Skip to main content

Governance

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: governance · 25 operations

GET /v1/tenants/{tenant_slug}/governance/check-suite-policy​

Read the tenant's API change check suite policy

Each component — lint, breaking, consumers, contract, sdk — is required (it decides the verdict), advisory (evaluated and reported, never deciding) or off (not evaluated). Absent components take their documented defaults: lint, breaking and consumers required; contract and sdk advisory.

requiredForPublish: true refuses to publish a version whose current content has no passing (or skipped) evaluation under the policy in force; force-publish with a reason stays the escape, and is audited.

Requires projects:view.

Operation id: get_tenant_check_suite_policy_v1_tenants__tenant_slug__governance_check_suite_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for read the tenant's api change check suite policy.application/json CheckSuitePolicyOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/check-suite-policy​

Save the tenant's API change check suite policy

Each component — lint, breaking, consumers, contract, sdk — is required (it decides the verdict), advisory (evaluated and reported, never deciding) or off (not evaluated). Absent components take their documented defaults: lint, breaking and consumers required; contract and sdk advisory.

requiredForPublish: true refuses to publish a version whose current content has no passing (or skipped) evaluation under the policy in force; force-publish with a reason stays the escape, and is audited.

Requires a signed-in tenant administrator. Audited as governance.check_suite_policy.update.

Operation id: put_tenant_check_suite_policy_v1_tenants__tenant_slug__governance_check_suite_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for save the tenant's api change check suite policy.

Responses

StatusDescriptionBody
200Successful response for save the tenant's api change check suite policy.application/json CheckSuitePolicyOut
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/tenants/{tenant_slug}/governance/check-suite-policy​

Clear the tenant's API change check suite policy

Drop the tenant-wide policy so the documented default governs. Project overrides are left in place. Returns the policy now in force.

Requires a signed-in tenant administrator. Audited as governance.check_suite_policy.clear.

Operation id: delete_tenant_check_suite_policy_v1_tenants__tenant_slug__governance_check_suite_policy_delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for clear the tenant's api change check suite policy.application/json CheckSuitePolicyOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/deploy-gate-policy​

Get the tenant's deploy-gate policy

The thresholds every project in this tenant is judged under unless it saves its own override. A tenant that has never saved one gets the documented default with source: "default".

Thresholds are two-rung: each signal carries a warn threshold and a fail threshold, either of which may be null to disable that rung. Absent keys take their documented defaults, so a body naming one threshold configures exactly that one.

The default policy fails on a breaking change and on a broken consumer, and warns on a lint grade below B or a verification older than a day.

Requires versions:view.

Operation id: get_tenant_gate_policy_v1_tenants__tenant_slug__governance_deploy_gate_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get the tenant's deploy-gate policy.application/json DeployGatePolicyOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/deploy-gate-policy​

Set the tenant's deploy-gate thresholds

Save the tenant-wide policy, replacing whatever it held. Project overrides are left alone: they were configured deliberately, and a tenant-wide edit that silently reset them would move bars nobody asked to move.

Thresholds are two-rung: each signal carries a warn threshold and a fail threshold, either of which may be null to disable that rung. Absent keys take their documented defaults, so a body naming one threshold configures exactly that one.

The default policy fails on a breaking change and on a broken consumer, and warns on a lint grade below B or a verification older than a day.

Requires verification_targets:edit. Audited as governance.deploy_gate_policy.update.

Operation id: put_tenant_gate_policy_v1_tenants__tenant_slug__governance_deploy_gate_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set the tenant's deploy-gate thresholds.

Responses

StatusDescriptionBody
200Successful response for set the tenant's deploy-gate thresholds.application/json DeployGatePolicyOut
422The threshold body is not valid.—

DELETE /v1/tenants/{tenant_slug}/governance/deploy-gate-policy​

Remove the tenant's deploy-gate policy

Drop the tenant-wide policy so the documented default governs again. Project overrides are not cascaded away.

Requires verification_targets:delete. Audited as governance.deploy_gate_policy.clear.

