Discovery¶
Unauthenticated endpoints describing the server itself. These anchor the
DNS trust chain: a verifier reads _revoked.<domain> from DNS, fetches
the root key here, and checks that the two agree before believing
anything an identity signed.
GET /healthz¶
Liveness probe
Unauthenticated
Callable with no credential.
Returns ok when the process is serving. Used by the container healthcheck.
Responses
| Status | Meaning |
|---|---|
200 |
Serving. |
GET /api/server¶
Server identity and domain claim
Unauthenticated
Callable with no credential.
The server's domain claim, root public key and a freshly signed assertion, plus the TXT record an operator must publish.
A verifier compares fingerprint against the _revoked.<domain> TXT
record. They must agree; the served key alone proves nothing, since
whoever serves the response also chooses what it says.
Responses
| Status | Meaning |
|---|---|
200 |
The server's claim about itself. |
Response fields
| Field | Type | Notes |
|---|---|---|
domain |
string | The domain this server claims. |
fingerprint |
string | SHA-256 fingerprint of the root public key. |
publicKey |
string | Root public key |
assertion |
object | A freshly signed statement of the above. |
txt |
object | The DNS record an operator publishes to complete the chain. |
limits |
object | Operator policy a client should respect before uploading. |
GET /api/permissions¶
Permission catalogue
Unauthenticated
Callable with no credential.
The permissions a member or API key can hold, and the scopes each expands to. Grants are stored expanded, so this is what lets a stored grant be named back as the permissions that were picked.
Serving it means a client never has to hardcode scope strings and drift from what the server enforces.
Responses
| Status | Meaning |
|---|---|
200 |
The catalogue. |
Response fields
| Field | Type | Notes |
|---|---|---|
permissions |
array of Permission |
GET /api/certificate¶
Server certificate, public material only
Unauthenticated
Callable with no credential.
Public key material for this server's certificate authority. The private half is filtered out before serialization and is never served.
Responses
| Status | Meaning |
|---|---|
200 |
Public view of the server certificate. |