Download the raw OpenAPI 3.0 contract for use with code generators and SDK clients.

MethodPathDescription
GET /healthz/live Always-200 liveness probe (no database call). Used by orchestrators.
GET /healthz DB-aware readiness probe. Returns 200 with {"status":"Healthy","checks":[{"name":"database",...}]} or 503 when degraded.
GET /Status Public-safe human-readable status page (this deployment).
MethodPathDescription
GET /api/v1/platform/me Returns the calling API client's tenantId, apiClientId, and granted scopes. Requires policy catalog.read.
GET /api/v1/tenants/{tenantId}/platform/me Same payload, but bound to the tenant in the URL. Requires policy tenant.catalog.read. The token's tenant_id claim must equal the path tenantId; mismatches are rejected with 404.

Both routes require headers X-Api-Client-Identifier and X-Api-Client-Secret (or Authorization: ApiKey {id}:{secret}). Bad credentials return 401. Cross-tenant attempts return 404 (not 403) so tenant existence is not leaked.

The full OpenAPI 3.0 document is available at /openapi.json. It includes all operator health and machine-API routes, request/response schemas, and security schemes.

PathAuthDescription
/PublicLanding page with live platform status and CTA.
/StatusPublicLive health snapshot (this page).
/DocsPublicThis page.
/Home/PrivacyPublicPrivacy statement.
/Access/RequestPublicSelf-service "request access" form. Creates a Pending tenant and an access.requested audit row.
/Account/LoginPublicIdentity sign-in (cookie session).
/Account/RegisterPublicSelf-service registration for the client role.
/Account/ManageAuthenticatedSelf-service profile + per-user audit tail + change-password form.
/PortalAuthenticatedAuthenticated landing for non-admins.
/Admin and belowAdministrator roleTenant CRUD, API-client lifecycle, dashboard with metrics and recent audit, and notifications management.

This page is hand-curated and serves alongside the machine-readable OpenAPI contract. Generated SDKs are not yet shipped; bring your own from the contract.