Skip to content

Schemas

Shapes shared across more than one endpoint.

AppError

The stable error envelope. Key off code, never off message — the prose may change, the code will not.

Messages may echo what the caller sent, never server-held state: an error outlives the credential that produced it and lands in logs and screenshots read by people who hold no key.

Field Type Notes
code string
message string
status integer

IdentityStatusAssertion

A root-signed statement about one fingerprint.

Field Type Notes
payload string Base64url JSON. Its first field is type: identity-status-v1, which is what stops the endpoint being a signing oracle.
signature string Root key signature over the payload.

Member

Field Type Notes
id string
user string
email string
role string (admin | member) Derived, never chosen: set to admin exactly when the member may invite. Gate on permissions, not on this.
permissions array of Permission
isSelf boolean
isLastAdmin boolean Removing them would leave the workspace unadministrable.
joined string

Permission

Field Type Notes
key string
label string
description string
destructive boolean Whether holding it lets someone extend or revoke other people's access.
membersOnly boolean Grantable to a member, never to an API key. The vault permissions are: creating a key with one, or with a scope of one, fails with api_key_vault_scope.
scopes array of string What the permission expands to when stored.

ServerClaim

What the serving domain claims about itself. Verify it against DNS.

Field Type Notes
domain string
rootFingerprint string

Sharer

The identity behind a share or request. Every field here is a claim until the chain is walked: fetch the named domain's root key, confirm it against DNS, verify parentSignature, then ask the issuer whether the identity still stands.

Field Type Notes
identityId string
name string
fingerprint string
parentSignature string
domainAtIssue string
status string (active | revoked)
statusAssertion IdentityStatusAssertion The issuer's signed answer, stapled so a verifier need not make a second round trip.

TemplateItem

Field Type Notes
key string
label string
type string
format string
required boolean
reason string Why the requester is asking for it.
records array of TemplateItem Present when this item is a section.