Operation id: delete_tenant_gate_policy_v1_tenants__tenant_slug__governance_deploy_gate_policy_delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove the tenant's deploy-gate policy.application/json DeployGatePolicyOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/quality-policy​

Get the tenant's import/export quality policy

The quality policy in force for this tenant (IXH-2.3). A tenant that has never saved one gets the documented default — no floors, advisory only, override permitted — with isDefault: true, so an upgrade changes no behaviour.

Readable by any tenant member: the import wizard renders the verdict it produces, and a user who cannot see the policy cannot understand why a commit was refused.

Operation id: get_quality_policy_v1_tenants__tenant_slug__governance_quality_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get the tenant's import/export quality policy.application/json QualityPolicyOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/quality-policy​

Save a new version of the tenant's import/export quality policy

Append a new policy version (IXH-2.3). Policy rows are immutable so that a verdict recorded against a version stays reproducible; omitted sections carry forward from the current version.

Tenant administrators only. The change is written to the access audit with the full policy body.

Operation id: put_quality_policy_v1_tenants__tenant_slug__governance_quality_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for save a new version of the tenant's import/export quality policy.

Responses

StatusDescriptionBody
200Successful response for save a new version of the tenant's import/export quality policy.application/json QualityPolicyOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/quality-policy/versions​

List saved quality-policy versions

The tenant's saved policy versions, newest first. Policy rows are immutable, so this is the change history: every verdict names the policyVersionId it applied.

Operation id: list_quality_policy_versions_v1_tenants__tenant_slug__governance_quality_policy_versions_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
limitqueryintegernoMaximum versions to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list saved quality-policy versions.application/json QualityPolicyVersionListResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/quality-waivers​

List import/export quality waivers

The tenant's recorded waivers, newest first (IXH-2.3). By default only waivers that are still honoured are returned; pass activeOnly=false to include expired ones, which the shared waiver-expiry sweep has already notified on.

Operation id: list_quality_waivers_v1_tenants__tenant_slug__governance_quality_waivers_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
scopequerystring or nullnoRestrict to 'import' or 'export'; omit for both.
activeOnlyquerybooleannoDrop waivers whose expiry has passed.
limitqueryintegernoMaximum waivers to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list import/export quality waivers.application/json QualityWaiverListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/governance/quality-waivers​

Record a waiver against a blocking quality verdict

Record accepted risk so a blocked import (or delivery) may proceed (IXH-2.3). The waiver carries the actor, the reason, the scope, and an expiry of the policy's waiverTtlHours; the gate honours it until then, after which the shared waiver-expiry sweep has already warned the tenant.

Refused with 403 when the policy forbids overrides or does not name the caller's effective role — the check is server-side, so a client cannot grant itself one.

Operation id: create_quality_waiver_v1_tenants__tenant_slug__governance_quality_waivers_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for record a waiver against a blocking quality verdict.

Responses

StatusDescriptionBody
201Successful response for record a waiver against a blocking quality verdict.application/json QualityWaiverOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/sdk-generation-settings​

Get the workspace generation defaults

The package naming, licence header and user-agent every project in the workspace inherits unless it overrides them.

Settings are merged key by key, tenant first: a project that overrides only its user-agent still inherits its tenant's package patterns. packageNamePatterns merges one ecosystem at a time.

A key absent from a body inherits the next scope up; a key present as null is deliberately none, and blocks that inheritance.

Patterns may contain the tokens {tenant}, {project}, {version}, {year}, substituted from the scope being resolved. A package pattern is validated by resolving it against probe values and checking the result against its registry's naming rules, so @acme/{project}-sdk is accepted and @ACME/{project} is not.

Ecosystems: npm, pypi, gomod. licenseHeader is capped at 4,000 characters; userAgent at 200 and to characters legal in an HTTP header.

publicSdkEnabled (boolean, default false) is the SDK-3.3 gate: it opens the public browse portal's Get SDK client-kit download and its anonymous per-operation snippets for the project. It is the one setting that is an access control rather than branding, so an unset value means not allowed — a workspace or project owner must opt in.

Requires projects:view.

Operation id: get_tenant_sdk_settings_v1_tenants__tenant_slug__governance_sdk_generation_settings_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get the workspace generation defaults.application/json SdkGenerationSettingsOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/sdk-generation-settings​

Set the workspace generation defaults

Save the workspace-wide defaults, replacing whatever they held. Projects that have saved their own override keep it for the keys it names.

