{
  "openapi": "3.0.3",
  "info": {
    "title": "Kolm API",
    "version": "1.0.0",
    "description": "HTTP contract for the kolm compiler. Auto-generated from src/router.js via scripts/build-openapi.cjs.",
    "license": {
      "name": "Apache-2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0"
    }
  },
  "servers": [
    {
      "url": "https://kolm.ai",
      "description": "Managed production"
    },
    {
      "url": "http://localhost:8080",
      "description": "Local dev (kolm serve)"
    }
  ],
  "tags": [
    {
      "name": "ab",
      "description": "Ab"
    },
    {
      "name": "ab-tests",
      "description": "Ab Tests"
    },
    {
      "name": "account",
      "description": "Account"
    },
    {
      "name": "active-learning",
      "description": "Active Learning"
    },
    {
      "name": "admin",
      "description": "Admin"
    },
    {
      "name": "agents",
      "description": "Agents"
    },
    {
      "name": "airgap",
      "description": "Airgap"
    },
    {
      "name": "anon",
      "description": "Anonymous bootstrap"
    },
    {
      "name": "approvals",
      "description": "Approvals"
    },
    {
      "name": "artifact",
      "description": "Artifact"
    },
    {
      "name": "artifacts",
      "description": "Artifacts"
    },
    {
      "name": "assistant",
      "description": "Assistant"
    },
    {
      "name": "assurance",
      "description": "Assurance"
    },
    {
      "name": "audio",
      "description": "Audio"
    },
    {
      "name": "audit",
      "description": "Audit"
    },
    {
      "name": "auth",
      "description": "Auth"
    },
    {
      "name": "automations",
      "description": "Automations"
    },
    {
      "name": "autopilot",
      "description": "Autopilot"
    },
    {
      "name": "bakeoff",
      "description": "Bakeoff"
    },
    {
      "name": "bakeoffs",
      "description": "Bakeoffs"
    },
    {
      "name": "bench",
      "description": "Bench"
    },
    {
      "name": "billing",
      "description": "Billing"
    },
    {
      "name": "bridges",
      "description": "Bridges"
    },
    {
      "name": "build",
      "description": "Build"
    },
    {
      "name": "builder",
      "description": "Builder"
    },
    {
      "name": "builds",
      "description": "Builds"
    },
    {
      "name": "bundle",
      "description": "Bundle"
    },
    {
      "name": "buyer",
      "description": "Buyer"
    },
    {
      "name": "byoc",
      "description": "Bring-your-own-cloud"
    },
    {
      "name": "capability",
      "description": "Capability"
    },
    {
      "name": "capture",
      "description": "Capture"
    },
    {
      "name": "captures",
      "description": "Captures"
    },
    {
      "name": "carbon",
      "description": "Carbon"
    },
    {
      "name": "cc",
      "description": "Cc"
    },
    {
      "name": "changelog",
      "description": "Changelog"
    },
    {
      "name": "chargeback",
      "description": "Chargeback"
    },
    {
      "name": "chat",
      "description": "OpenAI-compatible chat"
    },
    {
      "name": "cid",
      "description": "Cid"
    },
    {
      "name": "client-error",
      "description": "Client Error"
    },
    {
      "name": "cloud",
      "description": "Cloud"
    },
    {
      "name": "compile",
      "description": "Compile"
    },
    {
      "name": "compliance",
      "description": "Compliance"
    },
    {
      "name": "compose",
      "description": "Compose"
    },
    {
      "name": "concepts",
      "description": "Concepts"
    },
    {
      "name": "connectors",
      "description": "Connectors"
    },
    {
      "name": "conversations",
      "description": "Conversations"
    },
    {
      "name": "copyright",
      "description": "Copyright"
    },
    {
      "name": "credential",
      "description": "Credential"
    },
    {
      "name": "datasets",
      "description": "Datasets"
    },
    {
      "name": "deploy",
      "description": "Deploy"
    },
    {
      "name": "device",
      "description": "Device"
    },
    {
      "name": "devices",
      "description": "Devices"
    },
    {
      "name": "diagnose",
      "description": "Diagnose"
    },
    {
      "name": "distill",
      "description": "Distill"
    },
    {
      "name": "draft",
      "description": "Draft"
    },
    {
      "name": "drift",
      "description": "Drift"
    },
    {
      "name": "drift-alert",
      "description": "Drift Alert"
    },
    {
      "name": "embed",
      "description": "Embed"
    },
    {
      "name": "embeddings",
      "description": "Embeddings"
    },
    {
      "name": "eval",
      "description": "Evaluation"
    },
    {
      "name": "evidence",
      "description": "Evidence"
    },
    {
      "name": "experts",
      "description": "Experts"
    },
    {
      "name": "export",
      "description": "Export"
    },
    {
      "name": "exports",
      "description": "Exports"
    },
    {
      "name": "failure-modes",
      "description": "Failure Modes"
    },
    {
      "name": "federated",
      "description": "Federated"
    },
    {
      "name": "fit",
      "description": "Fit"
    },
    {
      "name": "fl",
      "description": "Fl"
    },
    {
      "name": "fleet",
      "description": "Fleet"
    },
    {
      "name": "free",
      "description": "Free"
    },
    {
      "name": "gateway",
      "description": "Gateway"
    },
    {
      "name": "gemini",
      "description": "Gemini"
    },
    {
      "name": "govern",
      "description": "Govern"
    },
    {
      "name": "groups",
      "description": "Groups"
    },
    {
      "name": "hardware",
      "description": "Hardware"
    },
    {
      "name": "health",
      "description": "Health"
    },
    {
      "name": "hub",
      "description": "Hub"
    },
    {
      "name": "import",
      "description": "Import"
    },
    {
      "name": "inspect",
      "description": "Inspect"
    },
    {
      "name": "integrations",
      "description": "Integrations"
    },
    {
      "name": "intent",
      "description": "Intent"
    },
    {
      "name": "ir",
      "description": "Ir"
    },
    {
      "name": "jobs",
      "description": "Jobs"
    },
    {
      "name": "keys",
      "description": "Keys"
    },
    {
      "name": "kolmbench",
      "description": "Kolmbench"
    },
    {
      "name": "kscore",
      "description": "Kscore"
    },
    {
      "name": "label-queue",
      "description": "Label Queue"
    },
    {
      "name": "labels",
      "description": "Labels"
    },
    {
      "name": "lake",
      "description": "Lake"
    },
    {
      "name": "lang",
      "description": "Lang"
    },
    {
      "name": "lead",
      "description": "Lead"
    },
    {
      "name": "library",
      "description": "Library"
    },
    {
      "name": "lineage",
      "description": "Lineage"
    },
    {
      "name": "lingual",
      "description": "Lingual"
    },
    {
      "name": "long-context",
      "description": "Long Context"
    },
    {
      "name": "loop",
      "description": "Value-loop"
    },
    {
      "name": "marketplace",
      "description": "Marketplace"
    },
    {
      "name": "mcp",
      "description": "Mcp"
    },
    {
      "name": "me",
      "description": "Me"
    },
    {
      "name": "media",
      "description": "Media"
    },
    {
      "name": "memory",
      "description": "Memory"
    },
    {
      "name": "merge",
      "description": "Merge"
    },
    {
      "name": "messages",
      "description": "Anthropic-compatible messages"
    },
    {
      "name": "meta",
      "description": "Meta"
    },
    {
      "name": "metrics",
      "description": "Metrics"
    },
    {
      "name": "migrate",
      "description": "Migrate"
    },
    {
      "name": "mit",
      "description": "Mit"
    },
    {
      "name": "model-card",
      "description": "Model Card"
    },
    {
      "name": "models",
      "description": "Models"
    },
    {
      "name": "moderations",
      "description": "Moderations"
    },
    {
      "name": "multimodal",
      "description": "Multimodal"
    },
    {
      "name": "namespaces",
      "description": "Namespaces"
    },
    {
      "name": "nl",
      "description": "Nl"
    },
    {
      "name": "notifications",
      "description": "Notifications"
    },
    {
      "name": "numeric",
      "description": "Numeric"
    },
    {
      "name": "oauth",
      "description": "OAuth"
    },
    {
      "name": "openrouter",
      "description": "Openrouter"
    },
    {
      "name": "opportunities",
      "description": "Opportunities"
    },
    {
      "name": "orgs",
      "description": "Orgs"
    },
    {
      "name": "packages",
      "description": "Packages"
    },
    {
      "name": "passport",
      "description": "Passport"
    },
    {
      "name": "pextract",
      "description": "Pextract"
    },
    {
      "name": "pipeline",
      "description": "Pipeline"
    },
    {
      "name": "pipelines",
      "description": "Pipelines"
    },
    {
      "name": "plans",
      "description": "Plans"
    },
    {
      "name": "playground",
      "description": "Playground"
    },
    {
      "name": "plugins",
      "description": "Plugins"
    },
    {
      "name": "poisoning",
      "description": "Poisoning"
    },
    {
      "name": "pricing",
      "description": "Pricing"
    },
    {
      "name": "privacy",
      "description": "Privacy"
    },
    {
      "name": "procurement",
      "description": "Procurement"
    },
    {
      "name": "product",
      "description": "Product"
    },
    {
      "name": "public",
      "description": "Public"
    },
    {
      "name": "publish",
      "description": "Publish"
    },
    {
      "name": "quality",
      "description": "Quality"
    },
    {
      "name": "quantization",
      "description": "Quantization"
    },
    {
      "name": "quantize",
      "description": "Quantize"
    },
    {
      "name": "ready",
      "description": "Ready"
    },
    {
      "name": "recall",
      "description": "Recall"
    },
    {
      "name": "receipts",
      "description": "Receipts"
    },
    {
      "name": "recipes",
      "description": "Recipes"
    },
    {
      "name": "redact",
      "description": "Redact"
    },
    {
      "name": "redteam",
      "description": "Redteam"
    },
    {
      "name": "reg",
      "description": "Reg"
    },
    {
      "name": "region",
      "description": "Region"
    },
    {
      "name": "registry",
      "description": "Registry"
    },
    {
      "name": "replay",
      "description": "Replay"
    },
    {
      "name": "residency",
      "description": "Residency"
    },
    {
      "name": "responses",
      "description": "OpenAI Responses"
    },
    {
      "name": "route",
      "description": "Route"
    },
    {
      "name": "routing",
      "description": "Routing"
    },
    {
      "name": "run",
      "description": "Run"
    },
    {
      "name": "runtime",
      "description": "Runtime"
    },
    {
      "name": "sales",
      "description": "Sales"
    },
    {
      "name": "savings",
      "description": "Savings"
    },
    {
      "name": "sbom",
      "description": "Sbom"
    },
    {
      "name": "scim",
      "description": "Scim"
    },
    {
      "name": "search",
      "description": "Search"
    },
    {
      "name": "seasonal",
      "description": "Seasonal"
    },
    {
      "name": "security",
      "description": "Security"
    },
    {
      "name": "seeds",
      "description": "Seeds"
    },
    {
      "name": "serve",
      "description": "Serve"
    },
    {
      "name": "session",
      "description": "Session"
    },
    {
      "name": "signin",
      "description": "Sign in"
    },
    {
      "name": "signout",
      "description": "Sign out"
    },
    {
      "name": "signup",
      "description": "Sign up"
    },
    {
      "name": "sigstore",
      "description": "Sigstore"
    },
    {
      "name": "sim",
      "description": "Simulation"
    },
    {
      "name": "simulations",
      "description": "Simulations"
    },
    {
      "name": "sla",
      "description": "Sla"
    },
    {
      "name": "sneakernet",
      "description": "Sneakernet"
    },
    {
      "name": "spec",
      "description": "Spec"
    },
    {
      "name": "spec-decode",
      "description": "Spec Decode"
    },
    {
      "name": "specialists",
      "description": "Specialists"
    },
    {
      "name": "speculative",
      "description": "Speculative"
    },
    {
      "name": "sso",
      "description": "Sso"
    },
    {
      "name": "staleness",
      "description": "Staleness"
    },
    {
      "name": "stat-sig",
      "description": "Stat Sig"
    },
    {
      "name": "status",
      "description": "Status"
    },
    {
      "name": "storage",
      "description": "Storage"
    },
    {
      "name": "streaming",
      "description": "Streaming"
    },
    {
      "name": "stripe",
      "description": "Stripe"
    },
    {
      "name": "sync",
      "description": "Sync"
    },
    {
      "name": "synthesize",
      "description": "Synthesis"
    },
    {
      "name": "synthetic",
      "description": "Synthetic"
    },
    {
      "name": "system",
      "description": "System"
    },
    {
      "name": "target-profiles",
      "description": "Target Profiles"
    },
    {
      "name": "teacher",
      "description": "Teacher"
    },
    {
      "name": "teacher-versions",
      "description": "Teacher Versions"
    },
    {
      "name": "team",
      "description": "Team"
    },
    {
      "name": "teams",
      "description": "Teams"
    },
    {
      "name": "telemetry",
      "description": "Telemetry"
    },
    {
      "name": "test-device",
      "description": "Test Device"
    },
    {
      "name": "test-quants",
      "description": "Test Quants"
    },
    {
      "name": "trace",
      "description": "Trace"
    },
    {
      "name": "training",
      "description": "Training"
    },
    {
      "name": "transparency-log",
      "description": "Transparency Log"
    },
    {
      "name": "trust",
      "description": "Trust"
    },
    {
      "name": "tunnel",
      "description": "Tunnel"
    },
    {
      "name": "tunnels",
      "description": "Tunnels"
    },
    {
      "name": "usage",
      "description": "Usage"
    },
    {
      "name": "verified-inference",
      "description": "Verified inference"
    },
    {
      "name": "verify",
      "description": "Verify"
    },
    {
      "name": "verticals",
      "description": "Verticals"
    },
    {
      "name": "video",
      "description": "Video"
    },
    {
      "name": "vision",
      "description": "Vision"
    },
    {
      "name": "vlm",
      "description": "Vlm"
    },
    {
      "name": "vlm-distill",
      "description": "Vlm Distill"
    },
    {
      "name": "webhooks",
      "description": "Webhooks"
    },
    {
      "name": "whoami",
      "description": "Whoami"
    },
    {
      "name": "workflows",
      "description": "Workflows"
    },
    {
      "name": "wrap",
      "description": "Wrap"
    },
    {
      "name": "xlang",
      "description": "Xlang"
    },
    {
      "name": "yaml",
      "description": "Yaml"
    }
  ],
  "paths": {
    "/.well-known/jwks.json": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getwellknownJwksjson",
        "summary": "NOW-3 - standards-conformant JWKS endpoint. Exposes the default receipt",
        "description": "NOW-3 - standards-conformant JWKS endpoint. Exposes the default receipt signing key as an RFC 8037 OKP JWK so any third-party verifier can fetch the key (kid == fingerprint) and check the X-Inference-Signature response header the gateway emits, WITHOUT trusting kolm (IETF inference-signature drafts).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3308 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/anthropic/v1/messages": {
      "post": {
        "tags": [
          "system"
        ],
        "operationId": "postAnthropicV1Messages",
        "summary": "/anthropic/v1/messages so SDKs that point BASE_URL at https://kolm.ai/anthropic",
        "description": "Anthropic messages alias - same connector as /v1/messages, mounted under /anthropic/v1/messages so SDKs that point BASE_URL at https://kolm.ai/anthropic continue to work without rewriting the path.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5526 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/health": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getHealth",
        "summary": "hit /v1/health for the full snapshot including backend availability.",
        "description": "hit /v1/health for the full snapshot including backend availability. ok:true is the canonical liveness signal for ship-gate, status is preserved for older readers. W890-13: extended with `git`, `gateway`, `capture_store`, `signing_key` per plan Part K-1. Each field is a string so platform health probes can pattern-match without unpacking a struct.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1495 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/metrics": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getMetrics",
        "summary": "authMiddleware so a Prometheus scraper can reach it without an API",
        "description": "authMiddleware so a Prometheus scraper can reach it without an API key, optionally gated by KOLM_METRICS_BEARER for prod deployments. The honest-dev-default is public; setting the env var requires `Authorization: Bearer <token>` and returns a structured 401 envelope on mismatch so misconfigured scrapers fail loud.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1605 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/metrics/extended": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getMetricsExtended",
        "summary": "/metrics/extended",
        "description": "/metrics/extended",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/k8s-routes.js is registered from src/router.js:30112 after r.use(authMiddleware) at line 6376"
      }
    },
    "/r/{token}": {},
    "/r/{token}/*": {},
    "/ready": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getReady",
        "summary": "gates. /health stays green for static uptime; /ready fails when critical",
        "description": "Deploy readiness: public, low-detail, and suitable for platform health gates. /health stays green for static uptime; /ready fails when critical production-only configuration is missing.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1698 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/ready/deep": {
      "get": {
        "tags": [
          "system"
        ],
        "operationId": "getReadyDeep",
        "summary": "/ready/deep",
        "description": "/ready/deep",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/k8s-routes.js is registered from src/router.js:30112 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ab-tests": {
      "get": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "getV1Abtests",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27754 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/create": {
      "post": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "postV1AbtestsCreate",
        "summary": "Returns: {ok, ab_test_id, request_hash, arm, frozen, reason, version}",
        "description": "Returns: {ok, ab_test_id, request_hash, arm, frozen, reason, version} Auth-gated via req.tenant_record. Tenant fence forced from session, never from request body. Distinct prefix /v1/ab-tests/* so parallel agents on cannot collide on these route paths.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27728 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/{id}": {
      "get": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "getV1AbtestsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27771 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/{id}/assignments": {
      "get": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "getV1AbtestsIdAssignments",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27861 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/{id}/promote": {
      "post": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "postV1AbtestsIdPromote",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27814 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/{id}/rollback": {
      "post": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "postV1AbtestsIdRollback",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27839 carries route-local auth middleware"
      }
    },
    "/v1/ab-tests/{id}/stop": {
      "post": {
        "tags": [
          "ab-tests"
        ],
        "operationId": "postV1AbtestsIdStop",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27790 carries route-local auth middleware"
      }
    },
    "/v1/ab/configure": {
      "post": {
        "tags": [
          "ab"
        ],
        "operationId": "postV1AbConfigure",
        "summary": "── POST /v1/ab/configure ──────────────────────────────────────────────────",
        "description": "── POST /v1/ab/configure ────────────────────────────────────────────────── Body: { namespace, version_a, version_b, split?, idempotency_key? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/ab-routes.js is registered from src/router.js:30005 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ab/feedback": {
      "post": {
        "tags": [
          "ab"
        ],
        "operationId": "postV1AbFeedback",
        "summary": "thumb:'up'|'down'?, comment?, ab_test_id? }",
        "description": "thumb:'up'|'down'?, comment?, ab_test_id? } Persists a row to the event-store under workflow_id=AB_FEEDBACK_WORKFLOW so ab-metrics.aggregate() can read it. Also fans the row to the W720 self-improvement queue when deps.selfImprovement.enqueue is wired.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/ab-routes.js is registered from src/router.js:30005 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ab/metrics": {
      "get": {
        "tags": [
          "ab"
        ],
        "operationId": "getV1AbMetrics",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/ab-routes.js is registered from src/router.js:30005 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ab/promote": {
      "post": {
        "tags": [
          "ab"
        ],
        "operationId": "postV1AbPromote",
        "summary": "── POST /v1/ab/promote ────────────────────────────────────────────────────",
        "description": "── POST /v1/ab/promote ──────────────────────────────────────────────────── Body: { namespace, force?:boolean, thresholds?:{...} } When `force=true` we bypass the decide() gate and promote variant_b immediately. Otherwise we run the full evaluate() pipeline and only promote when decide() returns 'promote'.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/ab-routes.js is registered from src/router.js:30005 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ab/status": {
      "get": {
        "tags": [
          "ab"
        ],
        "operationId": "getV1AbStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/ab-routes.js is registered from src/router.js:30005 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/account": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1Account",
        "summary": "Account",
        "description": "Account",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9799 carries route-local auth middleware"
      }
    },
    "/v1/account/api-control-center": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountApicontrolcenter",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17735 carries route-local auth middleware"
      }
    },
    "/v1/account/api-control-center/adapter-manifests/validate": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountApicontrolcenterAdaptermanifestsValidate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15827 carries route-local auth middleware"
      }
    },
    "/v1/account/api-control-center/events": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountApicontrolcenterEvents",
        "summary": "Enterprise control-center intake alias. This exposes the advertised",
        "description": "Enterprise control-center intake alias. This exposes the advertised canonical event envelope directly from the account surface.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15822 carries route-local auth middleware"
      }
    },
    "/v1/account/api-control-center/exports": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountApicontrolcenterExports",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15840 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountApicontrolcenterExports",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15865 carries route-local auth middleware"
      }
    },
    "/v1/account/api-control-center/exports/{id}": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountApicontrolcenterExportsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15852 carries route-local auth middleware"
      }
    },
    "/v1/account/audit-log": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountAuditlog",
        "summary": "/v1/account/audit-log surfaces the audit ledger for the calling",
        "description": "/v1/account/audit-log surfaces the audit ledger for the calling tenant. The audit-log.html page renders {entries:[{at,actor,op,payload}]}. added ?format=csv (defaults to json) so the page's export button and `kolm audit --format csv` CLI verb hit the same route. Also added ?since=<iso|epoch> filter so the CLI can scope to a recent window.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10751 carries route-local auth middleware"
      }
    },
    "/v1/account/audit-log/verify": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountAuditlogVerify",
        "summary": "GET /v1/account/audit-log/verify - chain-verify the calling",
        "description": "GET /v1/account/audit-log/verify - chain-verify the calling tenant's audit ledger (no body). Returns { ok, verified, chain_length, broken_at? } so the audit-log page can render a green/red state.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8910 carries route-local auth middleware"
      }
    },
    "/v1/account/audit/retention": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountAuditRetention",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11060 carries route-local auth middleware"
      }
    },
    "/v1/account/billing": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountBilling",
        "summary": "Billing summary the account-billing page reads: plan, status, period, credit",
        "description": "Billing summary the account-billing page reads: plan, status, period, credit balance, tax fields, Full Readiness entitlements, continuous subscription, recent invoices, dunning state, and whether the portal can be opened.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12797 carries route-local auth middleware"
      },
      "patch": {
        "tags": [
          "account"
        ],
        "operationId": "patchV1AccountBilling",
        "summary": "M13 - capture VAT number / tax id (+ optional company + country) for the",
        "description": "M13 - capture VAT number / tax id (+ optional company + country) for the invoice header and Stripe automatic_tax. Tenant-fenced + audited.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12849 carries route-local auth middleware"
      }
    },
    "/v1/account/billing/portal": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountBillingPortal",
        "summary": "M9 - open a Stripe Billing Portal session so the customer can self-serve",
        "description": "M9 - open a Stripe Billing Portal session so the customer can self-serve payment-method updates, cancellation/downgrade, and receipt downloads. 503 when no Stripe secret key is configured; 409 when the tenant has no Stripe customer yet (no paid subscription has ever been created for them).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12765 carries route-local auth middleware"
      }
    },
    "/v1/account/cancel": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountCancel",
        "summary": "Self-serve cancel / downgrade-to-free. Any paid tenant can drop to the",
        "description": "Self-serve cancel / downgrade-to-free. Any paid tenant can drop to the free tier without contacting anyone.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13491 carries route-local auth middleware"
      }
    },
    "/v1/account/change-plan": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountChangeplan",
        "summary": "Self-serve plan changes. Free is applied instantly (this is also the",
        "description": "Self-serve plan changes. Free is applied instantly (this is also the downgrade / cancel path). Paid plans return a Stripe Payment Link with `client_reference_id=<tenant_id>`; the plan is flipped only when the webhook receives `checkout.session.completed`. This guarantees the tenant cannot get paid features without paying.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12666 carries route-local auth middleware"
      }
    },
    "/v1/account/compiler-overview": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountCompileroverview",
        "summary": "Compiler overview - a backend-owned application contract for the main",
        "description": "Compiler overview - a backend-owned application contract for the main product surface. The UI can render this instead of hard-coding an audit dashboard as the first-run experience.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17656 carries route-local auth middleware"
      }
    },
    "/v1/account/compliance-package": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountCompliancepackage",
        "summary": "can read end-to-end. Tenant metadata + signed receipts + audit log +",
        "description": "can read end-to-end. Tenant metadata + signed receipts + audit log + BAA-ready org details + control mapping snapshot. JSON only (no PHI ever transits this endpoint - receipts are payload-free by design). Auditors who want a literal ZIP can pipe `curl ... | jq -r .b64_zip | base64 -d`, but the JSON shape is the canonical artifact.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13584 carries route-local auth middleware"
      }
    },
    "/v1/account/delete": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountDelete",
        "summary": "Self-serve account delete. Soft-delete the tenant; receipts and artifacts",
        "description": "Self-serve account delete. Soft-delete the tenant; receipts and artifacts already shipped to users keep verifying since the cloud signing key is unchanged. The tenant can no longer authenticate. If they had an active Stripe subscription we ask Stripe to cancel it so they aren't charged again - best-effort, never blocks deletion.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13683 carries route-local auth middleware"
      }
    },
    "/v1/account/export": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountExport",
        "summary": "Self-serve data export (/privacy promises this). Returns a JSON bundle",
        "description": "Self-serve data export (/privacy promises this). Returns a JSON bundle of the tenant's row plus every concept, compile job, observation, and invocation we have on file for them. We strip secrets (api_key_hash, stripe_customer_id keeps existing for portability, billing tokens drop). Content-Disposition nudges browsers to save the file.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13537 carries route-local auth middleware"
      }
    },
    "/v1/account/invoices": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountInvoices",
        "summary": "M11 - list the tenant's invoices / receipts (newest first). Reads the local",
        "description": "M11 - list the tenant's invoices / receipts (newest first). Reads the local ledger populated by the invoice.payment_succeeded webhook.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12788 carries route-local auth middleware"
      }
    },
    "/v1/account/keys": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountKeys",
        "summary": "Account API key list - returns the tenant primary key metadata without the raw secret.",
        "description": "Account API key list - returns the tenant primary key metadata without the raw secret.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10630 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountKeys",
        "summary": "Account API key create - rotates the tenant primary key and audits the requested label.",
        "description": "Account API key create - rotates the tenant primary key and audits the requested label.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10646 carries route-local auth middleware"
      }
    },
    "/v1/account/keys/{prefix}": {
      "delete": {
        "tags": [
          "account"
        ],
        "operationId": "deleteV1AccountKeysPrefix",
        "summary": "Account API key revoke - rotates away a key prefix and returns the replacement secret.",
        "description": "Account API key revoke - rotates away a key prefix and returns the replacement secret.",
        "parameters": [
          {
            "name": "prefix",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "prefix path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10733 carries route-local auth middleware"
      }
    },
    "/v1/account/next-actions": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountNextactions",
        "summary": "Next-actions list - returns the top-5 ranked proactive actions for the tenant.",
        "description": "Next-actions list - returns the top-5 ranked proactive actions for the tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17050 carries route-local auth middleware"
      }
    },
    "/v1/account/next-actions/snooze": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountNextactionsSnooze",
        "summary": "Next-actions snooze - silences the matching dismiss_key for N days (default 14).",
        "description": "Next-actions snooze - silences the matching dismiss_key for N days (default 14).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17755 carries route-local auth middleware"
      }
    },
    "/v1/account/provider-keys": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountProviderkeys",
        "summary": "Provider-key vault: per-employee / per-team upstream provider keys",
        "description": "Provider-key vault: per-employee / per-team upstream provider keys The core of \"every employee's AI use, in one place you control\": a member stores their OpenAI/Anthropic/etc. key here; the gateway routes their traffic under it (see dispatch) and the call lands in the team lake attributed to them. Responses are always redacted (never the raw secret).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10664 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountProviderkeys",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10676 carries route-local auth middleware"
      }
    },
    "/v1/account/provider-keys/{id}": {
      "delete": {
        "tags": [
          "account"
        ],
        "operationId": "deleteV1AccountProviderkeysId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10699 carries route-local auth middleware"
      }
    },
    "/v1/account/receipt-secret/prune": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountReceiptsecretPrune",
        "summary": "Drop a specific previous key from the verification ring. Receipts signed",
        "description": "Drop a specific previous key from the verification ring. Receipts signed with that key will no longer verify against this tenant after this call. The current key cannot be pruned - rotate first to retire it.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12642 carries route-local auth middleware"
      }
    },
    "/v1/account/receipt-secrets": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountReceiptsecrets",
        "summary": "List receipt-signing key metadata for the calling tenant. Secrets are",
        "description": "List receipt-signing key metadata for the calling tenant. Secrets are never returned - only the key_id, status, and rotation timestamps.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12629 carries route-local auth middleware"
      }
    },
    "/v1/account/rotate-key": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountRotatekey",
        "summary": "Account API key rotation - rotates the tenant's primary API key and returns the new secret.",
        "description": "Account API key rotation - rotates the tenant's primary API key and returns the new secret.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9876 carries route-local auth middleware"
      }
    },
    "/v1/account/rotate-receipt-secret": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountRotatereceiptsecret",
        "summary": "Rotate the per-tenant receipt-signing secret. Previous secret is",
        "description": "Rotate the per-tenant receipt-signing secret. Previous secret is preserved so older signed artifacts and audit rows still verify.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12610 carries route-local auth middleware"
      }
    },
    "/v1/account/saml/acs": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountSamlAcs",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11779 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/account/saml/metadata": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountSamlMetadata",
        "summary": "SP metadata is a static document an IdP fetches at federation-config",
        "description": "SP metadata is a static document an IdP fetches at federation-config time. It does NOT depend on entitlement (publishing the SP entity ID is fine even for tenants who can't yet bind to it).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11487 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/account/scoped-keys": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountScopedkeys",
        "summary": "Scoped member API keys (multi-key, least-privilege)",
        "description": "Scoped member API keys (multi-key, least-privilege) Mint keys with a subset of scopes (e.g. capture:read, lake:export, namespace:<slug>, or *) so a teammate or a CI job gets only what it needs. Non-breaking: the tenant-primary key (rotate via /v1/account/keys) is full.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10714 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountScopedkeys",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10718 carries route-local auth middleware"
      }
    },
    "/v1/account/scoped-keys/{id}": {
      "delete": {
        "tags": [
          "account"
        ],
        "operationId": "deleteV1AccountScopedkeysId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10727 carries route-local auth middleware"
      }
    },
    "/v1/account/settings": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountSettings",
        "summary": "Account settings read - returns tenant settings merged with current defaults.",
        "description": "Account settings read - returns tenant settings merged with current defaults.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10834 carries route-local auth middleware"
      },
      "put": {
        "tags": [
          "account"
        ],
        "operationId": "putV1AccountSettings",
        "summary": "Account settings update - persists whitelisted tenant settings and audits changed fields.",
        "description": "Account settings update - persists whitelisted tenant settings and audits changed fields.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10845 carries route-local auth middleware"
      }
    },
    "/v1/account/sso/configure": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountSsoConfigure",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11342 carries route-local auth middleware"
      }
    },
    "/v1/account/sso/scim-token": {
      "post": {
        "tags": [
          "account"
        ],
        "operationId": "postV1AccountSsoScimtoken",
        "summary": "Generate (or rotate) the per-tenant SCIM bearer token an IdP uses to drive",
        "description": "Generate (or rotate) the per-tenant SCIM bearer token an IdP uses to drive SCIM 2.0 provisioning. Returned in plaintext exactly ONCE (on generation); only the hash is persisted. Rotating invalidates the previous token. The token is never written to logs or the audit payload.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11447 carries route-local auth middleware"
      }
    },
    "/v1/account/sso/status": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountSsoStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11317 carries route-local auth middleware"
      }
    },
    "/v1/account/state": {
      "get": {
        "tags": [
          "account"
        ],
        "operationId": "getV1AccountState",
        "summary": "/account/overview \"What's next\" engine reads. Returns artifact + capture",
        "description": "/account/overview \"What's next\" engine reads. Returns artifact + capture + namespace counts, the age of the last artifact, age of the primary api key, plus a flat `signals` array each rule in whats-next.js matches on. Auth-gated (NOT in PUBLIC_API) - cross-tenant state leaks were what made /v1/intent/next add tenant_id scoping in W432.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9895 carries route-local auth middleware"
      }
    },
    "/v1/active-learning/summary": {
      "get": {
        "tags": [
          "active-learning"
        ],
        "operationId": "getV1ActivelearningSummary",
        "summary": "Honest empty-state: if active-learning-queue.js isn't on disk yet",
        "description": "Honest empty-state: if active-learning-queue.js isn't on disk yet (sibling agent still building, or this is a fresh deploy), return ok:true with module_missing:true so the dashboard can render a useful empty state instead of a 500.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23254 carries route-local auth middleware"
      }
    },
    "/v1/admin/audit": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminAudit",
        "summary": "Admin audit feed - newest audit events with tenant and operation metadata.",
        "description": "Admin audit feed - newest audit events with tenant and operation metadata.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12990 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/compile-jobs": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminCompilejobs",
        "summary": "Admin compile job feed - newest compile jobs with tenant, task, status, and score.",
        "description": "Admin compile job feed - newest compile jobs with tenant, task, status, and score.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13010 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/control-files": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminControlfiles",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14486 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/control-files/{key}": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminControlfilesKey",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "key",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "key path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14522 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/diagnostics": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminDiagnostics",
        "summary": "Admin diagnostics - checks data/artifact directories and selected runtime env flags.",
        "description": "Admin diagnostics - checks data/artifact directories and selected runtime env flags.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14426 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/health": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminHealth",
        "summary": "Admin health snapshot - process, store, memory, region, and integration flags.",
        "description": "Admin health snapshot - process, store, memory, region, and integration flags.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13030 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/refund": {
      "post": {
        "tags": [
          "admin"
        ],
        "operationId": "postV1AdminRefund",
        "summary": "M13 - admin-issued refund. Owner/admin only (req.is_admin). Issues a Stripe",
        "description": "M13 - admin-issued refund. Owner/admin only (req.is_admin). Issues a Stripe refund against a charge, records a credit-memo in the tenant ledger, audits the action, and notifies the tenant. 503 when Stripe is not configured.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12886 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/stats": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminStats",
        "summary": "Admin stats - aggregate tenants, usage, compile jobs, and audit-event counts.",
        "description": "Admin stats - aggregate tenants, usage, compile jobs, and audit-event counts.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12962 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/submissions": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminSubmissions",
        "summary": "Admin submissions list - returns all submitted project/contact records.",
        "description": "Admin submissions list - returns all submitted project/contact records.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15210 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/tenant": {
      "post": {
        "tags": [
          "admin"
        ],
        "operationId": "postV1AdminTenant",
        "summary": "Admin tenant provision - creates a tenant with quota and returns its API key.",
        "description": "Admin tenant provision - creates a tenant with quota and returns its API key.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14415 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/tenants": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminTenants",
        "summary": "Admin tenant list - scrubbed cross-tenant view with q/limit filters.",
        "description": "Admin tenant list - scrubbed cross-tenant view with q/limit filters.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12934 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/admin/waitlist": {
      "get": {
        "tags": [
          "admin"
        ],
        "operationId": "getV1AdminWaitlist",
        "summary": "Admin waitlist list - returns all waitlist rows for admin triage.",
        "description": "Admin waitlist list - returns all waitlist rows for admin triage.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15205 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/agents": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1Agents",
        "summary": "agent telemetry routes fence on req.tenant_record and forward",
        "description": "agent telemetry routes fence on req.tenant_record and forward req.tenant_record.id as tenant_id into the helper so cross-tenant rows never appear in the rollup. _tenantScope() returns null for admin (cross-tenant reads allowed) and the canonical tenant_id otherwise.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21419 carries route-local auth middleware"
      }
    },
    "/v1/agents/failing": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1AgentsFailing",
        "summary": "Top failing agent sessions for the caller's tenant.",
        "description": "Top failing agent sessions for the caller's tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21473 carries route-local auth middleware"
      }
    },
    "/v1/agents/recommend": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1AgentsRecommend",
        "summary": "Agent model recommendation for a tenant-scoped application and task hint.",
        "description": "Agent model recommendation for a tenant-scoped application and task hint.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21458 carries route-local auth middleware"
      }
    },
    "/v1/agents/sessions": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1AgentsSessions",
        "summary": "Agent sessions list for the caller's tenant.",
        "description": "Agent sessions list for the caller's tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21432 carries route-local auth middleware"
      }
    },
    "/v1/agents/sessions/{id}": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1AgentsSessionsId",
        "summary": "Agent session detail scoped to the caller's tenant.",
        "description": "Agent session detail scoped to the caller's tenant.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21446 carries route-local auth middleware"
      }
    },
    "/v1/agents/stats": {
      "get": {
        "tags": [
          "agents"
        ],
        "operationId": "getV1AgentsStats",
        "summary": "Agent telemetry aggregate stats for the caller's tenant.",
        "description": "Agent telemetry aggregate stats for the caller's tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21487 carries route-local auth middleware"
      }
    },
    "/v1/airgap/bakeoff": {
      "post": {
        "tags": [
          "airgap"
        ],
        "operationId": "postV1AirgapBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/distill/run": {
      "post": {
        "tags": [
          "airgap"
        ],
        "operationId": "postV1AirgapDistillRun",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/distill/status/{id}": {
      "get": {
        "tags": [
          "airgap"
        ],
        "operationId": "getV1AirgapDistillStatusId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/doctor": {
      "get": {
        "tags": [
          "airgap"
        ],
        "operationId": "getV1AirgapDoctor",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/jobs": {
      "get": {
        "tags": [
          "airgap"
        ],
        "operationId": "getV1AirgapJobs",
        "summary": "/v1/airgap/jobs - bare collection GET that lists tenant air-gapped",
        "description": "/v1/airgap/jobs - bare collection GET that lists tenant air-gapped distill + sneakernet jobs. Each W831 job is keyed by run_id; the actual status route is /v1/airgap/distill/status/:id. This bare GET returns an empty envelope until a wave wires the per-tenant job index.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28643 carries route-local auth middleware"
      }
    },
    "/v1/airgap/sneakernet/bundle": {
      "post": {
        "tags": [
          "airgap"
        ],
        "operationId": "postV1AirgapSneakernetBundle",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/sneakernet/verify": {
      "post": {
        "tags": [
          "airgap"
        ],
        "operationId": "postV1AirgapSneakernetVerify",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/airgap-routes.js is registered from src/router.js:30126 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/airgap/status": {
      "get": {
        "tags": [
          "airgap"
        ],
        "operationId": "getV1AirgapStatus",
        "summary": "All four auth-gate on req.tenant_record. W411 defense-in-depth: every",
