{
  "name": "ATLAS",
  "description": "The verified route layer for the AI ecosystem. Maps goals to evidence-backed routes, stacks, receipts, and outcomes for humans and AI agents.",
  "version": "0.8.0",
  "bootstrap": "/agents.bootstrap.json",
  "audience": [
    "humans",
    "ai-agents"
  ],
  "contact": "hello@atlasaipaths.com",
  "contactMailbox": {
    "status": "pending-proof",
    "proven": false,
    "note": "This mailbox is still being set up, so mail sent to it directly may be answered late. The contact form is the reliable way to reach us."
  },
  "capabilities": [
    {
      "name": "record-permalinks",
      "description": "Every verified route and tracked entity is addressable at its own URL, with a machine twin at the same path plus .json. The twin carries the same freshness decision, exclusions, and receipt pointers as the page. Blocked confidence is null with freshness.decision \"block\", never zero.",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "pattern": {
        "route": "/routes/{pathId}.json",
        "entity": "/entities/{entityId}.json"
      },
      "humanPattern": {
        "route": "/routes/{pathId}",
        "entity": "/entities/{entityId}"
      },
      "published": {
        "routes": [
          "/routes/ai-video-stack-under-50.json",
          "/routes/ai-image-generation-workflow.json",
          "/routes/ai-music-production-under-50.json",
          "/routes/ai-coding-agent-setup.json",
          "/routes/ai-voice-agent-mvp.json",
          "/routes/ai-research-workflow.json",
          "/routes/ai-content-creation-pipeline.json",
          "/routes/ai-presentation-from-brief.json"
        ],
        "entityCount": 25
      },
      "cacheable": true
    },
    {
      "name": "trust-contract",
      "description": "The rules a claim must satisfy before ATLAS may publish it. Not a verification claim about any route or entity.",
      "endpoint": "/trust-contract.json",
      "humanReadable": "/trust",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "verified-paths",
      "description": "Curated, evidence-backed routes from goals to recommended stacks",
      "endpoint": "/verified-paths",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "entities",
      "description": "AI tools, models, agents, and frameworks tracked by ATLAS",
      "endpoint": "/entities",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "route-generation",
      "description": "Generate a verified route from a natural-language goal and optional constraints. Constraints re-rank routes toward the ones that satisfy them (each ranked match reports constraintsMet/constraintsUnmet); matchStrength flags a weak-relevance match so an agent knows when the top route is a guess rather than a recommendation.",
      "endpoint": "/routes/generate",
      "format": "application/json",
      "methods": [
        "POST"
      ],
      "input": {
        "goal": "string",
        "constraints": "string[] (concept keys — see recognizedConcepts)",
        "topN": "number (optional, default 3)",
        "profile": {
          "type": "object",
          "additionalProperties": false,
          "properties": {
            "experience": {
              "type": "string",
              "enum": [
                "unspecified",
                "beginner",
                "intermediate",
                "experienced"
              ]
            },
            "timeMinutes": {
              "type": [
                "integer",
                "null"
              ],
              "minimum": 5,
              "maximum": 10080
            },
            "existingTools": {
              "type": "array",
              "maxItems": 12,
              "items": {
                "type": "string",
                "minLength": 1,
                "maxLength": 80
              }
            },
            "privacy": {
              "type": "string",
              "enum": [
                "unspecified",
                "public",
                "confidential",
                "local-only"
              ]
            },
            "budget": {
              "type": [
                "object",
                "null"
              ],
              "additionalProperties": false,
              "required": [
                "amount",
                "period"
              ],
              "properties": {
                "amount": {
                  "type": "number",
                  "minimum": 0,
                  "maximum": 1000000000
                },
                "period": {
                  "type": "string",
                  "enum": [
                    "monthly",
                    "yearly",
                    "weekly",
                    "daily",
                    "one-time"
                  ]
                }
              }
            },
            "constraints": {
