{
  "openapi": "3.1.0",
  "info": {
    "title": "AuthHub NHS ReBAC Authorization & Governance API",
    "version": "1.0.0",
    "description": "Production REST, AuthZEN, SCIM 2.0, and Zanzibar ReBAC Authorization Platform for NHS Clinical and Enterprise AI Systems.",
    "termsOfService": "https://fga.authhub.cloud/register/terms",
    "contact": {
      "name": "AuthHub Platform Engineering",
      "url": "https://fga.authhub.cloud/docs",
      "email": "support@authhub.cloud"
    },
    "license": {
      "name": "Proprietary / NHS Digital Framework",
      "url": "https://fga.authhub.cloud/register/terms"
    }
  },
  "servers": [
    {
      "url": "https://fga.authhub.cloud",
      "description": "Production Global Ingress Gateway"
    },
    {
      "url": "http://localhost:3000",
      "description": "Local Developer Daemon Gateway"
    }
  ],
  "tags": [
    {
      "name": "Group 1: ReBAC Core",
      "description": "SpiceDB Google Zanzibar relationship-based access control and REST alternatives"
    },
    {
      "name": "Group 2: AuthZEN SARC",
      "description": "OpenID AuthZEN SARC evaluation, batch decisions, and reverse search"
    },
    {
      "name": "Group 3: Lifecycle & SCIM",
      "description": "RFC 7644 SCIM 2.0 directory ingestion, connection administration, and deprovisioning guard"
    },
    {
      "name": "Group 4: Workload Identity",
      "description": "RFC 8693 token exchange, introspection, and trust domain issuers"
    },
    {
      "name": "Group 5: Analytics & Telemetry",
      "description": "Real-time authorization telemetry, latency percentiles, error heatmaps, and audit exports"
    },
    {
      "name": "Group 6: AI Agent Registry",
      "description": "Registration, credential management, MCP tool authorization, and service identities"
    },
    {
      "name": "Group 7: COAZ Mappings",
      "description": "Context-aware authorization JSONPath transformations and simulation engine"
    },
    {
      "name": "Group 8: Webhooks & DLQ",
      "description": "HMAC-SHA256 event streams, delivery retries, and dead-letter queue replay"
    },
    {
      "name": "Group 9: Break-Glass REST",
      "description": "Emergency medical access escalation, Caldicott justification, and RFC 3161 audit verification"
    },
    {
      "name": "Group 10: Policy Administration",
      "description": "Schema AST definition parsing, per-object-type CRUD, and version rollback"
    },
    {
      "name": "Group 11: OIDC Discovery",
      "description": "OpenID configuration, RFC 8414 server metadata, RFC 9728 protected resource metadata, and JWKS"
    },
    {
      "name": "Group 12: HSM & BYOK",
      "description": "FIPS 140-2 Level 3 hardware security module attestation, rotation, and envelope wrapping"
    },
    {
      "name": "Group 13: CIMD & Billing",
      "description": "Client-ID-Metadata validation policies, plan quotas, and Stripe billing lifecycle"
    },
    {
      "name": "Group 14: Health & Diagnostics",
      "description": "Multi-system liveness/readiness probes, Prometheus metrics, and operator auth"
    },
    {
      "name": "Specialist: NHI Management",
      "description": "Non-human identity state machine, machine credentials, and automated self-repair"
    },
    {
      "name": "Specialist: Governance Signals",
      "description": "Multi-clock risk scoring, clinical registry freezes, and automated policy overrides"
    },
    {
      "name": "Specialist: Autonomous Governance",
      "description": "Real-time policy invariants, compliance boundaries, and auto-quarantine actions"
    },
    {
      "name": "Specialist: Continuous Testing",
      "description": "5-tier continuous automated contract, scenario, and invariant test harnesses"
    },
    {
      "name": "Specialist: Database Access Gateways",
      "description": "Enterprise cloud database registration, ReBAC query proxying, in-flight PII masking, and kill switch controls"
    }
  ],
  "components": {
    "securitySchemes": {
      "BearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT",
        "description": "Tenant or administrative Bearer JWT token"
      },
      "TenantIdHeader": {
        "type": "apiKey",
        "in": "header",
        "name": "X-Tenant-ID",
        "description": "Primary tenant identifier UUID"
      },
      "SubTenantIdHeader": {
        "type": "apiKey",
        "in": "header",
        "name": "X-Sub-Tenant-ID",
        "description": "Sub-tenant namespace isolation identifier"
      },
      "UserIdentityHeader": {
        "type": "apiKey",
        "in": "header",
        "name": "X-User-Identity",
        "description": "Identity of the human or agent caller executing the operation"
      },
      "DPoPProofHeader": {
        "type": "apiKey",
        "in": "header",
        "name": "DPoP",
        "description": "RFC 9449 Demonstrating Proof-of-Possession asymmetric JWT signature"
      }
    },
    "schemas": {
      "ErrorEnvelope": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string",
            "description": "Human-readable error description or error code"
          },
          "details": {
            "type": "string",
            "description": "Underlying diagnostic context or validation issues"
          },
          "code": {
            "type": "string",
            "description": "Standard machine-readable error token"
          }
        }
      },
      "PermissionCheckRequest": {
        "type": "object",
        "required": [
          "subjectType",
          "subjectId",
          "permission",
          "resourceType",
          "resourceId"
        ],
        "properties": {
          "subjectType": {
            "type": "string",
            "example": "user"
          },
          "subjectId": {
            "type": "string",
            "example": "dr-smith"
          },
          "permission": {
            "type": "string",
            "example": "view_record"
          },
          "resourceType": {
            "type": "string",
            "example": "patient"
          },
          "resourceId": {
            "type": "string",
            "example": "patient-123"
          }
        }
      },
      "PermissionCheckResponse": {
        "type": "object",
        "required": [
          "allowed",
          "checkedAt"
        ],
        "properties": {
          "allowed": {
            "type": "boolean",
            "example": true
          },
          "checkedAt": {
            "type": "string",
            "format": "date-time"
          },
          "latencyMs": {
            "type": "number",
            "example": 3
          },
          "governance": {
            "type": "boolean",
            "example": false
          },
          "reason": {
            "type": "string",
            "example": "GOVERNANCE_SUSPENSION"
          },
          "suspensionId": {
            "type": "string",
            "example": "susp_01HYX..."