        "description": "All four auth-gate on req.tenant_record. W411 defense-in-depth: every route binds tenant into the args so a future schema change cannot leak across tenants.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27602 carries route-local auth middleware"
      }
    },
    "/v1/airgap/test": {
      "post": {
        "tags": [
          "airgap"
        ],
        "operationId": "postV1AirgapTest",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27617 carries route-local auth middleware"
      }
    },
    "/v1/anon/bootstrap": {
      "post": {
        "tags": [
          "anon"
        ],
        "operationId": "postV1AnonBootstrap",
        "summary": "Anonymous CLI auth (robots / agents)",
        "description": "Anonymous CLI auth (robots / agents) Bootstrap: returns an anon_token that the CLI stores locally. 30-day TTL. No email, no signup. Designed for agents that need to start working in <1 second.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2818 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/anon/claim": {
      "post": {
        "tags": [
          "anon"
        ],
        "operationId": "postV1AnonClaim",
        "summary": "Claim: convert an anonymous workspace into a permanent account.",
        "description": "Claim: convert an anonymous workspace into a permanent account. if email matches an existing real tenant: merge the anon's recipes into it, return existing key else: upgrade the anon tenant in-place to a real tenant, rotate to ks_*, return new key WC14 - share the bootstrap limiter (50/24h/ip) so brute-forcing kao_ tokens through this endpoint is bounded.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2837 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/approvals": {
      "get": {
        "tags": [
          "approvals"
        ],
        "operationId": "getV1Approvals",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28055 carries route-local auth middleware"
      }
    },
    "/v1/approvals/request": {
      "post": {
        "tags": [
          "approvals"
        ],
        "operationId": "postV1ApprovalsRequest",
        "summary": "Tenant fence: tenant_id forced from req.tenant_record.id. Status",
        "description": "Tenant fence: tenant_id forced from req.tenant_record.id. Status transitions return honest invalid_transition envelopes - never silently re-write state. version stamp matches /^w782-/.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28031 carries route-local auth middleware"
      }
    },
    "/v1/approvals/{id}": {
      "get": {
        "tags": [
          "approvals"
        ],
        "operationId": "getV1ApprovalsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28075 carries route-local auth middleware"
      }
    },
    "/v1/approvals/{id}/approve": {
      "post": {
        "tags": [
          "approvals"
        ],
        "operationId": "postV1ApprovalsIdApprove",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28094 carries route-local auth middleware"
      }
    },
    "/v1/approvals/{id}/notify": {
      "post": {
        "tags": [
          "approvals"
        ],
        "operationId": "postV1ApprovalsIdNotify",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28138 carries route-local auth middleware"
      }
    },
    "/v1/approvals/{id}/reject": {
      "post": {
        "tags": [
          "approvals"
        ],
        "operationId": "postV1ApprovalsIdReject",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28116 carries route-local auth middleware"
      }
    },
    "/v1/artifact/diff": {
      "post": {
        "tags": [
          "artifact"
        ],
        "operationId": "postV1ArtifactDiff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7543 carries route-local auth middleware"
      }
    },
    "/v1/artifact/lineage": {
      "post": {
        "tags": [
          "artifact"
        ],
        "operationId": "postV1ArtifactLineage",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7519 carries route-local auth middleware"
      }
    },
    "/v1/artifact/verify-manifest": {
      "post": {
        "tags": [
          "artifact"
        ],
        "operationId": "postV1ArtifactVerifymanifest",
        "summary": "for callers that have the manifest hashes block in hand (e.g. a CLI",
        "description": "for callers that have the manifest hashes block in hand (e.g. a CLI that just downloaded the artifact and parsed its manifest.json). No auth required - the check is pure: recompute CID from hashes, compare to the claimed CID. Returns `manifest_hash_mismatch` envelope on disagreement, `verified:true` + recomputed cid on match.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13982 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts": {
      "get": {
        "tags": [
          "artifacts"
        ],
        "operationId": "getV1Artifacts",
        "summary": "Artifact list - exposes completed compile jobs as artifact records with hashes and downloads.",
        "description": "Artifact list - exposes completed compile jobs as artifact records with hashes and downloads.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8718 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/dependency-graph": {
      "post": {
        "tags": [
          "artifacts"
        ],
        "operationId": "postV1ArtifactsDependencygraph",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2427 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/{id}": {
      "get": {
        "tags": [
          "artifacts"
        ],
        "operationId": "getV1ArtifactsId",
        "summary": "Artifact detail - returns one tenant-scoped compile artifact by job id.",
        "description": "Artifact detail - returns one tenant-scoped compile artifact by job id.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8724 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/{id}/download": {
      "get": {
        "tags": [
          "artifacts"
        ],
        "operationId": "getV1ArtifactsIdDownload",
        "summary": "Artifact download - streams the completed artifact zip by id with readiness/expiry errors.",
        "description": "Artifact download - streams the completed artifact zip by id with readiness/expiry errors.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8731 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/{id}/evidence-trace": {
      "get": {
        "tags": [
          "artifacts"
        ],
        "operationId": "getV1ArtifactsIdEvidencetrace",
        "summary": "GET /v1/artifacts/:id/evidence-trace - return the full ancestor DAG",
        "description": "GET /v1/artifacts/:id/evidence-trace - return the full ancestor DAG for an artifact. Returns 404 when the artifact has no evidence DAG on disk. The shape is { ok, artifact_id, dag: {nodes, edges} } so the caller can re-build the DAG client-side and walk it.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9082 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/{id}/lifecycle": {
      "get": {
        "tags": [
          "artifacts"
        ],
        "operationId": "getV1ArtifactsIdLifecycle",
        "summary": "GET /v1/artifacts/:id/lifecycle - current_state + full history.",
        "description": "R-2 - artifact lifecycle introspection. GET /v1/artifacts/:id/lifecycle - current_state + full history.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8759 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/artifacts/{id}/lifecycle/transition": {
      "post": {
        "tags": [
          "artifacts"
        ],
        "operationId": "postV1ArtifactsIdLifecycleTransition",
        "summary": "POST /v1/artifacts/:id/lifecycle/transition - record a state transition.",
        "description": "POST /v1/artifacts/:id/lifecycle/transition - record a state transition. Body: {to_state, reason, evidence_id?, successor_id?}.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8786 carries route-local auth middleware"
      }
    },
    "/v1/assistant": {
      "post": {
        "tags": [
          "assistant"
        ],
        "operationId": "postV1Assistant",
        "summary": "POST /v1/assistant { prompt } returns a parsed-intent action + result.",
        "description": "Natural-language assistant POST /v1/assistant { prompt } returns a parsed-intent action + result. Scoped to req.tenant_record; never calls an external LLM; deterministic.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9678 carries route-local auth middleware"
      }
    },
    "/v1/assistant/chat": {
      "post": {
        "tags": [
          "assistant"
        ],
        "operationId": "postV1AssistantChat",
        "summary": "chat widget on every authed /account page. Routes through the W888-P",
        "description": "chat widget on every authed /account page. Routes through the W888-P AssistantClient three-layer fallback (local GGUF -> kolm.ai -> gateway frontier). Tier-gated to paid plans; rate-limited to 60 calls/hour/tenant. Returns the W888-P envelope verbatim plus the canonical aliases (provider_used / latency_ms) the widget consumes.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10519 carries route-local auth middleware"
      }
    },
    "/v1/assistant/chat-docs": {
      "post": {
        "tags": [
          "assistant"
        ],
        "operationId": "postV1AssistantChatdocs",
        "summary": "(formatted as a docs-anchored system prompt). The response surfaces the",
        "description": "(formatted as a docs-anchored system prompt). The response surfaces the sources back to the client so the UI renders the same URLs it sent in. KOLM_ASSISTANT_TEST_SHIM=1 wires deterministic shims for tests; this same env var is used by tests/wave888p-cli-nl-routing.test.js.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10108 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/assurance/artifact/{id}": {
      "get": {
        "tags": [
          "assurance"
        ],
        "operationId": "getV1AssuranceArtifactId",
        "summary": "GET /v1/assurance/workspace/:id?format=json|pdf",
        "description": "GET /v1/assurance/workspace/:id?format=json|pdf Same shape, workspace-level - the artifact-derived claims are omitted and only the vault-derived jurisdiction claim + the 8 required control rows remain.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9109 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/assurance/workspace/{id}": {
      "get": {
        "tags": [
          "assurance"
        ],
        "operationId": "getV1AssuranceWorkspaceId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9151 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audio/bakeoff": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26002 carries route-local auth middleware"
      }
    },
    "/v1/audio/capture-detect": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioCapturedetect",
        "summary": "stamped by captureAudioMessage (NEVER the raw audio bytes).",
        "description": "stamped by captureAudioMessage (NEVER the raw audio bytes). All three are tenant-fenced via req.tenant_record.id (W411). Honest envelopes on bad input - no silent passthrough.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25978 carries route-local auth middleware"
      }
    },
    "/v1/audio/captures": {
      "get": {
        "tags": [
          "audio"
        ],
        "operationId": "getV1AudioCaptures",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26036 carries route-local auth middleware"
      }
    },
    "/v1/audio/speech": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioSpeech",
        "summary": "audio routes. Real proxy when configured; fixture returns deterministic",
        "description": "audio routes. Real proxy when configured; fixture returns deterministic bodies; otherwise honest 501 with a structured \"not yet supported\" envelope so SDKs see something better than 404. These concrete audio endpoints use the OpenAI connector when a key is present.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5519 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audio/tokenize": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioTokenize",
        "summary": "GET /v1/audio/tokenize/doctor",
        "description": "GET /v1/audio/tokenize/doctor Auth-gated. Returns the worker doctor envelope - reports python3 presence + transformers/torch/librosa/soundfile availability + which tokenizer command is wired.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27045 carries route-local auth middleware"
      }
    },
    "/v1/audio/tokenize/doctor": {
      "get": {
        "tags": [
          "audio"
        ],
        "operationId": "getV1AudioTokenizeDoctor",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27082 carries route-local auth middleware"
      }
    },
    "/v1/audio/transcriptions": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioTranscriptions",
        "summary": "audio routes. Real proxy when configured; fixture returns deterministic",
        "description": "audio routes. Real proxy when configured; fixture returns deterministic bodies; otherwise honest 501 with a structured \"not yet supported\" envelope so SDKs see something better than 404. These concrete audio endpoints use the OpenAI connector when a key is present.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5519 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audio/translations": {
      "post": {
        "tags": [
          "audio"
        ],
        "operationId": "postV1AudioTranslations",
        "summary": "audio routes. Real proxy when configured; fixture returns deterministic",
        "description": "audio routes. Real proxy when configured; fixture returns deterministic bodies; otherwise honest 501 with a structured \"not yet supported\" envelope so SDKs see something better than 404. These concrete audio endpoints use the OpenAI connector when a key is present.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5519 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/*": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1Audit",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/continuous/checkout": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditContinuousCheckout",
        "summary": "POST /v1/audit/continuous/checkout - subscribe to Continuous re-attestation.",
        "description": "POST /v1/audit/continuous/checkout - subscribe to Continuous re-attestation. body: { plan: \"starter\" | \"growth\" }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/continuous/deploy-hook": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditContinuousDeployhook",
        "summary": "POST /v1/audit/continuous/deploy-hook - Growth \"on every deploy\": force an",
        "description": "POST /v1/audit/continuous/deploy-hook - Growth \"on every deploy\": force an immediate re-attestation for the caller's active subscription(s). Auth-gated by the tenant's own API key (call it from CI after a deploy).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/continuous/tick": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditContinuousTick",
        "summary": "POST /v1/audit/continuous/tick (cron-secret gated, in PUBLIC_API) - run",
        "description": "POST /v1/audit/continuous/tick (cron-secret gated, in PUBLIC_API) - run every Continuous subscription whose re-attestation is due. Driven by an EXTERNAL scheduler hitting this with x-kolm-cron-secret (containers restart, so no in-process timer). Idempotent: claim-then-run, never double-signs.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/export": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditExport",
        "summary": "preview without offering a backdoor full dump.",
        "description": "preview without offering a backdoor full dump. All three routes auth-gate on req.tenant_record. Honest envelope on bad format / missing tenant - no silent passthrough.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25509 carries route-local auth middleware"
      }
    },
    "/v1/audit/export/formats": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditExportFormats",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25537 carries route-local auth middleware"
      }
    },
    "/v1/audit/export/preview": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditExportPreview",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25547 carries route-local auth middleware"
      }
    },
    "/v1/audit/import": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditImport",
        "summary": "Tier-A bridge: source 'kolm-capture' skips the inline/url transport and",
        "description": "Tier-A bridge: source 'kolm-capture' skips the inline/url transport and audits the CALLING tenant's own stored gateway captures (grade A). The label is reserved - source_label may never claim it for vendor logs.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/issuer-key": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditIssuerkey",
        "summary": "server signs evidence reports with, so a buyer (or the /verify page's",
        "description": "server signs evidence reports with, so a buyer (or the /verify page's trusted-issuer keyring) can pin against the authoritative source instead of trusting whatever key a report embeds. Returns ONLY the public half; the private key never leaves the signer. Never throws.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/issuer-key/{fp}/revoke": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditIssuerkeyFpRevoke",
        "summary": "reason:'issuer_key_revoked' for any report signed by that key, and the",
        "description": "reason:'issuer_key_revoked' for any report signed by that key, and the public status endpoint reports valid:false. Gated by ADMIN_KEY (Bearer ADMIN_KEY via authMiddleware -> req.is_admin, or an x-admin-key header). body: { reason? }",
        "parameters": [
          {
            "name": "fp",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "fp path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/issuer-key/{fp}/status": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditIssuerkeyFpStatus",
        "summary": "issuer key fingerprint: 'live' | 'rotated' | 'revoked' + valid flag, so a",
        "description": "issuer key fingerprint: 'live' | 'rotated' | 'revoked' + valid flag, so a buyer's verifier can confirm the key that signed a report is still trusted RIGHT NOW (a signature that verifies against a REVOKED key must be refused). Pure read over the persisted key-revocation store; never throws.",
        "parameters": [
          {
            "name": "fp",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "fp path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/log": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditLog",
        "summary": "write path with HMAC-chained signatures); this implementation gives the",
        "description": "write path with HMAC-chained signatures); this implementation gives the dashboard real entries from day one without that wiring. Probe-safe: when unauth'd, returns the same 200 envelope with entries=[] rather than 401/503 so frontend probes don't fall over.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15043 carries route-local auth middleware"
      }
    },
    "/v1/audit/package/checkout": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditPackageCheckout",
        "summary": "plus -> $3,500/mo Continuous-Plus (flows through the existing subscription",
        "description": "plus -> $3,500/mo Continuous-Plus (flows through the existing subscription path; activated by activateSubscription with product_key 'plus'). Env-gated 503 degrade: when the product is not wired, createAsrCheckout throws BillingNotConfiguredError (statusCode 503) listing the exact env vars.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/report/checkout": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditReportCheckout",
        "summary": "POST /v1/audit/report/checkout - start the $750 one-time purchase of the",
        "description": "POST /v1/audit/report/checkout - start the $750 one-time purchase of the Signed Readiness Report for a specific audit. body: { audit_id }. The audit must belong to the caller and already have a (watermarked) report.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/report/verify": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditReportVerify",
        "summary": "issuer.recognized - tier 2: that key is one this product publishes (the",
        "description": "issuer.recognized - tier 2: that key is one this product publishes (the live signer or a key in public/keys/kolm-issuers.json). trusted - verify.ok AND issuer.recognized. A consumer that only checks verify.ok would accept a rogue-signed forgery; check trusted.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/reports": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditReports",
        "summary": "GET /v1/audit/reports - the tenant's report dashboard data. Lists every",
        "description": "GET /v1/audit/reports - the tenant's report dashboard data. Lists every audit/report this tenant owns (scan previews + paid reports) plus which ASR products are currently purchasable. Powers public/dashboard.html.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/scan": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditScan",
        "summary": "tenant's own stored gateway captures/receipts instead of a vendor export.",
        "description": "tenant's own stored gateway captures/receipts instead of a vendor export. The resulting report carries evidence grade A (first-party capture). The source value is reserved: supplying it WITH logs is a clean 400, so vendor logs can never masquerade as gateway captures.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditSessions",
        "summary": "POST /v1/audit/sessions - open a session.",
        "description": "POST /v1/audit/sessions - open a session. body: { subject?, source?, retention_days? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditSessionsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/delta": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditSessionsIdDelta",
        "summary": "by session id (audses_*) OR report id (asrr_*). BOTH ids must resolve to a",
        "description": "by session id (audses_*) OR report id (asrr_*). BOTH ids must resolve to a report owned by this tenant - a foreign / unknown id is {ok:false} (404/403), never another tenant's data. No re-sign; computeAuditDelta is pure + never throws. The :id is \"current\"; ?against=<id> is the prior baseline.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/export": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditSessionsIdExport",
        "summary": "The signed report reshaped into a procurement-ingestible artifact. Auth",
        "description": "The signed report reshaped into a procurement-ingestible artifact. Auth gated + tenant-fenced exactly like the sibling /report route (the export is a view over the SAME signed envelope - it carries the key fingerprint + verify URL so an importer can always trace it back to the signed source).",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/ingest": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditSessionsIdIngest",
        "summary": "POST /v1/audit/sessions/:id/ingest - append logs.",
        "description": "POST /v1/audit/sessions/:id/ingest - append logs. body: { logs } (JSONL text, JSON array, or array of records)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/questionnaire": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditSessionsIdQuestionnaire",
        "summary": "(AUTH, tenant-fenced) - the openable GET alias of the POST above, so a",
        "description": "(AUTH, tenant-fenced) - the openable GET alias of the POST above, so a seller can pull their session's autofilled questionnaire from a browser / a simple link. Identical auth + tenant fence + pure-view semantics; query-only (no body). The POST form stays for callers that prefer to send { template }.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditSessionsIdQuestionnaire",
        "summary": "(AUTH, tenant-fenced) - the SELLER pre-fills a questionnaire from their own",
        "description": "(AUTH, tenant-fenced) - the SELLER pre-fills a questionnaire from their own session's signed report (e.g. to attach to an RFP response before sharing). Tenant-fenced exactly like the sibling /report + /export routes. body may carry { template, format } as an alternative to the query string.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/report": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditSessionsIdReport",
        "summary": "GET /v1/audit/sessions/:id/report?format=json|html|pdf - the artifact.",
        "description": "GET /v1/audit/sessions/:id/report?format=json|html|pdf - the artifact. Returns the bare signed envelope (json), rendered HTML, or a PDF stream each is a downloadable deliverable, not an {ok}-wrapped API envelope.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/sessions/{id}/run": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditSessionsIdRun",
        "summary": "POST /v1/audit/sessions/:id/run - run the audit + build+sign the report.",
        "description": "POST /v1/audit/sessions/:id/run - run the audit + build+sign the report. body: { subject?, source?, retention_days?, sign? }",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/verify": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditVerify",
        "summary": "Verify the HMAC chain over this tenant's audit_events rows. Returns",
        "description": "Verify the HMAC chain over this tenant's audit_events rows. Returns ok=true when every row hashes to its declared event_hash given the previous row's hash, ok=false with the list of breaks otherwise.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15177 carries route-local auth middleware"
      }
    },
    "/v1/audit/{id}/oscal": {
      "get": {
        "tags": [
          "audit"
        ],
        "operationId": "getV1AuditIdOscal",
        "summary": "OSCAL assessment-results JSON; ?format=poam returns the POA&M-style",
        "description": "OSCAL assessment-results JSON; ?format=poam returns the POA&M-style remediation table. kolm MAPS to standards; this is an assessment-results export, never a certification. Read-only view over the SAME signed report. Tiers: Full Readiness ($15,000) and Continuous-Plus ($3,500/mo).",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/audit/{id}/retest": {
      "post": {
        "tags": [
          "audit"
        ],
        "operationId": "postV1AuditIdRetest",
        "summary": "foreign / unknown id is 404, never another tenant's data. No re-sign here;",
        "description": "foreign / unknown id is 404, never another tenant's data. No re-sign here; runFixRetest is pure + never throws (the diff is computeAuditDelta). Tier: a Continuous ($299/$999 per month) on-demand tick, or a follow-on $750 Signed Readiness Report that embeds result.delta.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/auth/github": {
      "get": {
        "tags": [
          "auth"
        ],
        "operationId": "getV1AuthGithub",
        "summary": "4 - short OAuth aliases: GET /v1/auth/github redirects to the",
        "description": "4 - short OAuth aliases: GET /v1/auth/github redirects to the canonical /v1/oauth/github/start (preserving any ?redirect= query). Same for /v1/auth/github/callback (forwards code+state to the canonical callback). When env vars are missing, the canonical route returns the operator-facing 503 oauth_not_configured envelope.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2806 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/auth/github/callback": {
      "get": {
        "tags": [
          "auth"
        ],
        "operationId": "getV1AuthGithubCallback",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2810 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/auth/login": {
      "post": {
        "tags": [
          "auth"
        ],
        "operationId": "postV1AuthLogin",
        "summary": "API key (ks_*/kao_*) + OAuth; there is no password endpoint. We add live",
        "description": "API key (ks_*/kao_*) + OAuth; there is no password endpoint. We add live deprecation aliases that 410 Gone with redirect hints so the routes are not \"dead\" - the deprecated-endpoint lock-in in W890-9 expects every routed path to have a handler. Both alias handlers carry the canonical {ok:false, error:'<id>'} envelope so W890-9 lock-in 9 stays green.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2862 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/auth/signup": {
      "post": {
        "tags": [
          "auth"
        ],
        "operationId": "postV1AuthSignup",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2872 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/automations": {
      "get": {
        "tags": [
          "automations"
        ],
        "operationId": "getV1Automations",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "automations"
        ],
        "operationId": "postV1Automations",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/automations/tick": {
      "post": {
        "tags": [
          "automations"
        ],
        "operationId": "postV1AutomationsTick",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/automations/{id}": {
      "patch": {
        "tags": [
          "automations"
        ],
        "operationId": "patchV1AutomationsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "automations"
        ],
        "operationId": "deleteV1AutomationsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/automations/{id}/run": {
      "post": {
        "tags": [
          "automations"
        ],
        "operationId": "postV1AutomationsIdRun",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/autopilot/analyze": {
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotAnalyze",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26899 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/disable": {
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotDisable",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26755 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/enable": {
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotEnable",
        "summary": "All five are tenant-fenced via req.tenant_record.id (W411 law). The",
        "description": "All five are tenant-fenced via req.tenant_record.id (W411 law). The route layer ALWAYS forces tenant_id from auth - body.tenant_id is ignored even if the client tries to pass one.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26731 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/plan": {
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotPlan",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26875 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/savings": {
      "get": {
        "tags": [
          "autopilot"
        ],
        "operationId": "getV1AutopilotSavings",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26798 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/simulate": {
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotSimulate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26923 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/status": {
      "get": {
        "tags": [
          "autopilot"
        ],
        "operationId": "getV1AutopilotStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26777 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/temporal": {
      "get": {
        "tags": [
          "autopilot"
        ],
        "operationId": "getV1AutopilotTemporal",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26968 carries route-local auth middleware"
      }
    },
    "/v1/autopilot/tick": {
      "get": {
        "tags": [
          "autopilot"
        ],
        "operationId": "getV1AutopilotTick",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26821 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "autopilot"
        ],
        "operationId": "postV1AutopilotTick",
        "summary": "NEW full-lifecycle tick. The GET /v1/autopilot/tick route above stays",
        "description": "NEW full-lifecycle tick. The GET /v1/autopilot/tick route above stays the heartbeat (tests/wave775-autopilot.test.js asserts action:'disabled'); this POST handler runs the full lifecycle via tickAutopilotFull.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26993 carries route-local auth middleware"
      }
    },
    "/v1/bakeoff/run": {
      "post": {
        "tags": [
          "bakeoff"
        ],
        "operationId": "postV1BakeoffRun",
        "summary": "Bakeoff run - evaluates a set of contestant models against a dataset and",
        "description": "Bakeoff run - evaluates a set of contestant models against a dataset and returns ranked rows + winner. Body: { dataset_id (required), contestants, opts }. Used by /account/bakeoffs and `kolm bakeoff run`.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21962 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bakeoffs": {
      "get": {
        "tags": [
          "bakeoffs"
        ],
        "operationId": "getV1Bakeoffs",
        "summary": "/v1/bakeoffs - list + run alias for /v1/bakeoff/run. The bakeoff module",
        "description": "/v1/bakeoffs - list + run alias for /v1/bakeoff/run. The bakeoff module does not persist runs to a registry (each call returns a fresh result), so GET returns an empty array; the page already handles that shape via `{bakeoffs: []}` in its .catch fallback.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23473 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "bakeoffs"
        ],
        "operationId": "postV1Bakeoffs",
        "summary": "Bakeoffs run alias - SDK-friendly synonym for /v1/bakeoff/run with the",
        "description": "Bakeoffs run alias - SDK-friendly synonym for /v1/bakeoff/run with the added W411 tenant fence at the dataset boundary (cross-tenant dataset_id returns 404). Same body: { dataset_id, contestants, opts }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23479 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bench/humaneval": {
      "post": {
        "tags": [
          "bench"
        ],
        "operationId": "postV1BenchHumaneval",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23749 carries route-local auth middleware"
      }
    },
    "/v1/bench/inference": {
      "get": {
        "tags": [
          "bench"
        ],
        "operationId": "getV1BenchInference",
        "summary": "W-INTEG-3: signed inference-economics benchmark",
        "description": "W-INTEG-3: signed inference-economics benchmark",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11960 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bench/inference/run": {
      "post": {
        "tags": [
          "bench"
        ],
        "operationId": "postV1BenchInferenceRun",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11967 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bench/mmlu": {
      "post": {
        "tags": [
          "bench"
        ],
        "operationId": "postV1BenchMmlu",
        "summary": "envelope when called without a tester-supplied DI seam.",
        "description": "envelope when called without a tester-supplied DI seam. The routes import lazily so the bench modules don't pay startup cost on cold daemons that never call them.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23720 carries route-local auth middleware"
      }
    },
    "/v1/bench/mtbench": {
      "post": {
        "tags": [
          "bench"
        ],
        "operationId": "postV1BenchMtbench",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23774 carries route-local auth middleware"
      }
    },
    "/v1/billing/breakdown": {
      "get": {
        "tags": [
          "billing"
        ],
        "operationId": "getV1BillingBreakdown",
        "summary": "it walks the team's member tenants and rolls up.",
        "description": "it walks the team's member tenants and rolls up. Tenant fence: tenant_id is forced from req.tenant_record.id - never read from the request body or query string. Team caller is forced to be a member of the named team (non-members get 403 forbidden).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23095 carries route-local auth middleware"
      }
    },
    "/v1/billing/checkout": {
      "post": {
        "tags": [
          "billing"
        ],
        "operationId": "postV1BillingCheckout",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11980 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/billing/meters": {
      "get": {
        "tags": [
          "billing"
        ],
        "operationId": "getV1BillingMeters",
        "summary": "Returns the static catalog of legacy W384 meters merged with the W409y",
        "description": "Returns the static catalog of legacy W384 meters merged with the W409y billing-unit catalog (10 units the auditor signed off on). The W409y entries carry tier_soft + tier_hard limits resolved from the caller's tenant plan when an authenticated key is present.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23020 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/billing/ready": {
      "get": {
        "tags": [
          "billing"
        ],
        "operationId": "getV1BillingReady",
        "summary": "W-INTEG-3: Stripe billing activation (operator sets price-id env vars)",
        "description": "W-INTEG-3: Stripe billing activation (operator sets price-id env vars)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11976 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/billing/tiers": {
      "get": {
        "tags": [
          "billing"
        ],
        "operationId": "getV1BillingTiers",
        "summary": "P0-3 closure: /v1/billing/tiers as a public alias of /v1/plans so the",
        "description": "P0-3 closure: /v1/billing/tiers as a public alias of /v1/plans so the CLI `kolm billing tiers` (+ alias `plans`) returns useful data without requiring auth. Includes a billing_configured flag tied to the actual STRIPE_PAYMENT_LINK_* env presence so the UI can demote when unwired.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2775 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/billing/usage": {
      "get": {
        "tags": [
          "billing"
        ],
        "operationId": "getV1BillingUsage",
        "summary": "Returns the current-period usage map for the caller's tenant. The",
        "description": "Returns the current-period usage map for the caller's tenant. The dashboard at /account/billing reads this endpoint; the CLI `kolm billing usage [--period]` hits it directly.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23064 carries route-local auth middleware"
      }
    },
    "/v1/bridges/auto-synthesize": {
      "post": {
        "tags": [
          "bridges"
        ],
        "operationId": "postV1BridgesAutosynthesize",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15952 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bridges/observations": {
      "get": {
        "tags": [
          "bridges"
        ],
        "operationId": "getV1BridgesObservations",
        "summary": "GET /v1/bridges/observations - flat list of recent captures for the /captures inbox.",
        "description": "GET /v1/bridges/observations - flat list of recent captures for the /captures inbox. Filters: ?namespace=<ns> (optional), ?limit=<n> (default 50, max 200), ?include_discarded=1.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15893 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bridges/observations/{id}": {
      "post": {
        "tags": [
          "bridges"
        ],
        "operationId": "postV1BridgesObservationsId",
        "summary": "POST /v1/bridges/observations/:id - soft-update an observation (keep/discard).",
        "description": "POST /v1/bridges/observations/:id - soft-update an observation (keep/discard). Body: { discarded: true } | { kept: true } | { discarded: false }. Tenant-scoped.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15939 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bridges/observe": {
      "post": {
        "tags": [
          "bridges"
        ],
        "operationId": "postV1BridgesObserve",
        "summary": "POST /v1/bridges/observe - agents log a (model, prompt, response) tuple.",
        "description": "POST /v1/bridges/observe - agents log a (model, prompt, response) tuple. After ≥4 calls with the same template signature we surface a synthesis suggestion. 1: persists via insertCapture (durable contract). 503 on store failure - same envelope as the capture proxy handlers.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15816 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bridges/specialist-candidates": {
      "get": {
        "tags": [
          "bridges"
        ],
        "operationId": "getV1BridgesSpecialistcandidates",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16611 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bridges/suggestions": {
      "get": {
        "tags": [
          "bridges"
        ],
        "operationId": "getV1BridgesSuggestions",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15868 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/build/preview": {
      "post": {
        "tags": [
          "build"
        ],
        "operationId": "postV1BuildPreview",
        "summary": "POST /v1/build/preview. Richer dry-run preview that powers the",
        "description": "POST /v1/build/preview. Richer dry-run preview that powers the builder UI's results pane: returns k_score, first 3 train rows, first 3 holdout rows, production_ready verdict + gate reasons, and the synth metadata. Public + rate-limited; no artifact write, no charge. Accepts {spec, seeds_jsonl_text}. Errors map to 400 (validation) or 500.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4331 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/build/strategy": {
      "get": {
        "tags": [
          "build"
        ],
        "operationId": "getV1BuildStrategy",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16057 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "build"
        ],
        "operationId": "postV1BuildStrategy",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16079 carries route-local auth middleware"
      }
    },
    "/v1/build/strategy/catalog": {
      "get": {
        "tags": [
          "build"
        ],
        "operationId": "getV1BuildStrategyCatalog",
        "summary": "Build strategy brain - shared planner for capture, prompt/RAG/routing,",
        "description": "Build strategy brain - shared planner for capture, prompt/RAG/routing, training, distillation, cloud compute, compilation, quantization, and local runtime. It never launches work and never returns secret values.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16023 carries route-local auth middleware"
      }
    },
    "/v1/builder/compile": {
      "post": {
        "tags": [
          "builder"
        ],
        "operationId": "postV1BuilderCompile",
        "summary": "{task, examples} payload into a real compile job. Validation matches",
        "description": "{task, examples} payload into a real compile job. Validation matches /v1/builder/preview so a Preview→Compile flow that passes preview also passes here; the only added requirement is the API key (handled by authMiddleware mounted above this line). Recipe class and namespace are forced so builder-originated artifacts are distinguishable in audits.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8618 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/builder/preview": {
      "post": {
        "tags": [
          "builder"
        ],
        "operationId": "postV1BuilderPreview",
        "summary": "POST /v1/builder/preview - synthesize a recipe and estimate K-score.",
        "description": "POST /v1/builder/preview - synthesize a recipe and estimate K-score. Rate-limited; no auth. Inputs are validated tightly so this cannot be used as a generic compute oracle. The 10 KB per-example cap matches the body limit on /v1/compile and keeps the synthesis cost bounded.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4245 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/builder/templates": {
      "get": {
        "tags": [
          "builder"
        ],
        "operationId": "getV1BuilderTemplates",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4236 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/builds": {
      "get": {
        "tags": [
          "builds"
        ],
        "operationId": "getV1Builds",
        "summary": "/v1/builds - aliases the compile-job list for /account/builds.html.",
        "description": "/v1/builds - aliases the compile-job list for /account/builds.html. builds.html expects {builds:[{job_id, status, ...}]}; the canonical /v1/compile/jobs returns {jobs:[...]}, so we adapt the shape here.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23414 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/bundle/airgap": {
      "post": {
        "tags": [
          "bundle"
        ],
        "operationId": "postV1BundleAirgap",
        "summary": "an HTTP response would balloon memory, leak the server's checkout layout,",
        "description": "an HTTP response would balloon memory, leak the server's checkout layout, and lock the route into one host's filesystem. The CLI is the supported path - `kolm bundle airgap --out <path>`. The route still exists so surface discovery + docs can link to it and so a future CDN-backed implementation has a stable URL.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27648 carries route-local auth middleware"
      }
    },
    "/v1/buyer/portfolio": {
      "get": {
        "tags": [
          "buyer"
        ],
        "operationId": "getV1BuyerPortfolio",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/buyer/watchlist": {
      "post": {
        "tags": [
          "buyer"
        ],
        "operationId": "postV1BuyerWatchlist",
        "summary": "POST /v1/buyer/watchlist - add a vendor Trust slug to the buyer's watchlist.",
        "description": "owning tenant via req.tenant_record.id. A buyer seat lives under the EXISTING Continuous $999/mo shape - no new price or tier. POST /v1/buyer/watchlist - add a vendor Trust slug to the buyer's watchlist. body: { slug, label? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/byoc/attestation": {
      "post": {
        "tags": [
          "byoc"
        ],
        "operationId": "postV1ByocAttestation",
        "summary": "Attestation callback - UNAUTH (no API key). Identifies via enroll_token,",
        "description": "Attestation callback - UNAUTH (no API key). Identifies via enroll_token, which was minted by the deploy endpoint and embedded in the deploy script. The token is single-use-equivalent: if an attacker has the token they could spoof the public_url, but the deployment row is owned by a specific tenant_id and the URL is visible in their dashboard - they'll notice.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18757 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/byoc/deploy": {
      "post": {
        "tags": [
          "byoc"
        ],
        "operationId": "postV1ByocDeploy",
        "summary": "Customer deploys a .kolm artifact to their own Fly / AWS Nitro / GCP CVM",
        "description": "Customer deploys a .kolm artifact to their own Fly / AWS Nitro / GCP CVM / Azure CVM / Docker host. We issue a signed deploy manifest + a deploy script the customer runs. The deployed instance POSTs an attestation (image SHA, plus TEE measurement on confidential targets) back to /v1/byoc/attestation. kolm.ai never runs the artifact.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18700 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/byoc/deployments": {
      "get": {
        "tags": [
          "byoc"
        ],
        "operationId": "getV1ByocDeployments",
        "summary": "BYOC deployments list - returns tenant deployments, optionally team-scoped after membership check.",
        "description": "BYOC deployments list - returns tenant deployments, optionally team-scoped after membership check.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18719 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/byoc/deployments/{id}": {
      "get": {
        "tags": [
          "byoc"
        ],
        "operationId": "getV1ByocDeploymentsId",
        "summary": "BYOC deployment detail - returns one deployment owned by the tenant or one of their teams.",
        "description": "BYOC deployment detail - returns one deployment owned by the tenant or one of their teams.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18730 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "byoc"
        ],
        "operationId": "deleteV1ByocDeploymentsId",
        "summary": "BYOC deployment teardown - marks an owned deployment torn down and hides it from listings.",
        "description": "BYOC deployment teardown - marks an owned deployment torn down and hides it from listings.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18741 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/byoc/status": {
      "get": {
        "tags": [
          "byoc"
        ],
        "operationId": "getV1ByocStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11013 carries route-local auth middleware"
      }
    },
    "/v1/byoc/targets": {
      "get": {
        "tags": [
          "byoc"
        ],
        "operationId": "getV1ByocTargets",
        "summary": "BYOC targets - lists supported deploy targets for the public form and CLI.",
        "description": "BYOC targets - lists supported deploy targets for the public form and CLI.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18766 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capability/build": {
      "post": {
        "tags": [
          "capability"
        ],
        "operationId": "postV1CapabilityBuild",
        "summary": "Capability build - constructs a capability descriptor block from an",
        "description": "Capability build - constructs a capability descriptor block from an artifact manifest, declaring what the artifact can do (modalities, budgets, K-floor, attestation requirements). Pairs with /v1/lineage/build.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19169 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capability/validate": {
      "post": {
        "tags": [
          "capability"
        ],
        "operationId": "postV1CapabilityValidate",
        "summary": "Capability validate - checks a capability descriptor block for structural",
        "description": "Capability validate - checks a capability descriptor block for structural consistency and that declared budgets/K-floor are internally coherent. Returns {ok:true, block} on success, {ok:false, error} otherwise.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19177 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/anthropic": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureAnthropic",
        "summary": "POST /v1/capture/anthropic - proxy to Anthropic, capture the round-trip.",
