{"apiVersion":"v1","release":"3.9.0-beta.39","documentation":"/developers","readOnly":true,"authentication":"none","cors":{"enabled":true,"credentials":false,"methods":["GET","OPTIONS"]},"rateLimit":{"requests":60,"intervalSeconds":60,"scope":"default per-IP bucket for public v1 reference routes","overrides":[{"endpoint":"/api/v1/evidence-collections","requests":30,"intervalSeconds":60},{"endpoint":"/api/v1/change-events","requests":30,"intervalSeconds":60},{"endpoint":"/api/v1/agent/*","requests":30,"intervalSeconds":60}]},"cache":{"maxAgeSeconds":300,"policy":"public, max-age=60, s-maxage=300"},"boundaries":["Only public evidence or curated public-reference metadata is exposed.","The API does not expose policy text, raw failure reasons, admin logs, private records, or credentials. Evidence collections may repeat public snapshot and packet fingerprints already exposed by the selected Evidence Packets.","Observatory entries are a curated local registry with review timestamps, not an automated external news feed.","Published records remain subject to source availability and public-evidence gates.","The change-event feed is a forward-polling surface. It does not confirm notification delivery or replace future signed webhook controls.","The residency evidence pack distinguishes public documents, operator declarations, deployment-dependent facts and open evidence; it does not prove the live deployment region."],"residencyEvidence":{"endpoint":"/api/v1/residency-evidence","contract":"dated bounded evidence register with deterministic SHA-256 digest","humanReview":"/trust/residency"},"agentGateway":{"contract":"/api/v1/agent/openapi.json","operations":["/api/v1/agent/capabilities","/api/v1/agent/change-brief","/api/v1/agent/observatory-brief"],"responseShape":"flattened deterministic public evidence brief","inputBoundary":"Bounded filters only; no prompt transcript, document body or selected contract text."},"sources":[{"id":"dashboardCompanies","endpoint":"/api/companies","method":"GET","evidenceGate":"public-policy","freshness":{"mode":"request","maxAgeSeconds":0},"allowedPathParams":[],"allowedQueryParams":[],"description":"Public companies with gated policies and their latest public change."},{"id":"companyComparison","endpoint":"/api/compare","method":"GET","evidenceGate":"public-change","freshness":{"mode":"request","maxAgeSeconds":0},"allowedPathParams":[],"allowedQueryParams":["companyA","companyB"],"description":"Evidence-gated company and industry KPI benchmark profiles."},{"id":"marketPulse","endpoint":"/api/changes","method":"GET","evidenceGate":"public-change","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":["company","from","industry","kpi","page","pageSize","q","risk","to"],"description":"Paginated public policy-change event stream."},{"id":"policyDetails","endpoint":"/api/policies/{policyId}","method":"GET","evidenceGate":"public-change","freshness":{"mode":"request","maxAgeSeconds":0},"allowedPathParams":["policyId"],"allowedQueryParams":[],"description":"Public policy detail with gated snapshots and public change analysis."},{"id":"sourceSuspensions","endpoint":"/api/source-suspensions","method":"GET","evidenceGate":"public-suspension","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":[],"description":"Sanitized metadata for sources withheld by publication gates."},{"id":"sourceContinuity","endpoint":"/api/source-continuity","method":"GET","evidenceGate":"public-suspension","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":[],"description":"Sanitized history of source retrieval and publication-state transitions."},{"id":"observatoryRegistry","endpoint":"/api/v1/observatory","method":"GET","evidenceGate":"public-reference","freshness":{"mode":"short-ttl","maxAgeSeconds":300},"allowedPathParams":[],"allowedQueryParams":["lang"],"description":"Curated public registry of governance, privacy, standards and event references."},{"id":"evidenceCollections","endpoint":"/api/v1/evidence-collections","method":"GET","evidenceGate":"public-change","freshness":{"mode":"short-ttl","maxAgeSeconds":300},"allowedPathParams":[],"allowedQueryParams":["changes","format"],"description":"Deterministic JSON, Markdown, CSV or vendor-neutral review handoff for up to 12 exact public change records."},{"id":"publicChangeEvents","endpoint":"/api/v1/change-events","method":"GET","evidenceGate":"public-change","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":["cursor","lang","limit"],"description":"Forward-only polling feed for already-published policy change events."},{"id":"webhookVerificationKit","endpoint":"/api/v1/webhook-verification-kit","method":"GET","evidenceGate":"public-reference","freshness":{"mode":"short-ttl","maxAgeSeconds":86400},"allowedPathParams":[],"allowedQueryParams":[],"description":"Versioned receiver-verification contract, public test vector and implementation examples; no delivery service."},{"id":"webhookConformanceSuite","endpoint":"/api/v1/webhook-conformance-suite","method":"GET","evidenceGate":"public-reference","freshness":{"mode":"short-ttl","maxAgeSeconds":86400},"allowedPathParams":[],"allowedQueryParams":[],"description":"Eight deterministic positive and negative receiver cases; no endpoint or delivery test."},{"id":"riskTrends","endpoint":"/api/trends","method":"GET","evidenceGate":"public-change","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":["companyId","industry"],"description":"Chronological public risk-change observations with snapshot provenance."},{"id":"kpiMatrix","endpoint":"/api/matrix","method":"GET","evidenceGate":"public-policy","freshness":{"mode":"short-ttl","maxAgeSeconds":60},"allowedPathParams":[],"allowedQueryParams":[],"description":"Cross-company KPI aggregation over public policy evidence."}]}