          }
        }
      },
      "TupleWriteRequest": {
        "type": "object",
        "required": [
          "objectType",
          "objectId",
          "relation",
          "subjectType",
          "subjectId"
        ],
        "properties": {
          "objectType": {
            "type": "string",
            "example": "patient"
          },
          "objectId": {
            "type": "string",
            "example": "patient-123"
          },
          "relation": {
            "type": "string",
            "example": "treating_clinician"
          },
          "subjectType": {
            "type": "string",
            "example": "user"
          },
          "subjectId": {
            "type": "string",
            "example": "dr-smith"
          }
        }
      },
      "TupleWriteResponse": {
        "type": "object",
        "properties": {
          "objectType": {
            "type": "string"
          },
          "objectId": {
            "type": "string"
          },
          "relation": {
            "type": "string"
          },
          "subjectType": {
            "type": "string"
          },
          "subjectId": {
            "type": "string"
          },
          "zetaToken": {
            "type": "string",
            "example": "GhUKEzE3MTk4NTcxODkyMzg1NTE4MjEYASAB"
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "AuthZenEvaluationRequest": {
        "type": "object",
        "required": [
          "subject",
          "action",
          "resource"
        ],
        "properties": {
          "subject": {
            "type": "object",
            "required": [
              "type",
              "id"
            ],
            "properties": {
              "type": {
                "type": "string"
              },
              "id": {
                "type": "string"
              }
            }
          },
          "action": {
            "type": "object",
            "required": [
              "name"
            ],
            "properties": {
              "name": {
                "type": "string"
              }
            }
          },
          "resource": {
            "type": "object",
            "required": [
              "type",
              "id"
            ],
            "properties": {
              "type": {
                "type": "string"
              },
              "id": {
                "type": "string"
              }
            }
          },
          "context": {
            "type": "object"
          }
        }
      },
      "AuthZenEvaluationResponse": {
        "type": "object",
        "required": [
          "decision"
        ],
        "properties": {
          "decision": {
            "type": "boolean"
          },
          "context": {
            "type": "object",
            "properties": {
              "reason": {
                "type": "array",
                "items": {
                  "type": "object"
                }
              },
              "obligations": {
                "type": "array",
                "items": {
                  "type": "object"
                }
              }
            }
          }
        }
      },
      "BreakGlassFulfillmentRequest": {
        "type": "object",
        "required": [
          "event_id",
          "justification",
          "authorising_clinician",
          "duration_seconds"
        ],
        "properties": {
          "event_id": {
            "type": "string",
            "format": "uuid"
          },
          "justification": {
            "type": "string"
          },
          "authorising_clinician": {
            "type": "string",
            "format": "email"
          },
          "duration_seconds": {
            "type": "integer",
            "default": 1800
          }
        }
      },
      "DatabaseConnectionRegistrationRequest": {
        "type": "object",
        "required": [
          "name",
          "database_type",
          "host",
          "port",
          "database",
          "user",
          "password"
        ],
        "properties": {
          "name": {
            "type": "string",
            "example": "aiven-market-data-prod"
          },
          "database_type": {
            "type": "string",
            "enum": [
              "postgres",
              "mysql",
              "cockroach"
            ],
            "example": "postgres"
          },
          "host": {
            "type": "string",
            "example": "pg-authhub1-authhub-poc1.f.aivencloud.com"
          },
          "port": {
            "type": "integer",
            "example": 10952
          },
          "database": {
            "type": "string",
            "example": "defaultdb"
          },
          "user": {
            "type": "string",
            "example": "avnadmin"
          },
          "password": {
            "type": "string",
            "writeOnly": true,
            "example": "••••••••••••"
          },
          "ssl": {
            "oneOf": [
              {
                "type": "boolean"
              },
              {
                "type": "string",
                "enum": [
                  "require",
                  "disable"
                ]
              }
            ],
            "example": "require"
          },
          "governance": {
            "type": "object",
            "properties": {
              "technical_owner": {
                "type": "string",
                "example": "Hanif@NiloDevelopments.onmicrosoft.com"
              },
              "business_owner": {
                "type": "string",
                "example": "aaron.barlow@authhub.cloud"
              },
              "deputies": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "example": [
                  "abby.nguyen@authhub.cloud",
                  "adam.atkins@authhub.cloud"
                ]
              },
              "escalation_contact": {
                "type": "string",
                "example": "Hanif@NiloDevelopments.onmicrosoft.com"
              }
            }
          },
          "security_controls": {
            "type": "object",
            "properties": {
              "max_rows_per_query": {
                "type": "integer",
                "example": 50
              },
              "prohibited_keywords": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "example": [
                  "DROP",
                  "TRUNCATE",
                  "ALTER",
                  "DELETE"
                ]
              },
              "pii_masking": {
                "type": "boolean",
                "example": true
              },
              "require_where_clause": {
                "type": "boolean",
                "example": true
              }
            }
          }
        }
      },
      "DatabaseConnectionResponse": {
        "type": "object",
        "properties": {
          "status": {
            "type": "string",
            "example": "success"
          },
          "connection": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "format": "uuid",
                "example": "8f700688-46fb-40a2-a05e-a6119f6f6004"
              },
              "name": {
                "type": "string",
                "example": "aiven-market-data-prod"
              },
              "database_type": {
                "type": "string",
                "example": "postgres"
              },
              "host": {
                "type": "string",
                "example": "pg-authhub1-authhub-poc1.f.aivencloud.com"
              },
              "port": {
                "type": "integer",
                "example": 10952
              },
              "database": {
                "type": "string",
                "example": "defaultdb"
              },
              "user": {
                "type": "string",
                "example": "avnadmin"
              },
              "ssl": {
                "type": "string",
                "example": "require"
              },
              "assigned_gateway_url": {
                "type": "string",
                "example": "https://api.authhub.cloud/api/v1/tenant/database-connections/8f700688-46fb-40a2-a05e-a6119f6f6004/query"
              },
              "governance": {
                "type": "object"
              },
              "security_controls": {
                "type": "object"
              },
              "discovered_tables": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "example": [
                  "market_data.trade_executions",
                  "market_data.portfolio_summary"
                ]
              },
              "created_at": {
                "type": "string",
                "format": "date-time"
              }
            }
          }
        }
      },
      "DatabaseQueryRequest": {
        "type": "object",
        "required": [
          "sql",
          "agent_id",
          "user_id"
        ],
        "properties": {
          "sql": {
            "type": "string",
            "example": "SELECT trade_id, trader_account, symbol, execution_price FROM market_data.trade_executions"
          },
          "agent_id": {
            "type": "string",
            "example": "nhi-market-analyst-agent-01"
          },
          "user_id": {
            "type": "string",
            "example": "Hanif@NiloDevelopments.onmicrosoft.com"
          },
          "action": {
            "type": "string",
            "default": "query",
            "example": "query"
          }
        }
      },
      "DatabaseQueryResponse": {
        "type": "object",
        "properties": {
          "status": {
            "type": "string",
            "example": "success"
          },
          "connection_id": {
            "type": "string",
            "format": "uuid"
          },
          "rows": {
            "type": "array",
            "items": {
              "type": "object"
            }
          },
          "row_count": {
            "type": "integer",
            "example": 10
