"/api/v2/explorer/strategies","title":"EXPLORER: Strategies","description":"EXPLORER: Strategies through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · strategies","owners":["strategy-evidence-read-model"],"applications":["Strategy Pools","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/strategies","source":"APIRoutes.py · view_explorer_strategies"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/strategies","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1strategies/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Strategies"],"parameters":[{"name":"strategy_code","location":"query","required":false,"type":"strategy code · max 96","description":"Exact canonical strategy code.","example":"strategy-code-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Strategies through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to strategies before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Liquidity Management","Trust Center","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-strategies-execution-uuid","method":"GET","path":"/api/v2/explorer/strategies/{execution_uuid}","title":"EXPLORER: Strategy","description":"EXPLORER: Strategy through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · strategies","owners":["strategy-evidence-read-model"],"applications":["Strategy Pools","Execution Studio","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/strategies/{execution_uuid}","source":"APIRoutes.py · view_explorer_strategy"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1strategies~1{execution_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Strategy"],"parameters":[{"name":"execution_uuid","location":"path","required":true,"type":"identifier","description":"Canonical execution uuid.","example":"execution-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Strategy through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to strategy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","content-addressed package development","reproducible build and policy validation","immutable private, workspace, or public publication"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Liquidity Management","Trust Center","Contract Studio","Barriers","Evidence Streams"]}},{"id":"get-api-v2-explorer-strategy-pools","method":"GET","path":"/api/v2/explorer/strategy-pools","title":"EXPLORER: Strategy pools","description":"EXPLORER: Strategy pools through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · strategy pools","owners":["strategy-evidence-read-model"],"applications":["Strategy Pools","Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/strategy-pools","source":"APIRoutes.py · view_explorer_strategy_pools"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/strategy-pools","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1strategy-pools/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Strategy pools"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Strategy pools through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to strategy pools before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Trust Center","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-strategy-pools-pool-reference","method":"GET","path":"/api/v2/explorer/strategy-pools/{pool_reference}","title":"EXPLORER: Strategy pool","description":"EXPLORER: Strategy pool through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · strategy pools","owners":["strategy-evidence-read-model"],"applications":["Strategy Pools","Liquidity Management","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/strategy-pools/{pool_reference}","source":"APIRoutes.py · view_explorer_strategy_pool"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1strategy-pools~1{pool_reference}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Strategy pool"],"parameters":[{"name":"pool_reference","location":"path","required":true,"type":"identifier","description":"Canonical pool reference.","example":"pool-reference-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Strategy pool through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to strategy pool before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["strategy discovery","allocation tracking","performance and lifecycle review","pool monitoring","liquidity allocation planning","flow and performance reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an eligible portfolio and jurisdiction","current strategy disclosures and limits"],"agentGuidance":["Historical performance is not execution authority or a return guarantee.","Re-read terms and capacity before any allocation mutation.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Trading","Trust Center","Wallets","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-summary","method":"GET","path":"/api/v2/explorer/summary","title":"EXPLORER: Get Chain Summary","description":"EXPLORER: Get Chain Summary through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · summary","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/summary","operation":"EXPLORER: Get Chain Summary"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/summary","source":"APIRoutes.py · view_explorer_summary"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/summary","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1summary/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Chain Summary"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Chain Summary through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get chain summary before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-testnet-supply-gate-attestations","method":"GET","path":"/api/v2/explorer/testnet/supply-gate/attestations","title":"EXPLORER: Testnet supply gate attestations","description":"EXPLORER: Testnet supply gate attestations through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · testnet","owners":["explorer-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations","source":"APIRoutes.py · view_explorer_testnet_supply_gate_attestations"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1testnet~1supply-gate~1attestations/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Testnet supply gate attestations"],"parameters":[{"name":"limit","location":"query","required":false,"type":"integer · 1–200","description":"Maximum attestations to return.","example":50},{"name":"cursor","location":"query","required":false,"type":"opaque string","description":"Cursor returned by the previous page.","example":"eyJvZmZzZXQiOjUwfQ"},{"name":"observer","location":"query","required":false,"type":"identifier","description":"Exact observer filter.","example":"observer-01"},{"name":"commitment","location":"query","required":false,"type":"SHA-256 commitment","description":"Exact attestation commitment.","example":"commitment-01"},{"name":"from","location":"query","required":false,"type":"RFC 3339 timestamp","description":"Inclusive observation start.","example":"2026-09-30T20:00:00Z"},{"name":"to","location":"query","required":false,"type":"RFC 3339 timestamp","description":"Inclusive observation end.","example":"2026-09-30T20:00:00Z"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Testnet supply gate attestations through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to testnet supply gate attestations before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-testnet-supply-gate-attestations-commitment","method":"GET","path":"/api/v2/explorer/testnet/supply-gate/attestations/{commitment}","title":"EXPLORER: Testnet supply gate attestation","description":"EXPLORER: Testnet supply gate attestation through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · testnet","owners":["explorer-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations/{commitment}","source":"APIRoutes.py · view_explorer_testnet_supply_gate_attestation"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1testnet~1supply-gate~1attestations~1{commitment}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Testnet supply gate attestation"],"parameters":[{"name":"commitment","location":"path","required":true,"type":"identifier","description":"Canonical commitment.","example":"commitment-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Testnet supply gate attestation through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to testnet supply gate attestation before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-testnet-supply-gate-attestations-latest","method":"GET","path":"/api/v2/explorer/testnet/supply-gate/attestations/latest","title":"EXPLORER: Testnet supply gate latest","description":"EXPLORER: Testnet supply gate latest through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · testnet","owners":["explorer-read-model"],"applications":["Trust Center","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/attestations/latest","source":"APIRoutes.py · view_explorer_testnet_supply_gate_latest"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1testnet~1supply-gate~1attestations~1latest/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Testnet supply gate latest"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Testnet supply gate latest through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to testnet supply gate latest before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["identity onboarding","policy, consent, and retention disclosure","KYC/AML posture review","age or eligibility commitment review","credential and attestation lifecycle reconciliation","subject claim management"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","subject-scoped trust authority for subject actions, with separate issuer or reviewer authority for their own future lifecycles","an applicable policy ID, immutable version, jurisdiction, evidence purpose, consent record, and retention basis","a relying-party rule for acceptable issuer, proof type, lifecycle, freshness, assurance, disclosure, and revocation checking"],"agentGuidance":["Trust signals are scoped, versioned, purpose-limited, and time-bound evidence—not a universal score or permission to pay, transfer, trade, disclose, administer, or bypass another domain's policy.","No one authority substitutes for another: a subject can consent and manage eligible claims, a provider can report bounded evidence, a reviewer can evaluate an assigned case, an issuer can create or revoke its credential, and a relying party can apply its own acceptance policy.","A policy catalog entry means a workflow is available; it does not mean the subject started, completed, or passed it. A provider callback, captured evidence item, completed check, reviewer action, final decision, issued credential, and relying-party acceptance are distinct lifecycle facts.","Evaluate verification status and checks, credential or attestation lifecycle, validity window, issuer signature posture, proof type, assurance, revocation freshness, and commitments together.","Treat verification evidence as metadata plus commitments, not retrievable media; keep claim cleartext, personal and address data, identity documents, selfies, biometric material, screening matches, provider payloads, and reviewer notes out of prompts, URLs, logs, analytics, and shared caches.","A self-asserted claim may be unverified and include_in_credential is intent only; never represent