              "type": "array",
              "maxItems": 12,
              "items": {
                "type": "string",
                "minLength": 1,
                "maxLength": 256
              }
            }
          }
        }
      },
      "output": {
        "route": "VerifiedPath",
        "receipt": "Receipt",
        "guide": "atlas.guide@1.0 — executable personal tailored instance, independent of catalog verification; includes profile, waypoints, branches, gaps, evidence and receipt boundary",
        "matchStrength": "{ weakMatch: boolean, topScore: number, strength: \"weak\"|\"moderate\"|\"strong\", advice: string|null }",
        "interpretedGoal": "{ budget, excluded, ambiguity: { ambiguous, missingDimensions, questions, answerSlots }, recommendedNextAction: \"clarify\"|\"route\" }",
        "rankedMatches": "[{ pathId, title, matchScore, matchReason, constraintsMet, constraintsUnmet, overBudget, budgetAssessment: { requestedBudget, pathCeiling, status: \"within\"|\"over\"|\"unknown\", overBy }, matchEvidence: { semantic, constraintCount, budgetStatus, excludedConflictCount }, excludedHits, caveats }]",
        "decisionTrace": "{ schemaVersion: \"1.0\", kind: \"route-decision-trace\", signed: false, verification: \"selection-context-only\", fingerprint: \"fnv1a32:...\", interpretedGoal, requestedConstraints, selected, alternatives, relevanceDisclosure, authoritativeEvidence }"
      },
      "recognizedConcepts": [
        "affordable",
        "ai_image",
        "ai_music",
        "ai_video",
        "ai_voice",
        "animated",
        "api",
        "apiavailable",
        "audio",
        "avatar",
        "beginner",
        "beginner_to_intermediate",
        "budget",
        "business",
        "cinematic",
        "clip",
        "commercial",
        "commercial_rights",
        "copy",
        "developer",
        "footage",
        "illustration",
        "image",
        "music",
        "narration",
        "photo",
        "production",
        "professional",
        "sound",
        "soundtrack",
        "text",
        "trailer",
        "tts",
        "under",
        "video",
        "visual",
        "voice",
        "voiceover",
        "writing"
      ]
    },
    {
      "name": "receipt-generation",
      "description": "Generate an evidence receipt for a verified path",
      "endpoint": "/receipts/generate",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "signed-receipts",
      "description": "Generate and verify HMAC-signed path receipts with a freshness decision and validity boundary when the Worker receipt secret is configured",
      "endpoint": "/paths/{pathId}/receipt",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "related": [
        "/receipts/verify"
      ]
    },
    {
      "name": "path-comparison",
      "description": "Compare 2 or 3 verified paths side by side and return a recommendation",
      "endpoint": "/paths/compare",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "terrain-diff",
      "description": "Show stack deltas and confidence changes between two paths. Diff items are enriched objects — iterate item.name, item.category, item.verificationStatus rather than treating items as raw strings.",
      "endpoint": "/terrain/diff",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "input": {
        "base": "string (pathId)",
        "compare": "string (pathId)"
      },
      "output": {
        "base": "{ id: string, routeConfidence: number|null, routeConfidenceWithheld: boolean }",
        "compare": "{ id: string, routeConfidence: number|null, routeConfidenceWithheld: boolean }",
        "diff": {
          "added": "[{ id: string, name: string, category: string|null, verificationStatus: string }]",
          "removed": "[{ id: string, name: string, category: string|null, verificationStatus: string }]",
          "shared": "[{ id: string, name: string, category: string|null, verificationStatus: string }]"
        },
        "confidenceDelta": "number|null (null when confidenceDeltaWithheld)",
        "confidenceDeltaWithheld": "boolean (true when either side withholds its digit)",
        "diffedAt": "ISO8601"
      }
    },
    {
      "name": "outcomes",
      "description": "Record whether a path worked - closes the verification loop",
      "endpoint": "/outcomes",
      "format": "application/json",
      "methods": [
        "GET",
        "POST"
      ]
    },
    {
      "name": "api-contract",
      "description": "Complete manifest-derived route table and safe smoke profile for AI agents",
      "endpoint": "/api-contract.json",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "terrain-statistics",
      "description": "Precomputed aggregate corpus, citation-coverage, recency, and unavailable-state snapshot. It reports structure, not route verification or launch approval.",
