{
  "routes": [
    {
      "method": "GET",
      "path": "/api/health",
      "auth": "none",
      "forwards_content": false,
      "what": "liveness, readiness and which adapters are bound"
    },
    {
      "method": "GET",
      "path": "/api/statement",
      "auth": "none",
      "forwards_content": false,
      "what": "the privacy statement, verbatim, as data"
    },
    {
      "method": "GET",
      "path": "/api/routes",
      "auth": "none",
      "forwards_content": false,
      "what": "every route this portal exposes"
    },
    {
      "method": "GET",
      "path": "/api/mail-states",
      "auth": "none",
      "forwards_content": false,
      "what": "every named outcome of a sign-in send"
    },
    {
      "method": "GET",
      "path": "/api/tones",
      "auth": "none",
      "forwards_content": false,
      "what": "the colour law for interface states"
    },
    {
      "method": "GET",
      "path": "/api/entitlement/states",
      "auth": "none",
      "forwards_content": false,
      "what": "the entitlement classifier contract"
    },
    {
      "method": "GET",
      "path": "/api/entitlement/policy",
      "auth": "none",
      "forwards_content": false,
      "what": "the owner-held sunset policy"
    },
    {
      "method": "GET",
      "path": "/api/v7/status",
      "auth": "none",
      "forwards_content": false,
      "what": "the pinned 94-case V7 status without a release claim"
    },
    {
      "method": "POST",
      "path": "/api/signin/request",
      "auth": "none",
      "forwards_content": false,
      "what": "send a single-use six-digit email code"
    },
    {
      "method": "POST",
      "path": "/api/signin/verify",
      "auth": "none",
      "forwards_content": false,
      "what": "spend the code once and create a 24-hour session"
    },
    {
      "method": "POST",
      "path": "/api/signout",
      "auth": "session",
      "forwards_content": false,
      "what": "drop the current session and cookie"
    },
    {
      "method": "GET",
      "path": "/api/me",
      "auth": "session",
      "forwards_content": false,
      "what": "the account and its entitlement state"
    },
    {
      "method": "GET",
      "path": "/api/pair",
      "auth": "session",
      "forwards_content": false,
      "what": "the stored four-field machine bookmark"
    },
    {
      "method": "POST",
      "path": "/api/pair",
      "auth": "session",
      "forwards_content": false,
      "what": "store the bookmark after direct browser-to-machine pairing"
    },
    {
      "method": "DELETE",
      "path": "/api/pair",
      "auth": "session",
      "forwards_content": false,
      "what": "forget the bookmark and return a receipt"
    },
    {
      "method": "POST",
      "path": "/api/entitlement/issue",
      "auth": "session",
      "forwards_content": false,
      "what": "mint a fresh 24-hour agent entitlement"
    },
    {
      "method": "POST",
      "path": "/api/entitlement/checkin",
      "auth": "token",
      "forwards_content": false,
      "what": "return ENTITLED or REVOKED explicitly"
    },
    {
      "method": "POST",
      "path": "/api/entitlement/broker-check",
      "auth": "broker",
      "forwards_content": false,
      "what": "authoritative entitlement answer for the tunnel broker"
    },
    {
      "method": "POST",
      "path": "/api/admin/revoke",
      "auth": "operator",
      "forwards_content": false,
      "what": "revoke an account and append an audit record"
    },
    {
      "method": "POST",
      "path": "/api/admin/reinstate",
      "auth": "operator",
      "forwards_content": false,
      "what": "reinstate an account and append an audit record"
    },
    {
      "method": "GET",
      "path": "/api/admin/audit",
      "auth": "operator",
      "forwards_content": false,
      "what": "the append-only operator record"
    }
  ],
  "proxy_routes": [],
  "max_body_bytes": 4096,
  "law": "No route on this portal forwards session content, a model call, or estate bytes. The browser talks directly to the owner's machine."
}