        "description": "OPENAI_BASE_URL=https://kolm.ai/v1/capture/openai → POST .../v1/chat/completions The suffix is discarded; the flat provider-specific capture endpoints use the same handler. Express's `?` makes the suffix optional, and the wildcard absorbs any depth. POST /v1/capture/anthropic - proxy to Anthropic, capture the round-trip. The body is the upstream Anthropic Messages payload, unmodified.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17815 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/browse": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureBrowse",
        "summary": "/v1/capture/browse / /v1/capture/bulk / /v1/capture/export - page",
        "description": "/v1/capture/browse / /v1/capture/bulk / /v1/capture/export - page surface for the captures.html admin view. Browse paginates, bulk acts on a set of capture ids, export streams JSONL/CSV. Empty-tenant safe.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8933 carries route-local auth middleware"
      }
    },
    "/v1/capture/bulk": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureBulk",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8968 carries route-local auth middleware"
      }
    },
    "/v1/capture/export": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureExport",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8998 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureExport",
        "summary": "POST shim so account/captures.html bulk-export button (sends",
        "description": "POST shim so account/captures.html bulk-export button (sends {capture_ids:[...]} in body) doesn't 404. Filters to the listed ids and returns the rows inline as JSON so the page can blob-download client-side.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9023 carries route-local auth middleware"
      }
    },
    "/v1/capture/gemini": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureGemini",
        "summary": "base_url=https://kolm.ai/v1/capture/gemini and keep using chat.completions.",
        "description": "Gemini capture and OpenAI-compatible aliases. These route to Google's /v1beta/openai compatibility surface so OpenAI SDK clients can set base_url=https://kolm.ai/v1/capture/gemini and keep using chat.completions.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5949 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/gemini/chat/completions": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureGeminiChatCompletions",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5950 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/gemini/v1/chat/completions": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureGeminiV1ChatCompletions",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5951 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/health": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureHealth",
        "summary": "GET /v1/capture/health - operator probe. Honest answer about whether",
        "description": "GET /v1/capture/health - operator probe. Honest answer about whether the next insertCapture call will persist beyond a single lambda. Used by the /captures + /security pages and the `kolm doctor` flow.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16883 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/log": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureLog",
        "summary": "POST /v1/capture/log - batch (input, output) insert. Returns 503 with",
        "description": "POST /v1/capture/log - batch (input, output) insert. Returns 503 with capture_store_unavailable when every item failed to persist (no swallow).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16790 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/media": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureMedia",
        "summary": "Capture media - multipart upload endpoint for image/audio/video/blob",
        "description": "Capture media - multipart upload endpoint for image/audio/video/blob captures. Streams parts through mediaStoreBlob and appends one event per blob to the tenant-scoped lake. Requires Content-Type: multipart/form-data.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22946 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/openai": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureOpenai",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17891 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/openrouter": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureOpenrouter",
        "summary": "OpenRouter capture and base-URL aliases. The direct base-URL forms support",
        "description": "OpenRouter capture and base-URL aliases. The direct base-URL forms support SDKs that point BASE_URL at https://kolm.ai/v1/openrouter.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5936 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/openrouter/chat/completions": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureOpenrouterChatCompletions",
        "summary": "OpenRouter capture chat completions alias for clients whose base URL is",
        "description": "OpenRouter capture chat completions alias for clients whose base URL is https://kolm.ai/v1/capture/openrouter and which append /chat/completions.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5939 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/openrouter/v1/chat/completions": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureOpenrouterV1ChatCompletions",
        "summary": "OpenRouter capture alias for SDKs that append the OpenAI chat-completions path.",
        "description": "OpenRouter capture alias for SDKs that append the OpenAI chat-completions path.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5941 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/rbac/evaluate": {
      "post": {
        "tags": [
          "capture"
        ],
        "operationId": "postV1CaptureRbacEvaluate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2415 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/rbac/policy": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureRbacPolicy",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2411 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/snippet": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureSnippet",
        "summary": "GET /v1/capture/snippet - copy-paste snippet for the Capture tab.",
        "description": "GET /v1/capture/snippet - copy-paste snippet for the Capture tab. Fills tenant key when authed, placeholder otherwise.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1459 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/capture/stream": {
      "get": {
        "tags": [
          "capture"
        ],
        "operationId": "getV1CaptureStream",
        "summary": "Payload shape is the CLI/UI contract (W258-BE-6): capture_id /",
        "description": "Payload shape is the CLI/UI contract (W258-BE-6): capture_id / captured_at / namespace / model / provider / latency_us / status / prompt_head / response_head / x_kolm_capture_durable. The raw store row is shimmed here so the dashboard and `kolm tail captures` see the same shape without one of them having to translate.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16911 carries route-local auth middleware"
      }
    },
    "/v1/captures/forget": {
      "post": {
        "tags": [
          "captures"
        ],
        "operationId": "postV1CapturesForget",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24914 carries route-local auth middleware"
      }
    },
    "/v1/captures/forgotten": {
      "get": {
        "tags": [
          "captures"
        ],
        "operationId": "getV1CapturesForgotten",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24942 carries route-local auth middleware"
      }
    },
    "/v1/captures/list": {
      "get": {
        "tags": [
          "captures"
        ],
        "operationId": "getV1CapturesList",
        "summary": "W-G wrapper-completion - GET /v1/captures/list",
        "description": "W-G wrapper-completion - GET /v1/captures/list Paginated capture browser feed for /account/captures.html. Filters: ?namespace, ?status (pending|approved|rejected|quarantined, multi-comma), ?risk_min, ?risk_max (0..1), ?pii (multi-comma), ?from, ?to (ISO), ?q (substring), ?limit (1-200), ?offset.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24567 carries route-local auth middleware"
      }
    },
    "/v1/captures/multi-turn": {
      "post": {
        "tags": [
          "captures"
        ],
        "operationId": "postV1CapturesMultiturn",
        "summary": "POST /v1/captures/multi-turn - append a multi-turn conversation row.",
        "description": "POST /v1/captures/multi-turn - append a multi-turn conversation row. Body shape: { namespace, conversation_id, conversation:[{role,content,tool_calls?,timestamp}], parent_message_id? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/multimodal-pipeline-routes.js is registered from src/router.js:30101 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/captures/multimodal": {
      "post": {
        "tags": [
          "captures"
        ],
        "operationId": "postV1CapturesMultimodal",
        "summary": "Body shape:",
        "description": "Body shape: { namespace, kind, payload, hash?, redaction_receipt? } If hash is omitted we compute one from the canonical payload so the caller can be lazy. kind MUST be in MULTIMODAL_KINDS.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/multimodal-pipeline-routes.js is registered from src/router.js:30101 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/captures/review-bulk": {
      "post": {
        "tags": [
          "captures"
        ],
        "operationId": "postV1CapturesReviewbulk",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24705 carries route-local auth middleware"
      }
    },
    "/v1/captures/{id}/inspect": {
      "get": {
        "tags": [
          "captures"
        ],
        "operationId": "getV1CapturesIdInspect",
        "summary": "W-G wrapper-completion - GET /v1/captures/:id/inspect",
        "description": "W-G wrapper-completion - GET /v1/captures/:id/inspect Single-row inspection (full prompt + response + receipt + chain hash).",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24632 carries route-local auth middleware"
      }
    },
    "/v1/captures/{id}/review": {
      "post": {
        "tags": [
          "captures"
        ],
        "operationId": "postV1CapturesIdReview",
        "summary": "W-G wrapper-completion - POST /v1/captures/:id/review",
        "description": "W-G wrapper-completion - POST /v1/captures/:id/review Approve / reject / quarantine a capture. Body: {action: 'approve'|'reject'|'quarantine', reason?}. Bulk variant: POST /v1/captures/review-bulk {ids:[...], action, reason?}.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24678 carries route-local auth middleware"
      }
    },
    "/v1/carbon/estimate": {
      "get": {
        "tags": [
          "carbon"
        ],
        "operationId": "getV1CarbonEstimate",
        "summary": "→ savingsReport envelope comparing local run vs frontier baseline.",
        "description": "→ savingsReport envelope comparing local run vs frontier baseline. Auth required (same pattern as billing/breakdown). Every envelope carries methodology='public-research-estimate' so a downstream consumer cannot mistake the estimate for a measured value. W786 honesty contract.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23149 carries route-local auth middleware"
      }
    },
    "/v1/cc/kinds": {
      "get": {
        "tags": [
          "cc"
        ],
        "operationId": "getV1CcKinds",
        "summary": "confidential compute",
        "description": "confidential compute",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19086 carries route-local auth middleware"
      }
    },
    "/v1/cc/shape/{kind}": {
      "get": {
        "tags": [
          "cc"
        ],
        "operationId": "getV1CcShapeKind",
        "summary": "Confidential-compute shape - returns the expected JSON shape for an",
        "description": "Confidential-compute shape - returns the expected JSON shape for an attestation report of the given kind (pccs, snp-report, nitro-attestation, nras). 404 if the kind is unknown. Lets callers validate before /v1/cc/verify.",
        "parameters": [
          {
            "name": "kind",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "kind path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19093 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cc/verify": {
      "post": {
        "tags": [
          "cc"
        ],
        "operationId": "postV1CcVerify",
        "summary": "Confidential-compute verify - validates an attestation report against its",
        "description": "Confidential-compute verify - validates an attestation report against its declared kind. Returns {state:'shape_ok'|...,verified:false} until a tenant registers a real crypto verifier via registerAttestationVerifier. Body: { kind, report, opts }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19104 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/changelog": {
      "get": {
        "tags": [
          "changelog"
        ],
        "operationId": "getV1Changelog",
        "summary": "public changelog - marketing surface, no auth, no tenant scoping.",
        "description": "public changelog - marketing surface, no auth, no tenant scoping. Source of truth lives in src/changelog.js (a single static WAVES array).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3657 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/chargeback": {
      "get": {
        "tags": [
          "chargeback"
        ],
        "operationId": "getV1Chargeback",
        "summary": "-> stream body w/ per-format Content-Type",
        "description": "-> stream body w/ per-format Content-Type Tenant fence: tenant_id forced from req.tenant_record.id; query/body never override. version stamp matches /^w783-/.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28251 carries route-local auth middleware"
      }
    },
    "/v1/chargeback/export": {
      "post": {
        "tags": [
          "chargeback"
        ],
        "operationId": "postV1ChargebackExport",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28273 carries route-local auth middleware"
      }
    },
    "/v1/chat/completions": {
      "post": {
        "tags": [
          "chat"
        ],
        "operationId": "postV1ChatCompletions",
        "summary": "the standard hosted-inference path with accelerated:false on the body",
        "description": "the standard hosted-inference path with accelerated:false on the body so the caller can still get a real chat completion. Defense-in-depth tenant fence: any accelerated call without req.tenant_record is hard 401-rejected - we never run the accelerated path anonymously, even on the local daemon, because the bench dashboard keys on tenant_id.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5351 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cid/{cid}": {
      "get": {
        "tags": [
          "cid"
        ],
        "operationId": "getV1CidCid",
        "summary": "CID lookup - content-addressed resolution within the caller's tenant",
        "description": "CID lookup - content-addressed resolution within the caller's tenant scope. Two compiles that produce the same bytes (same task spec, same recipes, same evals, same base model pointer) yield the same CID; this route is how downstream tools dedupe by content rather than job_id. CID format is strictly validated to keep the path safe from injection.",
        "parameters": [
          {
            "name": "cid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "cid path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9185 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/client-error": {
      "post": {
        "tags": [
          "client-error"
        ],
        "operationId": "postV1Clienterror",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/account-ui-routes.js is registered from src/router.js:30047 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cloud/broker": {
      "post": {
        "tags": [
          "cloud"
        ],
        "operationId": "postV1CloudBroker",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2367 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cloud/broker/catalog": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudBrokerCatalog",
        "summary": "Constraint-first compute planner for local, SSH, rented GPU, managed",
        "description": "Constraint-first compute planner for local, SSH, rented GPU, managed training, customer cloud, and edge runtime. This is a planning endpoint only: it never launches infrastructure and never returns secret values.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2363 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cloud/deploy-plan": {
      "post": {
        "tags": [
          "cloud"
        ],
        "operationId": "postV1CloudDeployplan",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2395 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cloud/deploy-targets": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudDeploytargets",
        "summary": "Secret-safe deploy catalog for account UI, CLI, CI, and unauthenticated",
        "description": "Secret-safe deploy catalog for account UI, CLI, CI, and unauthenticated evaluators. This does not create infrastructure and never returns secret values; it returns the concrete commands and env-secret references needed for BYOC, edge, GPU, and self-hosted deployments.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2391 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/cloud/distill": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudDistill",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28339 carries route-local auth middleware"
      }
    },
    "/v1/cloud/distill/meter/{job_id}": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudDistillMeterJobid",
        "summary": "NOTE: meter route registered BEFORE the ':job_id' route so the router",
        "description": "NOTE: meter route registered BEFORE the ':job_id' route so the router matches /meter/:job_id literally and does not interpret 'meter' as a job_id.",
        "parameters": [
          {
            "name": "job_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "job_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28365 carries route-local auth middleware"
      }
    },
    "/v1/cloud/distill/submit": {
      "post": {
        "tags": [
          "cloud"
        ],
        "operationId": "postV1CloudDistillSubmit",
        "summary": "Tenant fence: tenant_id forced from req.tenant_record.id; body/path never",
        "description": "Tenant fence: tenant_id forced from req.tenant_record.id; body/path never override. Backend honesty: when KOLM_CLOUD_DISTILL_ENDPOINT is unset, the submit response carries cloud_backend_status='no_pool_configured' so the caller knows the work is queued but not yet executing. version stamp /^w785-/.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28313 carries route-local auth middleware"
      }
    },
    "/v1/cloud/distill/{job_id}": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudDistillJobid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "job_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "job_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28384 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "cloud"
        ],
        "operationId": "deleteV1CloudDistillJobid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "job_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "job_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28403 carries route-local auth middleware"
      }
    },
    "/v1/cloud/readiness": {
      "get": {
        "tags": [
          "cloud"
        ],
        "operationId": "getV1CloudReadiness",
        "summary": "Cloud readiness is exposed directly for account UI, CI, and self-hosted",
        "description": "Cloud readiness is exposed directly for account UI, CI, and self-hosted operators. It reports configured categories and missing variable names, but never returns secret values.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2348 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile": {
      "get": {
        "tags": [
          "compile"
        ],
        "operationId": "getV1Compile",
        "summary": "Compile job list - returns the caller's recent tenant-scoped compile jobs.",
        "description": "Compile job list - returns the caller's recent tenant-scoped compile jobs.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8495 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "compile"
        ],
        "operationId": "postV1Compile",
        "summary": "Compile job creation - queues a tenant-scoped build and returns job_id, status, and poll URL.",
        "description": "Compile job creation - queues a tenant-scoped build and returns job_id, status, and poll URL. Validates task/model/output options, bills usage, and writes the compile audit record.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8275 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/cloud": {
      "post": {
        "tags": [
          "compile"
        ],
        "operationId": "postV1CompileCloud",
        "summary": "POST /v1/compile/cloud - W869 Persona B path: caller has no local GPU.",
        "description": "POST /v1/compile/cloud - W869 Persona B path: caller has no local GPU. Dispatches a compile to a partner GPU (modal/runpod/vast/lambda) using server-side credentials (KOLM_RUNPOD_TOKEN / KOLM_MODAL_TOKEN in env). Body: { backend, namespace, spec?, confirm, budget_usd, base_model? }. Without confirm:true we return a quote so the caller sees the cost first.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8529 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/estimate": {
      "get": {
        "tags": [
          "compile"
        ],
        "operationId": "getV1CompileEstimate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1359 is mounted before r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "compile"
        ],
        "operationId": "postV1CompileEstimate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1358 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/preview": {
      "post": {
        "tags": [
          "compile"
        ],
        "operationId": "postV1CompilePreview",
        "summary": "POST /v1/compile/preview - 5 synthetic Q&A pairs (stub). Real version",
        "description": "POST /v1/compile/preview - 5 synthetic Q&A pairs (stub). Real version would call the LLM bridge; this returns a deterministic sample so the Describe-tab \"Generate preview\" button works without any keys.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1364 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/start": {
      "post": {
        "tags": [
          "compile"
        ],
        "operationId": "postV1CompileStart",
        "summary": "POST /v1/compile/start - wizard \"Compile\" CTA. Returns a job id the",
        "description": "POST /v1/compile/start - wizard \"Compile\" CTA. Returns a job id the overlay opens an SSE stream against. Stubbed for the no-code path.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1389 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/stream/{job}": {
      "get": {
        "tags": [
          "compile"
        ],
        "operationId": "getV1CompileStreamJob",
        "summary": "GET /v1/compile/stream/:job - SSE event stream powering the compile",
        "description": "GET /v1/compile/stream/:job - SSE event stream powering the compile overlay. Reload-safe via ?cursor. See src/compile-stream.js for the event contract.",
        "parameters": [
          {
            "name": "job",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "job path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1405 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/{id}": {
      "get": {
        "tags": [
          "compile"
        ],
        "operationId": "getV1CompileId",
        "summary": "Compile job status - returns a safe tenant-scoped snapshot plus artifact_url when complete.",
        "description": "Compile job status - returns a safe tenant-scoped snapshot plus artifact_url when complete.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8500 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compile/{id}/.kolm": {
      "get": {
        "tags": [
          "compile"
        ],
        "operationId": "getV1CompileIdkolm",
        "summary": "Compile artifact download - streams the completed .kolm zip or reports readiness/expiry.",
        "description": "Compile artifact download - streams the completed .kolm zip or reports readiness/expiry.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8514 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compliance/ai-act/export": {
      "post": {
        "tags": [
          "compliance"
        ],
        "operationId": "postV1ComplianceAiactExport",
        "summary": "* /governance-report runs the loop body with a per-row tenant re-check",
        "description": "* /governance-report runs the loop body with a per-row tenant re-check so a future schema bug cannot leak across tenants. Distinct from sibling W767-cert / W768-modelcard / W769-residency / audit-export routes - no path collision possible.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25302 carries route-local auth middleware"
      }
    },
    "/v1/compliance/ai-act/governance-report": {
      "get": {
        "tags": [
          "compliance"
        ],
        "operationId": "getV1ComplianceAiactGovernancereport",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25367 carries route-local auth middleware"
      }
    },
    "/v1/compliance/ai-act/human-in-loop": {
      "post": {
        "tags": [
          "compliance"
        ],
        "operationId": "postV1ComplianceAiactHumaninloop",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25341 carries route-local auth middleware"
      }
    },
    "/v1/compliance/ai-act/risk-score": {
      "post": {
        "tags": [
          "compliance"
        ],
        "operationId": "postV1ComplianceAiactRiskscore",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25326 carries route-local auth middleware"
      }
    },
    "/v1/compliance/certification-packet": {
      "get": {
        "tags": [
          "compliance"
        ],
        "operationId": "getV1ComplianceCertificationpacket",
        "summary": "Compliance certification packet - local evidence exists, external auditor",
        "description": "Compliance certification packet - local evidence exists, external auditor and legal certifications remain explicitly gated.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1933 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compliance/certification-packet/template": {
      "get": {
        "tags": [
          "compliance"
        ],
        "operationId": "getV1ComplianceCertificationpacketTemplate",
        "summary": "Compliance certification manifest template - the exact evidence bundle a",
        "description": "Compliance certification manifest template - the exact evidence bundle a live auditor/legal/certification claim must provide before Kolm can call compliance certifications complete.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1975 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compliance/certification-packet/validate": {
      "post": {
        "tags": [
          "compliance"
        ],
        "operationId": "postV1ComplianceCertificationpacketValidate",
        "summary": "Compliance certification manifest validation - fails closed on missing",
        "description": "Compliance certification manifest validation - fails closed on missing auditor/legal evidence, unsigned proof hashes, non-HTTPS evidence URLs, placeholder fields, and secret-looking values.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2016 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/compliance/status": {
      "get": {
        "tags": [
          "compliance"
        ],
        "operationId": "getV1ComplianceStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11031 carries route-local auth middleware"
      }
    },
    "/v1/compose": {
      "post": {
        "tags": [
          "compose"
        ],
        "operationId": "postV1Compose",
        "summary": "Compose - dispatches one query across the top-k matching kolm artifacts and",
        "description": "Compose - dispatches one query across the top-k matching kolm artifacts and returns each artifact's output. Billable per non-cache, non-error dispatch. Body: { query, input, k=5, strategy='attention', tag }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14306 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/concepts": {
      "get": {
        "tags": [
          "concepts"
        ],
        "operationId": "getV1Concepts",
        "summary": "Layer 2: Registry",
        "description": "Layer 2: Registry",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14193 carries route-local auth middleware"
      }
    },
    "/v1/concepts/{id}": {
      "get": {
        "tags": [
          "concepts"
        ],
        "operationId": "getV1ConceptsId",
        "summary": "Concept detail - returns a readable concept with versions after tenant, team, or public visibility checks.",
        "description": "Concept detail - returns a readable concept with versions after tenant, team, or public visibility checks.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14199 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "concepts"
        ],
        "operationId": "deleteV1ConceptsId",
        "summary": "Concept delete - removes an owned concept and its versions; forbidden tenants receive 403.",
        "description": "Concept delete - removes an owned concept and its versions; forbidden tenants receive 403.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14206 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/concepts/{id}/lineage": {
      "get": {
        "tags": [
          "concepts"
        ],
        "operationId": "getV1ConceptsIdLineage",
        "summary": "Concept lineage - returns upstream and downstream head-version lineage after visibility checks.",
        "description": "Concept lineage - returns upstream and downstream head-version lineage after visibility checks.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14214 carries route-local auth middleware"
      }
    },
    "/v1/concepts/{id}/stats": {
      "get": {
        "tags": [
          "concepts"
        ],
        "operationId": "getV1ConceptsIdStats",
        "summary": "Per-concept usage stats: invocation count, latency percentiles, cache hit rate.",
        "description": "Per-concept usage stats: invocation count, latency percentiles, cache hit rate.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14221 carries route-local auth middleware"
      }
    },
    "/v1/connectors": {
      "get": {
        "tags": [
          "connectors"
        ],
        "operationId": "getV1Connectors",
        "summary": "Connectors - lists upstream provider connectors (openai, anthropic,",
        "description": "Connectors - lists upstream provider connectors (openai, anthropic, openrouter, etc.) with per-provider config status (key present, base URL, last reachable check). Read by /docs/connectors and `kolm connectors`.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23333 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/connectors/notify": {
      "post": {
        "tags": [
          "connectors"
        ],
        "operationId": "postV1ConnectorsNotify",
        "summary": "POST /v1/connectors/notify - capture an email for a not-yet-shipped",
        "description": "POST /v1/connectors/notify - capture an email for a not-yet-shipped connector tile on the Connect tab. Appends to data/connector-waitlist.jsonl. Best-effort: never breaks the UI.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1419 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/conversations": {
      "get": {
        "tags": [
          "conversations"
        ],
        "operationId": "getV1Conversations",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29115 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "conversations"
        ],
        "operationId": "postV1Conversations",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29103 carries route-local auth middleware"
      }
    },
    "/v1/conversations/{id}": {
      "get": {
        "tags": [
          "conversations"
        ],
        "operationId": "getV1ConversationsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29131 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "conversations"
        ],
        "operationId": "deleteV1ConversationsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29143 carries route-local auth middleware"
      }
    },
    "/v1/copyright/queue/{namespace}": {
      "get": {
        "tags": [
          "copyright"
        ],
        "operationId": "getV1CopyrightQueueNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20947 carries route-local auth middleware"
      }
    },
    "/v1/copyright/scan": {
      "post": {
        "tags": [
          "copyright"
        ],
        "operationId": "postV1CopyrightScan",
        "summary": "heuristic (flag_reason starts with `copyright_heuristic:`).",
        "description": "heuristic (flag_reason starts with `copyright_heuristic:`). Honest contract: this is HEURISTIC, not legal advice. The route stamps version:'w750-followup-vN.M' on every envelope so consumers can version-pin via regex (/^w750-followup-/).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20893 carries route-local auth middleware"
      }
    },
    "/v1/credential/verify": {
      "post": {
        "tags": [
          "credential"
        ],
        "operationId": "postV1CredentialVerify",
        "summary": "Returns: { valid: boolean, reason?: string, spec, type }",
        "description": "Returns: { valid: boolean, reason?: string, spec, type } This validates the HMAC signature using the server's receipt secret. For a future Ed25519 swap, the public key would live at /.well-known/ and verification would not need server auth. Today this endpoint is open.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14154 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/datasets": {
      "get": {
        "tags": [
          "datasets"
        ],
        "operationId": "getV1Datasets",
        "summary": "Datasets list - returns tenant-scoped dataset summaries for captured rows.",
        "description": "Datasets list - returns tenant-scoped dataset summaries for captured rows.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21710 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "datasets"
        ],
        "operationId": "postV1Datasets",
        "summary": "Dataset create - builds a tenant-stamped dataset from a namespace of captured calls.",
        "description": "Dataset create - builds a tenant-stamped dataset from a namespace of captured calls.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21719 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/datasets/{id}": {
      "get": {
        "tags": [
          "datasets"
        ],
        "operationId": "getV1DatasetsId",
        "summary": "Dataset detail - inspects one dataset and hides cross-tenant records as not found.",
        "description": "Dataset detail - inspects one dataset and hides cross-tenant records as not found.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21731 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/datasets/{id}/split": {
      "post": {
        "tags": [
          "datasets"
        ],
        "operationId": "postV1DatasetsIdSplit",
        "summary": "Dataset split - recomputes a deterministic train/holdout split for an owned dataset.",
        "description": "Dataset split - recomputes a deterministic train/holdout split for an owned dataset.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21746 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/deploy": {
      "post": {
        "tags": [
          "deploy"
        ],
        "operationId": "postV1Deploy",
        "summary": "HTTP control plane: POST /v1/deploy + /v1/deploy/canary +",
        "description": "HTTP control plane: POST /v1/deploy + /v1/deploy/canary + /v1/test-device + /v1/test-quants. All require auth (auth.js gates via PUBLIC_API allowlist; these paths are NOT in PUBLIC_API, so an unauth request returns 401 from the auth middleware). The handlers below simply do shape-validation + delegate to the same modules the CLI calls.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22657 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/deploy/canary": {
      "post": {
        "tags": [
          "deploy"
        ],
        "operationId": "postV1DeployCanary",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22677 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/deploy/runpod": {
      "post": {
        "tags": [
          "deploy"
        ],
        "operationId": "postV1DeployRunpod",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22563 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/deploy/runpod/{pod_id}": {
      "get": {
        "tags": [
          "deploy"
        ],
        "operationId": "getV1DeployRunpodPodid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "pod_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "pod_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22615 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "deploy"
        ],
        "operationId": "deleteV1DeployRunpodPodid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "pod_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "pod_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22627 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/deploy/runpod/{pod_id}/logs": {
      "get": {
        "tags": [
          "deploy"
        ],
        "operationId": "getV1DeployRunpodPodidLogs",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "pod_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "pod_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22639 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/device/check": {
      "post": {
        "tags": [
          "device"
        ],
        "operationId": "postV1DeviceCheck",
        "summary": "Device requirement check - compares a target profile against a named host profile.",
        "description": "Device requirement check - compares a target profile against a named host profile.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19070 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/device/probe": {
      "post": {
        "tags": [
          "device"
        ],
        "operationId": "postV1DeviceProbe",
        "summary": "Device host probe - detects this server's local profile using best-effort hardware probes.",
        "description": "Device host probe - detects this server's local profile using best-effort hardware probes.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19080 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/device/profiles": {
      "get": {
        "tags": [
          "device"
        ],
        "operationId": "getV1DeviceProfiles",
        "summary": "Device capability profiles - list static target profiles for artifact compatibility checks.",
        "description": "Device capability profiles - list static target profiles for artifact compatibility checks.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19058 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/device/profiles/{device_id}": {
      "get": {
        "tags": [
          "device"
        ],
        "operationId": "getV1DeviceProfilesDeviceid",
        "summary": "Device capability profile detail - returns one static profile or 404 for unknown device ids.",
        "description": "Device capability profile detail - returns one static profile or 404 for unknown device ids.",
        "parameters": [
          {
            "name": "device_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "device_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19063 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1Devices",
        "summary": "Device fleet list - enumerates operator-registered device profiles newest first.",
        "description": "Device fleet list - enumerates operator-registered device profiles newest first.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22035 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/add": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesAdd",
        "summary": "browser-form translator for /account/fleet \"Add device\" modal.",
        "description": "browser-form translator for /account/fleet \"Add device\" modal. The form posts {name, type, tags, connection:{host,user,key_path|base_url|kubeconfig,namespace}} which we flatten to DeviceRegistry.register() args.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22281 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/detect": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1DevicesDetect",
        "summary": "Device fleet detect - probes local hardware and persists the local fleet profile.",
        "description": "Device fleet detect - probes local hardware and persists the local fleet profile.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22043 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesDetect",
        "summary": "Device fleet detect with hints - refreshes local inventory using optional device hints.",
        "description": "Device fleet detect with hints - refreshes local inventory using optional device hints.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23560 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/installed": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1DevicesInstalled",
        "summary": "Device install list - returns staged artifact installs, optionally filtered by device_id.",
        "description": "Device install list - returns staged artifact installs, optionally filtered by device_id.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22132 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/list": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1DevicesList",
        "summary": "GET /v1/devices/list - list registered W888-C devices with filters",
        "description": "GET /v1/devices/list - list registered W888-C devices with filters ?type=<t>&tag=<t>&status=<t>&includeRemoved=1",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22100 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/recommend": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1DevicesRecommend",
        "summary": "Device recommendation default - recommends target and quantization for the detected profile.",
        "description": "Device recommendation default - recommends target and quantization for the detected profile.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22194 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesRecommend",
        "summary": "Device recommendation - chooses runtime target and quantization for profile/artifact inputs.",
        "description": "Device recommendation - chooses runtime target and quantization for profile/artifact inputs.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22182 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/register": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesRegister",
        "summary": "POST /v1/devices/register - registers a new device in the W888-C registry.",
        "description": "POST /v1/devices/register - registers a new device in the W888-C registry. Body matches DeviceRegistry.register() args: { id, name?, host?, port?, user?, type, keyPath?, tags?, hardware_hint? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22085 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/remove": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesRemove",
        "summary": "POST shim for /v1/devices/remove (fleet.html \"Remove\" button uses POST not DELETE).",
        "description": "POST shim for /v1/devices/remove (fleet.html \"Remove\" button uses POST not DELETE). Accepts {name|id, hard?}. Soft delete by default.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22309 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}": {
      "get": {
        "tags": [
          "devices"
        ],
        "operationId": "getV1DevicesId",
        "summary": "GET /v1/devices/:id - registry-first lookup; falls back to the W372",
        "description": "GET /v1/devices/:id - registry-first lookup; falls back to the W372 per-file store so existing dashboards stay working. NOTE: this is registered LAST so the more specific /v1/devices/detect, /v1/devices/list, /v1/devices/recommend, /v1/devices/installed routes above keep matching ahead of it.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22264 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "devices"
        ],
        "operationId": "deleteV1DevicesId",
        "summary": "DELETE /v1/devices/:id - soft delete; ?hard=1 to hard delete.",
        "description": "DELETE /v1/devices/:id - soft delete; ?hard=1 to hard delete. Guarded so we DO NOT intercept the legacy DELETE /v1/devices/:id/install/:artifact_id (Express route ordering means specific routes registered earlier win; we are below /v1/devices/:id/install handler so :id here only matches single segment).",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22248 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/heartbeat": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesIdHeartbeat",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22227 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/install": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesIdInstall",
        "summary": "Device artifact install - stages a .kolm artifact by path or hash onto a registered device.",
        "description": "Device artifact install - stages a .kolm artifact by path or hash onto a registered device.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22142 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/install/{artifact_id}": {
      "delete": {
        "tags": [
          "devices"
        ],
        "operationId": "deleteV1DevicesIdInstallArtifactid",
        "summary": "Device artifact uninstall - removes a staged artifact install for one registered device.",
        "description": "Device artifact uninstall - removes a staged artifact install for one registered device.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          },
          {
            "name": "artifact_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "artifact_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22165 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/probe": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesIdProbe",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22209 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/register": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesIdRegister",
        "summary": "Device fleet registration - validates and stores a canonical profile for a device id.",
        "description": "Device fleet registration - validates and stores a canonical profile for a device id.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22115 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/devices/{id}/test": {
      "post": {
        "tags": [
          "devices"
        ],
        "operationId": "postV1DevicesIdTest",
        "summary": "Device fleet test - probes reachability and runtime status for a registered device.",
        "description": "Device fleet test - probes reachability and runtime status for a registered device.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22124 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/diagnose": {
      "post": {
        "tags": [
          "diagnose"
        ],
        "operationId": "postV1Diagnose",
        "summary": "POST mirror - body carries artifact_cid (matches existing",
        "description": "POST mirror - body carries artifact_cid (matches existing /v1/pipeline/run + /v1/bakeoffs body shape).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7642 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/diagnose/{cid}": {
      "get": {
        "tags": [
          "diagnose"
        ],
        "operationId": "getV1DiagnoseCid",
        "summary": "GET twin - path param carries cid.",
        "description": "GET twin - path param carries cid.",
        "parameters": [
          {
            "name": "cid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "cid path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7647 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/distill/from-captures": {
      "post": {
        "tags": [
          "distill"
        ],
        "operationId": "postV1DistillFromcaptures",
        "summary": "Distill from captures - turns the caller's namespace captures into either",
        "description": "Distill from captures - turns the caller's namespace captures into either a recipe (template-cluster >=4 captures) or a specialist distill job (when total captures >=1000 or mode='specialist' is forced). Returns the synth result for recipes, {job_id, poll_url, bridge_source} (202) for specialists. Body: { namespace, min_pairs, mode, name }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16192 carries route-local auth middleware"
      }
    },
    "/v1/distill/from-captures/preview": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillFromcapturesPreview",
        "summary": "Commit (POST) picks recipe vs specialist by count (<1000 vs >=1000),",
        "description": "Commit (POST) picks recipe vs specialist by count (<1000 vs >=1000), forwards to /v1/bridges/auto-synthesize (recipe) or KOLM_TRAINER_BRIDGE_URL (specialist). Errors surface as 503 (capture-store) / 400 (not_enough/ no_cluster). W364: specialist arm always returns 202 with job_id (either remote bridge or in-tree worker via src/distill-bridge.js).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15987 carries route-local auth middleware"
      }
    },
    "/v1/distill/onpolicy": {
      "post": {
        "tags": [
          "distill"
        ],
        "operationId": "postV1DistillOnpolicy",
        "summary": "Run an on-policy distillation against a teacher-student pair via the",
        "description": "Run an on-policy distillation against a teacher-student pair via the tenant-installed trainer plug-in. Auth-gated. Body: { pairs_path, student_path, out_dir, namespace, max_steps }. Returns trainer envelope or no_trainer_installed.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16355 carries route-local auth middleware"
      }
    },
    "/v1/distill/onpolicy/doctor": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillOnpolicyDoctor",
        "summary": "Public trainer doctors. These report only local trainer availability and",
        "description": "Public trainer doctors. These report only local trainer availability and install hints, so CLIs can decide whether a host is train-capable before a tenant exists. Training jobs themselves remain authenticated below.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6066 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/distill/preference": {
      "post": {
        "tags": [
          "distill"
        ],
        "operationId": "postV1DistillPreference",