either as issuer-backed assurance or evidence of disclosure consent.","Legacy KYC payload, generic action, review, attestation, provider-callback, and sanctions-sync routes are bodyless 501 migration markers at the public V2 boundary. Never translate their legacy bodies; use only canonical operations present in live OpenAPI.","Reviewer queues and decisions, regulated evidence upload or retrieval, provider callbacks, sanctions synchronization, selective-disclosure challenges and presentations, and credential issuance, suspension, or revocation remain non-executable publicly until their exact owner-specific contracts appear in live OpenAPI.","Trading, matching, prediction, ingress, publisher, allowlist, suspension, market-status, and traffic controls remain frozen and cannot be changed by a trust signal, verification result, credential, attestation, claim, or compatibility route.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Identity & Login","Transfer Compliance","Identity Review","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-testnet-supply-gate-policy","method":"GET","path":"/api/v2/explorer/testnet/supply-gate/policy","title":"EXPLORER: Testnet supply gate policy","description":"EXPLORER: Testnet supply gate policy through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · testnet","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/policy","source":"APIRoutes.py · view_explorer_testnet_supply_gate_policy"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1testnet~1supply-gate~1policy/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Testnet supply gate policy"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Testnet supply gate policy through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to testnet supply gate policy before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-testnet-supply-gate-status","method":"GET","path":"/api/v2/explorer/testnet/supply-gate/status","title":"EXPLORER: Testnet supply gate status","description":"EXPLORER: Testnet supply gate status through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · testnet","owners":["explorer-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/testnet/supply-gate/status","source":"APIRoutes.py · view_explorer_testnet_supply_gate_status"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1testnet~1supply-gate~1status/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Testnet supply gate status"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Testnet supply gate status through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to testnet supply gate status before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-trades","method":"GET","path":"/api/v2/explorer/trades","title":"EXPLORER: Get Trades","description":"EXPLORER: Get Trades through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · trades","owners":["explorer-read-model","trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/trades","operation":"EXPLORER: Get Trades"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/trades","source":"APIRoutes.py · view_explorer_trades"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/trades","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1trades/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Trades"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Trades through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get trades before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-trades-trade-uuid","method":"GET","path":"/api/v2/explorer/trades/{trade_uuid}","title":"EXPLORER: Get Trade Details","description":"EXPLORER: Get Trade Details through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · trades","owners":["explorer-read-model","trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/trades/274d57e0823a4bb2bde937983e0450d8","operation":"EXPLORER: Get Trade Details"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/trades/{trade_uuid}","source":"APIRoutes.py · view_explorer_trade"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1trades~1{trade_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Trade Details"],"parameters":[{"name":"trade_uuid","location":"path","required":true,"type":"identifier","description":"Canonical trade uuid.","example":"trade-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Trade Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get trade details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-trades-uuid","method":"GET","path":"/api/v2/explorer/trades/{uuid}","title":"EXPLORER: · trades · uuid","description":"EXPLORER: · trades · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · trades","owners":["trading-read-model"],"applications":["Trading","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/trades/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/trades/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1trades~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· trades · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · trades · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · trades · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["market discovery","order and position monitoring","trade and balance reconciliation","chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","venue and market eligibility","explicit trading scope for mutations"],"agentGuidance":["A listed contract or readable market never enables order ingress or changes matching authority.","Respect the documented trading freeze and treat HTTP 202 as command acceptance only.