      "endpoint": "/stats.json",
      "humanReadable": "/stats",
      "bundleReceipt": "/stats-discovery-receipt.json",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "snapshotId": "sha256:0c37aa36fbbf946eec8ef41d6adda5ebb0d545ce82cf1b5eaae5fe72de657458",
      "computedAt": "2026-10-02T00:00:00.000Z",
      "precomputed": true
    },
    {
      "name": "runtime-status",
      "description": "Non-secret runtime storage status; reports whether mutable write surfaces are durable or ephemeral",
      "endpoint": "/api/runtime/status",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "mcp-server",
      "description": "MCP server for AI agents - query verified paths, score stacks, generate routes, compare paths, and verify receipts",
      "transport": "stdio",
      "endpoint": null,
      "protocol": "MCP v1 (stdio)",
      "tools": [
        "atlas.search_entities",
        "atlas.get_verified_path",
        "atlas.get_evidence_frontier",
        "atlas.generate_route",
        "atlas.score_stack",
        "atlas.generate_receipt",
        "atlas.compare_paths",
        "atlas.verify_receipt",
        "atlas.get_runtime_status",
        "atlas.get_route_for_goal",
        "atlas.record_outcome",
        "atlas.submit_evidence",
        "atlas.get_evidence_status",
        "atlas.get_outcome_record",
        "atlas.get_confidence_delta"
      ],
      "remote": {
        "transport": "json-rpc-over-http",
        "method": "POST",
        "path": "/mcp",
        "host": "api",
        "apiOrigin": "https://atlas-api.founder-d73.workers.dev",
        "protocol": "MCP JSON-RPC 2.0 (one message per request; JSON response; no SSE)",
        "tools": [
          "atlas.search_entities",
          "atlas.get_verified_path",
          "atlas.get_evidence_frontier",
          "atlas.generate_route",
          "atlas.score_stack",
          "atlas.generate_receipt",
          "atlas.compare_paths",
          "atlas.verify_receipt",
          "atlas.get_runtime_status",
          "atlas.get_route_for_goal"
        ],
        "restAlternatives": {
          "atlas.record_outcome": "POST /outcomes",
          "atlas.submit_evidence": "POST /evidence/submit",
          "atlas.get_evidence_status": "GET /evidence/submissions/{id}/status",
          "atlas.get_outcome_record": "GET /outcomes/aggregate/{pathId}",
          "atlas.get_confidence_delta": "GET /paths/{id}/delta"
        }
      },
      "writeTools": [
        {
          "name": "atlas.record_outcome",
          "scoreEffect": "none-pending-human-review",
          "requiresIdempotencyKey": false
        },
        {
          "name": "atlas.submit_evidence",
          "scoreEffect": "none-pending-human-review",
          "requiresIdempotencyKey": true
        }
      ]
    }
  ],
  "primitives": [
    "Goal",
    "Route",
    "Evidence",
    "Stack",
    "Receipt",
    "Outcome",
    "Waypoint",
    "Trail"
  ],
  "trust": {
    "scoringModel": "weighted sum: 0.45*evidenceQuality + 0.25*freshness + 0.2*agentReadiness + 10 (0–100)",
    "stalenessPolicy": "display blocked when freshnessScore < 55; freshness decays to that threshold at each signal's window (pricing 14d, trend 7d, commercial_terms 30d, api_docs 60d, description 90d); entities default to the pricing signal (~14d)",
    "paidPlacement": "never affects score (non-negotiable; enforced by automated tests)"
  },
  "schema": "https://github.com/VaultSparkStudios/atlas/blob/main/ATLAS_v0.8_Windows_Safe_Export/ATLAS_v08/atlas/packages/schemas/src/entity.schema.json",
  "openapi": "/api-schema.json",
  "apiContract": "/api-contract.json",
  "requestLimits": {
    "maxJsonBodyBytes": 65536
  },
  "errorContract": {
    "shape": {
      "error": "stable snake_case code — branch on this",
      "message": "human sentence — never match on this",
      "hint": "optional, actionable next step"
    },
    "codes": [
      {
        "code": "admin_audit_store_unavailable",
        "message": "The admin audit store is unavailable; the action was refused rather than performed unaudited."
      },
      {
        "code": "admin_auth_unconfigured",
        "message": "Operator auth is not configured; admin endpoints fail closed."
      },
      {
        "code": "admin_unauthorized",
        "message": "This endpoint requires operator credentials."
      },
      {
        "code": "atlas_api_error",
        "message": "The ATLAS API returned an error the MCP server passed through unrenamed.",
        "hint": "Read the payload error field for the API’s own stable code."
      },
      {
        "code": "atlas_api_not_configured",
        "message": "The MCP server has no ATLAS API origin configured, so the write was not attempted.",
        "hint": "Set ATLAS_API_URL on the MCP server. written:false means nothing was sent."
