Nappr machine API
Anonymous-friendly reference for the public surface of the platform.
Download the raw OpenAPI 3.0 contract for use with code generators and SDK clients.
Operator health
Anonymous, no auth required.
| Method | Path | Description |
|---|---|---|
GET |
/healthz/live |
Always-200 liveness probe (no database call). Used by orchestrators. |
GET |
/healthz |
DB-aware readiness probe. Returns 200 with {"status":"Healthy","checks":[{"name":"database",...}]} or 503 when degraded. |
GET |
/Status |
Public-safe human-readable status page (this deployment). |
Machine API: catalog
Authenticated with an API client. The rate limit is 120 requests / minute per client.
| Method | Path | Description |
|---|---|---|
GET |
/api/v1/platform/me |
Returns the calling API client's tenantId, apiClientId, and granted scopes. Requires policy catalog.read. |
GET |
/api/v1/tenants/{tenantId}/platform/me |
Same payload, but bound to the tenant in the URL. Requires policy tenant.catalog.read. The token's tenant_id claim must equal the path tenantId; mismatches are rejected with 404. |
Both routes require headers X-Api-Client-Identifier and X-Api-Client-Secret (or Authorization: ApiKey {id}:{secret}). Bad credentials return 401. Cross-tenant attempts return 404 (not 403) so tenant existence is not leaked.
OpenAPI contract
Machine-readable contract served at /openapi.json.
The full OpenAPI 3.0 document is available at /openapi.json. It includes all operator health and machine-API routes, request/response schemas, and security schemes.
Browser surface (anonymous)
Razor pages and admin endpoints.
| Path | Auth | Description |
|---|---|---|
/ | Public | Landing page with live platform status and CTA. |
/Status | Public | Live health snapshot (this page). |
/Docs | Public | This page. |
/Home/Privacy | Public | Privacy statement. |
/Access/Request | Public | Self-service "request access" form. Creates a Pending tenant and an access.requested audit row. |
/Account/Login | Public | Identity sign-in (cookie session). |
/Account/Register | Public | Self-service registration for the client role. |
/Account/Manage | Authenticated | Self-service profile + per-user audit tail + change-password form. |
/Portal | Authenticated | Authenticated landing for non-admins. |
/Admin and below | Administrator role | Tenant CRUD, API-client lifecycle, dashboard with metrics and recent audit, and notifications management. |
SDK generation
Use openapi.json with your preferred generator.
This page is hand-curated and serves alongside the machine-readable OpenAPI contract. Generated SDKs are not yet shipped; bring your own from the contract.