Settings are merged key by key, tenant first: a project that overrides only its user-agent still inherits its tenant's package patterns. packageNamePatterns merges one ecosystem at a time.

A key absent from a body inherits the next scope up; a key present as null is deliberately none, and blocks that inheritance.

Patterns may contain the tokens {tenant}, {project}, {version}, {year}, substituted from the scope being resolved. A package pattern is validated by resolving it against probe values and checking the result against its registry's naming rules, so @acme/{project}-sdk is accepted and @ACME/{project} is not.

Ecosystems: npm, pypi, gomod. licenseHeader is capped at 4,000 characters; userAgent at 200 and to characters legal in an HTTP header.

publicSdkEnabled (boolean, default false) is the SDK-3.3 gate: it opens the public browse portal's Get SDK client-kit download and its anonymous per-operation snippets for the project. It is the one setting that is an access control rather than branding, so an unset value means not allowed — a workspace or project owner must opt in.

Requires projects:edit. Audited as governance.sdk_generation_settings.update.

Operation id: put_tenant_sdk_settings_v1_tenants__tenant_slug__governance_sdk_generation_settings_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set the workspace generation defaults.

Responses

StatusDescriptionBody
200Successful response for set the workspace generation defaults.application/json SdkGenerationSettingsOut
422The settings body is not valid.—

DELETE /v1/tenants/{tenant_slug}/governance/sdk-generation-settings​

Clear the workspace generation defaults

Remove the workspace defaults. Project overrides are not cascaded away — they were configured deliberately. Returns the settings now in force at workspace scope.

Requires projects:edit. Audited as governance.sdk_generation_settings.clear.

Operation id: delete_tenant_sdk_settings_v1_tenants__tenant_slug__governance_sdk_generation_settings_delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for clear the workspace generation defaults.application/json SdkGenerationSettingsOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/sdk-registry-credentials​

List the workspace's package-registry credentials

A credential is write-only: this API stores the token encrypted at rest and never returns it. What comes back is its public scheme prefix (npm_, pypi-), its length and a truncated SHA-256 — enough to confirm which token is stored, not enough to use it.

A project credential replaces the workspace one for that ecosystem. Unlike SDK-3.4's generation settings, credentials do not merge field by field: a token is atomic.

Ecosystems: npm, pypi. gomod is absent because a Go module is released by pushing a tag (SDK-4.2), not by uploading to a registry.

registryUrl defaults to the ecosystem's public registry and must be https:// — a publish token sent over plain HTTP is a token disclosed.

Requires projects:view.

Operation id: list_tenant_registry_credentials_v1_tenants__tenant_slug__governance_sdk_registry_credentials_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list the workspace's package-registry credentials.application/json RegistryCredentialListResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/sdk-registry-credentials/{ecosystem}​

Store the workspace's credential for one registry

A credential is write-only: this API stores the token encrypted at rest and never returns it. What comes back is its public scheme prefix (npm_, pypi-), its length and a truncated SHA-256 — enough to confirm which token is stored, not enough to use it.

A project credential replaces the workspace one for that ecosystem. Unlike SDK-3.4's generation settings, credentials do not merge field by field: a token is atomic.

Ecosystems: npm, pypi. gomod is absent because a Go module is released by pushing a tag (SDK-4.2), not by uploading to a registry.

registryUrl defaults to the ecosystem's public registry and must be https:// — a publish token sent over plain HTTP is a token disclosed.

Requires projects:edit. Audited as governance.sdk_registry_credential.update — the audit row records the token's fingerprint, never the token.

Operation id: put_tenant_registry_credential_v1_tenants__tenant_slug__governance_sdk_registry_credentials__ecosystem__put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
ecosystempathstringyesPath parameter identifying the ecosystem segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for store the workspace's credential for one registry.

Responses

StatusDescriptionBody
200Successful response for store the workspace's credential for one registry.application/json RegistryCredentialOut
422The token, registry URL or ecosystem is not acceptable.—
503No credential-encryption key is configured on this deployment.—

DELETE /v1/tenants/{tenant_slug}/governance/sdk-registry-credentials/{ecosystem}​

Remove the workspace's credential for one registry

Nothing cascades: a project that stored its own credential keeps publishing with it.