      },
      {
        "code": "atlas_api_timeout",
        "message": "The ATLAS API did not respond before the bounded timeout.",
        "hint": "The write may or may not have landed. Retry with the SAME idempotencyKey."
      },
      {
        "code": "atlas_api_unreachable",
        "message": "The ATLAS API origin could not be reached.",
        "hint": "Distinct from a timeout: no connection was established, so the write did not land."
      },
      {
        "code": "base_and_compare_required",
        "message": "Both base and compare query parameters are required.",
        "hint": "Call /terrain/diff?base=<pathId>&compare=<pathId>."
      },
      {
        "code": "base_path_not_found",
        "message": "The base path was not found."
      },
      {
        "code": "blocked_host",
        "message": "The fetch target resolves to a private, local or metadata address."
      },
      {
        "code": "blocked_url",
        "message": "That URL points at a private, local or metadata address.",
        "hint": "Private, local and metadata addresses are refused. Submit a publicly reachable source."
      },
      {
        "code": "body_read_failed",
        "message": "The source response body could not be read within the bounded capture."
      },
      {
        "code": "body_unavailable",
        "message": "The source response does not expose a readable body stream."
      },
      {
        "code": "challenge_delivery_failed",
        "message": "The challenge email could not be delivered."
      },
      {
        "code": "challenge_delivery_unavailable",
        "message": "Challenge delivery is not available on this deployment."
      },
      {
        "code": "challenge_invalid_or_expired",
        "message": "The challenge token is invalid or has expired.",
        "hint": "Request a new challenge."
      },
      {
        "code": "challenge_token_required",
        "message": "A challenge token is required."
      },
      {
        "code": "claim_revision_store_unavailable",
        "message": "The public claim revision store is unavailable."
      },
      {
        "code": "compare_path_not_found",
        "message": "The compare path was not found."
      },
      {
        "code": "content_fetch_failed",
        "message": "The source content could not be fetched.",
        "hint": "Retry with backoff; diagnosticFingerprint correlates the privacy-safe failure."
      },
      {
        "code": "content_http_error",
        "message": "The source returned a non-success HTTP status.",
        "hint": "Inspect httpStatus before deciding whether and when to retry."
      },
      {
        "code": "dispatch_failed",
        "message": "The MCP dispatch queue failed while handling the request."
      },
      {
        "code": "email_and_message_required",
        "message": "Both email and message are required."
      },
      {
        "code": "email_not_configured",
        "message": "Outbound email is not configured on this deployment."
      },
      {
        "code": "email_required",
        "message": "An email address is required."
      },
      {
        "code": "email_send_failed",
        "message": "The outbound email could not be delivered."
      },
      {
        "code": "entity_id_and_url_required",
        "message": "Both entityId and url are required."
      },
      {
        "code": "entity_not_found",
        "message": "That entity does not exist."
      },
      {
        "code": "evidence_review_store_unavailable",
        "message": "The durable evidence review store is unavailable."
      },
      {
        "code": "evidence_store_unavailable",
        "message": "The durable evidence store is unavailable."
      },
      {
        "code": "evidence_submission_already_reviewed",
        "message": "That submission has already received a terminal review decision."
      },
      {
        "code": "evidence_submission_not_found",
        "message": "No evidence submission with that id."
      },
      {
        "code": "fetch_failed",
        "message": "The fetch target could not be reached (DNS failure, connection refused, or timeout).",
        "hint": "Distinct from blocked_host: this target was permitted, it simply did not answer. See urlErrorDetail for the raw cause."
      },
      {
        "code": "goal_too_large",
        "message": "goal exceeds the accepted length.",
        "hint": "Limit goal to 4,000 characters."
      },
      {
        "code": "idempotency_conflict",
        "message": "This Idempotency-Key was already used for a different payload.",
        "hint": "Do not retry this payload with the same key. Surface the conflict and mint a new key."
      },
      {
        "code": "idempotency_key_required",
        "message": "This write requires an Idempotency-Key header.",
        "hint": "Send an Idempotency-Key header so retries cannot duplicate the write."
      },
      {
        "code": "ids_required",
        "message": "One or more ids are required.",
        "hint": "Pass ?ids= with a comma-separated list."