        "summary": "Train a preference-pair objective (dpo/simpo/orpo/kto) via the tenant",
        "description": "Train a preference-pair objective (dpo/simpo/orpo/kto) via the tenant installed trainer plug-in. Auth-gated. Body: { pairs_path, student_path, objective, out_dir, namespace, beta }. Returns trainer envelope.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16377 carries route-local auth middleware"
      }
    },
    "/v1/distill/preference/doctor": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillPreferenceDoctor",
        "summary": "Preference distillation doctor - unauthenticated capability report for the",
        "description": "Preference distillation doctor - unauthenticated capability report for the DPO/SIMPO/ORPO/KTO training path and its local dependency hints.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6077 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/distill/runs": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillRuns",
        "summary": "Reads ~/.kolm/distill-runs/run_<id>/{run-meta.json, progress.jsonl, manifest.json}.",
        "description": "Reads ~/.kolm/distill-runs/run_<id>/{run-meta.json, progress.jsonl, manifest.json}. Tenant-scoped: listDistillRuns filters by req.tenant_record.id (fail closed on missing tag). The progress.jsonl events are emitted from distill() each step so the dashboard can replay the loss curve without re-running the job.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16314 carries route-local auth middleware"
      }
    },
    "/v1/distill/runs/{id}": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillRunsId",
        "summary": "Distill run detail - reads ~/.kolm/distill-runs/run_<id>/{run-meta.json,",
        "description": "Distill run detail - reads ~/.kolm/distill-runs/run_<id>/{run-meta.json, progress.jsonl, manifest.json} for one run. Tenant-scoped - 404 when run belongs to another tenant or id doesn't match /^run_[a-z0-9_]+$/i.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16330 carries route-local auth middleware"
      }
    },
    "/v1/distill/strategy": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillStrategy",
        "summary": "Distill strategy plan - ranks the next backend action from current data,",
        "description": "Distill strategy plan - ranks the next backend action from current data, holdout, privacy, teacher, preference, latency, and budget constraints. This planner does not launch training or call providers.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16142 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "distill"
        ],
        "operationId": "postV1DistillStrategy",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16164 carries route-local auth middleware"
      }
    },
    "/v1/distill/strategy/catalog": {
      "get": {
        "tags": [
          "distill"
        ],
        "operationId": "getV1DistillStrategyCatalog",
        "summary": "Distill strategy catalog - static decision vocabulary for data collection,",
        "description": "Distill strategy catalog - static decision vocabulary for data collection, rule/cache first paths, supervised fine-tune, teacher distillation, preference optimization, on-policy improvement, and speculative decoding.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16105 carries route-local auth middleware"
      }
    },
    "/v1/draft/save": {
      "post": {
        "tags": [
          "draft"
        ],
        "operationId": "postV1DraftSave",
        "summary": "POST /v1/draft/save - autosave wizard draft state. Returns a draft_id",
        "description": "POST /v1/draft/save - autosave wizard draft state. Returns a draft_id so authed callers can later resume; anon callers also get an id but the persistence flag is false (the page falls back to localStorage).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1450 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/drift-alert": {
      "get": {
        "tags": [
          "drift-alert"
        ],
        "operationId": "getV1Driftalert",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/drift-alert/snapshot": {
      "post": {
        "tags": [
          "drift-alert"
        ],
        "operationId": "postV1DriftalertSnapshot",
        "summary": "tie-in: when shouldAlert() fires the route calls",
        "description": "tie-in: when shouldAlert() fires the route calls driftAlertStore.registerDriftWarning() so the NEXT W709 routing decision can stamp `drift_warning:true`. Honest fallback: if the W709 routing-events module is not loaded, the warning is still registered (it is in-memory) and the W709 hook simply never reads it.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20669 carries route-local auth middleware"
      }
    },
    "/v1/drift-alert/webhooks": {
      "post": {
        "tags": [
          "drift-alert"
        ],
        "operationId": "postV1DriftalertWebhooks",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20836 carries route-local auth middleware"
      }
    },
    "/v1/drift-alert/{namespace}": {
      "get": {
        "tags": [
          "drift-alert"
        ],
        "operationId": "getV1DriftalertNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20735 carries route-local auth middleware"
      }
    },
    "/v1/drift/alerts": {
      "get": {
        "tags": [
          "drift"
        ],
        "operationId": "getV1DriftAlerts",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26613 carries route-local auth middleware"
      }
    },
    "/v1/drift/auto-remediate": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftAutoremediate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26635 carries route-local auth middleware"
      }
    },
    "/v1/drift/configure": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftConfigure",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26581 carries route-local auth middleware"
      }
    },
    "/v1/drift/detect": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftDetect",
        "summary": "Drift detect - compares two drift snapshots (baseline vs current) and",
        "description": "Drift detect - compares two drift snapshots (baseline vs current) and returns signals + verdict ('within' | 'drift' | 'breach') with breach/drift counts. Body: { baseline_snapshot, current_snapshot, tolerances }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20611 carries route-local auth middleware"
      }
    },
    "/v1/drift/report": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftReport",
        "summary": "Drift report - builds a full drift report (signals + narrative + tolerance",
        "description": "Drift report - builds a full drift report (signals + narrative + tolerance block + caller notes) from two snapshots. Same inputs as /v1/drift/detect but returns the formatted report ready for archival or UI rendering.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20633 carries route-local auth middleware"
      }
    },
    "/v1/drift/scan": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftScan",
        "summary": "unless config.auto_remediate_drift === true AND body.dry_run !== true.",
        "description": "unless config.auto_remediate_drift === true AND body.dry_run !== true. dry_run defaults to TRUE so a misclick cannot kick off a re-distill. All five are tenant-fenced via req.tenant_record.id (W411 law).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26455 carries route-local auth middleware"
      }
    },
    "/v1/drift/snapshot": {
      "post": {
        "tags": [
          "drift"
        ],
        "operationId": "postV1DriftSnapshot",
        "summary": "the 12-step compile→verify→run→drift→retrain loop. W434 exposes three",
        "description": "the 12-step compile→verify→run→drift→retrain loop. W434 exposes three tenant-scoped POST routes that wrap the existing pure functions. The routes are stateless (no server-side persistence) - the report's hash is verifiable client-side, so the round-trip is just \"validate my inputs + compute signals + return the report you can persist anywhere.\"",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20589 carries route-local auth middleware"
      }
    },
    "/v1/drift/status": {
      "get": {
        "tags": [
          "drift"
        ],
        "operationId": "getV1DriftStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26516 carries route-local auth middleware"
      }
    },
    "/v1/embed": {
      "post": {
        "tags": [
          "embed"
        ],
        "operationId": "postV1Embed",
        "summary": "Tokenize-and-ingest a path (or array of paths). The path must live on the",
        "description": "Tokenize-and-ingest a path (or array of paths). The path must live on the server; for now we support self-host where the kolm cloud runs alongside a tenant's mounted corpus directory. For the SaaS path we'll add an upload endpoint in Sprint 2.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9593 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/embeddings": {
      "post": {
        "tags": [
          "embeddings"
        ],
        "operationId": "postV1Embeddings",
        "summary": "OpenAI-compatible passthrough for the responses, embeddings, and",
        "description": "OpenAI-compatible passthrough for the responses, embeddings, and moderations endpoints. Each routes through __connectorProxy('openai', ...) so the upstream OpenAI API is reached with the configured key, and the request/response is captured into the tenant lake.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5512 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/adversarial/generate": {
      "post": {
        "tags": [
          "eval"
        ],
        "operationId": "postV1EvalAdversarialGenerate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26946 carries route-local auth middleware"
      }
    },
    "/v1/eval/benchmark-evidence": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalBenchmarkevidence",
        "summary": "Benchmark evidence readiness for comparative claims. This route audits",
        "description": "Benchmark evidence readiness for comparative claims. This route audits local evidence files and reports the exact public data lanes still needed; it never calls providers and never returns secret values.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2178 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/benchmark-evidence/template": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalBenchmarkevidenceTemplate",
        "summary": "Benchmark evidence template - returns the strict provider/runtime lane",
        "description": "Benchmark evidence template - returns the strict provider/runtime lane schema required before comparative benchmark claims can be marked public.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2225 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/benchmark-evidence/validate": {
      "post": {
        "tags": [
          "eval"
        ],
        "operationId": "postV1EvalBenchmarkevidenceValidate",
        "summary": "Benchmark evidence validation - validates a proposed provider matrix",
        "description": "Benchmark evidence validation - validates a proposed provider matrix without saving it, calling providers, or exposing secrets.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2260 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/gate": {
      "post": {
        "tags": [
          "eval"
        ],
        "operationId": "postV1EvalGate",
        "summary": "Compile/promote eval gate (standalone evaluation endpoint)",
        "description": "Compile/promote eval gate (standalone evaluation endpoint)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11926 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/k-score-calibration": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalKscorecalibration",
        "summary": "K-score calibration - public, frozen benchmark contract for the score",
        "description": "K-score calibration - public, frozen benchmark contract for the score formula, 30-case suite, class mix, axis means, and manual-review leaderboard. This proves how K-score is computed; live model ranking claims require separate public benchmark evidence.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2103 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/quality-calibration": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalQualitycalibration",
        "summary": "Quality judge calibration - public, deterministic fixture for the",
        "description": "Quality judge calibration - public, deterministic fixture for the per-call quality judge. This is calibration evidence, not a broad claim that autonomous judging matches every review domain.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2301 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/eval/tenant_holdout": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalTenantholdout",
        "summary": "Tenant holdout list - returns the authenticated tenant's retained shadow corpus metadata.",
        "description": "Tenant holdout list - returns the authenticated tenant's retained shadow corpus metadata.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14087 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "eval"
        ],
        "operationId": "postV1EvalTenantholdout",
        "summary": "All four are authed (mounted below authMiddleware) and per-tenant scoped:",
        "description": "All four are authed (mounted below authMiddleware) and per-tenant scoped: a tenant can only read/write/delete corpora under its own tenant_id. The tenant_id is derived from req.tenant_record.id (the authenticated tenant) rather than accepted as a body field, so a forged tenant_id is impossible.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14042 carries route-local auth middleware"
      }
    },
    "/v1/eval/tenant_holdout/{corpus_id}": {
      "get": {
        "tags": [
          "eval"
        ],
        "operationId": "getV1EvalTenantholdoutCorpusid",
        "summary": "Tenant holdout detail - returns hash and size metadata without exposing corpus rows.",
        "description": "Tenant holdout detail - returns hash and size metadata without exposing corpus rows.",
        "parameters": [
          {
            "name": "corpus_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "corpus_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14099 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "eval"
        ],
        "operationId": "deleteV1EvalTenantholdoutCorpusid",
        "summary": "Tenant holdout delete - removes one authenticated tenant corpus and audits the deletion.",
        "description": "Tenant holdout delete - removes one authenticated tenant corpus and audits the deletion.",
        "parameters": [
          {
            "name": "corpus_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "corpus_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14125 carries route-local auth middleware"
      }
    },
    "/v1/evidence": {
      "get": {
        "tags": [
          "evidence"
        ],
        "operationId": "getV1Evidence",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8905 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/evidence/readiness": {
      "get": {
        "tags": [
          "evidence"
        ],
        "operationId": "getV1EvidenceReadiness",
        "summary": "Evidence readiness - one public, secret-safe aggregate for every proof gate",
        "description": "Evidence readiness - one public, secret-safe aggregate for every proof gate that can keep product copy from saying \"final\" too early. This mirrors `kolm evidence --json` so account UI, docs, CLI, and release audits share the same local/external boundary.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1785 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/evidence/{id}": {
      "get": {
        "tags": [
          "evidence"
        ],
        "operationId": "getV1EvidenceId",
        "summary": "GET /v1/evidence/:id - return the single node detail for an evidence id.",
        "description": "GET /v1/evidence/:id - return the single node detail for an evidence id. Looks up the owning artifact via the per-node reverse index; returns the verbatim node record (id, kind, plus any caller-supplied attrs). 404 when the node id is not in any artifact's DAG.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8823 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/evidence/{id}/revoke": {
      "post": {
        "tags": [
          "evidence"
        ],
        "operationId": "postV1EvidenceIdRevoke",
        "summary": "lifecycle revoke transition).",
        "description": "lifecycle revoke transition). Returns { revoked, needs_review[] }. The revoke verdict does NOT mutate the artifact's signed receipt - receipts seal bytes, not operational provenance - so propagation is a verdict written to the caller's audit trail, not a state-machine transition.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8846 carries route-local auth middleware"
      }
    },
    "/v1/experts": {
      "post": {
        "tags": [
          "experts"
        ],
        "operationId": "postV1Experts",
        "summary": "POST /v1/experts - analyze MoE expert activation distribution for a .kolm.",
        "description": "POST /v1/experts - analyze MoE expert activation distribution for a .kolm. Body: { artifact_path, threshold? } The artifact must be operator-side (path on the server). Returns per-expert activation + prune candidates + estimated K-Score impact.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28829 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/export": {
      "post": {
        "tags": [
          "export"
        ],
        "operationId": "postV1Export",
        "summary": "POST /v1/export - emit an export plan for a .kolm artifact (target =",
        "description": "POST /v1/export - emit an export plan for a .kolm artifact (target = gguf/awq/exl2/mlx/onnx/tflite/coreml/openvino). Returns the plan + estimated size + invocation hint; actual export runs via the CLI worker.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29067 carries route-local auth middleware"
      }
    },
    "/v1/exports": {
      "get": {
        "tags": [
          "exports"
        ],
        "operationId": "getV1Exports",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29179 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "exports"
        ],
        "operationId": "postV1Exports",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29163 carries route-local auth middleware"
      }
    },
    "/v1/exports/{id}": {
      "get": {
        "tags": [
          "exports"
        ],
        "operationId": "getV1ExportsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29191 carries route-local auth middleware"
      }
    },
    "/v1/failure-modes": {
      "post": {
        "tags": [
          "failure-modes"
        ],
        "operationId": "postV1Failuremodes",
        "summary": "POST mirror - body carries artifact_cid.",
        "description": "POST mirror - body carries artifact_cid.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8253 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/failure-modes/feed-active-learning": {
      "post": {
        "tags": [
          "failure-modes"
        ],
        "operationId": "postV1FailuremodesFeedactivelearning",
        "summary": "Auth-gated via req.tenant_record. Tenant fence is forced from the",
        "description": "Auth-gated via req.tenant_record. Tenant fence is forced from the authenticated record - any body.tenant value is overridden so a caller cannot point this at another tenant's namespace. The namespace IS read from the body because a single tenant routinely operates many namespaces and W816 closes the loop per-namespace.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27285 carries route-local auth middleware"
      }
    },
    "/v1/failure-modes/{cid}": {
      "get": {
        "tags": [
          "failure-modes"
        ],
        "operationId": "getV1FailuremodesCid",
        "summary": "GET twin - path param carries cid.",
        "description": "GET twin - path param carries cid.",
        "parameters": [
          {
            "name": "cid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "cid path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8258 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/aggregate": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedAggregate",
        "summary": "Federated approval aggregate - returns DP-noised counts across local and peer approval hashes.",
        "description": "Federated approval aggregate - returns DP-noised counts across local and peer approval hashes.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20249 carries route-local auth middleware"
      }
    },
    "/v1/federated/audit": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedAudit",
        "summary": "Federated audit - returns recent hash-only approval-share envelopes for the tenant.",
        "description": "Federated audit - returns recent hash-only approval-share envelopes for the tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20274 carries route-local auth middleware"
      }
    },
    "/v1/federated/consortium": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedConsortium",
        "summary": "/v1/federated/consortium - bare GET that points the TUI at the W830",
        "description": "/v1/federated/consortium - bare GET that points the TUI at the W830 members collection. The federated-consortium-routes module owns the tenant-scoped membership reads; here we add a no-query alias that returns the empty-state envelope when no consortium_id is supplied so the TUI view always has something to render.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28627 carries route-local auth middleware"
      }
    },
    "/v1/federated/consortium/aggregations": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedConsortiumAggregations",
        "summary": "Returns recent aggregation runs with status, epsilon spent, and",
        "description": "Returns recent aggregation runs with status, epsilon spent, and participant count. Defense-in-depth: only returns rows where this tenant is a participant OR rows are visible to the consortium's listed members (default).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/consortium/budget": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedConsortiumBudget",
        "summary": "Returns the consortium-wide privacy budget: epsilon_spent (summed across",
        "description": "Returns the consortium-wide privacy budget: epsilon_spent (summed across recorded aggregation rounds) vs epsilon_allocated (from the consortium state). Also surfaces per-tenant epsilon_spent_by_self so a tenant can see how much budget THEY have burned.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/consortium/members": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedConsortiumMembers",
        "summary": "GET /v1/federated/consortium/members?consortium_id=...",
        "description": "GET /v1/federated/consortium/members?consortium_id=... Returns the list of opted-in members. Every member row includes its contribution_count + last_share_at so the UI can show \"who's pulling their weight\". The caller's own member row is always included.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/consortium/opt-in": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedConsortiumOptin",
        "summary": "Body: { consortium_id, scope?:[ns...], epsilon_allocated?:number, note? }",
        "description": "Body: { consortium_id, scope?:[ns...], epsilon_allocated?:number, note? } Writes the member row into the consortium's single-tenant view + audits contribution_count=0 baseline + last_share_at=null.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/consortium/opt-out": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedConsortiumOptout",
        "summary": "POST /v1/federated/consortium/opt-out",
        "description": "POST /v1/federated/consortium/opt-out Body: { consortium_id, reason? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/consortium/verify-mia": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedConsortiumVerifymia",
        "summary": "Body: { artifact_id, test_inputs:[...], shadow_models?:[...],",
        "description": "Body: { artifact_id, test_inputs:[...], shadow_models?:[...], train_set?:[...], holdout_set?:[...], p_threshold? } Honest stub when shadow_models empty (returns mia_requires_shadow_models).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/federated-consortium-routes.js is registered from src/router.js:30119 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/federated/opt-in": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedOptin",
        "summary": "Federated opt-in - records tenant namespaces and peers for hash-only approval sharing.",
        "description": "Federated opt-in - records tenant namespaces and peers for hash-only approval sharing.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20202 carries route-local auth middleware"
      }
    },
    "/v1/federated/opt-out": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedOptout",
        "summary": "Federated opt-out - clears tenant approval-sharing opt-in state and records the reason.",
        "description": "Federated opt-out - clears tenant approval-sharing opt-in state and records the reason.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20218 carries route-local auth middleware"
      }
    },
    "/v1/federated/peers": {
      "get": {
        "tags": [
          "federated"
        ],
        "operationId": "getV1FederatedPeers",
        "summary": "Federated peers - lists other opted-in approval-sharing peers visible to the tenant.",
        "description": "Federated peers - lists other opted-in approval-sharing peers visible to the tenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20264 carries route-local auth middleware"
      }
    },
    "/v1/federated/share-approvals": {
      "post": {
        "tags": [
          "federated"
        ],
        "operationId": "postV1FederatedShareapprovals",
        "summary": "Federated approval share - emits hash-only approval rows for an opted-in namespace.",
        "description": "Federated approval share - emits hash-only approval rows for an opted-in namespace.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20229 carries route-local auth middleware"
      }
    },
    "/v1/fit": {
      "post": {
        "tags": [
          "fit"
        ],
        "operationId": "postV1Fit",
        "summary": "POST /v1/fit - estimate VRAM use for (params × quant × context).",
        "description": "POST /v1/fit - estimate VRAM use for (params × quant × context). Body: { model_params_b, quant, vram_gb, context?, batch?, kv_precision? } Returns the same envelope as the CLI: {fits, est_total_gb, est_weights_gb, est_kv_gb, est_activations_gb, headroom_gb, recommendation}.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28797 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fl/aggregate": {
      "post": {
        "tags": [
          "fl"
        ],
        "operationId": "postV1FlAggregate",
        "summary": "Federated aggregate - folds verified client deltas into one foundation-state aggregate receipt.",
        "description": "Federated aggregate - folds verified client deltas into one foundation-state aggregate receipt.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19141 carries route-local auth middleware"
      }
    },
    "/v1/fl/contribution/verify": {
      "post": {
        "tags": [
          "fl"
        ],
        "operationId": "postV1FlContributionVerify",
        "summary": "Federated contribution verify - checks a client update receipt against the announced round.",
        "description": "Federated contribution verify - checks a client update receipt against the announced round.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19131 carries route-local auth middleware"
      }
    },
    "/v1/fl/round/new": {
      "post": {
        "tags": [
          "fl"
        ],
        "operationId": "postV1FlRoundNew",
        "summary": "Federated round create - creates a foundation-state round and returns its stable round hash.",
        "description": "Federated round create - creates a foundation-state round and returns its stable round hash.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19123 carries route-local auth middleware"
      }
    },
    "/v1/fl/strategies": {
      "get": {
        "tags": [
          "fl"
        ],
        "operationId": "getV1FlStrategies",
        "summary": "federated learning",
        "description": "federated learning",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19114 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fleet/deploy": {
      "post": {
        "tags": [
          "fleet"
        ],
        "operationId": "postV1FleetDeploy",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22398 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fleet/monitor": {
      "get": {
        "tags": [
          "fleet"
        ],
        "operationId": "getV1FleetMonitor",
        "summary": "GET /v1/fleet/monitor - one monitor tick (synchronous, no streaming).",
        "description": "GET /v1/fleet/monitor - one monitor tick (synchronous, no streaming). For long-running monitoring use the CLI `kolm fleet monitor` instead.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22455 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fleet/rollback": {
      "post": {
        "tags": [
          "fleet"
        ],
        "operationId": "postV1FleetRollback",
        "summary": "POST /v1/fleet/rollback - body {tag?, namespace?, device?, confirm?}",
        "description": "POST /v1/fleet/rollback - body {tag?, namespace?, device?, confirm?} Browser button passes {device}; CLI passes {tag|namespace, confirm:true}.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22419 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fleet/status": {
      "get": {
        "tags": [
          "fleet"
        ],
        "operationId": "getV1FleetStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22386 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/fleet/stop": {
      "post": {
        "tags": [
          "fleet"
        ],
        "operationId": "postV1FleetStop",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22437 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/free/chat": {
      "post": {
        "tags": [
          "free"
        ],
        "operationId": "postV1FreeChat",
        "summary": "20 messages/day to tinker with the intent classifier; if a tenant key is",
        "description": "20 messages/day to tinker with the intent classifier; if a tenant key is attached the route upgrades to the full /v1/intent/ask snapshot. This is the SAME pipe pre-auth and post-auth, so the homepage chat box and the /account console chat box share the contract. Anon callers cannot read tenant state - snapshotContext is called with tenant_id=null.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10023 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/free/cli": {
      "post": {
        "tags": [
          "free"
        ],
        "operationId": "postV1FreeCli",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10380 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/free/cli/allowlist": {
      "get": {
        "tags": [
          "free"
        ],
        "operationId": "getV1FreeCliAllowlist",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10444 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/gateway/dashboard": {
      "get": {
        "tags": [
          "gateway"
        ],
        "operationId": "getV1GatewayDashboard",
        "summary": "W-G wrapper-completion - GET /v1/gateway/dashboard",
        "description": "W-G wrapper-completion - GET /v1/gateway/dashboard Aggregate routing breakdown + cost-savings + recent calls for the /account/gateway.html dashboard. Tenant-scoped via findByTenant.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:6255 carries route-local auth middleware"
      }
    },
    "/v1/gateway/dispatch": {
      "post": {
        "tags": [
          "gateway"
        ],
        "operationId": "postV1GatewayDispatch",
        "summary": "6. Build the kolm-audit-1 receipt, sign it, persist + return.",
        "description": "6. Build the kolm-audit-1 receipt, sign it, persist + return. Every fallback marks `capture_eligible: true` so the flywheel picks up the cases where the local model fell short.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:6479 carries route-local auth middleware"
      }
    },
    "/v1/gateway/health": {
      "get": {
        "tags": [
          "gateway"
        ],
        "operationId": "getV1GatewayHealth",
        "summary": "5 - public gateway liveness probe. Mirrors /health for the",
        "description": "5 - public gateway liveness probe. Mirrors /health for the gateway sub-system: ok:true + version + module-loadable signal. Mounted before r.use(authMiddleware) so it is reachable without an API key. Ship-gate consumers use this to confirm the gateway dispatch path is wired without paying for a real upstream call.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6091 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/gateway/mode": {
      "get": {
        "tags": [
          "gateway"
        ],
        "operationId": "getV1GatewayMode",
        "summary": "GET /v1/gateway/mode reports the current gateway mode + reachability.",
        "description": "GET /v1/gateway/mode reports the current gateway mode + reachability. Auth-gated (mounted after r.use(authMiddleware)). Probes both local backends with a 1-second HEAD timeout so a slow / unreachable backend never blocks the dashboard. The response surfaces the resolved mode (NOT the raw env value) so a callers sees what currentMode() actually decided.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6220 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/gateway/providers": {
      "get": {
        "tags": [
          "gateway"
        ],
        "operationId": "getV1GatewayProviders",
        "summary": "W-G wrapper-completion - GET /v1/gateway/providers",
        "description": "W-G wrapper-completion - GET /v1/gateway/providers Return the 11 supported providers with the customer's per-tenant config overlaid (enabled, rate_limit, position-in-chain). Reads the registry for the canonical list, then merges per-tenant overrides if any.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:6337 carries route-local auth middleware"
      }
    },
    "/v1/gateway/providers/config": {
      "post": {
        "tags": [
          "gateway"
        ],
        "operationId": "postV1GatewayProvidersConfig",
        "summary": "W-G wrapper-completion - POST /v1/gateway/providers/config",
        "description": "W-G wrapper-completion - POST /v1/gateway/providers/config Persist per-tenant provider overrides (enabled toggle, position-in-chain, RPM limit). API keys are NEVER stored in the row - operators set them as environment variables; we only persist the FLAG that one is set.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:6368 carries route-local auth middleware"
      }
    },
    "/v1/gateway/test-connection": {
      "post": {
        "tags": [
          "gateway"
        ],
        "operationId": "postV1GatewayTestconnection",
        "summary": "W-G wrapper-completion - POST /v1/gateway/test-connection",
        "description": "W-G wrapper-completion - POST /v1/gateway/test-connection Fire a tiny ping against an upstream to verify the key works. Body: {provider: 'anthropic', api_key: 'sk-ant-...'}. Returns {ok, status, elapsed_ms} but never echoes the key back.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:6407 carries route-local auth middleware"
      }
    },
    "/v1/gemini/chat/completions": {
      "post": {
        "tags": [
          "gemini"
        ],
        "operationId": "postV1GeminiChatCompletions",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:5953 carries route-local auth middleware"
      }
    },
    "/v1/gemini/v1/chat/completions": {
      "post": {
        "tags": [
          "gemini"
        ],
        "operationId": "postV1GeminiV1ChatCompletions",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5952 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/anchor/batch": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernAnchorBatch",
        "summary": "ANCHOR - Merkle batch anchoring of receipts.",
        "description": "ANCHOR - Merkle batch anchoring of receipts.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/anchor/status": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernAnchorStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/anchor/verify": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernAnchorVerify",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/c2pa/sign": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernC2paSign",
        "summary": "C2PA - content credentials for model outputs.",
        "description": "C2PA - content credentials for model outputs.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/c2pa/verify": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernC2paVerify",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/compliance/ai-act/art12": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernComplianceAiactArt12",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/compliance/ai-act/art12-export": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernComplianceAiactArt12export",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/compliance/ai-act/art72": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernComplianceAiactArt72",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/compliance/export": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernComplianceExport",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/compliance/frameworks": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernComplianceFrameworks",
        "summary": "COMPLIANCE - framework evidence + EU AI Act live reports.",
        "description": "COMPLIANCE - framework evidence + EU AI Act live reports.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/drift/standard": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernDriftStandard",
        "summary": "DRIFT - standard signals.",
        "description": "DRIFT - standard signals.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/intoto/verify": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernIntotoVerify",
        "summary": "POST /v1/govern/intoto/verify",
        "description": "POST /v1/govern/intoto/verify body: { bundle | envelope, public_key?, subject_digest_map? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/intoto-receipt-routes.js is registered from src/router.js:30082 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/intoto/{receipt_id}": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernIntotoReceiptid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "receipt_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "receipt_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/intoto-receipt-routes.js is registered from src/router.js:30082 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/provenance/build": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernProvenanceBuild",
        "summary": "PROVENANCE - in-toto / SLSA build provenance.",
        "description": "PROVENANCE - in-toto / SLSA build provenance.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/provenance/verify": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernProvenanceVerify",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/transparency/append": {
      "post": {
        "tags": [
          "govern"
        ],
        "operationId": "postV1GovernTransparencyAppend",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/transparency/head": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernTransparencyHead",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/govern/transparency/proof/{seq}": {
      "get": {
        "tags": [
          "govern"
        ],
        "operationId": "getV1GovernTransparencyProofSeq",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "seq",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "seq path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/govern-routes.js is registered from src/router.js:30048 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/groups": {
      "get": {
        "tags": [
          "groups"
        ],
        "operationId": "getV1Groups",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20037 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "groups"
        ],
        "operationId": "postV1Groups",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20048 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/groups/{slug}": {
      "get": {
        "tags": [
          "groups"
        ],
        "operationId": "getV1GroupsSlug",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20065 carries route-local auth middleware"
      },
      "patch": {
        "tags": [
          "groups"
        ],
        "operationId": "patchV1GroupsSlug",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20077 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "groups"
        ],
        "operationId": "deleteV1GroupsSlug",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20095 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/hardware": {
      "get": {
        "tags": [
          "hardware"
        ],
        "operationId": "getV1Hardware",
        "summary": "GET /v1/hardware - detect SERVER hardware (GPU vendor/vram/cc, supported quants).",
        "description": "GET /v1/hardware - detect SERVER hardware (GPU vendor/vram/cc, supported quants). Unauthed: returns the operator's local accelerator profile so an Account UI running on the same host can render a \"what fits\" picker without auth.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28763 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/health": {
      "get": {
        "tags": [
          "health"
        ],
        "operationId": "getV1Health",
        "summary": "Authenticated /v1/health - full snapshot including provider availability",
        "description": "Authenticated /v1/health - full snapshot including provider availability and feature flags. Admin-only because the booleans are useful signal for staff debugging but unnecessary surface for tenants. Public /health (above the authMiddleware) is the lightweight no-leak version.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7076 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/hub": {
      "get": {
        "tags": [
          "hub"
        ],
        "operationId": "getV1Hub",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9485 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/hub/publish": {
      "post": {
        "tags": [
          "hub"
        ],
        "operationId": "postV1HubPublish",
        "summary": "POST /v1/hub/publish",
        "description": "POST /v1/hub/publish body: { name, visibility?: 'public'|'private', artifact_b64, metadata? } Stores the artifact bytes + metadata. Returns { handle, owner, name, sha256, url }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9385 carries route-local auth middleware"
      }
    },
    "/v1/hub/{owner}/{name}": {
      "get": {
        "tags": [
          "hub"
        ],
        "operationId": "getV1HubOwnerName",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "owner",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "owner path parameter"
          },
          {
            "name": "name",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "name path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9513 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/hub/{owner}/{name}/download": {
      "get": {
        "tags": [
          "hub"
        ],
        "operationId": "getV1HubOwnerNameDownload",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "owner",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "owner path parameter"
          },
          {
            "name": "name",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "name path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9549 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/import/inspect": {
      "post": {
        "tags": [
          "import"
        ],
        "operationId": "postV1ImportInspect",
        "summary": "Both routes are auth-gated. The python3 parsers live in",
        "description": "Both routes are auth-gated. The python3 parsers live in apps/import/{gguf,safetensors,onnx}.py and run in-process via spawnSync from src/import.js; missing python3 surfaces a 503 python3_missing envelope - never a 500, never a silent fake.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7281 carries route-local auth middleware"
      }
    },
    "/v1/import/wrap": {
      "post": {
        "tags": [
          "import"
        ],
        "operationId": "postV1ImportWrap",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7306 carries route-local auth middleware"
      }
    },
    "/v1/inspect": {
      "post": {
        "tags": [
          "inspect"
        ],
        "operationId": "postV1Inspect",
        "summary": "POST /v1/inspect - inspect a model (HF id or local .kolm path).",
        "description": "POST /v1/inspect - inspect a model (HF id or local .kolm path). Body: { model_id?: string, kolm_path?: string } For HF id: fetches config.json over the public HF endpoint. For .kolm: reads manifest from disk (operator-side path) with signature bypass since inspection is read-only.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28777 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/integrations/runpod": {
      "get": {
        "tags": [
          "integrations"
        ],
        "operationId": "getV1IntegrationsRunpod",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22528 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "integrations"
        ],
        "operationId": "postV1IntegrationsRunpod",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22509 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "integrations"
        ],
        "operationId": "deleteV1IntegrationsRunpod",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22554 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/integrations/runpod/test": {
      "post": {
        "tags": [
          "integrations"
        ],
        "operationId": "postV1IntegrationsRunpodTest",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22541 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/intent/ask": {
      "post": {
        "tags": [
          "intent"
        ],
        "operationId": "postV1IntentAsk",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10453 carries route-local auth middleware"
      }
    },
    "/v1/intent/next": {
      "get": {
        "tags": [
          "intent"
        ],
        "operationId": "getV1IntentNext",
        "summary": "pair locally; this route runs it server-side so the post-auth dashboard",
        "description": "pair locally; this route runs it server-side so the post-auth dashboard can render the same top-N ranked actions without shelling out. Auth-gated. Response envelope: { ok, recommendations: [{action, command, why, rank}], generated_at, snapshot_summary: {captures, opps, ...} }",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9975 carries route-local auth middleware"
      }
    },
    "/v1/ir/compile": {
      "post": {
        "tags": [
          "ir"
        ],
        "operationId": "postV1IrCompile",
        "summary": "ir",
        "description": "ir",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18875 carries route-local auth middleware"
      }
    },
    "/v1/ir/replay": {
      "post": {
        "tags": [
          "ir"
        ],
        "operationId": "postV1IrReplay",
        "summary": "IR replay - replays every workflow IR seed and reports deterministic mismatches.",
        "description": "IR replay - replays every workflow IR seed and reports deterministic mismatches.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18924 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ir/stats": {
      "post": {
        "tags": [
          "ir"
        ],
        "operationId": "postV1IrStats",
        "summary": "IR stats - validates a body-supplied workflow IR and returns node, edge, seed, kind, and hash counts.",
        "description": "IR stats - validates a body-supplied workflow IR and returns node, edge, seed, kind, and hash counts.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18906 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/ir/validate": {
      "post": {
        "tags": [
          "ir"
        ],
        "operationId": "postV1IrValidate",
        "summary": "IR validate - checks body-supplied workflow IR structure and returns its receipt-bound hash.",
        "description": "IR validate - checks body-supplied workflow IR structure and returns its receipt-bound hash.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18915 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/jobs/{id}": {
      "get": {
        "tags": [
          "jobs"
        ],
        "operationId": "getV1JobsId",
        "summary": "Job status (used by HF / URL queued jobs + W229 on-disk job registry +",
        "description": "Job status (used by HF / URL queued jobs + W229 on-disk job registry + distill bridge). Order: corpus_jobs / specialists in-DB, then the src/jobs.js per-file on-disk registry.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14670 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/keys/challenge": {
      "post": {
        "tags": [
          "keys"
        ],
        "operationId": "postV1KeysChallenge",
        "summary": "Key challenge - issues a proof-of-control nonce for Ed25519 key registration.",
        "description": "Key challenge - issues a proof-of-control nonce for Ed25519 key registration.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3364 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/keys/public": {
      "get": {
        "tags": [
          "keys"
        ],
        "operationId": "getV1KeysPublic",
        "summary": "Public keys list - returns registered Ed25519 verification keys and directory stats.",
        "description": "Public keys list - returns registered Ed25519 verification keys and directory stats. additionally surface the default receipt signing pubkey under source:'system' so /v1/verify callers can discover it without going through the challenge→sign→register flow first.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3325 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/keys/public/{fingerprint}": {
      "get": {
        "tags": [
          "keys"
        ],
        "operationId": "getV1KeysPublicFingerprint",
        "summary": "Public key lookup - fetches one registered Ed25519 key by short or full fingerprint.",
        "description": "Public key lookup - fetches one registered Ed25519 key by short or full fingerprint.",
        "parameters": [
          {