Requires projects:edit. Audited as governance.sdk_registry_credential.clear.

Operation id: delete_tenant_registry_credential_v1_tenants__tenant_slug__governance_sdk_registry_credentials__ecosystem__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
ecosystempathstringyesPath parameter identifying the ecosystem segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove the workspace's credential for one registry.application/json object
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/secret-scrub-policy​

Get the tenant's intake secret-scrub policy

The secret-scrub policy in force for this tenant (MFI-29.6). A tenant that has never saved one gets the documented default — enforce, with entropy detection on — with isDefault: true, which is the behaviour every tenant already had, so an upgrade changes nothing.

Readable by any tenant member: an import summary reports what was redacted, and a user who cannot see the policy cannot understand why.

Operation id: get_secret_scrub_policy_v1_tenants__tenant_slug__governance_secret_scrub_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get the tenant's intake secret-scrub policy.application/json SecretScrubPolicyOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/secret-scrub-policy​

Save a new version of the tenant's intake secret-scrub policy

Append a new policy version (MFI-29.6). Policy rows are immutable so that an import summary recorded against a version stays reproducible; omitted fields carry forward from the current version.

Tenant administrators only, and audited with the full policy body: switching to warn_only means uploaded credentials persist unredacted, which must be attributable. Note that the collection and captured-traffic formats listed in alwaysEnforcedFormats stay enforced unless a per-format override says otherwise.

Operation id: put_secret_scrub_policy_v1_tenants__tenant_slug__governance_secret_scrub_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for save a new version of the tenant's intake secret-scrub policy.

Responses

StatusDescriptionBody
200Successful response for save a new version of the tenant's intake secret-scrub policy.application/json SecretScrubPolicyOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/secret-scrub-policy/versions​

List saved secret-scrub policy versions

The tenant's saved scrub-policy versions, newest first. Policy rows are immutable, so this is the change history: every import summary names the policyVersionId that governed it.

Operation id: list_secret_scrub_policy_versions_v1_tenants__tenant_slug__governance_secret_scrub_policy_versions_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
limitqueryintegernoMaximum versions to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list saved secret-scrub policy versions.application/json SecretScrubPolicyVersionListResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/verification-policy​

Get the tenant's evidence-backed verification policy

The publish/deploy verification policy in force (ECA-3.1). A tenant that has never saved one gets the documented default — advisory, no required digests, warn on whole-spec breaking — with isDefault: true.

Operation id: get_verification_policy_v1_tenants__tenant_slug__governance_verification_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get the tenant's evidence-backed verification policy.application/json VerificationPolicyOut
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/governance/verification-policy​

Save a new version of the tenant's verification policy

Append a new policy version (ECA-3.1). Rows are immutable. Omitted fields carry forward from the current version. Tenant administrators only.

Operation id: put_verification_policy_v1_tenants__tenant_slug__governance_verification_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for save a new version of the tenant's verification policy.

Responses

StatusDescriptionBody
200Successful response for save a new version of the tenant's verification policy.application/json VerificationPolicyOut
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/governance/verification-policy/evaluate​

Evaluate publish/deploy policy against evidence

Evaluate the tenant's verification policy for a subject revision. The decision cites exact ECA-1.3 evidence run IDs, persists an evaluation row, and is the same payload the dashboard and publish precheck consume. Breaking findings are whole-spec via version changelogs (#4475); consumer-aware acknowledgment is #4479.

Operation id: evaluate_verification_policy_route_v1_tenants__tenant_slug__governance_verification_policy_evaluate_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for evaluate publish/deploy policy against evidence.

Responses

StatusDescriptionBody
200Successful response for evaluate publish/deploy policy against evidence.application/json VerificationPolicyDecisionOut
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/verification-policy/evaluations​

List recent verification-policy evaluations

Operation id: list_verification_policy_evaluations_route_v1_tenants__tenant_slug__governance_verification_policy_evaluations_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
versionRecordIdquerystring or nullnoOptional catalog revision filter.
limitqueryintegernoMaximum number of rows to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list recent verification-policy evaluations.application/json VerificationPolicyEvaluationListResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/governance/verification-policy/versions​

List saved verification-policy versions

Operation id: list_verification_policy_versions_v1_tenants__tenant_slug__governance_verification_policy_versions_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
limitqueryintegernoMaximum number of rows to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list saved verification-policy versions.application/json VerificationPolicyVersionListResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

CheckSuitePolicyOut​

The suite policy in force for a scope.

