{"ok":true,"name":"SFI External Agent Gateway","version":"1.10.0","auth":"OAuth 2.0 authorization_code (user-bound) or X-SFI-Token/Bearer static token","base":"/api/external/v1","discovery":{"openapi":"/openapi.json","llms":"/llms.txt","llmsFull":"/llms-full.txt","cognitiveBootstrap":"/api/external/v1/bootstrap","mutationEvidence":"/api/public/mutations","mutationHistory":"/history/mutations","aiIndex":"/ai-index.json","fieldSchema":"/field-schema.json","privacy":"/privacy","oauthAuthorize":"/api/oauth/authorize","oauthToken":"/api/oauth/token"},"oauth":{"flow":"authorization_code","authorizationUrl":"/api/oauth/authorize","tokenUrl":"/api/oauth/token","tokenType":"Bearer","accessTokenTtlSeconds":3600,"authorizationCodeTtlSeconds":120,"pkce":"S256 supported","identity":"Authenticated SFI account. Client credentials identify the GPT/application, not the human principal.","institutionalAuthority":"ROOT receives the full configured gateway scope set. Registered institutional principals receive their explicit registry scopes.","personalAuthority":"Normal accounts receive only owner-scoped Case Platform, personal Lab, Cognitive and Studio scopes. Their tenant is user:<subject_id> and cannot enter the institutional proposal, execution, ROOT evidence or canonical-promotion planes.","caseIdentityBoundary":"Case Platform operations require user-bound OAuth and re-use existing tenant membership checks. Shared/static tokens cannot impersonate a case owner.","scopeOmission":"Scope omission defaults to the authenticated principal configured set.","studioIdentityBoundary":"Studio operations require user-bound OAuth and resolve ownership from token subject_id; shared/static tokens cannot impersonate an owner."},"operations":[{"id":"bootstrap","method":"GET","path":"/bootstrap","scope":"observe","tenant":"institutional","description":"Hydrate an authorized AI client with a versioned SFI cognitive contract, sealed Cognitive Spine snapshot, bounded memory/decisions and promoted learning only."},{"id":"console","method":"GET","path":"/console","scope":"observe","tenant":"institutional","description":"Read the compact governed machine console."},{"id":"execution-contract","method":"POST","path":"/execution-contract","scope":"observe","tenant":"institutional","description":"Describe an object and obtain the governed measurement contract without uploading raw content."},{"id":"structured-result","method":"POST","path":"/result","scope":"lab:write","tenant":"institutional","description":"Return structured measurements and provenance without raw-object persistence."},{"id":"signal-status","method":"GET","path":"/signal","scope":"observe","tenant":"institutional","description":"Read open cycles or one canonical cycle history."},{"id":"signal-cycle","method":"POST","path":"/signal","scope":"lab:write","tenant":"institutional","description":"Run governed institutional signal-cycle operations, including same-cycle resume, RETURN contrast and closure gates."},{"id":"observe","method":"POST","path":"/observe","scope":"observe","tenant":"institutional","description":"Read allowlisted proposal/evidence surfaces."},{"id":"case-read","method":"POST","path":"/cases","scope":"cases:read","tenant":"owner/member","body":{"operation":"list | read | reports | intake_plan"},"description":"Read Case Platform state and unresolved pre-case intake questions available to the OAuth subject."},{"id":"case-write","method":"POST","path":"/cases","scope":"cases:write","tenant":"owner/member","body":{"operation":"create | add_source | add_object | transition"},"description":"Create/populate bounded Case Platform records. Cannot mint accepted evidence, governance authority, intervention, observed RETURN or truth claims."},{"id":"propose","method":"POST","path":"/propose","scope":"propose","tenant":"institutional","description":"Submit a governed action proposal. ROOT authorization remains separate."},{"id":"evidence-candidate","method":"POST","path":"/evidence-candidates","scope":"propose","tenant":"institutional","description":"Submit an evidence candidate. It is not accepted evidence until ROOT accept/reject review; external principals cannot accept it themselves."},{"id":"execute","method":"POST","path":"/execute","scope":"execute","tenant":"institutional","description":"Dispatch only an already-authorized queued proposal. Cannot self-approve or promote canon."},{"id":"proposal-return","method":"POST","path":"/proposal-return","scope":"execute","tenant":"institutional","description":"Record an evidence-linked observed return for one queued proposal."},{"id":"lab-state","method":"POST","path":"/lab","scope":"lab:read","tenant":"institutional","body":{"operation":"state"},"description":"Read institutional Method Lab state."