{
  "openapi": "3.1.0",
  "info": {
    "title": "VIQTON Public Research Runtime API",
    "version": "1.3.0",
    "description": "Fixed-target, read-only research capability with explicit per-run consent. External providers are never mutated. Owner identity and independent outcome attestations are not provided."
  },
  "servers": [
    {
      "url": "https://viqton.com"
    }
  ],
  "paths": {
    "/api/capability-catalog": {
      "get": {
        "summary": "Capability registry",
        "responses": {
          "200": {
            "description": "Read-only capability description"
          }
        }
      }
    },
    "/api/runtime-trust": {
      "get": {
        "summary": "Operational trust limits",
        "responses": {
          "200": {
            "description": "Trust manifest: self-signing, identity and integrations"
          }
        }
      }
    },
    "/api/partner-discovery": {
      "get": {
        "summary": "Read-only public partner contract discovery",
        "description": "Only fixed HTTPS sources. ResultBond and Lumaion are NOT connected to VIQTON execution.",
        "responses": {
          "200": {
            "description": "Public key identifiers, version and provenance; no proof verification"
          }
        }
      }
    },
    "/api/observe": {
      "get": {
        "summary": "Public provider status signals",
        "parameters": [
          {
            "name": "scenario",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "enum": [
                "model",
                "search",
                "infra"
              ]
            }
          }
        ],
        "responses": {
          "200": {
            "description": "HTTP public observation only, no capability evaluation"
          }
        }
      }
    },
    "/api/capability-run": {
      "post": {
        "summary": "Execute one fixed public DNS lookup",
        "description": "Requires same-origin browser Origin and explicit consent. This public research demo does not verify owner identity. Subject to edge rate limit. No paid upstream calls.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": false,
                "required": [
                  "capability",
                  "mode",
                  "consent",
                  "maxSpendUSD"
                ],
                "properties": {
                  "capability": {
                    "const": "public.dns.resolve-a.v1"
                  },
                  "mode": {
                    "type": "string",
                    "enum": [
                      "normal",
                      "inject_primary_unavailable",
                      "dual_observe"
                    ]
                  },
                  "consent": {
                    "const": true
                  },
                  "maxSpendUSD": {
                    "const": 0
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Runtime observation with checksum or optional VIQTON self-attestation; no ResultBond or Lumaion verification"
          },
          "400": {
            "description": "No consent or action outside fixed scope"
          },
          "429": {
            "description": "Rate limit"
          }
        }
      }
    },
    "/api/capability-verify": {
      "post": {
        "summary": "Verify local checksum or configured Ed25519 self-attestation",
        "description": "The server only authenticates a VIQTON self-signature if configured. It does not return external ResultBond or Lumaion proofs.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "receipt"
                ],
                "properties": {
                  "receipt": {
                    "type": "object"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Explicit valid, authenticityVerified and independentWitness=false"
          }
        }
      }
    },
    "/api/policy-eval": {
      "post": {
        "summary": "Evaluate educational fallback preflight",
        "description": "Never grants actual owner authority.",
        "responses": {
          "200": {
            "description": "Hypothetical eligibility only"
          }
        }
      }
    }
  },
  "x-viqton-boundary": {
    "fixedTarget": "example.com",
    "providerOperators": [
      "Cloudflare DNS",
      "Google Public DNS"
    ],
    "externalMutation": false,
    "ownerIdentityVerified": false,
    "independentWitness": false,
    "resultbond": false,
    "lumaion": false,
    "publicRateLimit": "12 POST/minute/IP regional WAF"
  }
}