Attributes: schema_version: :data:POLICY_SCHEMA_VERSION. source: default (nothing saved), tenant or project. policy_id: The stored row; None for the documented default. content_fingerprint: Digest of the body. policy: The body itself. updated_at: When the stored policy last changed. updated_by: Who changed it. degraded: True when a saved policy could not be read and the default stood in, so "nothing is configured" and "I could not read what is" stay distinguishable.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
sourcestringyesdefault | tenant | project.
policyIdstring or nullnoPolicy ID.
contentFingerprintstringnoContent Fingerprint.
policyCheckSuitePolicynoPolicy.
updatedAtstring (date-time) or nullnoUpdated At.
updatedBystring or nullnoUpdated By.
degradedbooleannoDegraded.

CheckSuitePolicyPutRequest​

Body for saving a suite policy — the gnc.check-suite-policy.v1 document.

PropertyTypeRequiredDescription
componentsmap of stringnocomponent → required | advisory | off; absent components take defaults.
requiredForPublishbooleannoRequire a passing suite evaluation of the current content to publish.

DeployGatePolicyOut​

The threshold policy a gate response was judged under.

Attributes: source: default (nothing saved), tenant, or project. policy_id: Stored row id; None for the documented default. content_fingerprint: Digest of the threshold body. thresholds: The thresholds themselves. updated_at: When the stored policy last changed. updated_by: Who changed it. degraded: True when a saved policy could not be read and the default stood in. A gate has to answer, so an unreadable policy row falls back rather than failing — but a caller must be able to tell "nothing is configured" from "I could not read what is".

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
sourcestringyesdefault | tenant | project.
policyIdstring or nullnoPolicy ID.
contentFingerprintstringnoContent Fingerprint.
thresholdsDeployGateThresholdsnoThresholds.
updatedAtstring (date-time) or nullnoUpdated At.
updatedBystring or nullnoUpdated By.
degradedbooleannoTrue when a saved policy could not be read and the default stood in.

DeployGatePolicyPutRequest​

Body for saving a deploy-gate policy.

Attributes: thresholds: The ctg.gate-policy.v1 threshold body.

PropertyTypeRequiredDescription
thresholdsobjectnoPer-signal warn/fail thresholds. Absent groups and absent keys take their documented defaults.

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

QualityPolicyOut​

The tenant's import/export quality policy in force (IXH-2.3, #5098).

PropertyTypeRequiredDescription
policyVersionIdstring or nullnoRow id of the applied policy version; null when the tenant has none saved.
versionNumberintegernoMonotonic version number; 0 for the built-in default.
contentFingerprintstringnoSHA-256 over the canonicalized policy body ('default' for the default).
isDefaultbooleannoTrue when no tenant policy is saved and the advisory default applies.
importQualityPolicyThresholdsOutnoFloors applied to import intake.
exportQualityPolicyThresholdsOutnoFloors applied to export delivery.
formatOverridesobjectnoPer-adapter-key overrides, e.g. {'openapi': {'import': {'minGrade': 'B'}}}. Resolution is format override → tenant → default.
allowOverridebooleannoWhether a blocking verdict may be waived at all.
overrideRolesarray of stringnoRole slugs permitted to record a waiver (empty = nobody may).
waiverTtlHoursintegernoLifetime of a granted waiver, in hours.
actorLabelstring or nullnoWho saved this version.
createdAtstring (date-time) or string or nullnoWhen this version was saved.

QualityPolicyPutRequest​

Replace the tenant's import/export quality policy (IXH-2.3, #5098).

A PUT always appends a new version: policy rows are immutable so a verdict recorded against a version stays reproducible. Omitted sections keep the values the current policy holds, so a caller can raise the import floor without restating the export contract.