          },
          "authz_evaluation": {
            "type": "object",
            "properties": {
              "decision": {
                "type": "string",
                "example": "ALLOW"
              },
              "agent_id": {
                "type": "string"
              },
              "user_id": {
                "type": "string"
              },
              "reasons": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              }
            }
          },
          "security": {
            "type": "object",
            "properties": {
              "pii_masked": {
                "type": "boolean",
                "example": true
              },
              "masked_fields": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "example": [
                  "trader_account"
                ]
              },
              "execution_time_ms": {
                "type": "number",
                "example": 42
              }
            }
          }
        }
      },
      "DatabaseKillSwitchRequest": {
        "type": "object",
        "required": [
          "active"
        ],
        "properties": {
          "active": {
            "type": "boolean",
            "example": true
          },
          "reason": {
            "type": "string",
            "example": "High-frequency extraction anomaly detected"
          },
          "operator_id": {
            "type": "string",
            "example": "Hanif@NiloDevelopments.onmicrosoft.com"
          }
        }
      },
      "DatabaseKillSwitchResponse": {
        "type": "object",
        "properties": {
          "status": {
            "type": "string",
            "example": "success"
          },
          "connection_id": {
            "type": "string",
            "format": "uuid"
          },
          "kill_switch": {
            "type": "object",
            "properties": {
              "active": {
                "type": "boolean",
                "example": true
              },
              "activated_at": {
                "type": "string",
                "format": "date-time"
              },
              "reason": {
                "type": "string"
              },
              "operator_id": {
                "type": "string"
              }
            }
          }
        }
      }
    }
  },
  "paths": {
    "/api/v1/tenant/permissions/check": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Check Permission (REST)",
        "description": "Direct REST equivalent to gRPC CheckPermission. Evaluates governance suspensions and break-glass overrides.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/PermissionCheckRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Authorization check completed",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PermissionCheckResponse"
                }
              }
            }
          },
          "400": {
            "description": "Invalid parameters",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/tenant/permissions/expand": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Expand Permission Tree",
        "description": "Expands the full relationship graph tree explaining authorization decisions.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Expanded graph tree"
          }
        }
      }
    },
    "/api/v1/tenant/tuples": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Query Tuples (REST)",
        "description": "Read relationship tuples matching namespace, resource, or subject filters.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated list of relationship tuples"
          }
        }
      },
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Write Tuple (REST)",
        "description": "Write single relationship tuple with TOUCH semantics.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TupleWriteRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Tuple created",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TupleWriteResponse"
                }
              }
            }
          }
        }
      },
      "delete": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Delete Tuple (REST)",
        "description": "Delete relationship tuple from SpiceDB.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Tuple deleted"
          }
        }
      }
    },
    "/api/v1/tenant/schema": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Read Active Schema",
        "description": "Fetches active schema DSL text and current zeta_token.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Current schema definition"
          }
        }
      },
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Deploy Schema",
        "description": "Deploys a new schema text string to the isolated tenant namespace.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Schema deployed with new zeta_token"
          }
        }
      }
    },
    "/api/v1/tenant/schema/templates": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "List Vertical ReBAC Schema Templates",
        "description": "Retrieves pre-packaged, production-tested Zanzibar authorization schemas for Healthcare (NHS Caldicott/emergency override models) and Enterprise B2B SaaS (hierarchical RBAC-to-ReBAC tenancy models).",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Catalog of vertical schema templates"
          }
        }
      }
    },
    "/api/v1/tenant/schema/dry-run": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Dry-Run Schema Validation",
        "description": "Validates schema candidate without applying changes, returning structural diff.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Schema diff and safety validation"
          }
        }
      }
    },
    "/api/v1/tenant/schemas/diff": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Compare Schema Versions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Structural diff between versions"
          }
        }
      }
    },
    "/api/v1/tenant/schemas/versions/create": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Create Schema Version Draft",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Draft version created"
          }
        }
      }
    },
    "/api/v1/tenant/schemas/versions/list": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "List Schema Versions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "List of schema versions"
          }
        }
      }
    },
    "/api/v1/tenant/schemas/versions/rollback": {
      "post": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Rollback Schema Version",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Rolled back to prior schema version"
          }
        }
      }
    },
    "/api/v1/tenant/audit": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Get Admin Audit Trail",
        "description": "Paginated admin audit trail with filtering by operationType and actor.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "page",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 1
            }
          },
          {
            "name": "pageSize",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 20
            }
          },
          {
            "name": "operationType",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "actor",
            "in": "query",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated audit records"
          }
        }
      }
    },
    "/api/v1/tenant/audit/verify-chain": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Verify Merkle Hash Chain",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Chain validation result"
          }
        }
      }
    },
    "/api/v1/tenant/audit/graph-at": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Reconstruct Graph At Timestamp",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Historical graph topology"
          }
        }
      }
    },
    "/api/v1/tenant/audit/permission-at": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core"
        ],
        "summary": "Permission Check At Timestamp",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Historical permission check result"
          }
        }
      }
    },
    "/authzen/v1/evaluation": {
      "post": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Evaluate Single Access Request",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AuthZenEvaluationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuthZenEvaluationResponse"
                }
              }
            }
          }
        }
      }
    },
    "/authzen/v1/evaluations": {
      "post": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Batch Access Request Evaluations",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Batch decision list"
          }
        }
      }
    },
    "/authzen/v1/resource-search": {
      "post": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Resource Search (Reverse Lookup)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Permitted resources list"
          }
        }
      }
    },
    "/authzen/v1/subject-search": {
      "post": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Subject Search (Reverse Lookup)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Permitted subjects list"
          }
        }
      }
    },
    "/authzen/v1/action-search": {
      "post": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Action Search",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Permitted actions list"
          }
        }
      }
    },
    "/api/v1/tenant/authzen-audit": {
      "get": {
        "tags": [
          "Group 2: AuthZEN SARC"
        ],
        "summary": "Query AuthZEN Audit Records",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Historical AuthZEN decisions"
          }
        }
      }
    },
    "/scim/v2/{connectionId}/Users": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List & Filter Users",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM ListResponse"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Provision User",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Created SCIM User"