            "name": "fingerprint",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "fingerprint path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3353 is mounted before r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "keys"
        ],
        "operationId": "deleteV1KeysPublicFingerprint",
        "summary": "Public key delete - admin-only removal of a registered verification key.",
        "description": "Public key delete - admin-only removal of a registered verification key.",
        "parameters": [
          {
            "name": "fingerprint",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "fingerprint path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3395 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/keys/register": {
      "post": {
        "tags": [
          "keys"
        ],
        "operationId": "postV1KeysRegister",
        "summary": "Key register - verifies a signed challenge nonce and publishes the Ed25519 public key.",
        "description": "Key register - verifies a signed challenge nonce and publishes the Ed25519 public key.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3378 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/kolmbench/leaderboard": {
      "get": {
        "tags": [
          "kolmbench"
        ],
        "operationId": "getV1KolmbenchLeaderboard",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23909 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/kolmbench/spec": {
      "get": {
        "tags": [
          "kolmbench"
        ],
        "operationId": "getV1KolmbenchSpec",
        "summary": "only + safe to cache. Both POST routes require auth via the standard",
        "description": "only + safe to cache. Both POST routes require auth via the standard middleware path; submit additionally requires body.confirm:true as a spend-protection gate (the W411 confirm-pattern). Honest envelopes on every degraded path.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23895 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/kolmbench/submit": {
      "post": {
        "tags": [
          "kolmbench"
        ],
        "operationId": "postV1KolmbenchSubmit",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23946 carries route-local auth middleware"
      }
    },
    "/v1/kolmbench/validate": {
      "post": {
        "tags": [
          "kolmbench"
        ],
        "operationId": "postV1KolmbenchValidate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23921 carries route-local auth middleware"
      }
    },
    "/v1/kscore/series": {
      "get": {
        "tags": [
          "kscore"
        ],
        "operationId": "getV1KscoreSeries",
        "summary": "K-score time series for the namespaces flywheel chart (recorded by",
        "description": "K-score time series for the namespaces flywheel chart (recorded by the autopilot lifecycle). Tenant-fenced; honest empty series when none.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18520 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/label-queue/audit/{event_id}": {
      "get": {
        "tags": [
          "label-queue"
        ],
        "operationId": "getV1LabelqueueAuditEventid",
        "summary": "full audit trail for a single event_id. Tests assert that every",
        "description": "full audit trail for a single event_id. Tests assert that every approval/reject/edit decision is recorded with reviewer + timestamp + before/after output. The legacy /v1/labels/:event_id returns the last label only; this endpoint returns the whole sequence.",
        "parameters": [
          {
            "name": "event_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "event_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21917 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/label-queue/next": {
      "get": {
        "tags": [
          "label-queue"
        ],
        "operationId": "getV1LabelqueueNext",
        "summary": "The /account/labeling.html UI uses concrete label-queue aliases for the",
        "description": "The /account/labeling.html UI uses concrete label-queue aliases for the canonical labels routes. Rather than chase the legacy page (and break any client polling the old paths), we alias the known endpoints. The shapes also tolerate the older field names (label vs verdict, accepted vs approved, pending vs decided).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21828 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/label-queue/stats": {
      "get": {
        "tags": [
          "label-queue"
        ],
        "operationId": "getV1LabelqueueStats",
        "summary": "Label-queue stats alias; adapts canonical labels stats names for the legacy UI.",
        "description": "Label-queue stats alias; adapts canonical labels stats names for the legacy UI.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21858 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/label-queue/submit": {
      "post": {
        "tags": [
          "label-queue"
        ],
        "operationId": "postV1LabelqueueSubmit",
        "summary": "Label-queue submit alias; accepts legacy label names and stores canonical verdicts.",
        "description": "Label-queue submit alias; accepts legacy label names and stores canonical verdicts.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21879 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/labels": {
      "post": {
        "tags": [
          "labels"
        ],
        "operationId": "postV1Labels",
        "summary": "Label submit - records a reviewer verdict for one event and blocks cross-tenant decisions.",
        "description": "Label submit - records a reviewer verdict for one event and blocks cross-tenant decisions.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21776 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/labels/next": {
      "get": {
        "tags": [
          "labels"
        ],
        "operationId": "getV1LabelsNext",
        "summary": "Labels next - returns tenant-scoped unlabeled events with optional namespace/workflow filters.",
        "description": "Labels next - returns tenant-scoped unlabeled events with optional namespace/workflow filters.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21763 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/labels/stats": {
      "get": {
        "tags": [
          "labels"
        ],
        "operationId": "getV1LabelsStats",
        "summary": "Labels stats - returns tenant-scoped pending, approved, rejected, and edited counts.",
        "description": "Labels stats - returns tenant-scoped pending, approved, rejected, and edited counts.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21801 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/labels/synthesize-corpus": {
      "get": {
        "tags": [
          "labels"
        ],
        "operationId": "getV1LabelsSynthesizecorpus",
        "summary": "Returns the captured (input, output) pairs for a namespace as JSONL or",
        "description": "Returns the captured (input, output) pairs for a namespace as JSONL or a JSON envelope. This is what `kolm labels` downloads. Counts go to the status command so the customer can see \"ready to distill at 1000 pairs.\" 1: reads via the durable capture-store (listCaptures) so the distillation corpus comes from the same backend the proxy writes to.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17969 carries route-local auth middleware"
      }
    },
    "/v1/labels/{event_id}": {
      "get": {
        "tags": [
          "labels"
        ],
        "operationId": "getV1LabelsEventid",
        "summary": "Label detail - fetches one persisted decision and hides cross-tenant event ids.",
        "description": "Label detail - fetches one persisted decision and hides cross-tenant event ids.",
        "parameters": [
          {
            "name": "event_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "event_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21809 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lake/contribute": {
      "post": {
        "tags": [
          "lake"
        ],
        "operationId": "postV1LakeContribute",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24055 carries route-local auth middleware"
      }
    },
    "/v1/lake/export": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeExport",
        "summary": "GET /v1/lake/export → bulk export of canonical events.",
        "description": "GET /v1/lake/export → bulk export of canonical events. Supports format=jsonl (default) | json | csv. Streams the buffer back.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21669 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lake/opt-in": {
      "post": {
        "tags": [
          "lake"
        ],
        "operationId": "postV1LakeOptin",
        "summary": "GET /v1/lake/trends AUTH; rolled-up summary (no raw text, no identity)",
        "description": "GET /v1/lake/trends AUTH; rolled-up summary (no raw text, no identity) The W751 GET /v1/verticals/:id/fingerprint route already exists above; the module is consumed via the new pattern-lake helpers. New code paths (CLI lake subverbs, the W757 docs page) call these routes directly.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24002 carries route-local auth middleware"
      }
    },
    "/v1/lake/opt-out": {
      "post": {
        "tags": [
          "lake"
        ],
        "operationId": "postV1LakeOptout",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24033 carries route-local auth middleware"
      }
    },
    "/v1/lake/repeated": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeRepeated",
        "summary": "Lake repeated - finds clusters of repeated workflow inputs in the event",
        "description": "Lake repeated - finds clusters of repeated workflow inputs in the event store (the W384 \"repeated workflows\" surface). Returns up to ?limit (max 200, default 20) clusters with their representative input + member count.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21539 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lake/stats": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeStats",
        "summary": "Lake stats - per-tenant event-store roll-up: row counts, byte size, oldest",
        "description": "Lake stats - per-tenant event-store roll-up: row counts, byte size, oldest and newest timestamps, namespace breakdown. Accepts ?namespace, ?since, ?provider, ?model, ?status, ?min_latency_ms, ?max_latency_ms, and ?exclude_errors filters. Scoped via _tenantScope; admin sees cross-tenant aggregate.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21510 carries route-local auth middleware"
      }
    },
    "/v1/lake/storage": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeStorage",
        "summary": "GET /v1/lake/storage → small env probe for the Account UI so the",
        "description": "GET /v1/lake/storage → small env probe for the Account UI so the dashboard can show \"Local storage: ~/.kolm/events/events.sqlite (12 MB)\". Returns the same envelope storeInfo() emits, plus a coarse byte total.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21698 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lake/tail": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeTail",
        "summary": "GET /v1/lake/tail → recent canonical events for the inbox UI.",
        "description": "GET /v1/lake/tail → recent canonical events for the inbox UI. Reads directly from the event-store (NOT capture-store). Default limit 50, capped at 500. Returns newest first.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21654 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lake/trends": {
      "get": {
        "tags": [
          "lake"
        ],
        "operationId": "getV1LakeTrends",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24099 carries route-local auth middleware"
      }
    },
    "/v1/lang/augment-multilingual": {
      "post": {
        "tags": [
          "lang"
        ],
        "operationId": "postV1LangAugmentmultilingual",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24179 carries route-local auth middleware"
      }
    },
    "/v1/lang/detect": {
      "post": {
        "tags": [
          "lang"
        ],
        "operationId": "postV1LangDetect",
        "summary": "* Wilson 95% CI gated at n>=30 PER LANGUAGE. Below that the per-lang",
        "description": "* Wilson 95% CI gated at n>=30 PER LANGUAGE. Below that the per-lang k_score is null - never estimated. * augment-multilingual is dry_run by default. confirm:true required to incur translator cost. teacher_caller is DI'd from req.app.locals so tests never hit a real translation API.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24123 carries route-local auth middleware"
      }
    },
    "/v1/lang/kscore-by-lang/{namespace}": {
      "get": {
        "tags": [
          "lang"
        ],
        "operationId": "getV1LangKscorebylangNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24139 carries route-local auth middleware"
      }
    },
    "/v1/lead/enterprise": {
      "post": {
        "tags": [
          "lead"
        ],
        "operationId": "postV1LeadEnterprise",
        "summary": "Enterprise inquiry intake (KOLM-102)",
        "description": "Enterprise inquiry intake (KOLM-102) Public POST from /enterprise/inquiry. Validates 7 required fields, persists to in-memory enterpriseLeads, and emails sales@kolm.ai via Resend (best effort - sendMail() returns { skipped: true } when RESEND_API_KEY is unset).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14731 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lead/enterprise/{id}": {
      "get": {
        "tags": [
          "lead"
        ],
        "operationId": "getV1LeadEnterpriseId",
        "summary": "Admin-only read of a single enterprise lead. Useful for ops triage and",
        "description": "Admin-only read of a single enterprise lead. Useful for ops triage and for verifying the in-memory store after a submit during e2e checks.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14867 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/library": {
      "get": {
        "tags": [
          "library"
        ],
        "operationId": "getV1Library",
        "summary": "Library - returns the bundled kolm runtime library version and a human",
        "description": "Library - returns the bundled kolm runtime library version and a human description string. Used by the SDKs and `kolm version` for the runtime-library identifier (separate from the API/server version).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14410 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lineage/build": {
      "post": {
        "tags": [
          "lineage"
        ],
        "operationId": "postV1LineageBuild",
        "summary": "lineage + capability",
        "description": "lineage + capability",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19151 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lineage/validate": {
      "post": {
        "tags": [
          "lineage"
        ],
        "operationId": "postV1LineageValidate",
        "summary": "Lineage validate - checks an artifact-lineage block for structural",
        "description": "Lineage validate - checks an artifact-lineage block for structural consistency (parent links, build steps, version pins). Returns {ok:true, block} when the lineage is well-formed, {ok:false, error} otherwise.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19159 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lingual/distribution": {
      "get": {
        "tags": [
          "lingual"
        ],
        "operationId": "getV1LingualDistribution",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/lingual-routes.js is registered from src/router.js:30022 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lingual/manifest": {
      "get": {
        "tags": [
          "lingual"
        ],
        "operationId": "getV1LingualManifest",
        "summary": "/v1/lingual/manifest - bare GET aliasing the W833 manifest collection.",
        "description": "/v1/lingual/manifest - bare GET aliasing the W833 manifest collection. The shipped route is /v1/lingual/manifest/:artifact_id; without an artifact_id selected (the TUI default state) we return the tenant-wide language-mixture distribution so the view still renders.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28659 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lingual/manifest/{artifact_id}": {
      "get": {
        "tags": [
          "lingual"
        ],
        "operationId": "getV1LingualManifestArtifactid",
        "summary": "GET /v1/lingual/manifest/:artifact_id",
        "description": "GET /v1/lingual/manifest/:artifact_id Reads the per-language K-Score block off an artifact's manifest. Looks up the manifest via src/artifact.js (or registry.js) when available; falls back to an honest \"no_manifest_found\" envelope when the artifact isn't registered.",
        "parameters": [
          {
            "name": "artifact_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "artifact_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/lingual-routes.js is registered from src/router.js:30022 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lingual/mixture/auto-balance": {
      "post": {
        "tags": [
          "lingual"
        ],
        "operationId": "postV1LingualMixtureAutobalance",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/lingual-routes.js is registered from src/router.js:30022 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/lingual/synthesize": {
      "post": {
        "tags": [
          "lingual"
        ],
        "operationId": "postV1LingualSynthesize",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/lingual-routes.js is registered from src/router.js:30022 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/long-context/check": {
      "post": {
        "tags": [
          "long-context"
        ],
        "operationId": "postV1LongcontextCheck",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27995 carries route-local auth middleware"
      }
    },
    "/v1/long-context/p90": {
      "get": {
        "tags": [
          "long-context"
        ],
        "operationId": "getV1LongcontextP90",
        "summary": "Tenant fence: tenant_id forced from req.tenant_record.id; query/body",
        "description": "Tenant fence: tenant_id forced from req.tenant_record.id; query/body never override. Returns honest envelope (no_captures, insufficient_samples) rather than throwing. version stamp matches /^w781-/.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27973 carries route-local auth middleware"
      }
    },
    "/v1/loop/try": {
      "post": {
        "tags": [
          "loop"
        ],
        "operationId": "postV1LoopTry",
        "summary": "public anonymous \"try it\" demo of the capture-receipt shape.",
        "description": "public anonymous \"try it\" demo of the capture-receipt shape. No auth, no write side-effects; visitors on /value-loop POST a prompt+response and see the exact same receipt envelope a real authenticated /v1/bridges/observe would emit, with `demo:true` + `durable:false` so the body cannot lie.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1671 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1Marketplace",
        "summary": "Marketplace list - filters artifacts and overlays live verification before returning rows.",
        "description": "Marketplace list - filters artifacts and overlays live verification before returning rows.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19252 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/catalog.json": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceCatalogjson",
        "summary": "Marketplace catalog manifest - returns the signed catalog with live production-ready verdicts.",
        "description": "Marketplace catalog manifest - returns the signed catalog with live production-ready verdicts.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19242 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/download/{id}": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceDownloadId",
        "summary": "GET /v1/marketplace/download/:id",
        "description": "GET /v1/marketplace/download/:id Auth-gated. Streams artifact_uri bytes; records download counter. 402 if listing.paid AND tenant lacks entitlement.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/facets": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceFacets",
        "summary": "GET /v1/marketplace/facets",
        "description": "GET /v1/marketplace/facets Pure read: returns the enum set so the UI sidebar can render filter chips without hard-coding the lists in two places.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/finetune": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceFinetune",
        "summary": "POST /v1/marketplace/finetune",
        "description": "POST /v1/marketplace/finetune Auth-gated. Queue a transfer-learning fine-tune from a marketplace artifact.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/interest": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceInterest",
        "summary": "IP per 24h (see marketplaceInterestLimiter above).",
        "description": "IP per 24h (see marketplaceInterestLimiter above). Returns { ok, position } where position is the row's stable 1-indexed place in the early-access list. Stable means the position does not change on dedupe (we read the existing row's position back out).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19310 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/list": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceList",
        "summary": "explicit list endpoint used by /marketplace.html client render.",
        "description": "explicit list endpoint used by /marketplace.html client render. Always returns { artifacts: [...] } with live verified flag.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19270 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/listings": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceListings",
        "summary": "GET /v1/marketplace/listings",
        "description": "GET /v1/marketplace/listings Public read. Returns {ok:true, rows, total, page, limit, sort_by, all_count}.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceListings",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19412 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/payout-cycle": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplacePayoutcycle",
        "summary": "POST /v1/marketplace/payout-cycle",
        "description": "POST /v1/marketplace/payout-cycle Auth-gated. Forecast-only: aggregates revenue ledger and emits payout audit rows. Returns the per-listing split.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/publish": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplacePublish",
        "summary": "Distinct from /v1/marketplace/publish-request (manual review queue)",
        "description": "Distinct from /v1/marketplace/publish-request (manual review queue) this endpoint is the programmatic publish path the CLI uses after pipeline-ship has already enforced the production gate locally.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19582 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/publish-request": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplacePublishrequest",
        "summary": "Marketplace publish request - queues an artifact proposal for manual review without publishing bytes.",
        "description": "Marketplace publish request - queues an artifact proposal for manual review without publishing bytes.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19278 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/rate": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceRate",
        "summary": "POST /v1/marketplace/rate",
        "description": "POST /v1/marketplace/rate Auth-gated. Anti-gaming: 403 unless account_age >= 7d AND prior download.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/ratings/{id}": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceRatingsId",
        "summary": "GET /v1/marketplace/ratings/:id",
        "description": "GET /v1/marketplace/ratings/:id Public read of aggregate ratings.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/reviews": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceReviews",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19438 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/reviews/{cid}": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceReviewsCid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "cid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "cid path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19461 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/search": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceSearch",
        "summary": "* empty search results -> {ok:false, error:'marketplace_empty',",
        "description": "* empty search results -> {ok:false, error:'marketplace_empty', hint:'no artifacts registered yet', results:[]} * unauth POST -> 401 + {error:'auth_required'} * invalid payload -> 400 + {error:'<code>', detail:<msg>}",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19377 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/upload": {
      "post": {
        "tags": [
          "marketplace"
        ],
        "operationId": "postV1MarketplaceUpload",
        "summary": "Auth-gated. Body: {artifact_uri, manifest_sha256, signature_b64,",
        "description": "Auth-gated. Body: {artifact_uri, manifest_sha256, signature_b64, public_key_pem, id, title, vertical, task_type, hardware_targets[], k_score, teacher_model, paid, price_micro_usd}. publisher_tenant_id is FORCED from req.tenant_record.id.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/marketplace-routes.js is registered from src/router.js:30106 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/{slug}": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceSlug",
        "summary": "Marketplace detail - returns one artifact with live verification state or 404 for unknown slugs.",
        "description": "Marketplace detail - returns one artifact with live verification state or 404 for unknown slugs.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19472 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/marketplace/{slug}/download": {
      "get": {
        "tags": [
          "marketplace"
        ],
        "operationId": "getV1MarketplaceSlugDownload",
        "summary": "W339/W342 - install/download MUST refuse artifacts that don't pass",
        "description": "W339/W342 - install/download MUST refuse artifacts that don't pass productionReady(). Same gate the marketplace pill uses, so a user who sees no \"Verified\" badge ALSO can't `kolm marketplace install` it. force allowed via ?force=true query for CI testing / canary debug, matching `kolm run --force` semantics.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19498 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/mcp": {
      "post": {
        "tags": [
          "mcp"
        ],
        "operationId": "postV1Mcp",
        "summary": "MCP server (JSON-RPC 2.0)",
        "description": "MCP server (JSON-RPC 2.0)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11867 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/mcp/dispatch": {
      "post": {
        "tags": [
          "mcp"
        ],
        "operationId": "postV1McpDispatch",
        "summary": "transport?: 'stdio'|'http'|'sse',",
        "description": "transport?: 'stdio'|'http'|'sse', server_id?: string, // MCP server registry id call_id?: string, // pin for a reproducible id now?: number|string // injected clock (tests / determinism) }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/mcp-gateway-routes.js is registered from src/router.js:30083 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/mcp/verify/{id}": {
      "get": {
        "tags": [
          "mcp"
        ],
        "operationId": "getV1McpVerifyId",
        "summary": "── GET /v1/mcp/verify/:id ─────────────────────────────────────────────────",
        "description": "── GET /v1/mcp/verify/:id ───────────────────────────────────────────────── Tenant-fenced: only returns a receipt minted under THIS tenant. The verify result is deterministic (recompute canonical + Ed25519 check; no network).",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/mcp-gateway-routes.js is registered from src/router.js:30083 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/me/models": {
      "get": {
        "tags": [
          "me"
        ],
        "operationId": "getV1MeModels",
        "summary": "Model entitlements (employee/team model access)",
        "description": "Model entitlements (employee/team model access)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11835 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/media/redact": {
      "post": {
        "tags": [
          "media"
        ],
        "operationId": "postV1MediaRedact",
        "summary": "Media redact - text-extractable media redactor. Accepts {media_uri | text,",
        "description": "Media redact - text-extractable media redactor. Accepts {media_uri | text, mime} and either redacts inline text or loads the blob, sniffs mime, and routes text-extractable kinds (text/json/yaml/xml) through /v1/redact. Non-text kinds (image/audio/video/pdf) return {deferred:true, deferral} with a worker hint instead of attempting heavy ML in-process.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12090 carries route-local auth middleware"
      }
    },
    "/v1/media/redact-job": {
      "post": {
        "tags": [
          "media"
        ],
        "operationId": "postV1MediaRedactjob",
        "summary": "envelope so the caller knows exactly what to install.",
        "description": "envelope so the caller knows exactly what to install. Body: { media_uri | path, mime?, kind?, max_bytes?, model?, lang? } Sync mode (default): worker runs in-process via spawnSync. For long whisper passes, callers should pass {async:true} (deferred to W455).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12194 carries route-local auth middleware"
      }
    },
    "/v1/media/redact-job/doctor": {
      "get": {
        "tags": [
          "media"
        ],
        "operationId": "getV1MediaRedactjobDoctor",
        "summary": "worker self-doctor proxied through the API so `kolm media",
        "description": "worker self-doctor proxied through the API so `kolm media doctor --remote` can ask the server which extractors are wired.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12243 carries route-local auth middleware"
      }
    },
    "/v1/memory/recall": {
      "post": {
        "tags": [
          "memory"
        ],
        "operationId": "postV1MemoryRecall",
        "summary": "POST /v1/memory/recall - REM Memory ↔ Skills bridge.",
        "description": "POST /v1/memory/recall - REM Memory ↔ Skills bridge. Given a query, find recipes tagged with that namespace, run them, and return the merged result.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18155 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/merge": {
      "post": {
        "tags": [
          "merge"
        ],
        "operationId": "postV1Merge",
        "summary": "POST /v1/merge - compute a merge plan for two .kolm artifacts.",
        "description": "POST /v1/merge - compute a merge plan for two .kolm artifacts. Body: { base, head, method?, alpha?, dry_run? } Returns the merge envelope (lineage check, kscore delta heuristic, output path). When dry_run=true, no artifact is written.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28878 carries route-local auth middleware"
      }
    },
    "/v1/merge/{id}": {
      "get": {
        "tags": [
          "merge"
        ],
        "operationId": "getV1MergeId",
        "summary": "GET /v1/merge/:id - poll a merge job created by POST /v1/merge (dry_run=false).",
        "description": "GET /v1/merge/:id - poll a merge job created by POST /v1/merge (dry_run=false). Returns the durable merge_jobs record (status queued|running|completed| planned|failed). Tenant-scoped: a tenant can only read its own merge jobs.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29006 carries route-local auth middleware"
      }
    },
    "/v1/messages": {
      "post": {
        "tags": [
          "messages"
        ],
        "operationId": "postV1Messages",
        "summary": "Anthropic direct + alias.",
        "description": "Anthropic direct + alias.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5522 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/meta/predict": {
      "get": {
        "tags": [
          "meta"
        ],
        "operationId": "getV1MetaPredict",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/meta-routes.js is registered from src/router.js:30016 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/meta/retrain": {
      "post": {
        "tags": [
          "meta"
        ],
        "operationId": "postV1MetaRetrain",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/meta-routes.js is registered from src/router.js:30016 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/meta/status": {
      "get": {
        "tags": [
          "meta"
        ],
        "operationId": "getV1MetaStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/meta-routes.js is registered from src/router.js:30016 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/metrics/event": {
      "post": {
        "tags": [
          "metrics"
        ],
        "operationId": "postV1MetricsEvent",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10281 carries route-local auth middleware"
      }
    },
    "/v1/metrics/snapshot": {
      "get": {
        "tags": [
          "metrics"
        ],
        "operationId": "getV1MetricsSnapshot",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10298 carries route-local auth middleware"
      }
    },
    "/v1/migrate/discover": {
      "post": {
        "tags": [
          "migrate"
        ],
        "operationId": "postV1MigrateDiscover",
        "summary": "{ok, manifest, source_metadata, ...}.",
        "description": "{ok, manifest, source_metadata, ...}. Both are auth-gated. Discovery is local-filesystem only - no network call leaves the box. The python3 GGUF parser is reused; missing python3 surfaces a 503 envelope on the wrap path.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7354 carries route-local auth middleware"
      }
    },
    "/v1/migrate/wrap": {
      "post": {
        "tags": [
          "migrate"
        ],
        "operationId": "postV1MigrateWrap",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7394 carries route-local auth middleware"
      }
    },
    "/v1/mit/run": {
      "post": {
        "tags": [
          "mit"
        ],
        "operationId": "postV1MitRun",
        "summary": "* The forget route ALWAYS writes the audit event before returning ok.",
        "description": "* The forget route ALWAYS writes the audit event before returning ok. Idempotency is checked inside src/capture-forget.js (existing marker returns the original audit_event_id without writing a second row). * Tenant fence everywhere: every read/write is keyed on req.tenant_record.id; defense-in-depth lives inside capture-forget.js.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24519 carries route-local auth middleware"
      }
    },
    "/v1/mit/scan-pii": {
      "post": {
        "tags": [
          "mit"
        ],
        "operationId": "postV1MitScanpii",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24549 carries route-local auth middleware"
      }
    },
    "/v1/model-card/generate": {
      "post": {
        "tags": [
          "model-card"
        ],
        "operationId": "postV1ModelcardGenerate",
        "summary": "MUST regex-match (W604 anti-brittleness).",
        "description": "MUST regex-match (W604 anti-brittleness). Modules import lazily so cold daemons that never hit this surface don't pay for the schema/emitter trees.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25409 carries route-local auth middleware"
      }
    },
    "/v1/model-card/governance-mappings": {
      "get": {
        "tags": [
          "model-card"
        ],
        "operationId": "getV1ModelcardGovernancemappings",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25458 carries route-local auth middleware"
      }
    },
    "/v1/model-card/schema": {
      "get": {
        "tags": [
          "model-card"
        ],
        "operationId": "getV1ModelcardSchema",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25444 carries route-local auth middleware"
      }
    },
    "/v1/models": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1Models",
        "summary": "other teachers, but rows whose family hints at an Anthropic-shaped",
        "description": "other teachers, but rows whose family hints at an Anthropic-shaped client probe are also surfaced under an `anthropic:`-prefixed alias so a probe via the Anthropic SDK can discover them without colliding with the canonical HF id.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23615 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/cache": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsCache",
        "summary": "Models cache - returns the local model-weights cache index for the API",
        "description": "Models cache - returns the local model-weights cache index for the API host (cache_dir, total_bytes, per-entry rows). Used by `kolm models cache` and the device-detect picker to know which weights are already on disk.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6013 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/info/{id}": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsInfoId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6050 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/manifest": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsManifest",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5973 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/pull": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsPull",
        "summary": "Models pull - 302-redirects to a resolved Hugging Face download URL for",
        "description": "Models pull - 302-redirects to a resolved Hugging Face download URL for the requested model id+variant (default variant: q4_k_m). 404 for unknown variants, 410 when the variant exists but is marked unavailable.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5991 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/recommend": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsRecommend",
        "summary": "Model recommendation + model info. Public and secret-free: this powers the",
        "description": "Model recommendation + model info. Public and secret-free: this powers the post-auth model picker, CLI parity, and \"which backbone should I use?\" flows without requiring a tenant before the user understands the catalog.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:6028 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/{id}/access": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsIdAccess",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11840 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "models"
        ],
        "operationId": "postV1ModelsIdAccess",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11845 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "models"
        ],
        "operationId": "deleteV1ModelsIdAccess",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11856 carries route-local auth middleware"
      }
    },
    "/v1/models/{id}/updates": {
      "get": {
        "tags": [
          "models"
        ],
        "operationId": "getV1ModelsIdUpdates",
        "summary": "W-INTEG-3: on-device model self-update (signed, offline-verifiable)",
        "description": "W-INTEG-3: on-device model self-update (signed, offline-verifiable)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11940 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/models/{id}/versions": {
      "post": {
        "tags": [
          "models"
        ],
        "operationId": "postV1ModelsIdVersions",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11948 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/moderations": {
      "post": {
        "tags": [
          "moderations"
        ],
        "operationId": "postV1Moderations",
        "summary": "OpenAI-compatible passthrough for the responses, embeddings, and",
        "description": "OpenAI-compatible passthrough for the responses, embeddings, and moderations endpoints. Each routes through __connectorProxy('openai', ...) so the upstream OpenAI API is reached with the configured key, and the request/response is captured into the tenant lake.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5512 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/multimodal/bakeoff": {
      "get": {
        "tags": [
          "multimodal"
        ],
        "operationId": "getV1MultimodalBakeoff",
        "summary": "GET helper for TUI/CLI list-view: same shape as POST but with the",
        "description": "GET helper for TUI/CLI list-view: same shape as POST but with the contestants list pulled from the tenant's locally-compiled artifacts (~/.kolm/artifacts/). Query params: ?modality=image&namespace=ns&limit=20. Returns the same envelope shape; the TUI's get-view unwrap chain already handles the `contestants` array.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12552 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "multimodal"
        ],
        "operationId": "postV1MultimodalBakeoff",
        "summary": "POST /v1/multimodal/bakeoff runs an authenticated tenant's captured",
        "description": "POST /v1/multimodal/bakeoff runs an authenticated tenant's captured image/audio/video/PDF rows through selected .kolm artifacts and returns ranked contestants with token-overlap scoring and winner metadata.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12522 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/pipeline": {
      "get": {
        "tags": [
          "multimodal"
        ],
        "operationId": "getV1MultimodalPipeline",
        "summary": "/v1/multimodal/pipeline - collection GET listing tenant multimodal",
        "description": "/v1/multimodal/pipeline - collection GET listing tenant multimodal capture pipeline state. Real W829 routes (/v1/captures/multimodal, /v1/vlm-distill/runs) live in src/multimodal-pipeline-routes.js; this bare GET aggregates them for the TUI surface.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28610 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/redact-audio": {
      "post": {
        "tags": [
          "multimodal"
        ],
        "operationId": "postV1MultimodalRedactaudio",
        "summary": "multimodal audio voiceprint scrub. Anonymizes the speaker's",
        "description": "multimodal audio voiceprint scrub. Anonymizes the speaker's voiceprint while preserving content. Complementary to W462 image redact (faces/plates) and W454 audio transcript redact (text). Body: { media_uri | path, output_path?, strength?, max_bytes? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12330 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/redact-audio/doctor": {
      "get": {
        "tags": [
          "multimodal"
        ],
        "operationId": "getV1MultimodalRedactaudioDoctor",
        "summary": "audio-redact worker self-doctor.",
        "description": "audio-redact worker self-doctor.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12374 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/redact-image": {
      "post": {
        "tags": [
          "multimodal"
        ],
        "operationId": "postV1MultimodalRedactimage",
        "summary": "{ok:false, error:'no_detector_installed', install_hint:'...'} so the",
        "description": "{ok:false, error:'no_detector_installed', install_hint:'...'} so the caller never thinks redaction succeeded when it didn't. Body: { media_uri | path, output_path?, mode?, threshold?, face_model?, plate_model?, max_bytes? }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12280 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/redact-image/doctor": {
      "get": {
        "tags": [
          "multimodal"
        ],
        "operationId": "getV1MultimodalRedactimageDoctor",
        "summary": "image-redact worker self-doctor, proxied so the CLI's",
        "description": "image-redact worker self-doctor, proxied so the CLI's `kolm media image-doctor --remote` can ask the server.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12400 carries route-local auth middleware"
      }
    },
    "/v1/multimodal/tokenize": {
      "post": {
        "tags": [
          "multimodal"
        ],
        "operationId": "postV1MultimodalTokenize",
        "summary": "POST /v1/multimodal/tokenize tokenizes one local file path or directory",
        "description": "POST /v1/multimodal/tokenize tokenizes one local file path or directory on an authenticated local daemon or explicitly trusted self-hosted server. Hosted deployments deny server-side file access unless the operator sets KOLM_ALLOW_SERVER_FILE_TOKENIZE=1.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12468 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/multimodal/tokenize/doctor": {
      "get": {
        "tags": [
          "multimodal"
        ],
        "operationId": "getV1MultimodalTokenizeDoctor",
        "summary": "multimodal sidecar tokenizer. API mirror of",
        "description": "multimodal sidecar tokenizer. API mirror of `kolm media tokenize`: local-safe by default, hosted-disabled unless the operator explicitly allows server-side file access. Creates compile-ready Markdown sidecars using deterministic local feature tokens, with optional provider captions/transcripts when configured.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12436 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/namespaces": {
      "get": {
        "tags": [
          "namespaces"
        ],
        "operationId": "getV1Namespaces",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25171 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "namespaces"
        ],
        "operationId": "postV1Namespaces",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24977 carries route-local auth middleware"
      }
    },
    "/v1/namespaces/{slug}": {
      "get": {
        "tags": [
          "namespaces"
        ],
        "operationId": "getV1NamespacesSlug",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25020 carries route-local auth middleware"
      },
      "put": {
        "tags": [
          "namespaces"
        ],
        "operationId": "putV1NamespacesSlug",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25035 carries route-local auth middleware"
      }
    },
    "/v1/namespaces/{slug}/deploy": {
      "post": {
        "tags": [
          "namespaces"
        ],
        "operationId": "postV1NamespacesSlugDeploy",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25074 carries route-local auth middleware"
      }
    },
    "/v1/namespaces/{slug}/rollback": {
      "post": {
        "tags": [
          "namespaces"
        ],
        "operationId": "postV1NamespacesSlugRollback",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25141 carries route-local auth middleware"
      }
    },
    "/v1/namespaces/{slug}/stats": {
      "get": {
        "tags": [
          "namespaces"
        ],
        "operationId": "getV1NamespacesSlugStats",
        "summary": "GET /v1/namespaces/:slug/stats - counts of pending/approved/",
        "description": "GET /v1/namespaces/:slug/stats - counts of pending/approved/ rejected/quarantined captures in a namespace. Powers the \"ready to compile?\" readiness signal on /account/overview and the namespace badge on /account/namespaces. Tenant-union pattern to handle name-vs-id keys.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25187 carries route-local auth middleware"
      }
    },
    "/v1/namespaces/{slug}/undeploy": {
      "post": {
        "tags": [
          "namespaces"
        ],
        "operationId": "postV1NamespacesSlugUndeploy",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25119 carries route-local auth middleware"
      }
    },
    "/v1/nl/scaffold": {
      "post": {
        "tags": [
          "nl"
        ],
        "operationId": "postV1NlScaffold",
        "summary": "air-gap branch produces the same shape locally via scaffoldRecipeFromNl;",
        "description": "air-gap branch produces the same shape locally via scaffoldRecipeFromNl; this endpoint exists so a tenant that opts in (--network or KOLM_AIRGAP=0) can get an LLM-augmented scaffold without forking the CLI. The x-kolm-nl-source response header tells the caller which branch served (network = hosted LLM enrichment; airgap = deterministic fallback).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16592 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/notifications/config": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsConfig",
        "summary": "Notifications config - public VAPID/email capability flags and alert thresholds.",
        "description": "Notifications config - public VAPID/email capability flags and alert thresholds.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16974 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/notifications/log": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsLog",
        "summary": "Webhook notification log - returns the last 50 delivery attempts.",
        "description": "Webhook notification log - returns the last 50 delivery attempts.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17801 carries route-local auth middleware"
      }
    },
    "/v1/notifications/preferences": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsPreferences",
        "summary": "Notification preferences - returns tenant alert opt-in settings plus public config.",
        "description": "Notification preferences - returns tenant alert opt-in settings plus public config.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16978 carries route-local auth middleware"
      },
      "put": {
        "tags": [
          "notifications"
        ],
        "operationId": "putV1NotificationsPreferences",
        "summary": "Notification preferences update - sets threshold alert opt-in and optional email.",
        "description": "Notification preferences update - sets threshold alert opt-in and optional email.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16984 carries route-local auth middleware"
      }
    },
    "/v1/notifications/push-subscriptions": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsPushsubscriptions",
        "summary": "Push subscription list - returns registered WebPush endpoints without secret keys.",
        "description": "Push subscription list - returns registered WebPush endpoints without secret keys.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16994 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "notifications"
        ],
        "operationId": "postV1NotificationsPushsubscriptions",
        "summary": "Push subscription registration - stores an allowlisted HTTPS WebPush endpoint.",