PropertyTypeRequiredDescription
importQualityPolicyThresholdsOut or nullnoImport.
exportQualityPolicyThresholdsOut or nullnoExport.
formatOverridesobject or nullnoFormat Overrides.
allowOverrideboolean or nullnoAllow Override.
overrideRolesarray of string or nullnoOverride Roles.
waiverTtlHoursinteger or nullnoWaiver Ttl Hours.

QualityPolicyVersionListResponse​

The tenant's saved policy versions, newest first (IXH-2.3, #5098).

PropertyTypeRequiredDescription
versionsarray of QualityPolicyOutnoVersions.
countintegernoNumber of count.

QualityWaiverCreateRequest​

Record a waiver against a blocking quality verdict (IXH-2.3, #5098).

PropertyTypeRequiredDescription
scopeenum "import", "export"noWhich gate the waiver applies to.
subjectKeystringyesSubject identity: the SHA-256 of the candidate document for an import (the pre-flight report's cache.content_hash), or the delivery subject for an export.
reasonstringyesThe actor's stated justification for accepting the risk.
subjectLabelstring or nullnoDisplay label for the waived subject (filename / artifact name).
formatKeystring or nullnoAdapter key / export target the waiver applies to.
reportFingerprintstring or nullnoFingerprint of the lint report being waived.
scoreinteger or nullnoLint score at waiver time.
gradestring or nullnoLint grade at waiver time.

QualityWaiverListResponse​

A tenant's quality waivers, newest first (IXH-2.3, #5098).

PropertyTypeRequiredDescription
waiversarray of QualityWaiverOutnoWaivers.
countintegernoNumber of count.

QualityWaiverOut​

One recorded quality waiver (IXH-2.3, #5098).

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
scopestringyesScope.
subjectKeystringyesSubject Key.
subjectLabelstring or nullnoSubject Label.
formatKeystring or nullnoFormat Key.
reportFingerprintstring or nullnoReport Fingerprint.
scoreinteger or nullnoScore.
gradestring or nullnoGrade.
reasonstringyesReason.
expiresAtstring (date-time) or string or nullnoExpires At.
policyVersionIdstring or nullnoPolicy Version ID.
policyContentFingerprintstring or nullnoPolicy Content Fingerprint.
actorLabelstring or nullnoActor Label.
actorRolestring or nullnoActor Role.
createdAtstring (date-time) or string or nullnoCreated At.

RegistryCredentialListResponse​

The credentials configured for one scope.

Attributes: schema_version: The projection's shape. scope: The scope that was addressed. encryption_configured: Whether this deployment can store credentials at all. ecosystems: Which ecosystems can be published to. credentials: One entry per stored credential, tenant-wide first.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
scopestringyesScope.
encryptionConfiguredbooleanyesEncryption Configured.
ecosystemsarray of stringyesEcosystems.
credentialsarray of RegistryCredentialOutyesCredentials.

RegistryCredentialOut​

A stored credential, described without being revealed.

Attributes: schema_version: The projection's shape. ecosystem: npm or pypi. scope: tenant or project. project_id: The project this credential belongs to, when it is a project override. registry_url: Where it publishes. token_prefix: The public scheme prefix the token declares, when it declares one. token_length: How many characters the stored token has. token_fingerprint: A truncated SHA-256 of the token, for confirming a rotation. key_version: Which master key sealed it. readable: Whether the stored token can currently be decrypted. False means the key that sealed it is not configured — the credential is present but unusable, and saying so beats a publish failing with a decryption error. created_at: When it was first stored. updated_at: When it was last replaced. updated_by: Who last replaced it.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
ecosystemstringyesnpm or pypi.
scopestringyestenant or project.
projectIdstring or nullnoProject ID.
registryUrlstringyesRegistry URL.
tokenPrefixstring or nullnoToken Prefix.
tokenLengthinteger or nullnoToken Length.
tokenFingerprintstring or nullnoToken Fingerprint.
keyVersioninteger or nullnoKey Version.
readablebooleannoReadable.
createdAtstring (date-time) or nullnoCreated At.
updatedAtstring (date-time) or nullnoUpdated At.
updatedBystring or nullnoUpdated By.

RegistryCredentialPutRequest​

Body for storing a registry credential.

Attributes: token: The plaintext registry token. Sealed before it is written and never returned. registry_url: Where to publish; defaults to the ecosystem's public registry.