          }
        }
      }
    },
    "/scim/v2/{connectionId}/Users/{userId}": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Get SCIM User",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM User"
          }
        }
      },
      "patch": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Patch SCIM User",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Updated SCIM User"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Deprovision SCIM User",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Soft deleted"
          },
          "204": {
            "description": "Hard deleted"
          }
        }
      }
    },
    "/scim/v2/{connectionId}/Groups": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List SCIM Groups",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM Group List"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Create SCIM Group",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Created SCIM Group"
          }
        }
      }
    },
    "/scim/v2/{connectionId}/Groups/{groupId}": {
      "patch": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Update SCIM Group Membership",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Updated SCIM Group"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Delete SCIM Group",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "204": {
            "description": "Deleted SCIM Group"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List SCIM Connections",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "List of configured connections"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Create SCIM Connection",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Created connection with bearer token"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Inspect SCIM Connection",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Connection details"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Decommission SCIM Connection",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Connection soft-deleted"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/pause": {
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Pause SCIM Connection",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Connection paused"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/resume": {
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Resume SCIM Connection",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Connection resumed"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/rotate-token": {
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Rotate SCIM Inbound Token",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Token rotated with grace period"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/mappings": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Inspect SCIM Mapping Rules",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Ordered mapping rules"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/log": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "SCIM Historical Sync Log",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated synchronization events"
          }
        }
      }
    },
    "/api/v1/tenant/scim/connections/{connectionId}/held-events": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List Quarantined Deprovisioning Events",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Quarantined event queue"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Approve or Discard Held Events",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "UserIdentityHeader": []
          }
        ],
        "responses": {
          "200": {
            "description": "Decision processed"
          }
        }
      }
    },
    "/api/v1/tenant/scim/dashboard": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "SCIM Sync Telemetry Dashboard",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Aggregate sync statistics"
          }
        }
      }
    },
    "/api/v1/tenant/usage": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Get Tenant Resource Consumption",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Usage and plan quotas snapshot"
          }
        }
      }
    },
    "/api/v1/tenant/users": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List Synchronized Tenant Users",
        "description": "Query synchronized SCIM users across connections for the authenticated tenant with pagination and text search filtering.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "page",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 1
            }
          },
          {
            "name": "pageSize",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 50,
              "maximum": 200
            }
          },
          {
            "name": "filter",
            "in": "query",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated user list with connection metadata"
          }
        }
      }
    },
    "/api/v1/tenant/groups": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List Synchronized Tenant Groups",
        "description": "Query synchronized SCIM groups across connections with pagination and display name search.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "page",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 1
            }
          },
          {
            "name": "pageSize",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 50,
              "maximum": 200
            }
          },
          {
            "name": "filter",
            "in": "query",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated group list with connection metadata"
          }
        }
      }
    },
    "/api/v1/scim/{connectionId}/Users": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List & Filter Users (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM ListResponse"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Provision User (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Created SCIM User"
          }
        }
      }
    },
    "/api/v1/scim/{connectionId}/Users/{userId}": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Get SCIM User (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM User"
          }
        }
      },
      "patch": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Patch SCIM User (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Updated SCIM User"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Deprovision SCIM User (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Soft deleted"
          },
          "204": {
            "description": "Hard deleted"
          }
        }
      }
    },
    "/api/v1/scim/{connectionId}/Groups": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "List SCIM Groups (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "SCIM Group List"
          }
        }
      },
      "post": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Create SCIM Group (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Created SCIM Group"
          }
        }
      }
    },
    "/api/v1/scim/{connectionId}/Groups/{groupId}": {
      "patch": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Update SCIM Group Membership (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Updated SCIM Group"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 3: Lifecycle & SCIM"
        ],
        "summary": "Delete SCIM Group (Canonical Prefix)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "204": {
            "description": "Deleted SCIM Group"
          }
        }
      }
    },
    "/oauth/authorize": {
      "get": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "OAuth 2.0 Authorization Endpoint",
        "description": "Interactive authorization endpoint supporting RFC 7636 PKCE (S256). Redirects authenticated browser/agent sessions with auth code or renders IdP federation guidance.",
        "responses": {
          "200": {
            "description": "Federation guidance page"
          },
          "302": {
            "description": "Redirect to client callback URL with code and state"
          }
        }
      }
    },
    "/oauth/token": {
      "post": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "RFC 8693 Token Exchange",
        "description": "Exchange external OIDC/SAML subject tokens for fine-grained AuthHub access tokens.",
        "responses": {
          "200": {
            "description": "Exchanged access token"
          }
        }
      }
    },
    "/oauth/introspect": {
      "post": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "RFC 7662 Token Introspection",
        "responses": {
          "200": {
            "description": "Token active state and claims"
          }
        }
      }
    },
    "/oauth/revoke": {
      "post": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "RFC 7009 Token Revocation",
        "responses": {
          "200": {
            "description": "Token revoked"
          }
        }
      }
    },
    "/api/v1/tenants/{id}/issuers": {
      "get": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "List Trusted Identity Providers",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Configured OIDC issuers"
          }
        }
      },
      "post": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "Register Trusted Identity Provider",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Issuer registered"
          }
        }
      }
    },
    "/api/v1/tenants/{id}/workload-identities": {
      "get": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "List Workload Identities",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Configured workload identities"
          }
        }
      },
      "post": {
        "tags": [
          "Group 4: Workload Identity"
        ],