},{"id":"lab-report","method":"POST","path":"/lab","scope":"lab:read","tenant":"institutional","body":{"operation":"report"},"description":"Read institutional Method Lab analyses/evaluations."},{"id":"lab-persist","method":"POST","path":"/lab","scope":"lab:write","tenant":"institutional","body":{"operation":"persist"},"description":"Persist an institutional laboratory observation."},{"id":"lab-run","method":"POST","path":"/lab","scope":"lab:run","tenant":"institutional","body":{"operation":"run","confirm":true},"description":"Execute a supported institutional Method Lab runtime with explicit lab:run scope, confirmation and persisted evidence."},{"id":"personal-cognitive-state","method":"POST","path":"/cognitive","scope":"lab:read","tenant":"owner","body":{"operation":"state | patterns"},"description":"Read only the OAuth subject personal Cognitive workspace and owner-scoped cognition/observation pattern ledger."},{"id":"personal-cognitive-pattern-write","method":"POST","path":"/cognitive","scope":"lab:write","tenant":"owner","body":{"operation":"propose_pattern | confirm_pattern | reject_pattern"},"description":"Govern PERSON_CT cognition/observation representations. Inferred candidates require recurrent owned support and person confirmation; self-declarations remain DECLARED."},{"id":"personal-cognitive-run","method":"POST","path":"/cognitive","scope":"lab:run","tenant":"owner","body":{"operation":"run"},"description":"Auto-select and execute the minimum relevant bounded cognitive automations against owner-scoped evidence. A run never auto-creates a PERSON_CT pattern."},{"id":"personal-lab-state","method":"POST","path":"/personal-lab","scope":"lab:read","tenant":"owner","body":{"operation":"state"},"description":"Read only the OAuth subject personal Lab workspace."},{"id":"personal-lab-create-case","method":"POST","path":"/personal-lab","scope":"lab:write","tenant":"owner","body":{"operation":"create_case"},"description":"Create an owner-scoped personal Lab case."},{"id":"personal-lab-persist","method":"POST","path":"/personal-lab","scope":"lab:write","tenant":"owner","body":{"operation":"persist"},"description":"Persist evidence only into an owned personal Lab case."},{"id":"personal-lab-run","method":"POST","path":"/personal-lab","scope":"lab:run","tenant":"owner","body":{"operation":"run"},"description":"Run a supported personal Lab simulation using only owned case evidence."},{"id":"studio-list","method":"POST","path":"/studio","scope":"studio:read","tenant":"owner","body":{"operation":"list"},"description":"List only Studio objects owned by the OAuth principal."},{"id":"studio-inspect","method":"POST","path":"/studio","scope":"studio:read","tenant":"owner","body":{"operation":"inspect"},"description":"Inspect one owned Studio object."},{"id":"studio-content","method":"POST","path":"/studio","scope":"studio:content","tenant":"owner","body":{"operation":"content"},"description":"Issue a short-lived signed URL for one owned object."},{"id":"studio-analyze","method":"POST","path":"/studio","scope":"studio:run","tenant":"owner","body":{"operation":"analyze"},"description":"Run the existing server-side analyzer for owned audio/video."}],"storage":{"defaultObjectStorage":"REFERENCE_ONLY","rawObjectPersistence":false,"structuredResultPersistence":true},"cognitiveRuntime":{"executionModel":"event-triggered bounded cognitive automations","selection":"MetaOrchestrator selects the minimum relevant automation set and records selection reasons.","executor":"runtimeAgentExecutor -> agentExecutionMap -> deterministic cognitive functions","externalAuthorityBySelection":false,"deprecatedParallelRuntimeRemoved":true},"learning":{"quarantine":"Closed/completed cycles do not enter institutional learning automatically.","eligibleClass":"CALIBRATED_RETURN","rootPromotionRequired":true,"cognitiveSpineAdmissionEvent":"SFI_UNIVERSAL_LEARNING_PROMOTED","excluded":["TEST_SYNTHETIC","FAILED_EXPERIMENT","UNPROMOTED_OPERATIONAL_EVIDENCE","RAW_STRUCTURED_RESULT_HYPOTHESES"],"personCt":{"dimensions":["COGNITION","OBSERVATION"],"ownerScoped":true,"inferredPatternMinimumSupportRefs":2,"confirmationRequired":true,"institutionalInheritance":false}},"mutationEvidence":{"publicSurface":"/history/mutations","machineSurface":"/api/public/mutations","chain":["CODE_RECORDED","QA_VERIFIED","DEPLOYMENT_EVIDENCE_RECORDED","EXERCISED","CALIBRATED_LEARNING_LINKED"],"rule":"A verified GitHub commit proves repository mutation only; each later validation stage requires distinct evidence. Deployment references are not called verified until a deployment-provider verification lane exists."},"governance":"Observation, source registration, record/inference creation, evidence candidacy, evidence acceptance, proposal authorization, execution, return, calibration, learning candidacy and canonical promotion remain distinct governed states."}