PropertyTypeRequiredDescription
tokenstringyesThe registry token — an npm automation token or a PyPI API token. Stored envelope-encrypted; never returned by any route.
registryUrlstring or nullnoRegistry endpoint. Defaults to npm → https://registry.npmjs.org, pypi → https://upload.pypi.org/legacy/. Must be https://.

SdkGenerationSettingsOut​

The settings in force for a scope, and where each part of them came from.

Attributes: schema_version: The body shape these settings were read as. source: default (nothing saved anywhere), tenant, project, or merged when both scopes contributed. content_fingerprint: sha256: digest of the merged body — identical settings produce identical artifacts, and this is the value that proves it. settings: The merged settings themselves. resolved: The settings with their tokens substituted for this scope, ready to apply. scope: The scope this request addressed (tenant or project). scope_body: The body saved at exactly that scope, verbatim, or None when nothing is saved there. An editor needs this and not just settings: only the raw body says whether a key is absent (inherit) or present as null (deliberately none), and the merged view cannot tell those apart. tenant_settings_id: The contributing tenant-scope row, when there is one. project_settings_id: The contributing project-scope row, when there is one. updated_at: When the most specific contributing row was last written. updated_by: Who wrote it. degraded: True when a stored row could not be read and was skipped.

PropertyTypeRequiredDescription
schemaVersionstringnoThe settings body shape.
sourcestringyesdefault | tenant | project | merged.
contentFingerprintstringyessha256 digest of the merged settings body.
settingsSdkGenerationSettingsnoSettings.
resolvedResolvedBrandingOutyesThe settings with tokens substituted for this scope.
scopestringnoThe scope this request addressed: tenant | project.
scopeBodyobject or nullnoThe body saved at exactly this scope, verbatim, or null when nothing is saved here. Only this distinguishes an absent key (inherit) from an explicit null (deliberately none).
tenantSettingsIdstring or nullnoTenant Settings ID.
projectSettingsIdstring or nullnoProject Settings ID.
updatedAtstring (date-time) or nullnoUpdated At.
updatedBystring or nullnoUpdated By.
degradedbooleannoTrue when a stored row could not be read and was skipped.

SdkGenerationSettingsPutRequest​

Body for saving SDK generation settings.

Attributes: settings: The sdk.generation-settings.v1 body. Only the keys it names are stored.

PropertyTypeRequiredDescription
settingsobjectnoThe settings to save. Only the keys named here are stored, so a body naming one setting configures exactly that one and leaves the rest inheriting.

SecretScrubPolicyOut​

The tenant's intake secret-scrub policy in force (MFI-29.6, #4393).

PropertyTypeRequiredDescription
policyVersionIdstring or nullnoRow id of the applied policy version; null when the tenant has none saved.
versionNumberintegernoMonotonic version number; 0 for the built-in default.
contentFingerprintstringnoSHA-256 over the canonicalized policy body ('default' for the default).
isDefaultbooleannoTrue when no tenant policy is saved and the enforce default applies.
modeenum "enforce", "warn_only"no'enforce' redacts credential values from the source intake persists; 'warn_only' reports the same findings and stores the content unmodified.
entropyDetectionbooleannoWhether the high-entropy heuristic runs alongside the named credential patterns. The named patterns always run and cannot be disabled.
formatOverridesobjectnoPer-adapter-key mode overrides, e.g. {'openapi': {'mode': 'warn_only'}}. Resolution is format override → format default → tenant → default.
alwaysEnforcedFormatsarray of stringnoAdapter keys that resolve to 'enforce' regardless of the tenant mode — the collection and captured-traffic formats. A per-format override still wins.
actorLabelstring or nullnoHuman-readable actor who saved this version.
createdAtstring (date-time) or nullnoWhen the version was saved; null for the built-in default.

SecretScrubPolicyPutRequest​

Replace the tenant's intake secret-scrub policy (MFI-29.6, #4393).

A PUT always appends a new version: policy rows are immutable so a job summary recorded against a version stays reproducible. Omitted fields keep the values the current policy holds.

