{
  "components": {
    "schemas": {
      "Agent": {
        "additionalProperties": false,
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "owner_id": {
            "type": "string"
          },
          "public_key": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Authorization": {
        "additionalProperties": false,
        "properties": {
          "approver_id": {
            "type": "string"
          },
          "created_at": {
            "format": "int64",
            "type": "integer"
          },
          "delegation": {
            "$ref": "#/components/schemas/Delegation"
          },
          "envelope": {
            "$ref": "#/components/schemas/Envelope"
          },
          "id": {
            "type": "string"
          },
          "intent": {
            "$ref": "#/components/schemas/Intent"
          },
          "intent_digest": {
            "type": "string"
          },
          "policy": {
            "$ref": "#/components/schemas/Policy"
          },
          "provider_reference": {
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Checkpoint": {
        "additionalProperties": false,
        "properties": {
          "at": {
            "format": "int64",
            "type": "integer"
          },
          "digest": {
            "type": "string"
          },
          "org_id": {
            "type": "string"
          },
          "sequence": {
            "format": "int64",
            "type": "integer"
          }
        },
        "type": "object"
      },
      "CreateAgentRequest": {
        "additionalProperties": false,
        "properties": {
          "name": {
            "type": "string"
          },
          "public_key": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "CreateDeveloperKeyRequest": {
        "additionalProperties": false,
        "properties": {
          "expires_at": {
            "format": "int64",
            "type": "integer"
          },
          "name": {
            "type": "string"
          },
          "per_day": {
            "format": "int64",
            "type": "integer"
          },
          "per_minute": {
            "format": "int64",
            "type": "integer"
          },
          "scopes": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "CreatedDeveloperKey": {
        "additionalProperties": false,
        "properties": {
          "key": {
            "$ref": "#/components/schemas/DeveloperKey"
          },
          "token": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "DecisionRequest": {
        "additionalProperties": false,
        "properties": {
          "decision": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "intent_digest": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Delegation": {
        "additionalProperties": false,
        "properties": {
          "agent_id": {
            "type": "string"
          },
          "budget_minor": {
            "format": "int64",
            "type": "integer"
          },
          "expires_at": {
            "format": "int64",
            "type": "integer"
          },
          "id": {
            "type": "string"
          },
          "owner_id": {
            "type": "string"
          },
          "policy_id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "DeveloperKey": {
        "additionalProperties": false,
        "properties": {
          "created_at": {
            "format": "int64",
            "type": "integer"
          },
          "expires_at": {
            "format": "int64",
            "type": "integer"
          },
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "per_day": {
            "format": "int64",
            "type": "integer"
          },
          "per_minute": {
            "format": "int64",
            "type": "integer"
          },
          "revoked": {
            "type": "boolean"
          },
          "scopes": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "DeveloperKeys": {
        "additionalProperties": false,
        "properties": {
          "keys": {
            "items": {
              "$ref": "#/components/schemas/DeveloperKey"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "DeveloperUsage": {
        "additionalProperties": false,
        "properties": {
          "buckets": {
            "items": {
              "$ref": "#/components/schemas/UsageBucket"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "Empty": {
        "additionalProperties": false,
        "properties": {},
        "type": "object"
      },
      "Envelope": {
        "additionalProperties": false,
        "properties": {
          "payload": {
            "type": "string"
          },
          "signature": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Error": {
        "properties": {
          "error": {
            "properties": {
              "code": {
                "type": "string"
              },
              "message": {
                "type": "string"
              }
            },
            "type": "object"
          }
        },
        "type": "object"
      },
      "Event": {
        "additionalProperties": false,
        "properties": {
          "digest": {
            "type": "string"
          },
          "key_id": {
            "type": "string"
          },
          "payload": {
            "type": "string"
          },
          "sequence": {
            "format": "int64",
            "type": "integer"
          },
          "signature": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Evidence": {
        "additionalProperties": false,
        "properties": {
          "checkpoint": {
            "$ref": "#/components/schemas/Envelope"
          },
          "events": {
            "items": {
              "$ref": "#/components/schemas/Event"
            },
            "type": "array"
          },
          "format": {
            "type": "string"
          },
          "key_id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Health": {
        "additionalProperties": false,
        "properties": {
          "execution_mode": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ImportResult": {
        "additionalProperties": false,
        "properties": {
          "duplicates": {
            "format": "int64",
            "type": "integer"
          },
          "inserted": {
            "format": "int64",
            "type": "integer"
          },
          "source": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Intent": {
        "additionalProperties": false,
        "properties": {
          "action": {
            "type": "string"
          },
          "agent_id": {
            "type": "string"
          },
          "amount_minor": {
            "format": "int64",
            "type": "integer"
          },
          "audience": {
            "type": "string"
          },
          "authorization_id": {
            "type": "string"
          },
          "currency": {
            "type": "string"
          },
          "delegation_id": {
            "type": "string"
          },
          "expires_at": {
            "format": "int64",
            "type": "integer"
          },
          "intent_digest": {
            "type": "string"
          },
          "item_id": {
            "type": "string"
          },
          "nonce": {
            "type": "string"
          },
          "org_id": {
            "type": "string"
          },
          "quantity": {
            "format": "int64",
            "type": "integer"
          },
          "supplier_id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Item": {
        "additionalProperties": false,
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "supplier_id": {
            "type": "string"
          },
          "unit_minor": {
            "format": "int64",
            "type": "integer"
          }
        },
        "type": "object"
      },
      "LoginRequest": {