      },
      {
        "code": "ingestion_auth_unconfigured",
        "message": "Ingestion auth is not configured; the endpoint fails closed."
      },
      {
        "code": "ingestion_drift_store_unavailable",
        "message": "The source-drift review queue store is unavailable."
      },
      {
        "code": "ingestion_store_unavailable",
        "message": "The ingestion receipt store is unavailable."
      },
      {
        "code": "ingestion_unauthorized",
        "message": "This endpoint requires the ingestion credential."
      },
      {
        "code": "internal_error",
        "message": "An unexpected server error occurred.",
        "hint": "Retry with backoff; the requestId correlates this failure in diagnostics."
      },
      {
        "code": "invalid_action",
        "message": "Unsupported action."
      },
      {
        "code": "invalid_arguments",
        "message": "The MCP tool arguments exceed structural limits or have an invalid shape."
      },
      {
        "code": "invalid_claim_revision",
        "message": "The proposed public claim revision is invalid, so the review was not applied.",
        "hint": "Provide distinct before and after values, valid evidence ids, a public reason, and a supported claim field."
      },
      {
        "code": "invalid_compare_id_count",
        "message": "Comparing requires exactly 2 or 3 path ids.",
        "hint": "Call ?ids=a,b or ?ids=a,b,c."
      },
      {
        "code": "invalid_constraints",
        "message": "constraints must be an array of strings.",
        "hint": "Use the concept keys published as recognizedConcepts in /agents.json."
      },
      {
        "code": "invalid_decision",
        "message": "Unsupported review decision."
      },
      {
        "code": "invalid_detail",
        "message": "detail is not a supported response projection.",
        "hint": "Use compact or full."
      },
      {
        "code": "invalid_email",
        "message": "That email address is not valid."
      },
      {
        "code": "invalid_evidence_status_ids",
        "message": "Receipt status ids must be 1 to 100 opaque evidence receipt ids."
      },
      {
        "code": "invalid_fail_reason",
        "message": "failReason is not one of the published outcome fail reasons.",
        "hint": "Read the enum published in the tool input schema."
      },
      {
        "code": "invalid_fields",
        "message": "One or more requested projection fields are unknown.",
        "hint": "Pass ?fields= with published field names only."
      },
      {
        "code": "invalid_goal",
        "message": "goal must be a string."
      },
      {
        "code": "invalid_guide_profile",
        "message": "profile must contain supported, bounded guide preferences."
      },
      {
        "code": "invalid_idempotency_key",
        "message": "That Idempotency-Key is not usable.",
        "hint": "Use 8-200 printable ASCII characters."
      },
      {
        "code": "invalid_json",
        "message": "The request body is not valid JSON."
      },
      {
        "code": "invalid_outcome_status",
        "message": "Unsupported outcome status."
      },
      {
        "code": "invalid_query",
        "message": "query must be a string."
      },
      {
        "code": "invalid_return_to",
        "message": "The returnTo target is not an allowed origin."
      },
      {
        "code": "invalid_scheme",
        "message": "The fetch target must be http:// or https://."
      },
      {
        "code": "invalid_stack",
        "message": "stack must be an array of entity ids."
      },
      {
        "code": "invalid_status_filter",
        "message": "Unsupported status filter."
      },
      {
        "code": "invalid_submission_id",
        "message": "submissionId does not match the shape ATLAS ever issues."
      },
      {
        "code": "invalid_top_n",
        "message": "top_n is outside the supported range.",
        "hint": "Use an integer from 1 through 10."
      },
      {
        "code": "invalid_url",
        "message": "That URL is not parseable or valid.",
        "hint": "Must be http:// or https://"
      },
      {
        "code": "ledger_unavailable",
        "message": "The confidence ledger store is unavailable."
      },
      {
        "code": "maintenance_auth_unconfigured",
        "message": "Maintenance trigger authentication is not configured."
      },
      {
        "code": "maintenance_coordinator_unavailable",
        "message": "The durable maintenance coordinator is unavailable.",
        "hint": "Retry only with the original Idempotency-Key; a transport failure does not prove the run stopped."
      },
      {
        "code": "maintenance_run_in_progress",
        "message": "A maintenance run is already executing for this job and environment."
      },
      {
        "code": "maintenance_run_incomplete",
        "message": "At least one maintenance job did not complete successfully.",
        "hint": "Read the individual job verdicts; replay the same key to retrieve the stored result without repeating work."