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Strategy Pools","Liquidity Management","Trading & Matching Ops","Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-transactions","method":"GET","path":"/api/v2/explorer/transactions","title":"EXPLORER: Get All Transactions","description":"EXPLORER: Get All Transactions through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transactions","owners":["explorer-read-model","ledger-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/transactions","operation":"EXPLORER: Get All Transactions"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/transactions","source":"APIRoutes.py · view_explorer_transactions"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/transactions","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transactions/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get All Transactions"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get All Transactions through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all transactions before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-transactions-transaction-hash","method":"GET","path":"/api/v2/explorer/transactions/{transaction_hash}","title":"EXPLORER: Get Transaction Details","description":"EXPLORER: Get Transaction Details through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transactions","owners":["explorer-read-model","ledger-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/transactions/TRANSACTION_HASH","operation":"EXPLORER: Get Transaction Details"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/transactions/{transaction_hash}","source":"APIRoutes.py · view_explorer_transaction"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transactions~1{transaction_hash}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Transaction Details"],"parameters":[{"name":"transaction_hash","location":"path","required":true,"type":"identifier","description":"Canonical transaction hash.","example":"transaction-hash-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Transaction Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get transaction details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-transactions-uuid","method":"GET","path":"/api/v2/explorer/transactions/{uuid}","title":"EXPLORER: · transactions · uuid","description":"EXPLORER: · transactions · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transactions","owners":["ledger-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/transactions/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/transactions/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transactions~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· transactions · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · transactions · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · transactions · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-transfers","method":"GET","path":"/api/v2/explorer/transfers","title":"EXPLORER: Transfer compliance records","description":"EXPLORER: Transfer compliance records through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transfers","owners":["transfer-compliance-read-model"],"applications":["Transfer Compliance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/transfers","source":"APIRoutes.py · view_explorer_transfer_compliance_records"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/transfers","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transfers/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer compliance records"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Transfer compliance records through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to transfer compliance records before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-explorer-transfers-transfer-uuid","method":"GET","path":"/api/v2/explorer/transfers/{transfer_uuid}","title":"EXPLORER: Transfer compliance record","description":"EXPLORER: Transfer compliance record through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transfers","owners":["transfer-compliance-read-model"],"applications":["Transfer Compliance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/transfers/{transfer_uuid}","source":"APIRoutes.py · view_explorer_transfer_compliance_record"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transfers~1{transfer_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer compliance record"],"parameters":[{"name":"transfer_uuid","location":"path","required":true,"type":"identifier","description":"Canonical transfer uuid.","example":"transfer-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Transfer compliance record through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to transfer compliance record before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["Travel Rule and IVMS101 orchestration","counterparty screening and key selection","pre-settlement transfer eligibility","credential and wallet-control readiness","signed compliance evidence reconciliation","chain and transaction lookup"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","an authenticated owner profile","compliance:read for reads, compliance:write for subject workflow commands, or compliance:review for decisions","RFC 9421 request signing and a stable Idempotency-Key for every command","a defined jurisdictional and transfer policy","caller-owned acceptance rules for credentials, counterparties, evidence freshness, and state"],"agentGuidance":["Generate calls from deployed OpenAPI and bind every transfer, credential, vault, wallet, manifest, envelope authorization, and counterparty identifier to the authenticated owner and original workflow.","Never place regulated identity data, raw credentials, ciphertext, private endpoints, or