        "description": "Push subscription registration - stores an allowlisted HTTPS WebPush endpoint.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17002 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "notifications"
        ],
        "operationId": "deleteV1NotificationsPushsubscriptions",
        "summary": "Push subscription removal - deletes a subscription by endpoint from body or query.",
        "description": "Push subscription removal - deletes a subscription by endpoint from body or query.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17012 carries route-local auth middleware"
      }
    },
    "/v1/notifications/settings": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsSettings",
        "summary": "Webhook notification settings - returns Slack/HTTP/email channels plus event toggles.",
        "description": "Webhook notification settings - returns Slack/HTTP/email channels plus event toggles.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17770 carries route-local auth middleware"
      },
      "put": {
        "tags": [
          "notifications"
        ],
        "operationId": "putV1NotificationsSettings",
        "summary": "Webhook notification settings update - writes Slack/HTTP/email channels and event toggles.",
        "description": "Webhook notification settings update - writes Slack/HTTP/email channels and event toggles.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17776 carries route-local auth middleware"
      }
    },
    "/v1/notifications/state": {
      "get": {
        "tags": [
          "notifications"
        ],
        "operationId": "getV1NotificationsState",
        "summary": "Notification threshold state - returns per-namespace alert state and readiness.",
        "description": "Notification threshold state - returns per-namespace alert state and readiness.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17035 carries route-local auth middleware"
      }
    },
    "/v1/notifications/test": {
      "post": {
        "tags": [
          "notifications"
        ],
        "operationId": "postV1NotificationsTest",
        "summary": "Notification test alert - fires a synthetic threshold alert for a namespace.",
        "description": "Notification test alert - fires a synthetic threshold alert for a namespace.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17020 carries route-local auth middleware"
      }
    },
    "/v1/notifications/test-channel": {
      "post": {
        "tags": [
          "notifications"
        ],
        "operationId": "postV1NotificationsTestchannel",
        "summary": "Webhook notification test - dispatches a sample event payload to configured channels.",
        "description": "Webhook notification test - dispatches a sample event payload to configured channels.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:17786 carries route-local auth middleware"
      }
    },
    "/v1/numeric/calculator": {
      "post": {
        "tags": [
          "numeric"
        ],
        "operationId": "postV1NumericCalculator",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23840 carries route-local auth middleware"
      }
    },
    "/v1/numeric/eval": {
      "post": {
        "tags": [
          "numeric"
        ],
        "operationId": "postV1NumericEval",
        "summary": "contract - a stray request must not fire an evaluation by accident.",
        "description": "contract - a stray request must not fire an evaluation by accident. Honest envelope on every error path: ok:false + structured error + version stamp `w759-vN.M`. Consumers MUST version-pin via regex (/^w759-/), not literal equality (W604 anti-brittleness).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23817 carries route-local auth middleware"
      }
    },
    "/v1/numeric/namespace-flag/{namespace}": {
      "get": {
        "tags": [
          "numeric"
        ],
        "operationId": "getV1NumericNamespaceflagNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23862 carries route-local auth middleware"
      }
    },
    "/v1/oauth/providers": {
      "get": {
        "tags": [
          "oauth"
        ],
        "operationId": "getV1OauthProviders",
        "summary": "GET /v1/oauth/providers reports which hosted OAuth providers are configured.",
        "description": "GET /v1/oauth/providers reports which hosted OAuth providers are configured. Signup uses this public route to hide provider buttons until credentials exist.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/oauth.js is registered from src/router.js:3040 before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/oauth/{provider}/callback": {
      "get": {
        "tags": [
          "oauth"
        ],
        "operationId": "getV1OauthProviderCallback",
        "summary": "GET /v1/oauth/:provider/callback completes Google or GitHub OAuth sign-in.",
        "description": "GET /v1/oauth/:provider/callback completes Google or GitHub OAuth sign-in. Exchanges the provider code, creates or finds the tenant, then sets the session cookie.",
        "parameters": [
          {
            "name": "provider",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "provider path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/oauth.js is registered from src/router.js:3040 before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/oauth/{provider}/start": {
      "get": {
        "tags": [
          "oauth"
        ],
        "operationId": "getV1OauthProviderStart",
        "summary": "GET /v1/oauth/:provider/start begins Google or GitHub OAuth sign-in.",
        "description": "GET /v1/oauth/:provider/start begins Google or GitHub OAuth sign-in. Redirects to the provider when configured; returns 503 with an operator hint otherwise.",
        "parameters": [
          {
            "name": "provider",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "provider path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/oauth.js is registered from src/router.js:3040 before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/openrouter/chat/completions": {
      "post": {
        "tags": [
          "openrouter"
        ],
        "operationId": "postV1OpenrouterChatCompletions",
        "summary": "OpenRouter chat-completions alias without the extra /v1 segment.",
        "description": "OpenRouter chat-completions alias without the extra /v1 segment.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5945 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/openrouter/v1/chat/completions": {
      "post": {
        "tags": [
          "openrouter"
        ],
        "operationId": "postV1OpenrouterV1ChatCompletions",
        "summary": "OpenRouter base-URL alias for SDKs that append /v1/chat/completions.",
        "description": "OpenRouter base-URL alias for SDKs that append /v1/chat/completions.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5943 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/opportunities": {
      "get": {
        "tags": [
          "opportunities"
        ],
        "operationId": "getV1Opportunities",
        "summary": "every opportunity surface must be tenant-scoped. Without auth the",
        "description": "every opportunity surface must be tenant-scoped. Without auth the engine would surface another tenant's pattern detections (cache_candidate request_hash, repeated prompt clusters, etc). 401s use the canonical {ok:false, error:'auth required'} envelope.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21558 carries route-local auth middleware"
      }
    },
    "/v1/opportunities/{id}/accept": {
      "post": {
        "tags": [
          "opportunities"
        ],
        "operationId": "postV1OpportunitiesIdAccept",
        "summary": "Opportunity accept - marks one optimization opportunity (cache candidate,",
        "description": "Opportunity accept - marks one optimization opportunity (cache candidate, repeated-prompt cluster, replacement) as accepted by the tenant. Tenant scoped; cross-tenant ids 404. Body: { reason }. Recorded for audit log.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21579 carries route-local auth middleware"
      }
    },
    "/v1/opportunities/{id}/dismiss": {
      "post": {
        "tags": [
          "opportunities"
        ],
        "operationId": "postV1OpportunitiesIdDismiss",
        "summary": "Accept either /dismiss or /ignore - both map to ignoreOpportunity.",
        "description": "Accept either /dismiss or /ignore - both map to ignoreOpportunity.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21594 carries route-local auth middleware"
      }
    },
    "/v1/opportunities/{id}/ignore": {
      "post": {
        "tags": [
          "opportunities"
        ],
        "operationId": "postV1OpportunitiesIdIgnore",
        "summary": "Opportunity ignore - tenant-scoped synonym for /dismiss; marks the",
        "description": "Opportunity ignore - tenant-scoped synonym for /dismiss; marks the opportunity as ignored so it stops surfacing on the dashboard. Body: { reason }. Cross-tenant ids 404.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21611 carries route-local auth middleware"
      }
    },
    "/v1/opportunities/{id}/promote": {
      "post": {
        "tags": [
          "opportunities"
        ],
        "operationId": "postV1OpportunitiesIdPromote",
        "summary": "POST /v1/opportunities/:id/promote → dataset.",
        "description": "POST /v1/opportunities/:id/promote → dataset. Turns the opportunity into a real dataset by calling dataset-workbench createDataset() with the opportunity's namespace + provenance. Returns { ok, dataset_id, train_count, holdout_count, ... }. Marks the opportunity status='promoted' so subsequent reads show the badge.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21630 carries route-local auth middleware"
      }
    },
    "/v1/orgs": {
      "get": {
        "tags": [
          "orgs"
        ],
        "operationId": "getV1Orgs",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18456 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}": {
      "get": {
        "tags": [
          "orgs"
        ],
        "operationId": "getV1OrgsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18461 is mounted after r.use(authMiddleware) at line 6376"
      },
      "patch": {
        "tags": [
          "orgs"
        ],
        "operationId": "patchV1OrgsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18464 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}/audit": {
      "get": {
        "tags": [
          "orgs"
        ],
        "operationId": "getV1OrgsIdAudit",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18496 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}/invites": {
      "get": {
        "tags": [
          "orgs"
        ],
        "operationId": "getV1OrgsIdInvites",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18476 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "orgs"
        ],
        "operationId": "postV1OrgsIdInvites",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18482 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}/leave": {
      "post": {
        "tags": [
          "orgs"
        ],
        "operationId": "postV1OrgsIdLeave",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18501 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}/members": {
      "get": {
        "tags": [
          "orgs"
        ],
        "operationId": "getV1OrgsIdMembers",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18471 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/orgs/{id}/transfer-owner": {
      "post": {
        "tags": [
          "orgs"
        ],
        "operationId": "postV1OrgsIdTransferowner",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18508 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/packages/release-readiness": {
      "get": {
        "tags": [
          "packages"
        ],
        "operationId": "getV1PackagesReleasereadiness",
        "summary": "Package release readiness - local, secret-safe audit for SDK/runtime/install",
        "description": "Package release readiness - local, secret-safe audit for SDK/runtime/install package contracts. This is not a registry publication claim: it exposes manifest/docs/dry-run readiness and channel blockers for package-gated items.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1827 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/packages/release-readiness/template": {
      "get": {
        "tags": [
          "packages"
        ],
        "operationId": "getV1PackagesReleasereadinessTemplate",
        "summary": "Package release manifest template - the signed artifact/registry evidence",
        "description": "Package release manifest template - the signed artifact/registry evidence required before package-gated readiness can become publish-ready.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1857 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/packages/release-readiness/validate": {
      "post": {
        "tags": [
          "packages"
        ],
        "operationId": "postV1PackagesReleasereadinessValidate",
        "summary": "Package release manifest validation - dry-runs a proposed signed release",
        "description": "Package release manifest validation - dry-runs a proposed signed release manifest without publishing to npm, PyPI, crates, SwiftPM, Maven, winget, Homebrew, apt, or extension stores.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1893 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/passport/{job_id}": {
      "get": {
        "tags": [
          "passport"
        ],
        "operationId": "getV1PassportJobid",
        "summary": "canonical path for offline use; this HTTP route serves the same envelope",
        "description": "canonical path for offline use; this HTTP route serves the same envelope for a *compile job* the caller's tenant already owns (artifact lives in the local artifact store at /v1/compile/:id/.kolm). For arbitrary external .kolm files, the CLI remains the supported path. Returns 501 with a hint when the artifact is not local - never silent.",
        "parameters": [
          {
            "name": "job_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "job_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11189 carries route-local auth middleware"
      }
    },
    "/v1/pextract/detect-attempt": {
      "post": {
        "tags": [
          "pextract"
        ],
        "operationId": "postV1PextractDetectattempt",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24472 carries route-local auth middleware"
      }
    },
    "/v1/pextract/guard-request": {
      "post": {
        "tags": [
          "pextract"
        ],
        "operationId": "postV1PextractGuardrequest",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24484 carries route-local auth middleware"
      }
    },
    "/v1/pextract/redact-prompt": {
      "post": {
        "tags": [
          "pextract"
        ],
        "operationId": "postV1PextractRedactprompt",
        "summary": "Defense layering with W762 is intentional. W762's",
        "description": "Defense layering with W762 is intentional. W762's classifyPromptAdversarial covers a broader red-team taxonomy; is the system-prompt-extraction-specific guard. Overlapping matches (e.g. \"ignore previous instructions\") are correct, not a bug - defense in depth is the point.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24448 carries route-local auth middleware"
      }
    },
    "/v1/pipeline/compile": {
      "post": {
        "tags": [
          "pipeline"
        ],
        "operationId": "postV1PipelineCompile",
        "summary": "tenant gate. The pipeline runs compileFull which reads from the",
        "description": "tenant gate. The pipeline runs compileFull which reads from the event store; without forcing tenant scope it would compile another tenant's corpus into the caller's artifact namespace. opts.tenant_id is injected from req.tenant_record.id and supersedes anything the body sent.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20473 carries route-local auth middleware"
      }
    },
    "/v1/pipeline/distill": {
      "post": {
        "tags": [
          "pipeline"
        ],
        "operationId": "postV1PipelineDistill",
        "summary": "POST /v1/pipeline/distill - kick off distill-from-captures with mode=specialist.",
        "description": "POST /v1/pipeline/distill - kick off distill-from-captures with mode=specialist. Returns 202 + {job_id}. The actual distill work is delegated to the existing /v1/distill/from-captures path (in-process module call).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20401 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipeline/full": {
      "post": {
        "tags": [
          "pipeline"
        ],
        "operationId": "postV1PipelineFull",
        "summary": "job_id. Phases are streamed via /v1/pipeline/jobs/:id/stream (SSE).",
        "description": "job_id. Phases are streamed via /v1/pipeline/jobs/:id/stream (SSE). same tenant gate as /v1/pipeline/compile. The caller's req.tenant_record.id is the only tenant scope that ever reaches compileFull from this route.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20502 carries route-local auth middleware"
      }
    },
    "/v1/pipeline/jobs/{id}": {
      "get": {
        "tags": [
          "pipeline"
        ],
        "operationId": "getV1PipelineJobsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20526 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipeline/jobs/{id}/stream": {
      "get": {
        "tags": [
          "pipeline"
        ],
        "operationId": "getV1PipelineJobsIdStream",
        "summary": "GET /v1/pipeline/jobs/:id/stream - SSE that replays past phases then",
        "description": "GET /v1/pipeline/jobs/:id/stream - SSE that replays past phases then streams new ones until the job terminates.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20544 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipeline/run": {
      "post": {
        "tags": [
          "pipeline"
        ],
        "operationId": "postV1PipelineRun",
        "summary": "is just missing - we don't",
        "description": "is just missing - we don't wrap that as a 4xx) The runner returns latency_ms_breakdown unconditionally so dashboards can chart per-tenant classify+route p50/p99 without a second round-trip.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7188 carries route-local auth middleware"
      }
    },
    "/v1/pipeline/tokenize": {
      "post": {
        "tags": [
          "pipeline"
        ],
        "operationId": "postV1PipelineTokenize",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20350 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipelines": {
      "get": {
        "tags": [
          "pipelines"
        ],
        "operationId": "getV1Pipelines",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "pipelines"
        ],
        "operationId": "postV1Pipelines",
        "summary": "── POST /v1/pipelines ─────────────────────────────────────────────────────",
        "description": "── POST /v1/pipelines ───────────────────────────────────────────────────── Body: { name: string, yaml: string }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipelines/{id}": {
      "get": {
        "tags": [
          "pipelines"
        ],
        "operationId": "getV1PipelinesId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "pipelines"
        ],
        "operationId": "deleteV1PipelinesId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipelines/{id}/kscore": {
      "get": {
        "tags": [
          "pipelines"
        ],
        "operationId": "getV1PipelinesIdKscore",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pipelines/{id}/run": {
      "post": {
        "tags": [
          "pipelines"
        ],
        "operationId": "postV1PipelinesIdRun",
        "summary": "── POST /v1/pipelines/:id/run ─────────────────────────────────────────────",
        "description": "── POST /v1/pipelines/:id/run ───────────────────────────────────────────── Body: { input: any }",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/pipeline-routes.js is registered from src/router.js:30011 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/plans": {
      "get": {
        "tags": [
          "plans"
        ],
        "operationId": "getV1Plans",
        "summary": "Plans - public compiler plan catalog. Historical aliases still",
        "description": "Plans - public compiler plan catalog. Historical aliases still canonicalize server-side. Enterprise is contact-sales unless a custom checkout link is supplied by the operator.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2759 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/playground/proxy/{slug}": {
      "post": {
        "tags": [
          "playground"
        ],
        "operationId": "postV1PlaygroundProxySlug",
        "summary": "POST /v1/playground/proxy/:slug - public playground stub. Echo so",
        "description": "POST /v1/playground/proxy/:slug - public playground stub. Echo so /playground/[slug] renders without RunPod bound. 20/IP/day.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1474 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/plugins": {
      "get": {
        "tags": [
          "plugins"
        ],
        "operationId": "getV1Plugins",
        "summary": "Tenant scope: plugins live under ~/.kolm/plugins (the caller's KOLM_HOME).",
        "description": "Tenant scope: plugins live under ~/.kolm/plugins (the caller's KOLM_HOME). The HTTP routes are auth-gated so a multi-tenant host doesn't accidentally surface another tenant's plugin directory; for self-hosted single-tenant installs the auth gate is no-op once KOLM_API_KEY is set.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28171 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "plugins"
        ],
        "operationId": "postV1Plugins",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28188 carries route-local auth middleware"
      }
    },
    "/v1/plugins/{name}": {
      "get": {
        "tags": [
          "plugins"
        ],
        "operationId": "getV1PluginsName",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "name",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "name path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28223 carries route-local auth middleware"
      }
    },
    "/v1/poisoning/bind-teacher": {
      "post": {
        "tags": [
          "poisoning"
        ],
        "operationId": "postV1PoisoningBindteacher",
        "summary": "Model Poisoning Anomaly Detection routes. Distinct-named handlers so",
        "description": "Model Poisoning Anomaly Detection routes. Distinct-named handlers so parallel wave agents on W760 + W762..W765 do not collide on the suffix. Builds on W808 capture-anomaly + W750-followup copyright-detector + the teacher-response HMAC primitive.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24239 carries route-local auth middleware"
      }
    },
    "/v1/poisoning/namespace-risk/{namespace}": {
      "get": {
        "tags": [
          "poisoning"
        ],
        "operationId": "getV1PoisoningNamespaceriskNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24282 carries route-local auth middleware"
      }
    },
    "/v1/poisoning/quarantine": {
      "post": {
        "tags": [
          "poisoning"
        ],
        "operationId": "postV1PoisoningQuarantine",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24300 carries route-local auth middleware"
      }
    },
    "/v1/poisoning/verify-binding": {
      "post": {
        "tags": [
          "poisoning"
        ],
        "operationId": "postV1PoisoningVerifybinding",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24267 carries route-local auth middleware"
      }
    },
    "/v1/pricing": {
      "get": {
        "tags": [
          "pricing"
        ],
        "operationId": "getV1Pricing",
        "summary": "Pricing - public price catalog in USD per billable unit (tokens, compile,",
        "description": "Pricing - public price catalog in USD per billable unit (tokens, compile, replay, bakeoff, redact). Read by /pricing and the SDK shapers.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1714 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/pricing/estimate": {
      "get": {
        "tags": [
          "pricing"
        ],
        "operationId": "getV1PricingEstimate",
        "summary": "Pricing estimator - public, secret-safe workload calculator backed by the",
        "description": "Pricing estimator - public, secret-safe workload calculator backed by the same compiler PLAN_CATALOG as /v1/plans and /v1/billing/tiers.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2748 is mounted before r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "pricing"
        ],
        "operationId": "postV1PricingEstimate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2752 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/events": {
      "get": {
        "tags": [
          "privacy"
        ],
        "operationId": "getV1PrivacyEvents",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19767 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/policy": {
      "get": {
        "tags": [
          "privacy"
        ],
        "operationId": "getV1PrivacyPolicy",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19723 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/policy/{class}": {
      "put": {
        "tags": [
          "privacy"
        ],
        "operationId": "putV1PrivacyPolicyClass",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "class",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "class path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19729 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/redaction-benchmark": {
      "get": {
        "tags": [
          "privacy"
        ],
        "operationId": "getV1PrivacyRedactionbenchmark",
        "summary": "Redaction benchmark - public, synthetic, secret-safe proof that the PHI/PII",
        "description": "Redaction benchmark - public, synthetic, secret-safe proof that the PHI/PII redactor detects expected classes, redacts raw values, and fails closed on malformed identifiers. This is benchmark evidence, not a live compliance certification claim.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2058 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/report": {
      "get": {
        "tags": [
          "privacy"
        ],
        "operationId": "getV1PrivacyReport",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19745 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/scan": {
      "post": {
        "tags": [
          "privacy"
        ],
        "operationId": "postV1PrivacyScan",
        "summary": "POST /v1/privacy/scan - pure detector pass over { text } body. Returns",
        "description": "POST /v1/privacy/scan - pure detector pass over { text } body. Returns findings array + sensitive boolean + class counts. No state change.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19698 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/privacy/test": {
      "post": {
        "tags": [
          "privacy"
        ],
        "operationId": "postV1PrivacyTest",
        "summary": "POST /v1/privacy/test - apply the current policy to body.text and",
        "description": "POST /v1/privacy/test - apply the current policy to body.text and return { redacted, findings, policy_actions }. May 403 if policy says block on a class present.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19709 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/procurement": {
      "get": {
        "tags": [
          "procurement"
        ],
        "operationId": "getV1Procurement",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11143 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/procurement/{framework}": {
      "get": {
        "tags": [
          "procurement"
        ],
        "operationId": "getV1ProcurementFramework",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "framework",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "framework path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11157 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/product/capabilities": {
      "get": {
        "tags": [
          "product"
        ],
        "operationId": "getV1ProductCapabilities",
        "summary": "Public product capability contract for the compiler-first site. This is a",
        "description": "Public product capability contract for the compiler-first site. This is a descriptive map, not an auth bypass: operational routes below keep their own auth/rate-limit gates.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3675 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/product/experience": {
      "get": {
        "tags": [
          "product"
        ],
        "operationId": "getV1ProductExperience",
        "summary": "Product-experience contract. Public and secret-safe: this is the same",
        "description": "Product-experience contract. Public and secret-safe: this is the same source of truth exposed by `kolm surfaces --json` and `kolm tui --views`. Frontend/account/docs can consume it to avoid drifting from CLI/TUI/API.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1719 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/product/graph": {
      "get": {
        "tags": [
          "product"
        ],
        "operationId": "getV1ProductGraph",
        "summary": "Product graph - public, secret-safe, generated from the route-surface,",
        "description": "Product graph - public, secret-safe, generated from the route-surface, journey, readiness, and experience contracts. This is the canonical machine-readable map for account UI, CLI/TUI parity, docs, and release audits.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1737 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/public/concepts": {
      "get": {
        "tags": [
          "public"
        ],
        "operationId": "getV1PublicConcepts",
        "summary": "Public registry browsing - no auth needed for visibility=public",
        "description": "Public registry browsing - no auth needed for visibility=public",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3091 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/public/concepts/{id}": {
      "get": {
        "tags": [
          "public"
        ],
        "operationId": "getV1PublicConceptsId",
        "summary": "Public concept detail - returns one public-visibility concept by id (no",
        "description": "Public concept detail - returns one public-visibility concept by id (no auth required). 404 when the concept is missing or visibility != 'public'. Pairs with /v1/public/run for unauth try-it traffic.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3114 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/public/featured": {
      "get": {
        "tags": [
          "public"
        ],
        "operationId": "getV1PublicFeatured",
        "summary": "Public featured - hand-curated list of the most useful public recipes for",
        "description": "Public featured - hand-curated list of the most useful public recipes for the home registry view (classify-issue-type, is-spam, extract-emails, classify-toxicity, etc.). Returns id, name, description, tags, head_version.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15191 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/public/run": {
      "post": {
        "tags": [
          "public"
        ],
        "operationId": "postV1PublicRun",
        "summary": "Public read-only run for any public concept (lets unauth visitors try the runtime)",
        "description": "Public read-only run for any public concept (lets unauth visitors try the runtime)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3121 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/public/submit": {
      "post": {
        "tags": [
          "public"
        ],
        "operationId": "postV1PublicSubmit",
        "summary": "Public registry submissions (Phase E - Day 120-180)",
        "description": "Public registry submissions (Phase E - Day 120-180)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15017 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/publish": {
      "post": {
        "tags": [
          "publish"
        ],
        "operationId": "postV1Publish",
        "summary": "Publish an edited generator (no synthesis required)",
        "description": "Publish an edited generator (no synthesis required)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14169 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/quality/predict": {
      "get": {
        "tags": [
          "quality"
        ],
        "operationId": "getV1QualityPredict",
        "summary": "Wire the six built-but-unrouted autopilot components plus the full",
        "description": "Wire the six built-but-unrouted autopilot components plus the full lifecycle tick into HTTP, mirroring the existing autopilot route pattern above (auth-gate -> dynamic import -> envelope -> status).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26850 carries route-local auth middleware"
      }
    },
    "/v1/quantization/oracle": {
      "get": {
        "tags": [
          "quantization"
        ],
        "operationId": "getV1QuantizationOracle",
        "summary": "Quantization oracle plan - ranks quantization methods for task, device,",
        "description": "Quantization oracle plan - ranks quantization methods for task, device, memory, runtime, calibration, quality, and privacy constraints. This is a planner only: promotion still requires quantize doctor, hashes, and holdout eval.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22788 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "quantization"
        ],
        "operationId": "postV1QuantizationOracle",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22827 carries route-local auth middleware"
      }
    },
    "/v1/quantization/oracle/catalog": {
      "get": {
        "tags": [
          "quantization"
        ],
        "operationId": "getV1QuantizationOracleCatalog",
        "summary": "Quantization oracle catalog - lists supported planner methods and whether",
        "description": "Quantization oracle catalog - lists supported planner methods and whether each method is worker-backed, external-toolchain, runtime-policy, or baseline.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22751 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/quantize": {
      "post": {
        "tags": [
          "quantize"
        ],
        "operationId": "postV1Quantize",
        "summary": "POST /v1/quantize - alias over /v1/compile that auto-fills format+quant",
        "description": "POST /v1/quantize - alias over /v1/compile that auto-fills format+quant from a single --target shortcut (gguf-q4km, exl2-4bpw, nvfp4, etc.) so the Account UI and SDKs can call one route instead of constructing a spec. Body: { model_id, target, job_id?, ... } → returns the created job.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28848 carries route-local auth middleware"
      }
    },
    "/v1/ready/deep": {
      "get": {
        "tags": [
          "ready"
        ],
        "operationId": "getV1ReadyDeep",
        "summary": "/v1/ready/deep - /v1-prefixed alias of the W824 /ready/deep route so the",
        "description": "/v1/ready/deep - /v1-prefixed alias of the W824 /ready/deep route so the TUI's k8s-readiness view stays on the /v1/* convention every other view uses. Forwards through the registered handler instead of duplicating logic so a single k8s-routes change updates both paths.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28544 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recall": {
      "post": {
        "tags": [
          "recall"
        ],
        "operationId": "postV1Recall",
        "summary": "Recall",
        "description": "Recall Hybrid query against the tenant's qmd-indexed corpus. Returns top-k chunks. The compile orchestrator calls the same surface internally; this is the public route for à la carte usage and for the kolm CLI's `kolm recall`.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9575 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recall/sources/{id}": {
      "get": {
        "tags": [
          "recall"
        ],
        "operationId": "getV1RecallSourcesId",
        "summary": "Single-source debug view. Confirms a sidecar exists and returns its",
        "description": "Single-source debug view. Confirms a sidecar exists and returns its frontmatter + first 4KB of body so a UI can preview what qmd indexed.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9639 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recall/status": {
      "get": {
        "tags": [
          "recall"
        ],
        "operationId": "getV1RecallStatus",
        "summary": "Health check for the recall substrate.",
        "description": "Health check for the recall substrate.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9626 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/receipts/list": {
      "get": {
        "tags": [
          "receipts"
        ],
        "operationId": "getV1ReceiptsList",
        "summary": "W-D wrapper-completion - GET /v1/receipts/list",
        "description": "W-D wrapper-completion - GET /v1/receipts/list Tenant-scoped receipt list with namespace + since + limit filters.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24742 carries route-local auth middleware"
      }
    },
    "/v1/receipts/stats": {
      "get": {
        "tags": [
          "receipts"
        ],
        "operationId": "getV1ReceiptsStats",
        "summary": "where frontier_baseline = sum(local-route tokens × frontier per-token rate)",
        "description": "where frontier_baseline = sum(local-route tokens × frontier per-token rate) (the counterfactual cost if every local-routed call had gone frontier instead). The baseline uses cost-estimator at frontier defaults (anthropic claude-haiku-4-5 input $0.0008/1k, output $0.004/1k) so the savings number is dimensioned in the same way as the receipts' cost_usd.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24793 carries route-local auth middleware"
      }
    },
    "/v1/receipts/verify": {
      "post": {
        "tags": [
          "receipts"
        ],
        "operationId": "postV1ReceiptsVerify",
        "summary": "This is NOT public-key cryptographic verification; that requires either",
        "description": "This is NOT public-key cryptographic verification; that requires either the shared tenant receipt secret (issuer/holder offline path) or the roadmap Ed25519 receipt mode. Accepts the legacy rs-1 receipt (hmac field), v0.1 receipt (kolm_version=\"0.1\", chain[], signature), and the {artifact_hash, signature} drive-by shape.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3162 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/receipts/{hash}/public": {
      "get": {
        "tags": [
          "receipts"
        ],
        "operationId": "getV1ReceiptsHashPublic",
        "summary": "Public receipt lookup - resolves a receipt, artifact, CID, or signature hash without auth.",
        "description": "Public receipt lookup - resolves a receipt, artifact, CID, or signature hash without auth. Tenant identity is hidden unless the tenant opted into public receipts.",
        "parameters": [
          {
            "name": "hash",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "hash path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3527 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1Recipes",
        "summary": "Recipe aliases",
        "description": "Recipe aliases Forward-looking branding: \"recipe\" terminology mirrors \"concept\" endpoints. Both names route to the same handlers - full backward compatibility preserved.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14544 carries route-local auth middleware"
      }
    },
    "/v1/recipes/templates": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesTemplates",
        "summary": "GET /v1/recipes/templates - picker for the \"Start with a template\" empty",
        "description": "All routes are public+stubbed by default (declared in PUBLIC_API in src/auth.js) so the no-code wizard works pre-auth. Rate-limited inside the handler via freeChatLimiter (20/IP/day for the budget-bearing ones). GET /v1/recipes/templates - picker for the \"Start with a template\" empty state. Curated catalog; no tenant scoping.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1325 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes/templates/{name}": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesTemplatesName",
        "summary": "Recipe template detail - returns one template plus its sample CSV reference.",
        "description": "Recipe template detail - returns one template plus its sample CSV reference.",
        "parameters": [
          {
            "name": "name",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "name path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9209 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes/{id}": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesId",
        "summary": "Recipe artifact aliases over the artifact/job surface.",
        "description": "Recipe artifact aliases over the artifact/job surface. POST /v1/compile returns a job_id of shape `job_*`. Conventional SDKs expect GET /v1/recipes/{id} to return the recipe (artifact) and POST /v1/recipes/{id}/run to invoke it. We alias the existing handlers so developers don't dead-end on 404s.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9220 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes/{id}/download": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesIdDownload",
        "summary": "Recipe artifact download alias. Streams the completed .kolm artifact for a job id.",
        "description": "Recipe artifact download alias. Streams the completed .kolm artifact for a job id.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9233 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes/{id}/label-corpus": {
      "post": {
        "tags": [
          "recipes"
        ],
        "operationId": "postV1RecipesIdLabelcorpus",
        "summary": "Inline labeler - synchronous up to 500 rows",
        "description": "Inline labeler - synchronous up to 500 rows",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14589 carries route-local auth middleware"
      }
    },
    "/v1/recipes/{id}/label-corpus/stream": {
      "post": {
        "tags": [
          "recipes"
        ],
        "operationId": "postV1RecipesIdLabelcorpusStream",
        "summary": "SSE stream variant: emits progress as rows are labeled.",
        "description": "SSE stream variant: emits progress as rows are labeled.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14632 carries route-local auth middleware"
      }
    },
    "/v1/recipes/{id}/lineage": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesIdLineage",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16625 carries route-local auth middleware"
      }
    },
    "/v1/recipes/{id}/run": {
      "post": {
        "tags": [
          "recipes"
        ],
        "operationId": "postV1RecipesIdRun",
        "summary": "SDK-conventional REST alias: POST /v1/recipes/:id/run mirrors /v1/run",
        "description": "SDK-conventional REST alias: POST /v1/recipes/:id/run mirrors /v1/run with concept_id set from the URL param. Body's version_id (if provided) still wins so callers can pin a specific revision.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14301 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/recipes/{id}/stats": {
      "get": {
        "tags": [
          "recipes"
        ],
        "operationId": "getV1RecipesIdStats",
        "summary": "Recipe stats alias for concept invocation counts, cache hit rate, and latency.",
        "description": "Recipe stats alias for concept invocation counts, cache hit rate, and latency.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14554 carries route-local auth middleware"
      }
    },
    "/v1/redact": {
      "post": {
        "tags": [
          "redact"
        ],
        "operationId": "postV1Redact",
        "summary": "Redact - applies the tenant privacy policy to a text input and returns",
        "description": "Redact - applies the tenant privacy policy to a text input and returns the redacted text plus class counters and a map_hash so callers can pin reinjection without exposing PHI. Body: { text (required), dry_run }. 413 when text exceeds _REDACT_TEXT_LIMIT; 409 on policy_block.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:12043 carries route-local auth middleware"
      }
    },
    "/v1/redteam/bakeoff": {
      "post": {
        "tags": [
          "redteam"
        ],
        "operationId": "postV1RedteamBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24385 carries route-local auth middleware"
      }
    },
    "/v1/redteam/classify": {
      "post": {
        "tags": [
          "redteam"
        ],
        "operationId": "postV1RedteamClassify",
        "summary": "* /sanitize with policy=fallback_to_teacher returns",
        "description": "* /sanitize with policy=fallback_to_teacher returns `no_fallback_handler_configured` - the hosted route has no teacher handler injected. * generate-corpus + bakeoff are confirm-gated because they emit attack-framing patterns + dispatch a multi-run loop respectively.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24342 carries route-local auth middleware"
      }
    },
    "/v1/redteam/generate-corpus": {
      "post": {
        "tags": [
          "redteam"
        ],
        "operationId": "postV1RedteamGeneratecorpus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24355 carries route-local auth middleware"
      }
    },
    "/v1/redteam/sanitize": {
      "post": {
        "tags": [
          "redteam"
        ],
        "operationId": "postV1RedteamSanitize",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24420 carries route-local auth middleware"
      }
    },
    "/v1/reg/classify-risk": {
      "post": {
        "tags": [
          "reg"
        ],
        "operationId": "postV1RegClassifyrisk",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/reg/data-governance": {
      "get": {
        "tags": [
          "reg"
        ],
        "operationId": "getV1RegDatagovernance",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/reg/eu-aiact-docs": {
      "get": {
        "tags": [
          "reg"
        ],
        "operationId": "getV1RegEuaiactdocs",
        "summary": "/v1/reg/eu-aiact-docs - GET counterpart to the W834 POST. POST runs the",
        "description": "/v1/reg/eu-aiact-docs - GET counterpart to the W834 POST. POST runs the Annex IV generator; GET reads the most-recent generated packet (or an empty envelope if none has been produced yet) so the TUI view does not require the operator to first POST to view state.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28668 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "reg"
        ],
        "operationId": "postV1RegEuaiactdocs",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/reg/grc-export": {
      "post": {
        "tags": [
          "reg"
        ],
        "operationId": "postV1RegGrcexport",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/reg/hil/threshold": {
      "get": {
        "tags": [
          "reg"
        ],
        "operationId": "getV1RegHilThreshold",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "reg"
        ],
        "operationId": "postV1RegHilThreshold",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/reg/model-card": {
      "post": {
        "tags": [
          "reg"
        ],
        "operationId": "postV1RegModelcard",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/reg-routes.js is registered from src/router.js:30040 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/region/gateways": {
      "get": {
        "tags": [
          "region"
        ],
        "operationId": "getV1RegionGateways",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27546 carries route-local auth middleware"
      }
    },
    "/v1/region/route": {
      "post": {
        "tags": [
          "region"
        ],
        "operationId": "postV1RegionRoute",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27568 carries route-local auth middleware"
      }
    },
    "/v1/region/status": {
      "get": {
        "tags": [
          "region"
        ],
        "operationId": "getV1RegionStatus",
        "summary": "Cross-ref: W769 (data residency) is the per-capture tag; W780 is the",
        "description": "Cross-ref: W769 (data residency) is the per-capture tag; W780 is the request-routing gateway. The two are joined inside getRegionForCapture so a tenant who configures a namespace default region in W769 also pins the W780 capture routing for that namespace.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27517 carries route-local auth middleware"
      }
    },
    "/v1/registry/export": {
      "get": {
        "tags": [
          "registry"
        ],
        "operationId": "getV1RegistryExport",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4056 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/registry/public": {
      "get": {
        "tags": [
          "registry"
        ],
        "operationId": "getV1RegistryPublic",
        "summary": "/v1/registry/public - RS-1 contract alias over public concepts. Non-paginated;",
        "description": "/v1/registry/public - RS-1 contract alias over public concepts. Non-paginated; returns up to 200 of the most recent public concepts. The richer export (with bundled source) lives at /v1/registry/export above.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9258 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/registry/search": {
      "get": {
        "tags": [
          "registry"
        ],
        "operationId": "getV1RegistrySearch",
        "summary": "/v1/registry/search - programmatic discovery. Filters: task (substring on",
        "description": "/v1/registry/search - programmatic discovery. Filters: task (substring on name/description/tags), min_k_score, max_size_mb, hardware tag, limit. Public concepts only. Used by IDE plugins, CI gates, and the registry UI's chip filters. Returns same shape as /v1/registry/public.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9317 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/registry/submit": {
      "post": {
        "tags": [
          "registry"
        ],
        "operationId": "postV1RegistrySubmit",
        "summary": "/v1/registry/submit - community recipe intake. Validates the shape, logs",
        "description": "/v1/registry/submit - community recipe intake. Validates the shape, logs the submission to data/registry-submissions.jsonl, and returns 202 with a submission_id. Verification (fetch+CID-check+K-score-replay) is a manual step today; see /registry/submit for the human flow. POST body schema is SubmitRequest in /openapi.json.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9283 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/registry/verified-publishers/evaluate": {