        "summary": "Create Workload Identity Pool Binding",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Workload identity bound"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/overview": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Overview Summary Metrics",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "24-hour evaluation totals and health rates"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/evaluations": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Time-Series Evaluations",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Evaluation time-series data"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/latency": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Latency Percentiles (p50, p90, p99)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Rolling latency percentiles"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/errors": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Error Rate & Failure Codes",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Error breakdown"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/rollups/agents": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Agent Authorization Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Agent evaluation totals"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/rollups/break-glass": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Break-Glass Emergency Access Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Break-glass frequency metrics"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/rollups/tuples": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Tuple Mutation Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Tuple write/delete velocity"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/rollups/schema": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Schema Version Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Schema change telemetry"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/rollups/scim": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "SCIM Ingress Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Sync velocity"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/heatmap": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Hourly Traffic Heatmap Matrix",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Day-of-week by hour load distribution"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/trends": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Rolling Trendlines",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Comparative period trendlines"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/top-resources": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Most Accessed Resources",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "High-frequency resources list"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/top-subjects": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Most Active Callers / Subjects",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Top subject access counts"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/last-used": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Stale Permission & Tuple Detector",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Unused permissions report"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/export": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Export Analytics CSV",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "CSV stream"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/leaderboard": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Authorization Activity Leaderboard",
        "description": "Top clinicians, agents, and callers ranked by check volume and decision rate over the given time window.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "startDate",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "endDate",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Ranked caller leaderboard"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/agents": {
      "get": {
        "tags": [
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Agent Authorization Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Agent evaluation totals"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/scim": {
      "get": {
        "tags": [
          "Group 3: Lifecycle & SCIM",
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "SCIM Ingress Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Sync velocity"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/tuples": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core",
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Tuple Mutation Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Tuple write/delete velocity"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/schema": {
      "get": {
        "tags": [
          "Group 1: ReBAC Core",
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Schema Version Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Schema change telemetry"
          }
        }
      }
    },
    "/api/v1/tenant/analytics/break-glass": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST",
          "Group 5: Analytics & Telemetry"
        ],
        "summary": "Break-Glass Emergency Access Rollup",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Break-glass frequency metrics"
          }
        }
      }
    },
    "/mcp": {
      "post": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Model Context Protocol (MCP) Edge Gateway",
        "description": "Protected MCP JSON-RPC 2.0 gateway endpoint. Supports MCP spec versions 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26. Handles stateless server/discover capability discovery, RFC 9728 401 challenges with resource_metadata pointer, and inline AuthZEN SARC policy evaluations (<5ms) on tools/call.",
        "responses": {
          "200": {
            "description": "JSON-RPC 2.0 response (server/discover, initialize, tools/list, tools/call)"
          },
          "401": {
            "description": "Unauthorized — emits RFC 9728 WWW-Authenticate header with resource_metadata pointer"
          }
        }
      }
    },
    "/api/v1/tenant/agent-registry": {
      "get": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "List Registered AI Agents",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Agent registry catalog"
          }
        }
      },
      "post": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Register Autonomous AI Agent",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Agent registered with credentials"
          }
        }
      }
    },
    "/api/v1/tenant/agent-registry/{id}": {
      "get": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Get Agent Identity Details",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Agent profile"
          }
        }
      },
      "put": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Update Agent Configuration",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Agent updated"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Deregister AI Agent",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Agent revoked"
          }
        }
      }
    },
    "/api/v1/tenant/agent-registry/{id}/verify": {
      "post": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Verify Agent Public Key / Attestation",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Attestation valid"
          }
        }
      }
    },
    "/api/v1/tenant/agent-registry/{id}/rotate-secret": {
      "post": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Rotate Agent Secret",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Secret rotated"
          }
        }
      }
    },
    "/api/v1/tenant/discovery/{id}": {
      "get": {
        "tags": [
          "Group 6: AI Agent Registry"
        ],
        "summary": "Discover Agent Capabilities & Tools",
        "description": "Dynamic MCP tool discovery, agent endpoint resolution, and schema introspection.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Agent capabilities and tool manifests"
          }
        }
      }
    },
    "/api/v1/tenant/coaz-mappings": {
      "get": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "List COAZ Mappings",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Configured JSONPath mappings"
          }
        }
      },
      "post": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Create COAZ Mapping",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Mapping created"
          }
        }
      }
    },
    "/api/v1/tenant/coaz-mappings/{id}": {
      "get": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Get COAZ Mapping",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Mapping detail"
          }
        }
      },
      "put": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Update COAZ Mapping",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Mapping updated"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Delete COAZ Mapping",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Mapping deleted"
          }
        }
      }
    },
    "/api/v1/tenant/coaz-mappings/{id}/versions": {
      "get": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "List Mapping Version History",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Historical mapping versions"
          }
        }
      }
    },
    "/api/v1/tenant/coaz-mappings/simulate": {
      "post": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Simulate COAZ Mapping against Payload",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Extracted context resolution preview"
          }
        }
      }
    },
    "/api/v1/tenant/coaz-mappings/{id}/activate": {
      "post": {
        "tags": [
          "Group 7: COAZ Mappings"
        ],
        "summary": "Activate COAZ Mapping Version",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active version updated"
          }
        }
      }
    },
    "/api/v1/tenant/webhooks": {
      "get": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "List Webhook Subscriptions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active webhook configurations"
          }
        }
      },
