Skip to content

API reference

Generated from openapi.yaml. For the concepts behind these endpoints — how grants stay live, how the trust chain is walked, what a callback delivers — start with the guides alongside this section.

Group Covers
Discovery Unauthenticated endpoints describing the server itself. These anchor the DNS trust chain: a verifier reads _revoked.<domain> from DNS,…
Identity Identity material and, more importantly, whether the issuer still stands behind it. A certificate is minted for ten years and its parent…
Shares Reading a share by slug. The probe reports gates without revealing data; the resolve returns data and consumes a view.
Requests Submitting data to a request by slug.
Invites Previewing and accepting a workspace invitation.
Workspaces Membership and account-level operations.
Records The vault. Records hold the values that shares resolve at read time.
Grants Shares and requests as owned resources.
Sign-in People sign in with a passkey and nothing else; there are no passwords. A passkey is bound to the address it was made at, so the…
Connections Tools the owner connected. A tool proposes shares (revoked://p) and, once connected, reads the status of the links its proposals…
Schemas Shapes shared across more than one endpoint.

Machine-readable spec

The OpenAPI document is the source these pages are generated from. Point a client generator or an HTTP client at it directly rather than transcribing from here.