      "post": {
        "tags": [
          "registry"
        ],
        "operationId": "postV1RegistryVerifiedpublishersEvaluate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2423 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/registry/verified-publishers/policy": {
      "get": {
        "tags": [
          "registry"
        ],
        "operationId": "getV1RegistryVerifiedpublishersPolicy",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2419 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/replay": {
      "post": {
        "tags": [
          "replay"
        ],
        "operationId": "postV1Replay",
        "summary": "Replay - reruns a tenant's recent captures through the chosen artifact and",
        "description": "Replay - reruns a tenant's recent captures through the chosen artifact and returns per-row diffs (upstream output vs local output), K-score (Jaccard), success/failure counts, and cost delta. Body: { concept_id|version_id (one required), namespace, limit (1..200, default 25) }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16508 carries route-local auth middleware"
      }
    },
    "/v1/replay/preview": {
      "get": {
        "tags": [
          "replay"
        ],
        "operationId": "getV1ReplayPreview",
        "summary": "Replay preview - dry-run for /v1/replay. Resolves the artifact + namespace",
        "description": "Replay preview - dry-run for /v1/replay. Resolves the artifact + namespace + clamped limit (1..200) and reports how many captures would be replayed, without running them. Query: ?concept_id|version_id, ?namespace, ?limit.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16476 carries route-local auth middleware"
      }
    },
    "/v1/residency/capture-region/{capture_id}": {
      "get": {
        "tags": [
          "residency"
        ],
        "operationId": "getV1ResidencyCaptureregionCaptureid",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "capture_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "capture_id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25775 carries route-local auth middleware"
      }
    },
    "/v1/residency/configure-namespace": {
      "post": {
        "tags": [
          "residency"
        ],
        "operationId": "postV1ResidencyConfigurenamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25796 carries route-local auth middleware"
      }
    },
    "/v1/residency/regions": {
      "get": {
        "tags": [
          "residency"
        ],
        "operationId": "getV1ResidencyRegions",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25826 carries route-local auth middleware"
      }
    },
    "/v1/residency/tag-capture": {
      "post": {
        "tags": [
          "residency"
        ],
        "operationId": "postV1ResidencyTagcapture",
        "summary": "by country code - that's the perimeter geo-fence. W769 tags WHERE",
        "description": "by country code - that's the perimeter geo-fence. W769 tags WHERE DATA LIVES at capture time - that's the data-locality residency control. Both are required for a credible regulated-industry posture; they cover orthogonal threat models. The /compliance/data-residency landing surfaces the cross-reference explicitly.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25745 carries route-local auth middleware"
      }
    },
    "/v1/responses": {
      "post": {
        "tags": [
          "responses"
        ],
        "operationId": "postV1Responses",
        "summary": "OpenAI-compatible passthrough for the responses, embeddings, and",
        "description": "OpenAI-compatible passthrough for the responses, embeddings, and moderations endpoints. Each routes through __connectorProxy('openai', ...) so the upstream OpenAI API is reached with the configured key, and the request/response is captured into the tenant lake.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5512 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/route/chat/completions": {
      "post": {
        "tags": [
          "route"
        ],
        "operationId": "postV1RouteChatCompletions",
        "summary": "Response: original upstream JSON, additionally tagged with",
        "description": "Response: original upstream JSON, additionally tagged with { kolm_routing: { decision, segments, teacher_called, total_cost_micro_usd } }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5555 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/route/chat/completions/stream": {
      "post": {
        "tags": [
          "route"
        ],
        "operationId": "postV1RouteChatCompletionsStream",
        "summary": "__fixture_teacher_tokens: [{text}, ...]",
        "description": "__fixture_teacher_tokens: [{text}, ...] which makes the route end-to-end testable without standing up real student/teacher upstreams. Tests rely on this; production never sets these fields.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:5739 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/routing/summary": {
      "get": {
        "tags": [
          "routing"
        ],
        "operationId": "getV1RoutingSummary",
        "summary": "tenant. The /account/routing dashboard polls this endpoint.",
        "description": "tenant. The /account/routing dashboard polls this endpoint. Tenant fence: tenant_id is forced from req.tenant_record.id - never read from query string or body. namespace + since are optional filters.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23224 carries route-local auth middleware"
      }
    },
    "/v1/run": {
      "post": {
        "tags": [
          "run"
        ],
        "operationId": "postV1Run",
        "summary": "Runtime run - executes a concept_id or version_id against input and returns the output.",
        "description": "Runtime run - executes a concept_id or version_id against input and returns the output. Includes a signed receipt by default; pass receipt:false to skip receipt generation.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14296 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/adoption-packets": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimeAdoptionpackets",
        "summary": "Runtime adoption packets - local integration packets for model hubs,",
        "description": "Runtime adoption packets - local integration packets for model hubs, local runners, conversion tooling, and hardware partners.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3952 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/adoption-packets/template": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimeAdoptionpacketsTemplate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3992 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/adoption-packets/validate": {
      "post": {
        "tags": [
          "runtime"
        ],
        "operationId": "postV1RuntimeAdoptionpacketsValidate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4024 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/decide": {
      "post": {
        "tags": [
          "runtime"
        ],
        "operationId": "postV1RuntimeDecide",
        "summary": "Runtime decision - executes the policy ladder for one request and records the decision.",
        "description": "Runtime decision - executes the policy ladder for one request and records the decision.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22008 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/decisions": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimeDecisions",
        "summary": "Runtime decision history - returns the most recent recorded runtime decisions.",
        "description": "Runtime decision history - returns the most recent recorded runtime decisions.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22017 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/placement": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimePlacement",
        "summary": "/v1/runtime/placement - collection GET that emits the local placement",
        "description": "/v1/runtime/placement - collection GET that emits the local placement hierarchy snapshot. W826 ships detectMemoryHierarchy + placementDecision as pure functions; the TUI view needs a one-shot GET to read the hierarchy without staging an artifact size first.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28553 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/policy": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimePolicy",
        "summary": "Runtime policy read - returns the active runtime policy and available policy names.",
        "description": "Runtime policy read - returns the active runtime policy and available policy names.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21991 is mounted after r.use(authMiddleware) at line 6376"
      },
      "put": {
        "tags": [
          "runtime"
        ],
        "operationId": "putV1RuntimePolicy",
        "summary": "Runtime policy update - admin-only mutation of the active runtime routing policy.",
        "description": "Runtime policy update - admin-only mutation of the active runtime routing policy.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21999 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/runtime/replacement-stats": {
      "get": {
        "tags": [
          "runtime"
        ],
        "operationId": "getV1RuntimeReplacementstats",
        "summary": "Runtime replacement stats - summarizes replacement rate, savings, and spend over a window.",
        "description": "Runtime replacement stats - summarizes replacement rate, savings, and spend over a window.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22026 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sales/demo-request": {
      "post": {
        "tags": [
          "sales"
        ],
        "operationId": "postV1SalesDemorequest",
        "summary": "demoRequestLimiter above). Lighter-weight than /v1/lead/enterprise: a",
        "description": "demoRequestLimiter above). Lighter-weight than /v1/lead/enterprise: a buyer at the \"Book Demo\" CTA gives company + email + use_case + expected_volume_per_month + optional message. Stored under namespace 'sales/demo-requests' in the capture lake; mirror lives in salesDemoRequests for ops triage. Email best-effort to SALES_EMAIL.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14880 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/savings": {
      "get": {
        "tags": [
          "savings"
        ],
        "operationId": "getV1Savings",
        "summary": "/v1/savings - bare alias for the W835 summary endpoint so the TUI's",
        "description": "/v1/savings - bare alias for the W835 summary endpoint so the TUI's savings-tracker view has a stable collection-style URL. Forwards into the real /v1/savings/summary handler.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28683 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/savings/baseline": {
      "get": {
        "tags": [
          "savings"
        ],
        "operationId": "getV1SavingsBaseline",
        "summary": "GET /v1/savings/baseline - show whether a baseline window is active +",
        "description": "GET /v1/savings/baseline - show whether a baseline window is active + its start time + accumulated spend so far.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/savings-routes.js is registered from src/router.js:30000 after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "savings"
        ],
        "operationId": "postV1SavingsBaseline",
        "summary": "POST /v1/savings/baseline - start (or restart) a baseline window.",
        "description": "POST /v1/savings/baseline - start (or restart) a baseline window. Body: { namespace?, start_ts? }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/savings-routes.js is registered from src/router.js:30000 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/savings/displacement": {
      "get": {
        "tags": [
          "savings"
        ],
        "operationId": "getV1SavingsDisplacement",
        "summary": "frontier_provider (optional) - re-pricing target; falls back to receipt's own model",
        "description": "frontier_provider (optional) - re-pricing target; falls back to receipt's own model frontier_model (optional) - re-pricing target; falls back to receipt's own model artifact_id (optional) - for compile_cost + deployed_at lookup compile_cost_usd (optional) - explicit override deployed_at_ms (optional) - explicit override",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28703 carries route-local auth middleware"
      }
    },
    "/v1/savings/record": {
      "post": {
        "tags": [
          "savings"
        ],
        "operationId": "postV1SavingsRecord",
        "summary": "POST /v1/savings/record - record a teacher API call cost.",
        "description": "POST /v1/savings/record - record a teacher API call cost. Body: { namespace?, provider, model, input_tokens, output_tokens, ts? }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/savings-routes.js is registered from src/router.js:30000 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/savings/summary": {
      "get": {
        "tags": [
          "savings"
        ],
        "operationId": "getV1SavingsSummary",
        "summary": "GET /v1/savings/summary - full savings envelope.",
        "description": "GET /v1/savings/summary - full savings envelope. Query: ?period_days=30&namespace=default[&fee_rate=0.125]",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/savings-routes.js is registered from src/router.js:30000 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sbom/emit": {
      "post": {
        "tags": [
          "sbom"
        ],
        "operationId": "postV1SbomEmit",
        "summary": "confirm flag is honored on emit only; repo + verify are read-only.",
        "description": "confirm flag is honored on emit only; repo + verify are read-only. The route imports lazily so the SBOM module isn't paid for on cold daemons that never call it.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25233 carries route-local auth middleware"
      }
    },
    "/v1/sbom/repo": {
      "get": {
        "tags": [
          "sbom"
        ],
        "operationId": "getV1SbomRepo",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25255 carries route-local auth middleware"
      }
    },
    "/v1/sbom/verify": {
      "post": {
        "tags": [
          "sbom"
        ],
        "operationId": "postV1SbomVerify",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25268 carries route-local auth middleware"
      }
    },
    "/v1/scim/v2/Groups": {
      "get": {
        "tags": [
          "scim"
        ],
        "operationId": "getV1ScimV2Groups",
        "summary": "SCIM Groups CRUD (bound to kolm rbac roles)",
        "description": "SCIM Groups CRUD (bound to kolm rbac roles)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11685 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "scim"
        ],
        "operationId": "postV1ScimV2Groups",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11691 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/scim/v2/Groups/{id}": {
      "get": {
        "tags": [
          "scim"
        ],
        "operationId": "getV1ScimV2GroupsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11699 is mounted after r.use(authMiddleware) at line 6376"
      },
      "put": {
        "tags": [
          "scim"
        ],
        "operationId": "putV1ScimV2GroupsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11704 is mounted after r.use(authMiddleware) at line 6376"
      },
      "patch": {
        "tags": [
          "scim"
        ],
        "operationId": "patchV1ScimV2GroupsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11712 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "scim"
        ],
        "operationId": "deleteV1ScimV2GroupsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11720 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/scim/v2/ServiceProviderConfig": {
      "get": {
        "tags": [
          "scim"
        ],
        "operationId": "getV1ScimV2ServiceProviderConfig",
        "summary": "SCIM 2.0 Service Provider Configuration - RFC 7644 §5. IdPs read this",
        "description": "SCIM 2.0 Service Provider Configuration - RFC 7644 §5. IdPs read this to discover what SCIM operations the SP supports. Empty/false flags are honest signals to the IdP that bulk/patch/etag are not yet implemented.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11513 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/scim/v2/Users": {
      "get": {
        "tags": [
          "scim"
        ],
        "operationId": "getV1ScimV2Users",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11535 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "scim"
        ],
        "operationId": "postV1ScimV2Users",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11559 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/scim/v2/Users/{id}": {
      "get": {
        "tags": [
          "scim"
        ],
        "operationId": "getV1ScimV2UsersId",
        "summary": "SCIM Users per-resource lifecycle (RFC 7644 §3.5/§3.6)",
        "description": "SCIM Users per-resource lifecycle (RFC 7644 §3.5/§3.6)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11655 is mounted after r.use(authMiddleware) at line 6376"
      },
      "put": {
        "tags": [
          "scim"
        ],
        "operationId": "putV1ScimV2UsersId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11660 is mounted after r.use(authMiddleware) at line 6376"
      },
      "patch": {
        "tags": [
          "scim"
        ],
        "operationId": "patchV1ScimV2UsersId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11668 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "scim"
        ],
        "operationId": "deleteV1ScimV2UsersId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11676 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/search": {
      "post": {
        "tags": [
          "search"
        ],
        "operationId": "postV1Search",
        "summary": "Search - registry similarity search across the caller's tenant artifacts.",
        "description": "Search - registry similarity search across the caller's tenant artifacts. Returns top-k matches with embedding-distance scores. Body: { query (required), k=10, tag }. 500 errors are wrapped in {error, detail, matches:[]} so SDKs never see a raw 500 (W470 P0-2).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14246 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/seasonal": {
      "get": {
        "tags": [
          "seasonal"
        ],
        "operationId": "getV1Seasonal",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/seasonal/variant": {
      "post": {
        "tags": [
          "seasonal"
        ],
        "operationId": "postV1SeasonalVariant",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8118 carries route-local auth middleware"
      }
    },
    "/v1/seasonal/{namespace}": {
      "get": {
        "tags": [
          "seasonal"
        ],
        "operationId": "getV1SeasonalNamespace",
        "summary": "- bad params → 400 missing_field",
        "description": "- bad params → 400 missing_field - no matching variant for today's event/season → recommended:null + human-readable reason string (NEVER guess at the calendar). - hemisphere bias echoed in payload → callers can detect the N-bias.",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8038 carries route-local auth middleware"
      }
    },
    "/v1/security/audit-retention/status": {
      "get": {
        "tags": [
          "security"
        ],
        "operationId": "getV1SecurityAuditretentionStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25698 carries route-local auth middleware"
      }
    },
    "/v1/security/continuous-monitoring/snapshot": {
      "get": {
        "tags": [
          "security"
        ],
        "operationId": "getV1SecurityContinuousmonitoringSnapshot",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25709 carries route-local auth middleware"
      }
    },
    "/v1/security/iso27001/controls": {
      "get": {
        "tags": [
          "security"
        ],
        "operationId": "getV1SecurityIso27001Controls",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25640 carries route-local auth middleware"
      }
    },
    "/v1/security/soc2/checklist": {
      "get": {
        "tags": [
          "security"
        ],
        "operationId": "getV1SecuritySoc2Checklist",
        "summary": "(not kolm) supplies evidence (e.g. background-check policy).",
        "description": "(not kolm) supplies evidence (e.g. background-check policy). The retention + monitoring routes import lazily so the certification modules are not paid for on cold daemons that never call them.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25592 carries route-local auth middleware"
      }
    },
    "/v1/seeds/from-nl": {
      "post": {
        "tags": [
          "seeds"
        ],
        "operationId": "postV1SeedsFromnl",
        "summary": "POST /v1/seeds/from-nl - expand a seed into variants via the configured",
        "description": "POST /v1/seeds/from-nl - expand a seed into variants via the configured LLM, or deterministic local fallback when no LLM backend is configured.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4418 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/seeds/from-nl/health": {
      "get": {
        "tags": [
          "seeds"
        ],
        "operationId": "getV1SeedsFromnlHealth",
        "summary": "GET /v1/seeds/from-nl/health. Lets the UI hide the NL-seeds",
        "description": "GET /v1/seeds/from-nl/health. Lets the UI hide the NL-seeds button when no LLM backend is configured. Stable, no auth.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:4356 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/serve": {
      "post": {
        "tags": [
          "serve"
        ],
        "operationId": "postV1Serve",
        "summary": "POST /v1/serve - emit a deployment manifest (docker run / k8s yaml) for",
        "description": "POST /v1/serve - emit a deployment manifest (docker run / k8s yaml) for a .kolm artifact and runtime target. Body: { artifact, runtime, port?, docker?, k8s? } → { manifest, runtime, port }",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29031 carries route-local auth middleware"
      }
    },
    "/v1/serve/pods": {
      "get": {
        "tags": [
          "serve"
        ],
        "operationId": "getV1ServePods",
        "summary": "GET /v1/serve/pods - live serving pods for the tenant (which artifacts are",
        "description": "GET /v1/serve/pods - live serving pods for the tenant (which artifacts are currently served). No live-pod tracker is wired yet, so this returns an empty set; the /account/models UI uses it to badge \"serving\" state and degrades gracefully (it already .catch()es to {pods:[]}). Registering the route stops the prod 404 the models page hit.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:29023 carries route-local auth middleware"
      }
    },
    "/v1/session/login": {
      "post": {
        "tags": [
          "session"
        ],
        "operationId": "postV1SessionLogin",
        "summary": "POST /v1/session/login sets an httpOnly `kolm_session` cookie. Browsers can",
        "description": "Session cookie (S7) POST /v1/session/login sets an httpOnly `kolm_session` cookie. Browsers can then call authenticated API routes without exposing the key to JavaScript. The legacy localStorage path still works, but new pages should use this route and rely on the cookie.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3063 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/session/logout": {
      "post": {
        "tags": [
          "session"
        ],
        "operationId": "postV1SessionLogout",
        "summary": "Session logout - clears the kolm_session cookie set by /v1/session/login.",
        "description": "Session logout - clears the kolm_session cookie set by /v1/session/login. Returns {ok:true}; safe to call repeatedly (no-op when no cookie present).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3085 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/signin": {
      "post": {
        "tags": [
          "signin"
        ],
        "operationId": "postV1Signin",
        "summary": "/v1/signin and /v1/signout mirror /v1/session/login and /v1/session/logout",
        "description": "Signin / Signout aliases (RS-1 contract) /v1/signin and /v1/signout mirror /v1/session/login and /v1/session/logout for the homepage contract. POST {api_key} returns the same shape and sets the same kolm_session cookie. /v1/signout returns 204 to be friendly to CLI tools that ignore body.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3020 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/signout": {
      "post": {
        "tags": [
          "signout"
        ],
        "operationId": "postV1Signout",
        "summary": "/v1/session/logout; kept so older clients that POST /v1/signout still work.",
        "description": "Signout - clears the kolm_session cookie and returns 204. Legacy alias for /v1/session/logout; kept so older clients that POST /v1/signout still work.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3053 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/signup": {
      "post": {
        "tags": [
          "signup"
        ],
        "operationId": "postV1Signup",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2883 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sigstore/attest": {
      "post": {
        "tags": [
          "sigstore"
        ],
        "operationId": "postV1SigstoreAttest",
        "summary": "Sigstore attest - forwards a caller-signed receipt bundle to the",
        "description": "Sigstore attest - forwards a caller-signed receipt bundle to the configured Rekor instance and returns the merged bundle. The caller MUST pre-sign with their own key (server has no private key); receipt must already carry signature_ed25519 + dry-run signature_sigstore (Wave 150+).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3455 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sigstore/entry/{logIndex}": {
      "get": {
        "tags": [
          "sigstore"
        ],
        "operationId": "getV1SigstoreEntryLogIndex",
        "summary": "Sigstore entry fetch - forwards to the configured Rekor instance and",
        "description": "Sigstore entry fetch - forwards to the configured Rekor instance and returns the raw entry by logIndex. Public (Rekor itself is public). 503 when no KOLM_SIGSTORE_REKOR_URL is configured; 404 when Rekor 404s.",
        "parameters": [
          {
            "name": "logIndex",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "logIndex path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3434 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sigstore/health": {
      "get": {
        "tags": [
          "sigstore"
        ],
        "operationId": "getV1SigstoreHealth",
        "summary": "has a Rekor URL configured + whether the",
        "description": "has a Rekor URL configured + whether the integration is enabled. GET /v1/sigstore/entry/:logIndex forward to Rekor and return the raw entry. Public - Rekor is public.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3424 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sim": {
      "get": {
        "tags": [
          "sim"
        ],
        "operationId": "getV1Sim",
        "summary": "Sim list - returns saved workflow simulations plus the supported simulator type catalog.",
        "description": "Sim list - returns saved workflow simulations plus the supported simulator type catalog.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21942 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sim/run": {
      "post": {
        "tags": [
          "sim"
        ],
        "operationId": "postV1SimRun",
        "summary": "Sim run - creates a workflow simulation and emits synthetic events into its saved run record.",
        "description": "Sim run - creates a workflow simulation and emits synthetic events into its saved run record.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21927 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sim/{id}": {
      "get": {
        "tags": [
          "sim"
        ],
        "operationId": "getV1SimId",
        "summary": "Sim detail - returns one saved workflow simulation record by simulation id.",
        "description": "Sim detail - returns one saved workflow simulation record by simulation id.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21950 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/simulations": {
      "get": {
        "tags": [
          "simulations"
        ],
        "operationId": "getV1Simulations",
        "summary": "/v1/simulations - list + run alias for /v1/sim + /v1/sim/run. Plus a",
        "description": "/v1/simulations - list + run alias for /v1/sim + /v1/sim/run. Plus a promote endpoint that mirrors simulations.html's \"promote to holdout\" button (delegates to simulation.generateDatasetFromSim).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23508 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "simulations"
        ],
        "operationId": "postV1Simulations",
        "summary": "Simulations create+run - REST alias of /v1/sim/run that creates a",
        "description": "Simulations create+run - REST alias of /v1/sim/run that creates a workflow simulation and immediately runs it. Body: { workflow_id, type, n, personas, opts, toLake (default true) }. Returns sim_id + emitted events.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23517 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/simulations/{id}": {
      "get": {
        "tags": [
          "simulations"
        ],
        "operationId": "getV1SimulationsId",
        "summary": "Simulation detail - REST alias of /v1/sim/:id. Returns one saved workflow",
        "description": "Simulation detail - REST alias of /v1/sim/:id. Returns one saved workflow simulation record. 404 when the id is unknown.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23532 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/simulations/{id}/promote": {
      "post": {
        "tags": [
          "simulations"
        ],
        "operationId": "postV1SimulationsIdPromote",
        "summary": "Simulation promote - mirrors the \"promote to holdout\" button on",
        "description": "Simulation promote - mirrors the \"promote to holdout\" button on simulations.html. Calls simulation.generateDatasetFromSim to convert a sim into a dataset (synthetic rows + optional holdout). Body: { name, holdoutFromSim (default true) }. Returns the dataset id on success.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23543 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sla/dashboard": {
      "get": {
        "tags": [
          "sla"
        ],
        "operationId": "getV1SlaDashboard",
        "summary": "SLA dashboard - bundle of every surface rollup for /account/sla.html.",
        "description": "SLA dashboard - bundle of every surface rollup for /account/sla.html.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20314 carries route-local auth middleware"
      }
    },
    "/v1/sla/rollup": {
      "get": {
        "tags": [
          "sla"
        ],
        "operationId": "getV1SlaRollup",
        "summary": "SLA rollup - returns p50/p95/p99 latency + uptime_pct for one surface.",
        "description": "SLA rollup - returns p50/p95/p99 latency + uptime_pct for one surface.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20295 carries route-local auth middleware"
      }
    },
    "/v1/sla/series": {
      "get": {
        "tags": [
          "sla"
        ],
        "operationId": "getV1SlaSeries",
        "summary": "copy (\"Numbers come from the /v1/sla/series route\") binds straight to",
        "description": "SLA series - alias of /v1/sla/rollup so the placeholder /account/sla.html copy (\"Numbers come from the /v1/sla/series route\") binds straight to the persistent rollup once frontend wires.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20327 carries route-local auth middleware"
      }
    },
    "/v1/sneakernet/pack": {
      "post": {
        "tags": [
          "sneakernet"
        ],
        "operationId": "postV1SneakernetPack",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27660 carries route-local auth middleware"
      }
    },
    "/v1/sneakernet/unpack": {
      "post": {
        "tags": [
          "sneakernet"
        ],
        "operationId": "postV1SneakernetUnpack",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27684 carries route-local auth middleware"
      }
    },
    "/v1/spec": {
      "get": {
        "tags": [
          "spec"
        ],
        "operationId": "getV1Spec",
        "summary": "Public RS-1 spec document - open standard, no auth required.",
        "description": "Public RS-1 spec document - open standard, no auth required.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3789 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/spec-decode": {
      "post": {
        "tags": [
          "spec-decode"
        ],
        "operationId": "postV1Specdecode",
        "summary": "Train a speculative-decoding draft head (eagle/eagle2/eagle3/medusa)",
        "description": "Train a speculative-decoding draft head (eagle/eagle2/eagle3/medusa) via the tenant-installed trainer plug-in. Auth-gated. Body: { pairs_path, base_path, draft_kind, out_dir, namespace }. Returns trainer envelope.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16410 carries route-local auth middleware"
      }
    },
    "/v1/spec-decode/doctor": {
      "get": {
        "tags": [
          "spec-decode"
        ],
        "operationId": "getV1SpecdecodeDoctor",
        "summary": "Speculative decoding draft-head trainer doctor (EAGLE-2/3, Medusa).",
        "description": "Speculative decoding draft-head trainer doctor (EAGLE-2/3, Medusa). Reports whether $KOLM_SPECDECODE_TRAINER is resolvable; install_hint when not.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:16399 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/spec/governance-packet": {
      "get": {
        "tags": [
          "spec"
        ],
        "operationId": "getV1SpecGovernancepacket",
        "summary": "A device with this bundle can run every public recipe locally, offline,",
        "description": "A device with this bundle can run every public recipe locally, offline, forever, for free. Returns a portable JSON envelope of all public recipes with their executable source. This is the on-device runtime payload. Format governance packet - local evidence for neutral .kolm stewardship. External acceptance remains explicitly gated until a public venue accepts it.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3846 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/spec/governance-packet/template": {
      "get": {
        "tags": [
          "spec"
        ],
        "operationId": "getV1SpecGovernancepacketTemplate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3886 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/spec/governance-packet/validate": {
      "post": {
        "tags": [
          "spec"
        ],
        "operationId": "postV1SpecGovernancepacketValidate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3918 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists": {
      "get": {
        "tags": [
          "specialists"
        ],
        "operationId": "getV1Specialists",
        "summary": "Specialists list - returns tenant-visible specialist jobs without inline corpus rows.",
        "description": "Specialists list - returns tenant-visible specialist jobs without inline corpus rows.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14976 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists/auto-distill": {
      "post": {
        "tags": [
          "specialists"
        ],
        "operationId": "postV1SpecialistsAutodistill",
        "summary": "Specialist auto-distill - turns 1,000+ kept namespace captures into a distill job.",
        "description": "Specialist auto-distill - turns 1,000+ kept namespace captures into a distill job. Returns a job id and poll URL from the trainer bridge or the local distill worker.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18025 carries route-local auth middleware"
      }
    },
    "/v1/specialists/train": {
      "post": {
        "tags": [
          "specialists"
        ],
        "operationId": "postV1SpecialistsTrain",
        "summary": "Specialist train - queues tenant specialist training from an existing recipe and optional corpus.",
        "description": "Specialist train - queues tenant specialist training from an existing recipe and optional corpus.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14955 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists/waitlist": {
      "post": {
        "tags": [
          "specialists"
        ],
        "operationId": "postV1SpecialistsWaitlist",
        "summary": "Specialist waitlist - captures guided-training interest from teams before onboarding.",
        "description": "Specialist waitlist - captures guided-training interest from teams before onboarding.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14707 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists/{id}": {
      "get": {
        "tags": [
          "specialists"
        ],
        "operationId": "getV1SpecialistsId",
        "summary": "Specialist detail - returns one accessible specialist record for the tenant or admin.",
        "description": "Specialist detail - returns one accessible specialist record for the tenant or admin.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14982 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists/{id}/run": {
      "post": {
        "tags": [
          "specialists"
        ],
        "operationId": "postV1SpecialistsIdRun",
        "summary": "Specialist run - executes the specialist preview through its source recipe fallback.",
        "description": "Specialist run - executes the specialist preview through its source recipe fallback.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:15001 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/specialists/{id}/weights": {
      "get": {
        "tags": [
          "specialists"
        ],
        "operationId": "getV1SpecialistsIdWeights",
        "summary": "Specialist weights - returns completed weight metadata or 503 while training is pending.",
        "description": "Specialist weights - returns completed weight metadata or 503 while training is pending.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14990 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/speculative/acceptance": {
      "get": {
        "tags": [
          "speculative"
        ],
        "operationId": "getV1SpeculativeAcceptance",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27464 carries route-local auth middleware"
      }
    },
    "/v1/speculative/bench": {
      "post": {
        "tags": [
          "speculative"
        ],
        "operationId": "postV1SpeculativeBench",
        "summary": "Acceptance log query (workflow_id='speculative_teacher:log')",
        "description": "Acceptance log query (workflow_id='speculative_teacher:log') Auth-gated via req.tenant_record. Tenant fence forced from session, never from request body. Distinct prefix /v1/speculative/* so parallel agents on W811/W812/W813/W815 cannot collide on these route paths.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27352 carries route-local auth middleware"
      }
    },
    "/v1/speculative/bench/{id}": {
      "get": {
        "tags": [
          "speculative"
        ],
        "operationId": "getV1SpeculativeBenchId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27401 carries route-local auth middleware"
      }
    },
    "/v1/sso/status": {
      "get": {
        "tags": [
          "sso"
        ],
        "operationId": "getV1SsoStatus",
        "summary": "W869+ Persona D admin status aggregators.",
        "description": "W869+ Persona D admin status aggregators. Thin read-only composers for /account/enterprise. Each one stitches data from individual surfaces (sso/status, byoc/deployments, compliance/*, audit) into the shape the admin dashboard expects. Honest when state is missing: empty fields, no 404s.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10985 carries route-local auth middleware"
      }
    },
    "/v1/staleness": {
      "get": {
        "tags": [
          "staleness"
        ],
        "operationId": "getV1Staleness",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/staleness/apply-ttl": {
      "post": {
        "tags": [
          "staleness"
        ],
        "operationId": "postV1StalenessApplyttl",
        "summary": "Role gate: req.is_admin OR req.local_daemon OR req.tenant_record.kind === 'human'",
        "description": "Role gate: req.is_admin OR req.local_daemon OR req.tenant_record.kind === 'human' (the tenant_record.kind sentinel - human tenants are workspace owners by construction in src/auth.js; anon/api_only/etc. are not). We do NOT reuse teams.requireRole here because the staleness scope is per-namespace inside a tenant, not per-team. Adding team scoping is a follow-up (W746+1).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7731 carries route-local auth middleware"
      }
    },
    "/v1/staleness/{namespace}": {
      "get": {
        "tags": [
          "staleness"
        ],
        "operationId": "getV1StalenessNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7691 carries route-local auth middleware"
      }
    },
    "/v1/stat-sig/gate": {
      "get": {
        "tags": [
          "stat-sig"
        ],
        "operationId": "getV1StatsigGate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27926 carries route-local auth middleware"
      }
    },
    "/v1/stat-sig/test": {
      "post": {
        "tags": [
          "stat-sig"
        ],
        "operationId": "postV1StatsigTest",
        "summary": "GET /v1/stat-sig/gate?ab_test_id=X&alpha=Y&min_n=Z&min_effect_size=W",
        "description": "GET /v1/stat-sig/gate?ab_test_id=X&alpha=Y&min_n=Z&min_effect_size=W Returns: {ok, decision:'pass'|'fail'|'insufficient', reasons:[], welch:{...}, version} Auth-gated. Pure-math welchT does not need tenant fence; gate() reads via ab-router which forces tenant from session.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27904 carries route-local auth middleware"
      }
    },
    "/v1/status": {
      "get": {
        "tags": [
          "status"
        ],
        "operationId": "getV1Status",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:10233 carries route-local auth middleware"
      }
    },
    "/v1/status/receipts": {
      "get": {
        "tags": [
          "status"
        ],
        "operationId": "getV1StatusReceipts",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/website-status-routes.js is registered from src/router.js:6409 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/status/subscribe": {
      "post": {
        "tags": [
          "status"
        ],
        "operationId": "postV1StatusSubscribe",
        "summary": "Status subscribe - email opt-in from the /status page. Validates the address,",
        "description": "Status subscribe - email opt-in from the /status page. Validates the address, dedupes by email (returns duplicate:true on re-subscribe), inserts into status_subscribers with source:'status_page', and is rate-limited.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:1641 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/status/summary": {
      "get": {
        "tags": [
          "status"
        ],
        "operationId": "getV1StatusSummary",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/website-status-routes.js is registered from src/router.js:6409 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/storage/config": {
      "get": {
        "tags": [
          "storage"
        ],
        "operationId": "getV1StorageConfig",
        "summary": "Storage config - returns the event-store driver info + media blob base",
        "description": "Storage config - returns the event-store driver info + media blob base directory + supported media kinds. The config itself is env-var driven (KOLM_DATA_DIR, KOLM_MEDIA_DIR, KOLM_EVENT_STORE_DRIVER).",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23344 is mounted after r.use(authMiddleware) at line 6376"
      },
      "put": {
        "tags": [
          "storage"
        ],
        "operationId": "putV1StorageConfig",
        "summary": "Storage config update - admin-only echo endpoint that does NOT mutate",
        "description": "Storage config update - admin-only echo endpoint that does NOT mutate runtime config (storage settings live in env vars and require a daemon restart). Returns {ok, proposed, note, env_vars} so the dashboard can show what would change and which vars to set.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23360 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/storage/object-readiness": {
      "get": {
        "tags": [
          "storage"
        ],
        "operationId": "getV1StorageObjectreadiness",
        "summary": "Artifact object-store readiness for account UI and CI. This is split out",
        "description": "Artifact object-store readiness for account UI and CI. This is split out from generic cloud readiness because large .kolm/model bundles require a real object path (R2 S3, AWS S3, generic S3, Supabase S3, or local disk), not only provider env detection.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2379 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/storage/purge": {
      "post": {
        "tags": [
          "storage"
        ],
        "operationId": "postV1StoragePurge",
        "summary": "Storage purge - destructive admin-only event-store purge. Requires",
        "description": "Storage purge - destructive admin-only event-store purge. Requires {confirm:true} in the body; supports {before} timestamp + {namespace} filters. Returns purge counts. Used for lake-retention cleanups.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23377 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/streaming/capabilities": {
      "get": {
        "tags": [
          "streaming"
        ],
        "operationId": "getV1StreamingCapabilities",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2435 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/streaming/normalize": {
      "post": {
        "tags": [
          "streaming"
        ],
        "operationId": "postV1StreamingNormalize",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:2439 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/stripe/webhook": {
      "post": {
        "tags": [
          "stripe"
        ],
        "operationId": "postV1StripeWebhook",
        "summary": "(downgrade to free). Idempotent: each Stripe event id is recorded once.",
        "description": "(downgrade to free). Idempotent: each Stripe event id is recorded once. The route is mounted with `express.raw({ type: '*/*' })` ahead of `express.json()` in server.js - req.body must be a Buffer for signature verification to work (canonical JSON reordering breaks the HMAC).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13082 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/audit": {
      "get": {
        "tags": [
          "sync"
        ],
        "operationId": "getV1SyncAudit",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19831 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/inbox": {
      "post": {
        "tags": [
          "sync"
        ],
        "operationId": "postV1SyncInbox",
        "summary": "{events, namespace, source_device_id, state} envelope as the contract.",
        "description": "{events, namespace, source_device_id, state} envelope as the contract. The receiver writes incoming events into the local event store. WC14 - token-in-body endpoint: a fuzzer can spam any envelope shape. The syncInboxBackoff middleware locks an IP out for 15 min after 5 malformed attempts (a real peer always sends a typed envelope; bots typically don't).",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19846 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/pull": {
      "post": {
        "tags": [
          "sync"
        ],
        "operationId": "postV1SyncPull",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19817 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/push": {
      "post": {
        "tags": [
          "sync"
        ],
        "operationId": "postV1SyncPush",
        "summary": "POST /v1/sync/push - push events to the configured cloud_base. Returns",
        "description": "POST /v1/sync/push - push events to the configured cloud_base. Returns {pushed, skipped, blocked, audit_id, reasons}.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19802 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/state": {
      "put": {
        "tags": [
          "sync"
        ],
        "operationId": "putV1SyncState",
        "summary": "PUT /v1/sync/state - set sync state. Admin-only because it changes",
        "description": "PUT /v1/sync/state - set sync state. Admin-only because it changes what data leaves the device.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19788 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/sync/status": {
      "get": {
        "tags": [
          "sync"
        ],
        "operationId": "getV1SyncStatus",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19779 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/synthesize": {
      "post": {
        "tags": [
          "synthesize"
        ],
        "operationId": "postV1Synthesize",
        "summary": "Layer 1: Synthesis",
        "description": "Layer 1: Synthesis",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13718 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/synthesize/batch": {
      "post": {
        "tags": [
          "synthesize"
        ],
        "operationId": "postV1SynthesizeBatch",
        "summary": "Batch synthesis: multiple concepts in one round-trip. Sequential, since",
        "description": "Batch synthesis: multiple concepts in one round-trip. Sequential, since synthesis is CPU-bound - but billed once via shared overhead.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13814 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/synthesize/stream": {
      "post": {
        "tags": [
          "synthesize"
        ],
        "operationId": "postV1SynthesizeStream",
        "summary": "SSE: live synthesis events (candidate generated, verified, accepted, etc.)",
        "description": "SSE: live synthesis events (candidate generated, verified, accepted, etc.)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13761 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/synthetic/commit": {
      "post": {
        "tags": [
          "synthetic"
        ],
        "operationId": "postV1SyntheticCommit",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21226 carries route-local auth middleware"