      "post": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Create Webhook Subscription",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Webhook registered with HMAC secret"
          }
        }
      }
    },
    "/api/v1/tenant/webhooks/{id}": {
      "get": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Get Webhook Configuration",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Webhook details"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Delete Webhook Subscription",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Webhook deleted"
          }
        }
      }
    },
    "/api/v1/tenant/webhooks/{id}/rotate-secret": {
      "post": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Rotate Webhook HMAC Secret",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Dual-secret rotation period initiated"
          }
        }
      }
    },
    "/api/v1/tenant/webhooks/dlq": {
      "get": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Inspect Dead-Letter Queue",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Quarantined failed deliveries"
          }
        }
      }
    },
    "/api/v1/tenant/webhooks/dlq/{eventId}/replay": {
      "post": {
        "tags": [
          "Group 8: Webhooks & DLQ"
        ],
        "summary": "Replay Dead-Letter Queue Event",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Event redelivered"
          }
        }
      }
    },
    "/api/v1/break-glass": {
      "post": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Submit Emergency Break-Glass Request",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BreakGlassFulfillmentRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Emergency access granted with tamper audit token"
          }
        }
      }
    },
    "/api/v1/break-glass/audit": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Query Break-Glass Audit Trail",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Caldicott-compliant emergency audit events"
          }
        }
      }
    },
    "/api/v1/break-glass-config": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Get Break-Glass Configuration",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Current emergency access policy"
          }
        }
      },
      "put": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Update Break-Glass Configuration",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Emergency access policy updated"
          }
        }
      }
    },
    "/api/v1/tenant/break-glass-config": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "List Tenant Break-Glass Eligibility Rules",
        "description": "Query all configured resource and permission break-glass eligibility rules with TTL and witness requirements.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Break-glass eligibility rules list"
          }
        }
      },
      "post": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Create or Update Break-Glass Rule",
        "description": "Insert or update emergency escalation rule with TTL and max duration constraints.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Rule registered"
          }
        }
      }
    },
    "/api/v1/tenant/break-glass-config/{ruleId}": {
      "delete": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Delete Break-Glass Rule",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "ruleId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Rule removed"
          }
        }
      }
    },
    "/api/v1/break-glass/active": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "List Active Emergency Sessions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Currently active emergency overrides"
          }
        }
      }
    },
    "/api/v1/break-glass/revoke": {
      "post": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Revoke Active Emergency Session",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Emergency access revoked instantly"
          }
        }
      }
    },
    "/api/v1/break-glass/historical": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Historical Break-Glass Log",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Historical sessions"
          }
        }
      }
    },
    "/api/v1/break-glass/tamper-check": {
      "get": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Cryptographic Non-Repudiation Check",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Cryptographic verification status"
          }
        }
      }
    },
    "/api/v1/break-glass/verify-tsa": {
      "post": {
        "tags": [
          "Group 9: Break-Glass REST"
        ],
        "summary": "Verify RFC 3161 Timestamp Token",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "RFC 3161 TSA verification token valid"
          }
        }
      }
    },
    "/api/v1/tenant/policies": {
      "get": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "List Schema Policy Definitions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Object type definitions list"
          }
        }
      },
      "post": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Create Policy Definition",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Policy object type created"
          }
        }
      }
    },
    "/api/v1/tenant/policies/{objectType}": {
      "get": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Get Policy Definition",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Object type definition"
          }
        }
      },
      "put": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Update Policy Definition",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Object type definition updated"
          }
        }
      },
      "delete": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Delete Policy Definition",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Object type definition removed"
          }
        }
      }
    },
    "/api/v1/tenant/policies/history": {
      "get": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Schema Modification History",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Paginated schema version audit trail"
          }
        }
      }
    },
    "/api/v1/tenant/policies/export": {
      "get": {
        "tags": [
          "Group 10: Policy Administration"
        ],
        "summary": "Export SpiceDB .zed Schema File",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Standard SpiceDB schema DSL file"
          }
        }
      }
    },
    "/.well-known/openid-configuration": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "Root OIDC Discovery Document",
        "responses": {
          "200": {
            "description": "Standard OpenID Connect metadata"
          }
        }
      }
    },
    "/t/{tenant_id}/.well-known/openid-configuration": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "Tenant-Scoped OIDC Discovery Document",
        "responses": {
          "200": {
            "description": "Tenant-specific metadata"
          }
        }
      }
    },
    "/.well-known/jwks.json": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "Platform JSON Web Key Set (JWKS)",
        "responses": {
          "200": {
            "description": "Public verification keys"
          }
        }
      }
    },
    "/.well-known/oauth-authorization-server": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "RFC 8414 Authorization Server Metadata",
        "responses": {
          "200": {
            "description": "Token exchange, DPoP and RAR capabilities"
          }
        }
      }
    },
    "/.well-known/oauth-protected-resource": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "RFC 9728 Protected Resource Metadata",
        "responses": {
          "200": {
            "description": "MCP and AI tool resource server discovery"
          }
        }
      }
    },
    "/.well-known/ssf-configuration": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "OpenID Shared Signals and Events (CAEP)",
        "responses": {
          "200": {
            "description": "SSF transmitter configuration"
          }
        }
      }
    },
    "/discovery/v1/tenants": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "Multi-Region Tenant Routing Discovery",
        "responses": {
          "200": {
            "description": "Routing endpoints across regions"
          }
        }
      }
    },
    "/discovery/v1/tenants/{tenant_id}": {
      "get": {
        "tags": [
          "Group 11: OIDC Discovery"
        ],
        "summary": "Inspect Specific Tenant Region Binding",
        "responses": {
          "200": {
            "description": "Regional egress target"
          }
        }
      }
    },
    "/api/v1/tenant/hsm/status": {
      "get": {
        "tags": [
          "Group 12: HSM & BYOK"
        ],
        "summary": "HSM Partition Health & Session Pool",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "FIPS 140-2 Level 3 HSM partition telemetry"
          }
        }
      }
    },
    "/api/operator/keys": {
      "get": {
        "tags": [
          "Group 12: HSM & BYOK"
        ],
        "summary": "Operator Cryptographic Key Status",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active and retained signing keys"
          }
        }
      }
    },
    "/api/v1/operator/keys/rotate": {
      "post": {
        "tags": [
          "Group 12: HSM & BYOK"
        ],
        "summary": "Trigger Zero-Downtime Key Rotation",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Key rotation initiated"
          }
        }
      }
    },
    "/api/v1/tenant/hsm/import": {
      "post": {
        "tags": [
          "Group 12: HSM & BYOK"
        ],
        "summary": "Import BYOK Key with Envelope Wrapping",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Key imported into PKCS#11 partition"
          }
        }
      }
    },
    "/api/v1/tenant/cimd/policies/create": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Create Client ID Document Admission Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Admission rule created"
          }
        }
      }
    },
    "/api/v1/tenant/cimd/policies/list": {