PropertyTypeRequiredDescription
modeenum "enforce", "warn_only" or nullnoThe tenant-tier scrub mode.
entropyDetectionboolean or nullnoWhether the high-entropy heuristic runs.
formatOverridesobject or nullnoPer-adapter-key mode overrides; replaces the map wholesale when given.

SecretScrubPolicyVersionListResponse​

The tenant's saved secret-scrub policy versions, newest first (MFI-29.6, #4393).

PropertyTypeRequiredDescription
versionsarray of SecretScrubPolicyOutnoVersions.
countintegernoNumber of count.

VerificationPolicyDecisionOut​

Auditable evaluate decision shared by API, publish precheck, and dashboard.

PropertyTypeRequiredDescription
passedbooleanyesPassed.
enforcementstringyesEnforcement.
policyVersionIdstring or nullnoPolicy Version ID.
policyContentFingerprintstringyesPolicy Content Fingerprint.
evaluationIdstring or nullnoEvaluation ID.
evidenceRunIdsarray of stringnoEvidence Run IDs.
gateResultsarray of VerificationPolicyGateResultOutnoGate Results.
warningsarray of objectnoWarnings.
purposestringyesPurpose.
skippedbooleannoSkipped.

VerificationPolicyEvaluateRequest​

Evaluate publish/deploy policy for a subject revision (ECA-3.1, #4734).

PropertyTypeRequiredDescription
purposestringyesEvaluate purpose: publish or deploy.
projectSlugstring or nullnoProject slug (required with versionSlug, or when resolving versionId).
projectIdstring or nullnoProject ID.
versionIdstring or nullnoCatalog revision UUID (versions.id).
versionSlugstring or nullnoVersion slug within the project (e.g. 1.2.0).

VerificationPolicyEvaluationListResponse​

Recent verification-policy evaluations.

PropertyTypeRequiredDescription
evaluationsarray of VerificationPolicyEvaluationOutnoEvaluations.
countintegernoNumber of count.

VerificationPolicyOut​

The tenant's evidence-backed publish/deploy policy in force (ECA-3.1, #4734).

PropertyTypeRequiredDescription
policyVersionIdstring or nullnoRow id of the applied policy version; null when the tenant has none saved.
versionNumberintegernoMonotonic version number; 0 for the built-in default.
contentFingerprintstringnoSHA-256 over the canonicalized policy body.
isDefaultbooleannoTrue when no tenant policy is saved and the advisory default applies.
requiredSuiteDigestsarray of stringnoECA-1.1 suite digests that must have recent passing evidence.
maxEvidenceAgeSecondsinteger or nullnoMaximum age of cited evidence in seconds; null = no freshness gate.
requiredTargetNetworkClassstring or nullnoOptional public/private filter on cited evidence.
purposestringnoWhich evaluate purposes this policy covers: publish, deploy, or both.
breakingChangeActionstringnoWhole-spec breaking posture: ignore, warn, or block (#4475; not consumer-aware).
enforcementstringnoadvisory = report only; block = refuse publish/deploy when evaluate fails.
actorLabelstring or nullnoWho saved this version.
createdAtstring (date-time) or string or nullnoWhen this version was saved.

VerificationPolicyPutRequest​

Append a new evidence-backed verification policy version (ECA-3.1, #4734).

PropertyTypeRequiredDescription
requiredSuiteDigestsarray of string or nullnoECA-1.1 digests (sha256:<64 hex>); omit to keep the current list.
maxEvidenceAgeSecondsinteger or nullnoFreshness ceiling in seconds; omit to keep current; send null via clear flag.
clearMaxEvidenceAgeSecondsbooleannoWhen true, clears maxEvidenceAgeSeconds even if omitted.
requiredTargetNetworkClassstring or nullnoRequired Target Network Class.
clearRequiredTargetNetworkClassbooleannoWhen true, clears the network-class filter.
purposestring or nullnopublish, deploy, or both; omit to keep current.
breakingChangeActionstring or nullnoBreaking Change Action.
enforcementstring or nullnoadvisory or block; omit to keep current.

VerificationPolicyVersionListResponse​

Saved verification-policy versions, newest first (ECA-3.1, #4734).

PropertyTypeRequiredDescription
versionsarray of VerificationPolicyOutnoVersions.
countintegernoNumber of count.