settlement material in prompts, metadata, logs, or caches; the API accepts and returns commitments and applies no-store responses.","Reuse an Idempotency-Key only for the exact same method, path, owner, and body; generate a new key after any intended input change.","VASP candidate registration is not credential issuance, and envelope authorization neither receives nor delivers ciphertext; formal issuer and reviewer authority remain separate.","readiness.transfer_ready is prerequisite posture, proof_state=INTACT is evidence-chain continuity, and an APPROVED decision is compliance evidence; none of them signs, broadcasts, settles, or moves value.","Re-fetch counterparty and transfer state before use, preserve decimal amount strings exactly, tolerate new enumerated policy values, and fail closed when policy does not recognize a state.","The two remaining planned operations are non-executable until their separate formal credential issuance and assignment-filtered review-queue authority gates are completed.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Payments","Trust Center","Data Vault","Business Network","Evidence Streams","Wallets"]}},{"id":"get-api-v2-explorer-transfers-mpc-authorizations-authorization-uuid","method":"GET","path":"/api/v2/explorer/transfers/mpc-authorizations/{authorization_uuid}","title":"EXPLORER: Transfer compliance mpc authorization","description":"EXPLORER: Transfer compliance mpc authorization through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transfers","owners":["transfer-compliance-read-model"],"applications":["Wallets","Transfer Compliance","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/transfers/mpc-authorizations/{authorization_uuid}","source":"APIRoutes.py · view_explorer_transfer_compliance_mpc_authorization"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1transfers~1mpc-authorizations~1{authorization_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Transfer compliance mpc authorization"],"parameters":[{"name":"authorization_uuid","location":"path","required":true,"type":"identifier","description":"Canonical authorization uuid.","example":"authorization-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Transfer compliance mpc authorization through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to transfer compliance mpc authorization before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["wallet onboarding","portfolio and balance review","network-aware token discovery and enablement","custody lifecycle governance","Travel Rule and IVMS101 orchestration","counterparty screening and key selection"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","wallet scopes for the requested action","an active workspace and supported network","a registered public request-signing key and fresh purpose-bound step-up for sensitive mutations","approved custody, participant-domain, threshold, recovery, screening, and evidence policies"],"agentGuidance":["Never send entropy, mnemonic words, seeds, private keys, MPC shares, signing nonces, passwords, password hashes, encrypted password blobs, banking credentials, or reusable custody secrets.","Use opaque owner-safe wallet, destination, funding, and policy references; the bearer supplies workspace and owner boundaries.","Treat a contract asset as the pair (network_id, contract_address). Require the user or integration to select a network returned by /api/v2/wallets/token-import-networks; never guess, silently default, or rewrite the network or address.","Catalog visibility and custom-token enablement are portfolio metadata only. They do not create or activate a chain wallet and grant no enrollment, signing, withdrawal, broadcast, trading, or value authority.","Preparation, enrollment, attestation, activation, approval, estimate, intent, customer authorization, reservation, threshold signing, submission, confirmation, settlement, reversal, and recovery are distinct states; none implies another.","Preserve quantities, balances, amounts, and fees as exact decimal strings and bind mutations to last-read versions and commitments.","Treat legacy /api/v2/wallet/* mutations as bodyless 501 migration markers and verify every canonical replacement in live OpenAPI before calling it.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Governance","Funding","AI Wallet Control","Payments","Trust Center","Data Vault"]}},{"id":"get-api-v2-explorer-transfers-native","method":"GET","path":"/api/v2/explorer/transfers/native","title":"EXPLORER: Project native settlement transfers","description":"Planning marker for the Explorer website's native-transfer view. Canonical integrations read the implemented funding settlement-intents collection and interpret only the documented intent type, network, currency, amount, state, consent, sequence, and commitment fields.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · transfers","owners":["transfer-compliance-read-model"],"applications":["Chain Explorer"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"documented-composition","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/transfers/native","source":null}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-explorer-transfers-native","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Project native settlement transfers"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Planning marker for the Explorer website's native-transfer view. Canonical integrations read the implemented funding settlement-intents collection and interpret only the documented intent type, network, currency, amount, state, consent, sequence, and commitment fields.","whenToUse":"Use this registry entry to discover the canonical atomic reads behind a website view. Do not issue a request to the planning path.