      "get": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "List CIMD Admission Policies",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active policies and quota usage"
          }
        }
      }
    },
    "/api/v1/tenant/cimd/policies/update": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Update CIMD Admission Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Policy updated"
          }
        }
      }
    },
    "/api/v1/tenant/cimd/policies/delete": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Delete CIMD Admission Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Policy removed"
          }
        }
      }
    },
    "/api/v1/tenant/billing": {
      "get": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Get Subscription & Plan State",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active plan, billing period, and status"
          }
        }
      }
    },
    "/api/v1/tenant/billing/checkout": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Create Stripe Checkout Session",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Stripe Checkout URL"
          }
        }
      }
    },
    "/api/v1/tenant/billing/portal": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Open Stripe Customer Billing Portal",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Portal session URL"
          }
        }
      }
    },
    "/api/v1/tenant/billing/invoices": {
      "get": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "List Billing Invoices & Receipts",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Invoice history"
          }
        }
      }
    },
    "/api/v1/tenant/billing/downgrade": {
      "post": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Schedule End-of-Period Tier Downgrade",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Downgrade scheduled"
          }
        }
      }
    },
    "/api/v1/tenant/profile": {
      "get": {
        "tags": [
          "Group 13: CIMD & Billing"
        ],
        "summary": "Get Tenant Profile & Subscription Tier",
        "description": "Fetches organization details, active billing plan, and isolation parameters.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Tenant profile configuration"
          }
        }
      }
    },
    "/health": {
      "get": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Health & Readiness Probe",
        "description": "Comprehensive cluster diagnostic checking CockroachDB, Redis, SpiceDB, and Kafka brokers.",
        "responses": {
          "200": {
            "description": "System healthy and ready"
          },
          "503": {
            "description": "Subsystem degraded or unavailable"
          }
        }
      }
    },
    "/metrics": {
      "get": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Prometheus Exposition Metrics",
        "description": "Standard Prometheus text exposition format.",
        "responses": {
          "200": {
            "description": "Prometheus metrics text"
          }
        }
      }
    },
    "/auth/login": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Administrative Authentication",
        "description": "Authenticates administrative credentials and sets secure HttpOnly cookie session.",
        "responses": {
          "200": {
            "description": "Login successful"
          }
        }
      }
    },
    "/auth/refresh": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Refresh Administrative Token",
        "responses": {
          "200": {
            "description": "Token refreshed"
          }
        }
      }
    },
    "/auth/logout": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Administrative Logout",
        "responses": {
          "200": {
            "description": "Session terminated"
          }
        }
      }
    },
    "/auth/register": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Self-Service Tenant Registration",
        "responses": {
          "201": {
            "description": "Tenant registered"
          }
        }
      }
    },
    "/auth/verify-email": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Verify Tenant Email",
        "responses": {
          "200": {
            "description": "Email verified"
          }
        }
      }
    },
    "/auth/resend-code": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Resend Verification Code",
        "responses": {
          "200": {
            "description": "Code resent"
          }
        }
      }
    },
    "/auth/forgot-password": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Forgot Password Request",
        "responses": {
          "200": {
            "description": "Reset email dispatched"
          }
        }
      }
    },
    "/auth/reset-password": {
      "post": {
        "tags": [
          "Group 14: Health & Diagnostics"
        ],
        "summary": "Reset Password",
        "responses": {
          "200": {
            "description": "Password updated"
          }
        }
      }
    },
    "/api/v1/tenant/nhis": {
      "get": {
        "tags": [
          "Specialist: NHI Management"
        ],
        "summary": "List Non-Human Identities (NHIs)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "List of NHI machine identities"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: NHI Management"
        ],
        "summary": "Register Non-Human Identity (NHI)",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "NHI registered"
          }
        }
      }
    },
    "/api/v1/tenant/nhis/{id}": {
      "get": {
        "tags": [
          "Specialist: NHI Management"
        ],
        "summary": "Get NHI Profile",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "NHI profile"
          }
        }
      },
      "put": {
        "tags": [
          "Specialist: NHI Management"
        ],
        "summary": "Update NHI Configuration",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "NHI updated"
          }
        }
      },
      "delete": {
        "tags": [
          "Specialist: NHI Management"
        ],
        "summary": "Revoke Non-Human Identity",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "NHI revoked"
          }
        }
      }
    },
    "/api/v1/tenant/governance/signals": {
      "get": {
        "tags": [
          "Specialist: Governance Signals"
        ],
        "summary": "List Active Governance Signals",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active signal telemetry"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Governance Signals"
        ],
        "summary": "Emit Real-Time Governance Signal",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Signal processed"
          }
        }
      }
    },
    "/api/v1/tenant/governance/autonomous-policies": {
      "get": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "List Autonomous Governance Rules",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Configured self-healing policies"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "Register Autonomous Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Policy activated"
          }
        }
      }
    },
    "/api/v1/tenant/governance/suspensions": {
      "get": {
        "tags": [
          "Specialist: Governance Signals"
        ],
        "summary": "List Governance Suspensions",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active clinical and identity freezes"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Governance Signals"
        ],
        "summary": "Enforce Governance Suspension",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Subject suspended"
          }
        }
      }
    },
    "/api/v1/tenant/governance/drift-declarations": {
      "get": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "List Policy Drift Declarations",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Drift events and self-repair actions"
          }
        }
      }
    },
    "/api/v1/tenant/governance/policies": {
      "get": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "List Three-Clock Governance Policies",
        "description": "Fetches contextual authorization policies matching trigger fields, required attestations, and auto-expiry durations.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Active governance policies"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "Create Three-Clock Governance Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Policy registered"
          }
        }
      }
    },
    "/api/v1/tenant/governance/policies/{policyId}": {
      "delete": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "Deactivate Governance Policy",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "parameters": [
          {
            "name": "policyId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Policy deactivated"
          }
        }
      }
    },
    "/api/v1/tenant/governance/break-glass": {
      "post": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "Emergency Override Bypassing Governance Suspension",
        "description": "Sets a short-lived key in Redis overriding governance suspensions for emergency care.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "201": {
            "description": "Emergency override activated"
          }
        }
      }
    },
    "/api/v1/tenant/governance/audit": {
      "get": {
        "tags": [
          "Specialist: Autonomous Governance"
        ],
        "summary": "Query Governance Audit Log",
        "description": "Immutable audit trail of governance suspensions, re-attestations, and emergency overrides.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Governance audit log records"
          }
        }
      }
    },
    "/api/v1/tenant/test-suites": {
      "get": {
        "tags": [
          "Specialist: Continuous Testing"
        ],
        "summary": "List Continuous Testing Tiers",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Tier health, pass rates, and cadence"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Continuous Testing"