        "additionalProperties": false,
        "properties": {
          "email": {
            "type": "string"
          },
          "password": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "Ok": {
        "additionalProperties": false,
        "properties": {
          "ok": {
            "type": "boolean"
          }
        },
        "type": "object"
      },
      "Policy": {
        "additionalProperties": false,
        "properties": {
          "approval_above_minor": {
            "format": "int64",
            "type": "integer"
          },
          "currency": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "per_action_minor": {
            "format": "int64",
            "type": "integer"
          },
          "suppliers": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "version": {
            "format": "int64",
            "type": "integer"
          }
        },
        "type": "object"
      },
      "ProviderEvent": {
        "additionalProperties": false,
        "properties": {
          "amount_minor": {
            "format": "int64",
            "type": "integer"
          },
          "currency": {
            "type": "string"
          },
          "event_id": {
            "type": "string"
          },
          "fee_minor": {
            "format": "int64",
            "type": "integer"
          },
          "occurred_at": {
            "format": "int64",
            "type": "integer"
          },
          "reference": {
            "type": "string"
          },
          "revision": {
            "format": "int64",
            "type": "integer"
          },
          "status": {
            "type": "string"
          },
          "supplier_id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ProviderFeed": {
        "additionalProperties": false,
        "properties": {
          "events": {
            "items": {
              "$ref": "#/components/schemas/ProviderEvent"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "ReconItem": {
        "additionalProperties": false,
        "properties": {
          "authorization_id": {
            "type": "string"
          },
          "event_ids": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "expected_amount_minor": {
            "format": "int64",
            "type": "integer"
          },
          "expected_currency": {
            "type": "string"
          },
          "expected_supplier_id": {
            "type": "string"
          },
          "key": {
            "type": "string"
          },
          "observed": {
            "$ref": "#/components/schemas/ProviderEvent"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "reference": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ReconReview": {
        "additionalProperties": false,
        "properties": {
          "actor": {
            "type": "string"
          },
          "created_at": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "item_key": {
            "type": "string"
          },
          "note": {
            "type": "string"
          },
          "run_id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ReconRun": {
        "additionalProperties": false,
        "properties": {
          "at": {
            "format": "int64",
            "type": "integer"
          },
          "counts": {
            "additionalProperties": {
              "format": "int64",
              "type": "integer"
            },
            "type": "object"
          },
          "event_count": {
            "format": "int64",
            "type": "integer"
          },
          "id": {
            "type": "string"
          },
          "items": {
            "items": {
              "$ref": "#/components/schemas/ReconItem"
            },
            "type": "array"
          },
          "source": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ReconciliationState": {
        "additionalProperties": false,
        "properties": {
          "event_count": {
            "format": "int64",
            "type": "integer"
          },
          "reviews": {
            "items": {
              "$ref": "#/components/schemas/ReconReview"
            },
            "type": "array"
          },
          "runs": {
            "items": {
              "$ref": "#/components/schemas/ReconRun"
            },
            "type": "array"
          },
          "source": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ResourceRequest": {
        "additionalProperties": false,
        "properties": {
          "id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "ReviewRequest": {
        "additionalProperties": false,
        "properties": {
          "item_key": {
            "type": "string"
          },
          "note": {
            "type": "string"
          },
          "run_id": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "State": {
        "additionalProperties": false,
        "properties": {
          "agents": {
            "items": {
              "$ref": "#/components/schemas/Agent"
            },
            "type": "array"
          },
          "authorizations": {
            "items": {
              "$ref": "#/components/schemas/Authorization"
            },
            "type": "array"
          },
          "catalog": {
            "items": {
              "$ref": "#/components/schemas/Item"
            },
            "type": "array"
          },
          "delegations": {
            "items": {
              "$ref": "#/components/schemas/Delegation"
            },
            "type": "array"
          },
          "execution_mode": {
            "type": "string"
          },
          "organization": {
            "type": "string"
          },
          "policies": {
            "items": {
              "$ref": "#/components/schemas/Policy"
            },
            "type": "array"
          },
          "user": {
            "$ref": "#/components/schemas/User"
          }
        },
        "type": "object"
      },
      "TrustRoot": {
        "additionalProperties": false,
        "properties": {
          "key_id": {
            "type": "string"
          },
          "public_key": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "UsageBucket": {
        "additionalProperties": false,
        "properties": {
          "bucket": {
            "type": "string"
          },
          "enabled": {
            "type": "boolean"
          },
          "per_day": {
            "format": "int64",
            "type": "integer"
          },
          "per_minute": {
            "format": "int64",
            "type": "integer"
          },
          "used_day": {
            "format": "int64",
            "type": "integer"
          },
          "used_minute": {
            "format": "int64",
            "type": "integer"
          }
        },
        "type": "object"
      },
      "User": {
        "additionalProperties": false,
        "properties": {
          "email": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "org_id": {
            "type": "string"
          },
          "role": {
            "type": "string"
          }
        },
        "type": "object"
      }
    },
    "securitySchemes": {
      "developerKey": {
        "bearerFormat": "trl_dev_…",
        "scheme": "bearer",
        "type": "http"
      },
      "session": {
        "in": "cookie",
        "name": "trellis_session",
        "type": "apiKey"
      }
    }
  },
  "info": {
    "description": "Generated from proto/trellis/v1/trellis.proto. Go + PostgreSQL, simulated payments only. HTTP uses snake_case numeric JSON, not canonical ProtoJSON int64 strings. Signed payloads remain opaque base64url bytes; no reserialization before verification. Financial amounts are integer USD cents. Developer keys only support authorize and execute scopes; human administration remains session-authenticated.",
    "title": "Trellis local application API",
    "version": "0.2.0"
  },