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["chain and transaction lookup","asset and contract verification","public proof retrieval"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","a canonical public identifier or bounded search","awareness of chain finality and indexing lag"],"agentGuidance":["Do not call this alias. Use /api/v2/explorer/funding/settlement-intents with its optional limit, then follow the exact intent read when detail is required.","Filter only from returned typed fields; do not infer completion from display labels, missing proof events, or HTTP success.","A settlement intent is evidence of a requested or progressing transfer. Only its documented terminal state and retained proof establish completion.","Distinguish indexed projection time from chain finality.","Use exact identifiers and proof endpoints; do not scrape the website.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Developer Portal","Digital Assets","Evidence Streams"]}},{"id":"get-api-v2-explorer-vault-assets-uuid","method":"GET","path":"/api/v2/explorer/vault-assets/{uuid}","title":"EXPLORER: Compose public vault asset holdings","description":"Planning marker for the Explorer website's vault-holdings composition. Canonical integrations list assets with owner_vault_uuid, fetch exact asset records when holding-level detail is needed, and optionally join the public vault and vault-history reads by vault UUID.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · vault assets","owners":["custody-read-model"],"applications":["Data Vault","Chain Explorer"],"authentication":"none","exposure":"public","status":"planned-contract","parity":"documented-composition","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/vault-assets/{uuid}","source":null}],"contract":{"authority":"capability-registry","reference":"/api/v2/capabilities#get-api-v2-explorer-vault-assets-uuid","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"planned-profiled","requestShapeAuthority":"capability-registry-profile","exampleDisclaimer":"Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.","uxActions":["Compose public vault asset holdings"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"Planning marker for the Explorer website's vault-holdings composition. Canonical integrations list assets with owner_vault_uuid, fetch exact asset records when holding-level detail is needed, and optionally join the public vault and vault-history reads by vault UUID.","whenToUse":"Use this registry entry to discover the canonical atomic reads behind a website view. Do not issue a request to the planning path.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Do not call this website composition. Start with /api/v2/explorer/assets?owner_vault_uuid={uuid}&limit={limit}&offset={offset}.","For each returned asset UUID, call /api/v2/explorer/assets/{asset_uuid} only when holdings, supply, issuer, or proof detail is required; bound fan-out and cache immutable identifiers.","Join holdings where holding.vault_uuid exactly matches the requested vault UUID and preserve decimal balances as strings.","Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","This is a non-executable planning contract. Do not call it until the operation appears in the live production OpenAPI document."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-vaults","method":"GET","path":"/api/v2/explorer/vaults","title":"EXPLORER: Get All Vaults","description":"EXPLORER: Get All Vaults through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · vaults","owners":["custody-read-model","explorer-read-model"],"applications":["Data Vault","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/vaults","operation":"EXPLORER: Get All Vaults"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/vaults","source":"APIRoutes.py · view_explorer_vaults"},{"catalog":"website-adapter","method":"GET","path":"/api/explorer/vaults","source":null}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1vaults/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get All Vaults"],"parameters":[],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get All Vaults through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get all vaults before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-vaults-uuid","method":"GET","path":"/api/v2/explorer/vaults/{uuid}","title":"EXPLORER: · vaults · uuid","description":"EXPLORER: · vaults · uuid through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · vaults","owners":["custody-read-model"],"applications":["Data Vault","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"explorer-expansion","sourceKinds":["explorer-expansion"],"legacySources":[],"runtimeSources":[{"catalog":"website-adapter","method":"GET","path":"/api/explorer/vaults/{uuid}","source":null},{"catalog":"core","method":"GET","path":"/explorer/vaults/{uuid}","source":"Explorer website alias · exact Core read"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1vaults~1{uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["· vaults · uuid"],"parameters":[{"name":"uuid","location":"path","required":true,"type":"identifier","description":"Canonical uuid.","example":"uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: · vaults · uuid through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to · vaults · uuid before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-vaults-vault-uuid","method":"GET","path":"/api/v2/explorer/vaults/{vault_uuid}","title":"EXPLORER: Get Vault Details","description":"EXPLORER: Get Vault Details