        ],
        "summary": "Trigger On-Demand Test Run",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "202": {
            "description": "Test tier execution scheduled"
          }
        }
      }
    },
    "/api/tenant/testing/mcp-gateway": {
      "get": {
        "tags": [
          "Specialist: Continuous Testing"
        ],
        "summary": "Live MCP Gateway Protocol & RFC 9728 Synthetic Diagnostic Probe",
        "description": "Runs a 5-step end-to-end diagnostic probe against the live MCP gateway: RFC 9728 protected resource metadata, MCP 2026-07-28 server/discover handshake, RFC 9728 / RFC 6750 401 WWW-Authenticate challenge parsing, OIDC Discovery 1.0 schema compliance, and RFC 8693 ID-JAG token exchange.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Diagnostic probe execution summary with detailed assertion results"
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Continuous Testing"
        ],
        "summary": "Trigger Live MCP Gateway Synthetic Diagnostic Probe",
        "description": "Triggers on-demand synthetic execution of the 5-step MCP gateway protocol test.",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "responses": {
          "200": {
            "description": "Diagnostic probe execution summary"
          }
        }
      }
    },
    "/api/v1/tenant/database-connections": {
      "get": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "List Registered Database Connections",
        "description": "Retrieves all registered enterprise database connections for the tenant, including active gateway URLs and governance status.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "responses": {
          "200": {
            "description": "List of registered database connections",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "status": {
                      "type": "string",
                      "example": "success"
                    },
                    "connections": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/DatabaseConnectionResponse"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "Unauthorized or missing tenant header",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Register Cloud Database Connection",
        "description": "Registers an external enterprise database (e.g. Aiven PostgreSQL, AWS RDS, Cloud SQL) with live credential connectivity testing, schema introspection, and SpiceDB governance bindings.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseConnectionRegistrationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Database connection already registered (idempotent configuration update)",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseConnectionResponse"
                }
              }
            }
          },
          "201": {
            "description": "Database successfully tested, registered, and assigned a secure AuthHub Gateway URL",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseConnectionResponse"
                }
              }
            }
          },
          "400": {
            "description": "Invalid configuration payload or unsupported database type",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          },
          "502": {
            "description": "Live connection test failed against target database host",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/tenant/database-connections/{id}/query": {
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Execute Gated Database Query",
        "description": "Executes a Text-to-SQL or parameterized query through AuthHub AuthZEN SARC evaluation, AST safety checks, SpiceDB ReBAC permission evaluation, and in-flight HMAC-SHA256 PII masking.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          },
          {
            "UserIdentityHeader": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            },
            "description": "Unique database connection identifier"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseQueryRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Query permitted, executed against backend database, and results returned with PII masked",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseQueryResponse"
                }
              }
            }
          },
          "403": {
            "description": "Access denied by SpiceDB ReBAC, Clock-1 kill-switch, or AST safety rules",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          },
          "404": {
            "description": "Database connection not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/tenant/database-connections/{id}/kill-switch": {
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Trigger or Reset Database Gateway Kill Switch",
        "description": "Immediately suspends or restores all AI agent and workload access to this database gateway in sub-millisecond execution time.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            },
            "description": "Unique database connection identifier"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseKillSwitchRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Kill switch state updated successfully",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseKillSwitchResponse"
                }
              }
            }
          },
          "404": {
            "description": "Database connection not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/v1/tenant/database-connections": {
      "get": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "List Registered Database Connections",
        "description": "Direct alias for /api/v1/tenant/database-connections. Retrieves all registered enterprise database connections for the tenant.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "responses": {
          "200": {
            "description": "List of registered database connections",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "status": {
                      "type": "string",
                      "example": "success"
                    },
                    "connections": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/DatabaseConnectionResponse"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "Unauthorized or missing tenant header",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      },
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Register Cloud Database Connection",
        "description": "Direct alias for /api/v1/tenant/database-connections. Registers an external enterprise database with live connectivity testing, schema introspection, and SpiceDB governance bindings.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseConnectionRegistrationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Database connection already registered (idempotent configuration update)",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseConnectionResponse"
                }
              }
            }
          },
          "201": {
            "description": "Database successfully tested, registered, and assigned a secure AuthHub Gateway URL",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseConnectionResponse"
                }
              }
            }
          },
          "400": {
            "description": "Invalid configuration payload or unsupported database type",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          },
          "502": {
            "description": "Live connection test failed against target database host",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/v1/tenant/database-connections/{id}/query": {
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Execute Gated Database Query",
        "description": "Direct alias for /api/v1/tenant/database-connections/{id}/query. Executes a Text-to-SQL or parameterized query through AuthZEN SARC evaluation, AST safety checks, SpiceDB ReBAC evaluation, and HMAC PII masking.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          },
          {
            "UserIdentityHeader": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            },
            "description": "Unique database connection identifier"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseQueryRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Query permitted, executed against backend database, and results returned with PII masked",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseQueryResponse"
                }
              }
            }
          },
          "403": {
            "description": "Access denied by SpiceDB ReBAC, Clock-1 kill-switch, or AST safety rules",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          },
          "404": {
            "description": "Database connection not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    },
    "/v1/tenant/database-connections/{id}/kill-switch": {
      "post": {
        "tags": [
          "Specialist: Database Access Gateways"
        ],
        "summary": "Trigger or Reset Database Gateway Kill Switch",
        "description": "Direct alias for /api/v1/tenant/database-connections/{id}/kill-switch. Immediately suspends or restores all AI agent and workload access to this database gateway in sub-millisecond execution time.",
        "security": [
          {
            "BearerAuth": []
          },
          {
            "TenantIdHeader": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            },
            "description": "Unique database connection identifier"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DatabaseKillSwitchRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Kill switch state updated successfully",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DatabaseKillSwitchResponse"
                }
              }
            }
          },
          "404": {
            "description": "Database connection not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorEnvelope"
                }
              }
            }
          }
        }
      }
    }
  }
}