  "openapi": "3.0.3",
  "paths": {
    "/auth/login": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "Login",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/LoginRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/User"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": []
      }
    },
    "/auth/logout": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "Logout",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Empty"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Ok"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": []
      }
    },
    "/healthz": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetHealth",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Health"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": []
      }
    },
    "/v1/agents": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "CreateAgent",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateAgentRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Agent"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/approvals/{id}/decision": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "DecideApproval",
        "parameters": [
          {
            "in": "path",
            "name": "id",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "additionalProperties": false,
                "properties": {
                  "decision": {
                    "type": "string"
                  },
                  "intent_digest": {
                    "type": "string"
                  }
                },
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Authorization"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/authorizations": {
      "post": {
        "description": "Requires a scoped developer key (or same-organization human session) AND a valid agent signature over the unchanged Envelope payload bytes. Durable usage quotas apply, including retries and policy denials. API keys never replace delegation or payment budgets.",
        "operationId": "Authorize",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Envelope"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Authorization"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          },
          {
            "developerKey": []
          }
        ]
      }
    },
    "/v1/delegations": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "CreateDelegation",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Delegation"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Delegation"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/delegations/{id}/revoke": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "RevokeDelegation",
        "parameters": [
          {
            "in": "path",
            "name": "id",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "additionalProperties": false,
                "properties": {},
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Delegation"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/developer-keys": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "ListDeveloperKeys",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeveloperKeys"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      },
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "CreateDeveloperKey",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateDeveloperKeyRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CreatedDeveloperKey"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/developer-keys/{id}/revoke": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "RevokeDeveloperKey",
        "parameters": [
          {
            "in": "path",
            "name": "id",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "additionalProperties": false,
                "properties": {},
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Ok"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/developer-usage": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetDeveloperUsage",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeveloperUsage"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/evidence": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetEvidence",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Evidence"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/executions": {
      "post": {
        "description": "Requires a scoped developer key (or same-organization human session) AND a valid agent signature over the unchanged Envelope payload bytes. Durable usage quotas apply, including retries and policy denials. API keys never replace delegation or payment budgets.",
        "operationId": "Execute",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Envelope"
              }
            }
          },
          "required": true
        },
        "responses": {
          "202": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Authorization"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          },
          {
            "developerKey": []
          }
        ]
      }
    },
    "/v1/policies": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "CreatePolicy",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Policy"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Policy"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/reconciliation": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetReconciliation",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReconciliationState"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/reconciliation/example-feed": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetExampleFeed",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ProviderFeed"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/reconciliation/import": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "ImportProviderEvents",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ProviderFeed"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ImportResult"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/reconciliation/reviews": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "ReviewReconciliation",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReviewRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReconReview"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/reconciliation/runs": {
      "post": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "RunReconciliation",
        "parameters": [
          {
            "description": "Must exactly equal APP_ORIGIN. Also send Content-Type: application/json.",
            "in": "header",
            "name": "Origin",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Empty"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReconRun"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/state": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetState",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/State"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    },
    "/v1/trust-root": {
      "get": {
        "description": "Human session required. Organization and role checks are enforced server-side.",
        "operationId": "GetTrustRoot",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TrustRoot"
                }
              }
            },
            "description": "Success"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Usage or concurrency limit exceeded; retry after the indicated seconds. No new domain work is started.",
            "headers": {
              "Retry-After": {
                "schema": {
                  "type": "integer"
                }
              }
            }
          },
          "default": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            },
            "description": "Request error"
          }
        },
        "security": [
          {
            "session": []
          }
        ]
      }
    }
  },
  "servers": [
    {
      "url": "http://localhost:8080"
    }
  ]
}