      }
    },
    "/v1/synthetic/coverage": {
      "get": {
        "tags": [
          "synthetic"
        ],
        "operationId": "getV1SyntheticCoverage",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/synthetic/coverage/{namespace}": {
      "get": {
        "tags": [
          "synthetic"
        ],
        "operationId": "getV1SyntheticCoverageNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21068 carries route-local auth middleware"
      }
    },
    "/v1/synthetic/gaps": {
      "get": {
        "tags": [
          "synthetic"
        ],
        "operationId": "getV1SyntheticGaps",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/synthetic/gaps/{namespace}": {
      "get": {
        "tags": [
          "synthetic"
        ],
        "operationId": "getV1SyntheticGapsNamespace",
        "summary": "supply ANTHROPIC_API_KEY or KOLM_TEACHER_API_KEY in env. Missing key →",
        "description": "supply ANTHROPIC_API_KEY or KOLM_TEACHER_API_KEY in env. Missing key → 503 teacher_not_wired envelope. * Spend protection: POST /v1/synthetic/generate refuses to actually call the teacher unless body.confirm === true. Without confirm we return 200 + {ok:false, error:'synthetic_costs_money', estimated_cost_usd}.",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21017 carries route-local auth middleware"
      }
    },
    "/v1/synthetic/generate": {
      "post": {
        "tags": [
          "synthetic"
        ],
        "operationId": "postV1SyntheticGenerate",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21114 carries route-local auth middleware"
      }
    },
    "/v1/target-profiles": {
      "get": {
        "tags": [
          "target-profiles"
        ],
        "operationId": "getV1Targetprofiles",
        "summary": "(jetson-orin-nano, iphone-15-pro, rtx-5090, ...) to the recommended",
        "description": "(jetson-orin-nano, iphone-15-pro, rtx-5090, ...) to the recommended (--target, runtime, context, est tok/s) combo. The data is the same as `kolm compile --list-target-profiles --json` and ships with the CLI; the HTTP surface is here so the docs site and Studio compile wizard can read it without shelling out.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3634 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/target-profiles/{name}": {
      "get": {
        "tags": [
          "target-profiles"
        ],
        "operationId": "getV1TargetprofilesName",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "name",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "name path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [],
        "x-kolm-auth": "public",
        "x-kolm-auth-proof": "src/router.js:3642 is mounted before r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teacher-versions": {
      "get": {
        "tags": [
          "teacher-versions"
        ],
        "operationId": "getV1Teacherversions",
        "summary": ":namespace path param. The dashboard pages call these endpoints without a",
        "description": ":namespace path param. The dashboard pages call these endpoints without a selected namespace before the user picks one; previously they 404'd. We forward to the existing :namespace handler with namespace='default' so the account UI<->server parity test (W409f #4) passes and the page renders an empty-state from a real envelope instead of a 404.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28518 carries route-local auth middleware"
      }
    },
    "/v1/teacher-versions/{namespace}": {
      "get": {
        "tags": [
          "teacher-versions"
        ],
        "operationId": "getV1TeacherversionsNamespace",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "namespace",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "namespace path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7804 carries route-local auth middleware"
      }
    },
    "/v1/teacher/chat": {
      "post": {
        "tags": [
          "teacher"
        ],
        "operationId": "postV1TeacherChat",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7871 carries route-local auth middleware"
      }
    },
    "/v1/teacher/chat/health": {
      "get": {
        "tags": [
          "teacher"
        ],
        "operationId": "getV1TeacherChatHealth",
        "summary": "GET /v1/teacher/chat/health - which vendors have keys configured on this",
        "description": "GET /v1/teacher/chat/health - which vendors have keys configured on this kolm instance. No auth required (publishes only booleans). Lets a local distill worker pick which vendor to route through the proxy without burning a real call to test.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:8008 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/accept-invite": {
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamAcceptinvite",
        "summary": "POST /v1/team/accept-invite - PUBLIC. The invite_token IS the credential.",
        "description": "POST /v1/team/accept-invite - PUBLIC. The invite_token IS the credential. WC14 - token-in-body endpoint: teamAcceptBackoff locks an IP out for 15 min after 5 failed token attempts to bound brute-force search of the invite_token space.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19910 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/approvals": {
      "get": {
        "tags": [
          "team"
        ],
        "operationId": "getV1TeamApprovals",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19954 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamApprovals",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19969 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/approvals/{id}/decide": {
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamApprovalsIdDecide",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19982 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/invite": {
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamInvite",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19887 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/invites": {
      "get": {
        "tags": [
          "team"
        ],
        "operationId": "getV1TeamInvites",
        "summary": "/v1/team/invites - team.html invite list / create endpoint.",
        "description": "/v1/team/invites - team.html invite list / create endpoint. GET returns the calling tenant's outstanding invites; POST creates one.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9045 carries route-local auth middleware"
      },
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamInvites",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9056 carries route-local auth middleware"
      }
    },
    "/v1/team/member/{id}": {
      "delete": {
        "tags": [
          "team"
        ],
        "operationId": "deleteV1TeamMemberId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19941 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/members": {
      "get": {
        "tags": [
          "team"
        ],
        "operationId": "getV1TeamMembers",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19881 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/namespaces": {
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamNamespaces",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20003 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/role": {
      "put": {
        "tags": [
          "team"
        ],
        "operationId": "putV1TeamRole",
        "summary": "(source-indexed route; contract generated from route source)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19927 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/team/sync": {
      "post": {
        "tags": [
          "team"
        ],
        "operationId": "postV1TeamSync",
        "summary": "structured body; soft cap sets x-kolm-quota-warning.",
        "description": "structured body; soft cap sets x-kolm-quota-warning. Auth flows through the standard middleware (mounted later as r.use(authMiddleware) at the section below). The tenant_record is already attached when this handler runs.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:20117 carries route-local auth middleware"
      }
    },
    "/v1/team/workspace": {
      "get": {
        "tags": [
          "team"
        ],
        "operationId": "getV1TeamWorkspace",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19875 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1Teams",
        "summary": "Team list - returns active teams for the signed-in tenant with their role.",
        "description": "Team list - returns active teams for the signed-in tenant with their role.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18205 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1Teams",
        "summary": "Team creation - creates a paid-plan workspace and makes the caller the owner.",
        "description": "Team creation - creates a paid-plan workspace and makes the caller the owner.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18192 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/invites/{invite_id}": {
      "delete": {
        "tags": [
          "teams"
        ],
        "operationId": "deleteV1TeamsInvitesInviteid",
        "summary": "Team invite revoke - admin-only deletion of an outstanding invite by invite id.",
        "description": "Team invite revoke - admin-only deletion of an outstanding invite by invite id.",
        "parameters": [
          {
            "name": "invite_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "invite_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18549 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/invites/{token}": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsInvitesToken",
        "summary": "Team invite preview - public token lookup with invite role, expiry, and team summary.",
        "description": "Team invite preview - public token lookup with invite role, expiry, and team summary.",
        "parameters": [
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "token path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18529 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/invites/{token}/accept": {
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsInvitesTokenAccept",
        "summary": "Team invite acceptance - signed-in tenant accepts a valid invite for their email.",
        "description": "Team invite acceptance - signed-in tenant accepts a valid invite for their email.",
        "parameters": [
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "token path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18540 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsIdOrSlug",
        "summary": "Team detail - returns team, member, and pending-invite data for members or admins.",
        "description": "Team detail - returns team, member, and pending-invite data for members or admins.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18212 is mounted after r.use(authMiddleware) at line 6376"
      },
      "patch": {
        "tags": [
          "teams"
        ],
        "operationId": "patchV1TeamsIdOrSlug",
        "summary": "Team update - admin-only rename, plan, and seat-limit updates.",
        "description": "Team update - admin-only rename, plan, and seat-limit updates.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18377 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "teams"
        ],
        "operationId": "deleteV1TeamsIdOrSlug",
        "summary": "Team delete - owner-only soft delete that removes members and pending invites.",
        "description": "Team delete - owner-only soft delete that removes members and pending invites.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18390 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/captures": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsIdOrSlugCaptures",
        "summary": "team activity dashboard. Every member's captured AI traffic,",
        "description": "team activity dashboard. Every member's captured AI traffic, attributed (who / model / namespace / cost), plus a rollup. Any active team member may read; finer-grained capture:read RBAC is layered in Part A3.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18227 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/export": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsIdOrSlugExport",
        "summary": "team-scoped data export (admin + lake:export scope). Streams the",
        "description": "team-scoped data export (admin + lake:export scope). Streams the team's captured events so a team can hand an auditor or analyst the lake.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18334 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/invite": {
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsIdOrSlugInvite",
        "summary": "Team invite - admin-only invite that enforces seat limits and returns an accept URL.",
        "description": "Team invite - admin-only invite that enforces seat limits and returns an accept URL.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18418 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/members/{tenant_id}": {
      "patch": {
        "tags": [
          "teams"
        ],
        "operationId": "patchV1TeamsIdOrSlugMembersTenantid",
        "summary": "Team member role update - admin-only role changes, with owner changes routed via transfer.",
        "description": "Team member role update - admin-only role changes, with owner changes routed via transfer.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          },
          {
            "name": "tenant_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "tenant_id path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18560 is mounted after r.use(authMiddleware) at line 6376"
      },
      "delete": {
        "tags": [
          "teams"
        ],
        "operationId": "deleteV1TeamsIdOrSlugMembersTenantid",
        "summary": "Team member removal - members may leave; admins may remove non-owner members.",
        "description": "Team member removal - members may leave; admins may remove non-owner members.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          },
          {
            "name": "tenant_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "tenant_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18574 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/models": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsIdOrSlugModels",
        "summary": "team model registry. A member shares an artifact (a completed",
        "description": "team model registry. A member shares an artifact (a completed compile job) with the team; members list it and reach it via a STABLE endpoint. Backs \"train a model your team owns, then everyone uses it\" (including the intense cloud/GPU training path - any completed artifact).",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18272 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsIdOrSlugModels",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18284 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/models/{modelId}": {
      "delete": {
        "tags": [
          "teams"
        ],
        "operationId": "deleteV1TeamsIdOrSlugModelsModelId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          },
          {
            "name": "modelId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "modelId path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18306 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/models/{modelId}/endpoint": {
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsIdOrSlugModelsModelIdEndpoint",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          },
          {
            "name": "modelId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "modelId path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18319 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/retention": {
      "get": {
        "tags": [
          "teams"
        ],
        "operationId": "getV1TeamsIdOrSlugRetention",
        "summary": "team data-retention policy (admin sets retain_days; 0 = keep forever).",
        "description": "team data-retention policy (admin sets retain_days; 0 = keep forever).",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18354 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsIdOrSlugRetention",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18362 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/teams/{idOrSlug}/transfer": {
      "post": {
        "tags": [
          "teams"
        ],
        "operationId": "postV1TeamsIdOrSlugTransfer",
        "summary": "Team ownership transfer - owner-only handoff to an existing team member.",
        "description": "Team ownership transfer - owner-only handoff to an existing team member.",
        "parameters": [
          {
            "name": "idOrSlug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "idOrSlug path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18403 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/telemetry": {
      "get": {
        "tags": [
          "telemetry"
        ],
        "operationId": "getV1Telemetry",
        "summary": "Returns the v5 (kolm) summary AND the legacy invocations snapshot the",
        "description": "Returns the v5 (kolm) summary AND the legacy invocations snapshot the existing dashboard.html consumes. Dashboard keeps reading total_invocations/p50_us/cache; new surfaces (status, hero) read compiles_today/receipt_bearing_runs/k_score_median/artifacts_total/ active_tenants_24h.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:14325 carries route-local auth middleware"
      }
    },
    "/v1/test-device": {
      "post": {
        "tags": [
          "test-device"
        ],
        "operationId": "postV1Testdevice",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22695 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/test-quants": {
      "post": {
        "tags": [
          "test-quants"
        ],
        "operationId": "postV1Testquants",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:22712 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trace/append": {
      "post": {
        "tags": [
          "trace"
        ],
        "operationId": "postV1TraceAppend",
        "summary": "Trace append - validates and stores one span under the authenticated tenant.",
        "description": "Trace append - validates and stores one span under the authenticated tenant.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18852 carries route-local auth middleware"
      }
    },
    "/v1/trace/compile": {
      "post": {
        "tags": [
          "trace"
        ],
        "operationId": "postV1TraceCompile",
        "summary": "Trace compile - converts a tenant trace into replayable workflow IR seeds.",
        "description": "Trace compile - converts a tenant trace into replayable workflow IR seeds.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18942 carries route-local auth middleware"
      }
    },
    "/v1/trace/distill": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceDistill",
        "summary": "/v1/trace/distill - collection GET listing tenant reasoning-trace distill",
        "description": "/v1/trace/distill - collection GET listing tenant reasoning-trace distill jobs. Real W828 wiring lives in src/trace-compile.js; this collection stub returns an empty envelope until a wave wires the distill queue through a dedicated route module.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28595 carries route-local auth middleware"
      }
    },
    "/v1/trace/translate": {
      "post": {
        "tags": [
          "trace"
        ],
        "operationId": "postV1TraceTranslate",
        "summary": "Trace translate - rewrites trace IR provider/model fields for replay on another provider.",
        "description": "Trace translate - rewrites trace IR provider/model fields for replay on another provider.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:19019 carries route-local auth middleware"
      }
    },
    "/v1/trace/translate/detect": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceTranslateDetect",
        "summary": "Trace provider detect - detects source provider/model metadata for a tenant trace.",
        "description": "Trace provider detect - detects source provider/model metadata for a tenant trace.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18999 carries route-local auth middleware"
      }
    },
    "/v1/trace/translate/providers": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceTranslateProviders",
        "summary": "Trace translate providers - lists supported cross-provider trace rewrite targets.",
        "description": "Trace translate providers - lists supported cross-provider trace rewrite targets.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18993 carries route-local auth middleware"
      }
    },
    "/v1/trace/verify": {
      "post": {
        "tags": [
          "trace"
        ],
        "operationId": "postV1TraceVerify",
        "summary": "Trace replay verify - checks compiled replay outputs against captured trace spans.",
        "description": "Trace replay verify - checks compiled replay outputs against captured trace spans.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18964 carries route-local auth middleware"
      }
    },
    "/v1/trace/{trace_id}/chain": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceTraceidChain",
        "summary": "Trace chain - returns tenant-scoped parent/child span chain for a 32-hex trace id.",
        "description": "Trace chain - returns tenant-scoped parent/child span chain for a 32-hex trace id.",
        "parameters": [
          {
            "name": "trace_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "trace_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18830 carries route-local auth middleware"
      }
    },
    "/v1/trace/{trace_id}/export": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceTraceidExport",
        "summary": "Trace export - returns tenant-scoped raw spans for a 32-hex trace id.",
        "description": "Trace export - returns tenant-scoped raw spans for a 32-hex trace id.",
        "parameters": [
          {
            "name": "trace_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "trace_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18841 carries route-local auth middleware"
      }
    },
    "/v1/trace/{trace_id}/stats": {
      "get": {
        "tags": [
          "trace"
        ],
        "operationId": "getV1TraceTraceidStats",
        "summary": "Trace stats - returns tenant-scoped span counts and timing stats for a 32-hex trace id.",
        "description": "Trace stats - returns tenant-scoped span counts and timing stats for a 32-hex trace id.",
        "parameters": [
          {
            "name": "trace_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "trace_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18819 carries route-local auth middleware"
      }
    },
    "/v1/training/plan": {
      "post": {
        "tags": [
          "training"
        ],
        "operationId": "postV1TrainingPlan",
        "summary": "Training plan - drafts a training plan (model class, dataset split, eval",
        "description": "Training plan - drafts a training plan (model class, dataset split, eval protocol, expected K-floor) for a given dataset. Body: { dataset_id, plus optional model_class, holdout, budget }. Used by `kolm training plan`.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21979 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/training/token-dpo": {
      "get": {
        "tags": [
          "training"
        ],
        "operationId": "getV1TrainingTokendpo",
        "summary": "/v1/training/token-dpo - collection GET listing tenant token-DPO jobs.",
        "description": "/v1/training/token-dpo - collection GET listing tenant token-DPO jobs. Honest envelope: no token-DPO module is wired into the request path yet, so the items[] is empty + status='pending'. The operator still gets a real envelope rather than a 404 from the TUI view.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:28580 carries route-local auth middleware"
      }
    },
    "/v1/transparency-log/checkpoints": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogCheckpoints",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/transparency-log/checkpoints/latest": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogCheckpointsLatest",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/transparency-log/entries": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogEntries",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/transparency-log/entries/{seq}": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogEntriesSeq",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "seq",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "seq path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/transparency-log/proof/{seq}": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogProofSeq",
        "summary": "The RFC 9162 / RFC 6962 inclusion-proof fields (leaf_index, tree_size,",
        "description": "The RFC 9162 / RFC 6962 inclusion-proof fields (leaf_index, tree_size, audit_path, root_hash, leaf_hash) are surfaced at the TOP LEVEL so a buyer can verify inclusion directly against verifyInclusionProof without reaching into a nested object. The original `proof` + `checkpoint` keys are kept for backward compatibility (older clients still read response.proof.*).",
        "parameters": [
          {
            "name": "seq",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "seq path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/transparency-log/size": {
      "get": {
        "tags": [
          "transparency-log"
        ],
        "operationId": "getV1TransparencylogSize",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/transparency-log-routes.js is registered from src/router.js:6414 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/*": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1Trust",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/{slug}": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1TrustSlug",
        "summary": "review group. Renders the paid signed report (html default, ?format=json|pdf)",
        "description": "review group. Renders the paid signed report (html default, ?format=json|pdf) and verifies offline. The slug is an unguessable capability token; possession is the grant. Resolves a paid audit slug OR a subscription's stable slug (always-current). A lapsed subscription serves its last report with a banner.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/{slug}/badge.svg": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1TrustSlugBadgesvg",
        "summary": "issuer key is revoked goes grey 'report revoked', outranking staleness and",
        "description": "issuer key is revoked goes grey 'report revoked', outranking staleness and readiness), so it is cached for only 5 minutes - short enough that a revocation or freshness change propagates promptly. Allow-listed in src/auth.js PUBLIC_API alongside the other /v1/trust regexes.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/{slug}/delta": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1TrustSlugDelta",
        "summary": "resolved from the audit / subscription history (resolvePriorReport); a link",
        "description": "resolved from the audit / subscription history (resolvePriorReport); a link with no prior (a first-cycle Continuous report or a standalone $750 report) returns { ok:true, delta:null, note } rather than a 404. computeAuditDelta is pure + never-throws; this route never re-signs and touches no tenant data.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/{slug}/export": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1TrustSlugExport",
        "summary": "CSV / .xls / Drata / Vanta / exec / crosswalk artifact straight into their",
        "description": "CSV / .xls / Drata / Vanta / exec / crosswalk artifact straight into their GRC tool with no kolm account. Possession of the unguessable slug is the grant; resolveTrust only yields an envelope for a PAID audit or an active / lapsed Continuous subscription (a not-yet-generated subscription is 409).",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/trust/{slug}/questionnaire": {
      "get": {
        "tags": [
          "trust"
        ],
        "operationId": "getV1TrustSlugQuestionnaire",
        "summary": "the unguessable slug is the grant (same capability level as the report it",
        "description": "the unguessable slug is the grant (same capability level as the report it derives from); allow-listed in PUBLIC_API alongside GET /v1/trust/:slug. Answers are DERIVED from the report - a control the run never assessed is 'n/a', never an unsupported 'yes'.",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "slug path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/audit-routes.js is registered from src/router.js:30096 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/tunnel/agent/{token}": {
      "get": {
        "tags": [
          "tunnel"
        ],
        "operationId": "getV1TunnelAgentToken",
        "summary": "SSE long-poll: agent attaches and receives `request` events.",
        "description": "SSE long-poll: agent attaches and receives `request` events.",
        "parameters": [
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "token path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18638 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/tunnel/agent/{token}/response": {
      "post": {
        "tags": [
          "tunnel"
        ],
        "operationId": "postV1TunnelAgentTokenResponse",
        "summary": "Agent posts a response for a given request_id.",
        "description": "Agent posts a response for a given request_id.",
        "parameters": [
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "token path parameter"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18645 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/tunnel/register": {
      "post": {
        "tags": [
          "tunnel"
        ],
        "operationId": "postV1TunnelRegister",
        "summary": "The agent maintains an SSE connection to /v1/tunnel/agent/<token>, pulls",
        "description": "The agent maintains an SSE connection to /v1/tunnel/agent/<token>, pulls pending requests, runs the artifact, and posts responses back. The relay never decrypts payloads (we don't terminate TLS inside the user's machine), so the trust model is: trust kolm.ai to relay bytes in transit, or use BYOC TEE for payload-blind operation.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18594 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/tunnels": {
      "get": {
        "tags": [
          "tunnels"
        ],
        "operationId": "getV1Tunnels",
        "summary": "Tunnels list - returns the caller's active tenant tunnels (or team tunnels",
        "description": "Tunnels list - returns the caller's active tenant tunnels (or team tunnels when ?team_id is supplied). Each row carries token, public_url, expires_at, and agent attach status. Used by the dashboard + `kolm tunnel list`.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18616 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/tunnels/{token}": {
      "delete": {
        "tags": [
          "tunnels"
        ],
        "operationId": "deleteV1TunnelsToken",
        "summary": "Tunnel close - tears down one tunnel by token. Tenant-fenced (closeTunnel",
        "description": "Tunnel close - tears down one tunnel by token. Tenant-fenced (closeTunnel throws code:'forbidden' for cross-tenant tokens → 403). Disconnects the attached agent SSE stream.",
        "parameters": [
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "token path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:18626 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/usage/budget": {
      "get": {
        "tags": [
          "usage"
        ],
        "operationId": "getV1UsageBudget",
        "summary": "Spend-cap budget status",
        "description": "Spend-cap budget status",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11829 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verified-inference": {
      "post": {
        "tags": [
          "verified-inference"
        ],
        "operationId": "postV1Verifiedinference",
        "summary": "Verified-inference endpoint - Generator-Verifier asymmetry made shippable.",
        "description": "Verified-inference endpoint - Generator-Verifier asymmetry made shippable. Sample k candidates from a frontier model, run each through a deterministic Recipe verifier (test cases), pick the first that passes. Returns a receipt. P(correct) >= 1 - (1 - p*v)^k. For p=0.91 v=1 k=8: 99.9999%. Uses the server's ANTHROPIC_API_KEY, so a tenant API key is required.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:4213 carries route-local auth middleware"
      }
    },
    "/v1/verify": {
      "post": {
        "tags": [
          "verify"
        ],
        "operationId": "postV1Verify",
        "summary": "Verify - compiles caller-supplied source and runs the verify suite against",
        "description": "Verify - compiles caller-supplied source and runs the verify suite against positive/negative examples. Returns the verify result block (per-case pass/fail + summary). Rate-limited via publishLimiter. Body: { source (required), positives, negatives }.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13854 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verify/{cid}": {
      "get": {
        "tags": [
          "verify"
        ],
        "operationId": "getV1VerifyCid",
        "summary": "DoD step 9 closer. If the registry row carries `manifest.hashes`,",
        "description": "DoD step 9 closer. If the registry row carries `manifest.hashes`, recompute the CID from those hashes (cidFromManifestHashes) and refuse to return verified=true unless the recomputed CID matches the requested CID. Surfaces `manifest_hash_mismatch` envelope with both expected_cid and actual_cid so an auditor can diff the discrepancy without trusting us.",
        "parameters": [
          {
            "name": "cid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "cid path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:13876 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verify/{receipt_id}": {
      "get": {
        "tags": [
          "verify"
        ],
        "operationId": "getV1VerifyReceiptid",
        "summary": "W-D wrapper-completion - GET /v1/verify/:receipt_id",
        "description": "W-D wrapper-completion - GET /v1/verify/:receipt_id Public receipt verification surface. Returns the receipt JSON if known to this tenant + signature verification result. Used by the kolm-audit-1 `verify_url` field; the third-party can hit this without auth to get back the signed payload + a deterministic verify result.",
        "parameters": [
          {
            "name": "receipt_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "receipt_id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:24885 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verticals": {
      "get": {
        "tags": [
          "verticals"
        ],
        "operationId": "getV1Verticals",
        "summary": "from a human workspace, not a CI api_only key.",
        "description": "from a human workspace, not a CI api_only key. The fingerprint surface is intentionally non-404 - the route exists, it returns an honest \"w757_not_shipped\" envelope so callers can branch on the error code instead of probing for the URL.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21320 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verticals/register-stubs": {
      "post": {
        "tags": [
          "verticals"
        ],
        "operationId": "postV1VerticalsRegisterstubs",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21383 carries route-local auth middleware"
      }
    },
    "/v1/verticals/{id}": {
      "get": {
        "tags": [
          "verticals"
        ],
        "operationId": "getV1VerticalsId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21334 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/verticals/{id}/fingerprint": {
      "get": {
        "tags": [
          "verticals"
        ],
        "operationId": "getV1VerticalsIdFingerprint",
        "summary": "GET /v1/verticals/:id/fingerprint - declared BEFORE the :id route would",
        "description": "GET /v1/verticals/:id/fingerprint - declared BEFORE the :id route would otherwise shadow this on /v1/verticals/<id>/<fingerprint>. Express orders by registration, so this stays after /v1/verticals/:id but matches a strictly longer path; both are fine, the test pins both.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:21361 carries route-local auth middleware"
      }
    },
    "/v1/video/bakeoff": {
      "post": {
        "tags": [
          "video"
        ],
        "operationId": "postV1VideoBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26137 carries route-local auth middleware"
      }
    },
    "/v1/video/capture-detect": {
      "post": {
        "tags": [
          "video"
        ],
        "operationId": "postV1VideoCapturedetect",
        "summary": "Distinct paths from W771 vision-capture (/v1/vision/capture-detect,",
        "description": "Distinct paths from W771 vision-capture (/v1/vision/capture-detect, /v1/vision/captures) and W772 audio capture (/v1/audio/speech, /v1/audio/transcriptions, /v1/audio/translations) so the three parallel wave agents do not collide.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26110 carries route-local auth middleware"
      }
    },
    "/v1/video/captures": {
      "get": {
        "tags": [
          "video"
        ],
        "operationId": "getV1VideoCaptures",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26169 carries route-local auth middleware"
      }
    },
    "/v1/video/tokenize": {
      "post": {
        "tags": [
          "video"
        ],
        "operationId": "postV1VideoTokenize",
        "summary": "GET /v1/video/tokenize/doctor",
        "description": "GET /v1/video/tokenize/doctor Auth-gated. Returns the worker doctor envelope -- reports python3 presence + transformers/torch/decord/av/PIL availability + which tokenizer command is wired. ═══════════════════════════════════════════════════════════════════════",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27208 carries route-local auth middleware"
      }
    },
    "/v1/video/tokenize/doctor": {
      "get": {
        "tags": [
          "video"
        ],
        "operationId": "getV1VideoTokenizeDoctor",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27258 carries route-local auth middleware"
      }
    },
    "/v1/vision/bakeoff": {
      "post": {
        "tags": [
          "vision"
        ],
        "operationId": "postV1VisionBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25893 carries route-local auth middleware"
      }
    },
    "/v1/vision/capture-detect": {
      "post": {
        "tags": [
          "vision"
        ],
        "operationId": "postV1VisionCapturedetect",
        "summary": "{ok, count, captures[]} envelope.",
        "description": "{ok, count, captures[]} envelope. All three are tenant-fenced via req.tenant_record.id (W411). Honest envelopes on bad input - no silent passthrough.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25869 carries route-local auth middleware"
      }
    },
    "/v1/vision/captures": {
      "get": {
        "tags": [
          "vision"
        ],
        "operationId": "getV1VisionCaptures",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:25931 carries route-local auth middleware"
      }
    },
    "/v1/vlm-distill/run": {
      "post": {
        "tags": [
          "vlm-distill"
        ],
        "operationId": "postV1VlmdistillRun",
        "summary": "{ teacher, student_model, dataset_captures } - see src/vlm-distill.js",
        "description": "{ teacher, student_model, dataset_captures } - see src/vlm-distill.js When KOLM_VLM_TEACHER_API_KEY is unset the response envelope still has ok:true (because the job was enqueued honestly) but real_run:false + missing_env:'KOLM_VLM_TEACHER_API_KEY' so the caller knows nothing was actually trained.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/multimodal-pipeline-routes.js is registered from src/router.js:30101 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/vlm-distill/runs": {
      "get": {
        "tags": [
          "vlm-distill"
        ],
        "operationId": "getV1VlmdistillRuns",
        "summary": "(source-indexed route; contract generated from route source)",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "x-kolm-source-indexed": true,
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/multimodal-pipeline-routes.js is registered from src/router.js:30101 after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/vlm/tokenize": {
      "post": {
        "tags": [
          "vlm"
        ],
        "operationId": "postV1VlmTokenize",
        "summary": "GET /v1/vlm/tokenize/doctor",
        "description": "GET /v1/vlm/tokenize/doctor Auth-gated. Returns the worker doctor envelope -- reports python3 presence + transformers/torch/Pillow availability + which tokenizer command is wired.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27126 carries route-local auth middleware"
      }
    },
    "/v1/vlm/tokenize/doctor": {
      "get": {
        "tags": [
          "vlm"
        ],
        "operationId": "getV1VlmTokenizeDoctor",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:27162 carries route-local auth middleware"
      }
    },
    "/v1/webhooks": {
      "get": {
        "tags": [
          "webhooks"
        ],
        "operationId": "getV1Webhooks",
        "summary": "Webhooks CRUD",
        "description": "Webhooks CRUD",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11877 is mounted after r.use(authMiddleware) at line 6376"
      },
      "post": {
        "tags": [
          "webhooks"
        ],
        "operationId": "postV1Webhooks",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11882 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/webhooks/{id}": {
      "get": {
        "tags": [
          "webhooks"
        ],
        "operationId": "getV1WebhooksId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11891 carries route-local auth middleware"
      },
      "put": {
        "tags": [
          "webhooks"
        ],
        "operationId": "putV1WebhooksId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11899 is mounted after r.use(authMiddleware) at line 6376"
      },
      "patch": {
        "tags": [
          "webhooks"
        ],
        "operationId": "patchV1WebhooksId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11908 carries route-local auth middleware"
      },
      "delete": {
        "tags": [
          "webhooks"
        ],
        "operationId": "deleteV1WebhooksId",
        "summary": "(source-indexed route; contract generated from route source)",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "id path parameter"
          }
        ],
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:11917 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/whoami": {
      "get": {
        "tags": [
          "whoami"
        ],
        "operationId": "getV1Whoami",
        "summary": "/v1/whoami alias. SDKs (OpenAI/Anthropic/LangChain) follow the",
        "description": "/v1/whoami alias. SDKs (OpenAI/Anthropic/LangChain) follow the convention `GET /v1/whoami` (or `/v1/me`) for \"who is this key?\". The canonical kolm endpoint is GET /v1/account, but /v1/whoami forwards to the same handler so SDKs probing the conventional path get an answer instead of a 404 + bad first-impression. Auth-gated identically.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:9855 carries route-local auth middleware"
      }
    },
    "/v1/workflows/repeated": {
      "get": {
        "tags": [
          "workflows"
        ],
        "operationId": "getV1WorkflowsRepeated",
        "summary": "/v1/workflows/repeated - repeated-workflows.html surfaces the cluster",
        "description": "/v1/workflows/repeated - repeated-workflows.html surfaces the cluster summary from /v1/bridges/observations (the canonical W297 source) under a more discoverable URL. Returns {workflows:[{template,count,samples}]}.",
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:23441 is mounted after r.use(authMiddleware) at line 6376"
      }
    },
    "/v1/wrap/verified": {
      "post": {
        "tags": [
          "wrap"
        ],
        "operationId": "postV1WrapVerified",
        "summary": "If `corpus_namespace` is set, we ask the tenant's Recall index for the",
        "description": "If `corpus_namespace` is set, we ask the tenant's Recall index for the top-k chunks for the most-recent user message and prepend them as a system context block. This is the \"ground every Distill call in the user's corpus\" promise from the plan.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:4108 carries route-local auth middleware"
      }
    },
    "/v1/xlang/bakeoff": {
      "post": {
        "tags": [
          "xlang"
        ],
        "operationId": "postV1XlangBakeoff",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26331 carries route-local auth middleware"
      }
    },
    "/v1/xlang/balanced-sample": {
      "post": {
        "tags": [
          "xlang"
        ],
        "operationId": "postV1XlangBalancedsample",
        "summary": "* Hosted route has NO runOnArtifact/judge wired by default",
        "description": "* Hosted route has NO runOnArtifact/judge wired by default production injects via req.app.locals._w774_run_on_artifact + ._w774_judge. The honest envelope on missing wiring is the contract, not a 500. * All four routes are W411 tenant-fenced.",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26231 carries route-local auth middleware"
      }
    },
    "/v1/xlang/language-coverage": {
      "get": {
        "tags": [
          "xlang"
        ],
        "operationId": "getV1XlangLanguagecoverage",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26380 carries route-local auth middleware"
      }
    },
    "/v1/xlang/per-language-eval": {
      "post": {
        "tags": [
          "xlang"
        ],
        "operationId": "postV1XlangPerlanguageeval",
        "summary": "(source-indexed route; contract generated from route source)",
        "x-kolm-source-indexed": true,
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:26282 carries route-local auth middleware"
      }
    },
    "/v1/yaml/validate": {
      "post": {
        "tags": [
          "yaml"
        ],
        "operationId": "postV1YamlValidate",
        "summary": "* 200 + { ok:false, parsed, validation } on schema errors (parse",
        "description": "* 200 + { ok:false, parsed, validation } on schema errors (parse succeeded but the document violates the W732 schema - caller still gets the parsed tree so it can highlight the bad rows) * 400 + { ok:false, error:'yaml_parse_failed', detail, line } on a parser error (couldn't even read the document)",
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GenericRequest"
              },
              "example": {
                "ok": true
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/JsonEnvelope"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/ServerError"
          }
        },
        "security": [
          {
            "bearerAuth": []
          },
          {
            "apiKeyAuth": []
          }
        ],
        "x-kolm-auth": "authenticated",
        "x-kolm-auth-proof": "src/router.js:7122 carries route-local auth middleware"
      }
    }
  },
  "components": {
    "responses": {
      "JsonEnvelope": {
        "description": "Standard {ok, ...} envelope. Successful 2xx responses share this shape unless overridden.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/JsonEnvelope"
            },
            "example": {
              "ok": true
            }
          }
        }
      },
      "BadRequest": {
        "description": "400 — input validation failed. body: { ok:false, error, hint }.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/JsonEnvelope"
            },
            "example": {
              "ok": false,
              "error": "invalid_input",
              "hint": "check the request body / required fields"
            }
          }
        }
      },
      "Unauthorized": {
        "description": "401 — missing or invalid API key.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/JsonEnvelope"
            },
            "example": {
              "ok": false,
              "error": "unauthorized",
              "hint": "set Authorization: Bearer <kolm_api_key> (ks_*/kao_*) or X-API-Key header"
            }
          }
        }
      },
      "RateLimited": {
        "description": "429 — per-tenant rate limit hit. Retry-After header included.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/JsonEnvelope"
            },
            "example": {
              "ok": false,
              "error": "rate_limited",
              "retry_after_s": 60
            }
          }
        }
      },
      "ServerError": {
        "description": "500 — unexpected upstream error. The envelope describes the failure mode. The error_id header (X-Kolm-Error-Id) lets ops trace the failure.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/JsonEnvelope"
            },
            "example": {
              "ok": false,
              "error": "server_error",
              "error_id": "a1b2c3d4e5f6",
              "hint": "capture the error_id and include it in any bug report"
            }
          }
        }
      }
    },
    "schemas": {
      "JsonEnvelope": {
        "type": "object",
        "description": "Canonical envelope. Successful responses set ok=true; failures carry ok=false plus error/hint.",
        "properties": {
          "ok": {
            "type": "boolean"
          },
          "error": {
            "type": "string",
            "nullable": true
          },
          "hint": {
            "type": "string",
            "nullable": true
          }
        },
        "additionalProperties": true,
        "required": [
          "ok"
        ],
        "example": {
          "ok": true
        }
      },
      "GenericRequest": {
        "type": "object",
        "description": "Permissive request body envelope used for auto-generated route shells. Curated endpoints override this with a richer per-endpoint schema. additionalProperties is true so callers can pass forward-compatible fields without breaking the contract.",
        "additionalProperties": true,
        "example": {
          "ok": true
        }
      }
    },
    "securitySchemes": {
      "bearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "Kolm API key or session bearer",
        "description": "Authorization: Bearer <kolm API key or session token>."
      },
      "apiKeyAuth": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key",
        "description": "Kolm API key header accepted by authenticated API operations."
      }
    }
  }
}