      },
      {
        "code": "maintenance_run_uncertain",
        "message": "The prior maintenance run has an uncertain outcome.",
        "hint": "Inspect the original provider and job receipts; elapsed time does not authorize another execution."
      },
      {
        "code": "maintenance_schedule_time_required",
        "message": "A scheduled maintenance event requires a valid scheduledTime."
      },
      {
        "code": "maintenance_status_unavailable",
        "message": "Scheduled maintenance execution could not be observed."
      },
      {
        "code": "maintenance_store_unavailable",
        "message": "The durable maintenance state could not be read or claimed."
      },
      {
        "code": "maintenance_unauthorized",
        "message": "The maintenance trigger token was not accepted."
      },
      {
        "code": "method_not_allowed",
        "message": "This endpoint does not serve that HTTP method.",
        "hint": "Use the method named in the Allow header."
      },
      {
        "code": "not_found",
        "message": "No route matches this path.",
        "hint": "Read /agents.json for the route manifest."
      },
      {
        "code": "outcome_replay_unavailable",
        "message": "The durable outcome store is unavailable, so idempotent replay cannot be verified."
      },
      {
        "code": "path_id_and_status_required",
        "message": "Both pathId and status are required."
      },
      {
        "code": "path_id_required",
        "message": "A pathId is required."
      },
      {
        "code": "path_not_found",
        "message": "That verified path does not exist."
      },
      {
        "code": "path_not_in_ledger",
        "message": "The confidence ledger has no snapshots for this path yet."
      },
      {
        "code": "paths_not_found",
        "message": "None of the requested path ids exist."
      },
      {
        "code": "payload_too_large",
        "message": "The request body exceeds the accepted size.",
        "hint": "Bodies are capped at 64KB."
      },
      {
        "code": "rate_limited",
        "message": "Too many requests.",
        "hint": "Retry after the Retry-After header value."
      },
      {
        "code": "rate_limiter_unavailable",
        "message": "The rate limiter backing this endpoint is not available; the request was refused rather than served unthrottled."
      },
      {
        "code": "reason_required",
        "message": "A reason is required."
      },
      {
        "code": "receipt_and_signature_required",
        "message": "Both receipt and signature are required."
      },
      {
        "code": "receipt_secret_misconfigured",
        "message": "The receipt signing secret is absent or unusable, so no signed receipt can be produced."
      },
      {
        "code": "receipt_signing_unavailable",
        "message": "Receipt signing is not configured on this deployment."
      },
      {
        "code": "redirect_no_location",
        "message": "The target returned a redirect without a Location header."
      },
      {
        "code": "review_reason_required",
        "message": "Publishing a verification requires a written reason.",
        "hint": "The reason is recorded in the immutable audit trail; “approve” is not a reason."
      },
      {
        "code": "revision_requires_acknowledged_review",
        "message": "A public claim revision requires an acknowledged human review.",
        "hint": "Acknowledge the evidence review before attaching a public claim revision."
      },
      {
        "code": "server_busy",
        "message": "The MCP server has reached its bounded pending-dispatch ceiling.",
        "hint": "Retry with backoff."
      },
      {
        "code": "submission_id_required",
        "message": "A submissionId is required."
      },
      {
        "code": "subscription_auth_required",
        "message": "This endpoint requires a subscription bearer token."
      },
      {
        "code": "subscription_auth_store_unavailable",
        "message": "The subscription auth store is unavailable."
      },
      {
        "code": "subscription_owner_mismatch",
        "message": "The authenticated subscriber does not own this resource."
      },
      {
        "code": "subscription_store_unavailable",
        "message": "The subscription store is unavailable."
      },
      {
        "code": "too_many_redirects",
        "message": "The target redirected more than 3 times."
      },
      {
        "code": "tool_execution_failed",
        "message": "The MCP tool raised an unexpected error."
      },
      {
        "code": "unknown_tool",
        "message": "No MCP tool with that name is registered.",
        "hint": "Read /agents.json for the live tool list."
      },
      {
        "code": "unsupported_content_type",
        "message": "The source returned a content type that the text snapshotter does not accept.",
        "hint": "Use a public text, JSON, XML, or XHTML source."