through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · vaults","owners":["custody-read-model","explorer-read-model"],"applications":["Data Vault","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/vaults/b00dc220da8f480d86cdc+15555550123","operation":"EXPLORER: Get Vault Details"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/vaults/{vault_uuid}","source":"APIRoutes.py · view_explorer_vault"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1vaults~1{vault_uuid}/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Vault Details"],"parameters":[{"name":"vault_uuid","location":"path","required":true,"type":"identifier","description":"Canonical vault uuid.","example":"vault-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Vault Details through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get vault details before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network","Developer Portal","Digital Assets"]}},{"id":"get-api-v2-explorer-vaults-vault-uuid-history","method":"GET","path":"/api/v2/explorer/vaults/{vault_uuid}/history","title":"EXPLORER: Get Vault History","description":"EXPLORER: Get Vault History through the canonical Hybrid-Chain V2 interface.","chapter":"Explorer","chapterOrder":35,"capability":"Explorer · vaults","owners":["custody-read-model","explorer-read-model"],"applications":["Data Vault","Chain Explorer"],"authentication":"none","exposure":"public","status":"implemented-contract","parity":"equivalent","sourceKinds":["explorer-expansion","v1-parity"],"legacySources":[{"method":"GET","path":"/explorer/vaults/b00dc220da8f480d86cdc+15555550123/history","operation":"EXPLORER: Get Vault History"}],"runtimeSources":[{"catalog":"core","method":"GET","path":"/explorer/vaults/{vault_uuid}/history","source":"APIRoutes.py · view_explorer_vault_history"}],"contract":{"authority":"openapi","reference":"/api/v2/openapi.json#/paths/~1api~1v2~1explorer~1vaults~1{vault_uuid}~1history/get","scope":"none","idempotency":false,"maturity":"source-derived","documentationStatus":"implemented-openapi","requestShapeAuthority":"openapi","exampleDisclaimer":"Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.","uxActions":["Get Vault History"],"parameters":[{"name":"vault_uuid","location":"path","required":true,"type":"identifier","description":"Canonical vault uuid.","example":"vault-uuid-01"}],"responses":[{"status":200,"description":"Canonical resource projection.","example":null},{"status":422,"description":"Path, query, or body validation failed.","example":null},{"status":503,"description":"The authoritative service or read model is unavailable.","example":null}],"notes":["The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly."]},"businessContext":{"purpose":"EXPLORER: Get Vault History through the canonical Hybrid-Chain V2 interface.","whenToUse":"Use this operation when an integration needs to get vault history before selecting or reconciling a later action.","workflowRole":"discover-or-read","sideEffects":"Read-only projection; it grants no mutation, settlement, traffic, or authority change.","businessCases":["protected document inventory and bounded directory navigation","client-encrypted multipart storage","purpose- and recipient-bound retrieval","controlled sharing and grant revocation","retention, recycle, restore, and cryptographic-erasure governance","private-to-public evidence reconciliation"],"prerequisites":["No bearer token is required, but resource-specific availability and freshness rules still apply.","vault:read for implemented private reads and a separately promoted vault:write contract for mutations","an authenticated active workspace derived from the bearer","classification, retention, legal-hold, encryption, quota, recipient, and disclosure policy","a client-side encryption and key-management boundary outside the gateway","caller-owned rules for evidence freshness, storage readiness, ticket handling, and public-anchor finality"],"agentGuidance":["Keep cleartext content, base64 payloads, encryption or decryption material, object names, recipient identities, tickets, opaque content roots, private storage endpoints, and raw storage metadata out of shared prompts, logs, analytics, caches, URLs, and agent memory.","Use stable object identifiers for navigation and reconciliation; names and paths are mutable presentation values and never authorization keys.","Treat storage_readiness=READY, encrypted_content_root, shard counts, event commitments, and anchor state as limited posture. None grants download, decryption, sharing, disclosure, retention change, restore, or erasure authority.","A sharing invitation is not a grant, a grant is not delivery, a ticket is not decryption authority, revocation cannot claw back previously obtained cleartext, and a database deleted flag or IPFS unpin is not cryptographic-erasure proof.","Traverse deliberately with bounded depth and re-read current owner or grant state before every dependent action; another workspace's object must remain indistinguishable from a missing object.","The ten legacy /api/v2/quantum/storage/* POST routes are bodyless 501 migration markers. Do not translate their legacy bodies or infer canonical request schemas from caller-selected vault IDs, base64 content, raw metadata, or direct-download behavior.","Never call a planned modern lifecycle contract until its exact operation appears in the live production OpenAPI document.","Generate the executable request from the referenced OpenAPI operation; this narrative adds context but does not replace the machine schema."],"relatedApplications":["Transfer Compliance","Evidence Streams","Business Network","Developer Portal","Digital Assets"]}}]}