---
components:
  schemas:
    rest.CheckpointEntryResponse:
      properties:
        alg:
          type: string
        checkpoint_id:
          type: string
        created_at:
          type: string
        head_hash:
          type: string
        kid:
          type: string
        project_id:
          type: string
        sequence:
          format: int64
          type: integer
        signature:
          type: string
      type: object
    rest.LogEntryResponse:
      properties:
        alg:
          type: string
        batch_id:
          type: string
        chain_hash:
          type: string
        data:
          type: object
        hash:
          type: string
        kid:
          type: string
        manifest_id:
          type: string
        project_id:
          type: string
        sequence:
          format: int64
          type: integer
        signature:
          type: string
      type: object
    rest.ManifestEntryResponse:
      properties:
        alg:
          type: string
        batch_id:
          type: string
        batch_uri:
          type: string
        created_at:
          type: string
        data_hash:
          type: string
        head_hash:
          type: string
        kid:
          type: string
        manifest_id:
          type: string
        prev_hash:
          type: string
        project_id:
          type: string
        sequence:
          format: int64
          type: integer
        signature:
          type: string
      type: object
    rest.PageResponse-rest_CheckpointEntryResponse:
      properties:
        has_more:
          type: boolean
        items:
          items:
            "$ref": "#/components/schemas/rest.CheckpointEntryResponse"
          type: array
        next_cursor:
          type: string
      type: object
    rest.PageResponse-rest_LogEntryResponse:
      properties:
        has_more:
          type: boolean
        items:
          items:
            "$ref": "#/components/schemas/rest.LogEntryResponse"
          type: array
        next_cursor:
          type: string
      type: object
    rest.PageResponse-rest_ManifestEntryResponse:
      properties:
        has_more:
          type: boolean
        items:
          items:
            "$ref": "#/components/schemas/rest.ManifestEntryResponse"
          type: array
        next_cursor:
          type: string
      type: object
    restapi.ErrorResponse:
      properties:
        message:
          examples:
            - "Internal Server Error"
          type: string
      type: object
info:
  title: ""
  version: ""
openapi: "3.2.0"
paths:
  /audit/.well-known/jwks.json:
    get:
      description: "Returns the JWKS used to verify chain batch/manifest signatures. Public - no auth\nrequired. The key carries no \"alg\": signatures are ECDSA P-256/SHA-256 with the\nASN.1 DER encoding (see the batch/manifest response's alg field), not the raw R||S\nencoding a JOSE \"ES256\" verifier expects."
      operationId: JWKS
      parameters:
        - description: "Project (app space) GID (accepted for forward compatibility with per-project BYOK keys; not yet used to select a key)"
          in: query
          name: project_id
          required: true
          schema:
            type: string
      responses:
        "200":
          content:
            application/json:
              schema:
                additionalProperties: true
                type: object
          description: OK
        "400":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Bad Request"
        "500":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Internal Server Error"
      summary: "List signature verification keys"
      tags:
        - audit
  /audit/v1/checkpoints:
    get:
      description: "Pages through a project's signed checkpoints, newest first."
      operationId: ListCheckpoints
      parameters:
        - description: "Project (app space) GID"
          in: query
          name: project_id
          required: true
          schema:
            type: string
        - description: "Opaque page cursor from a previous response's next_cursor"
          in: query
          name: cursor
          required: false
          schema:
            type: string
        - description: "Maximum number of items to return (default 50, max 50)"
          in: query
          name: pagesize
          required: false
          schema:
            format: int32
            type: integer
      responses:
        "200":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/rest.PageResponse-rest_CheckpointEntryResponse"
          description: OK
        "400":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Bad Request"
        "401":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Unauthorized
        "403":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Forbidden
        "500":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Internal Server Error"
      summary: "List project checkpoints"
      tags:
        - audit
  /audit/v1/logs:
    get:
      description: "Pages through a project's chain batches (audit logs), in sequence order."
      operationId: ListLogs
      parameters:
        - description: "Project (app space) GID"
          in: query
          name: project_id
          required: true
          schema:
            type: string
        - description: "Opaque page cursor from a previous response's next_cursor"
          in: query
          name: cursor
          required: false
          schema:
            type: string
        - description: "Maximum number of items to return (default 50, max 50)"
          in: query
          name: pagesize
          required: false
          schema:
            format: int32
            type: integer
      responses:
        "200":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/rest.PageResponse-rest_LogEntryResponse"
          description: OK
        "400":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Bad Request"
        "401":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Unauthorized
        "403":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Forbidden
        "500":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Internal Server Error"
      summary: "List chain batches"
      tags:
        - audit
  /audit/v1/manifests:
    get:
      description: "Pages through a project's chain manifests, in sequence order."
      operationId: ListManifests
      parameters:
        - description: "Project (app space) GID"
          in: query
          name: project_id
          required: true
          schema:
            type: string
        - description: "Opaque page cursor from a previous response's next_cursor"
          in: query
          name: cursor
          required: false
          schema:
            type: string
        - description: "Maximum number of items to return (default 50, max 50)"
          in: query
          name: pagesize
          required: false
          schema:
            format: int32
            type: integer
      responses:
        "200":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/rest.PageResponse-rest_ManifestEntryResponse"
          description: OK
        "400":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Bad Request"
        "401":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Unauthorized
        "403":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: Forbidden
        "500":
          content:
            application/json:
              schema:
                "$ref": "#/components/schemas/restapi.ErrorResponse"
          description: "Internal Server Error"
      summary: "List chain manifests"
      tags:
        - audit
