Schemas
Shapes shared across more than one endpoint.
AppError
The stable error envelope. Key off code, never off message — the
prose may change, the code will not.
Messages may echo what the caller sent, never server-held state: an
error outlives the credential that produced it and lands in logs and
screenshots read by people who hold no key.
| Field |
Type |
Notes |
code |
string |
|
message |
string |
|
status |
integer |
|
IdentityStatusAssertion
A root-signed statement about one fingerprint.
| Field |
Type |
Notes |
payload |
string |
Base64url JSON. Its first field is type: identity-status-v1, which is what stops the endpoint being a signing oracle. |
signature |
string |
Root key signature over the payload. |
Member
| Field |
Type |
Notes |
id |
string |
|
user |
string |
|
email |
string |
|
role |
string (admin | member) |
Derived, never chosen: set to admin exactly when the member may invite. Gate on permissions, not on this. |
permissions |
array of Permission |
|
isSelf |
boolean |
|
isLastAdmin |
boolean |
Removing them would leave the workspace unadministrable. |
joined |
string |
|
Permission
| Field |
Type |
Notes |
key |
string |
|
label |
string |
|
description |
string |
|
destructive |
boolean |
Whether holding it lets someone extend or revoke other people's access. |
membersOnly |
boolean |
Grantable to a member, never to an API key. The vault permissions are: creating a key with one, or with a scope of one, fails with api_key_vault_scope. |
scopes |
array of string |
What the permission expands to when stored. |
ServerClaim
What the serving domain claims about itself. Verify it against DNS.
| Field |
Type |
Notes |
domain |
string |
|
rootFingerprint |
string |
|
Sharer
The identity behind a share or request. Every field here is a claim
until the chain is walked: fetch the named domain's root key, confirm
it against DNS, verify parentSignature, then ask the issuer whether
the identity still stands.
| Field |
Type |
Notes |
identityId |
string |
|
name |
string |
|
fingerprint |
string |
|
parentSignature |
string |
|
domainAtIssue |
string |
|
status |
string (active | revoked) |
|
statusAssertion |
IdentityStatusAssertion |
The issuer's signed answer, stapled so a verifier need not make a second round trip. |
TemplateItem
| Field |
Type |
Notes |
key |
string |
|
label |
string |
|
type |
string |
|
format |
string |
|
required |
boolean |
|
reason |
string |
Why the requester is asking for it. |
records |
array of TemplateItem |
Present when this item is a section. |