      }
    ]
  },
  "runtimeStatus": "/api/runtime/status",
  "persistenceReadiness": {
    "mode": "supabase",
    "status": "ready",
    "durableWrites": true,
    "requiredStore": "supabase",
    "criticalStores": [
      "entity-overrides",
      "admin-audit-log",
      "evidence-submissions",
      "outcomes",
      "path-subscriptions",
      "waitlist"
    ],
    "adapterReadyStores": [
      "waitlist",
      "outcomes",
      "path-subscriptions",
      "entity-overrides",
      "admin-audit-log",
      "evidence-submissions"
    ],
    "pendingStores": [],
    "statusEndpoint": "/api/runtime/status"
  },
  "x-api-routes": [
    {
      "id": "maintenance-public-status",
      "endpoint": "/maintenance/public-status",
      "methods": [
        "GET"
      ],
      "runtime": "cloudflare-worker",
      "authRequired": false,
      "safeToSmoke": false,
      "smokeSkipReason": "Worker-only public projection of scheduled execution receipts. Counts, timestamps and status only; smoke excluded and freshness expires after 26 hours. Configuration is not inferred from a receipt.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "maintenance-run",
      "endpoint": "/maintenance/run",
      "methods": [
        "POST"
      ],
      "runtime": "cloudflare-worker",
      "authRequired": true,
      "safeToSmoke": false,
      "smokeSkipReason": "Worker-only operator action; requires a Bearer trigger token, durable coordinator, and Idempotency-Key. Can send subscribed notifications. Use X-ATLAS-Maintenance-Delivery: suppress for mail-free checks; suppressed work remains partial.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "maintenance-bearer",
        "rateLimit": "durable-serialized",
        "durability": "durable-required",
        "retry": "idempotency-key",
        "sideEffect": "subscription-expiry-notifications-and-confidence-history",
        "idempotency": {
          "header": "Idempotency-Key",
          "minLength": 8,
          "maxLength": 200,
          "replayStatus": 200,
          "conflictStatus": 409
        }
      },
      "outputContract": null
    },
    {
      "id": "maintenance-status",
      "endpoint": "/maintenance/status",
      "methods": [
        "GET"
      ],
      "runtime": "cloudflare-worker",
      "authRequired": true,
      "safeToSmoke": false,
      "smokeSkipReason": "Worker-only authenticated operator receipt; never expose delivery or review details publicly.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "health",
      "endpoint": "/health",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "readiness",
      "endpoint": "/ready",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "path-deltas-batch",
      "endpoint": "/paths/deltas",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "path-delta",
      "endpoint": "/paths/{pathId}/delta",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "entities-list",
      "endpoint": "/entities",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "entity-overrides",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "entities-batch",
      "endpoint": "/entities/batch",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "entity-detail",
      "endpoint": "/entities/{entityId}",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "entity-overrides",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "entity-claim-revisions",
      "endpoint": "/entities/{entityId}/revisions",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "claim-revisions",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": {
        "appendOnly": true,
        "scoreEffect": "none",
        "privacy": "reviewer identity, private notes, and audit identifiers are never public"
      }
    },
    {
      "id": "admin-review",
      "endpoint": "/api/admin/review/{entityId}",
      "methods": [
        "POST"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "entity-overrides",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "admin-or-obelisk",
        "rateLimit": "required",
        "durability": "durable-required",
        "retry": "unsafe",
        "sideEffect": "verification-review-and-audit"
      },
      "outputContract": null
    },
    {
      "id": "admin-log",
      "endpoint": "/api/admin/log",
      "methods": [
        "GET"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "admin-audit-log",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "admin-evidence-queue",
      "endpoint": "/api/admin/evidence-queue",
      "methods": [
        "GET",
        "POST"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "evidence-submissions",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "admin-or-obelisk",
        "rateLimit": "admin-gated",
        "durability": "durable-required-production",
        "retry": "optimistic-single-transition",
        "sideEffect": "review-state-and-audit-only",
        "scoreEffect": "none",
        "verificationEffect": "none-acknowledged-is-not-verified"
      },
      "outputContract": null
    },
    {
      "id": "admin-status",
      "endpoint": "/api/admin/status",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "runtime-status",
      "endpoint": "/api/runtime/status",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "obelisk-verify",
      "endpoint": "/api/obelisk-verify",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": false,
      "smokeSkipReason": "External Obelisk IdP fetch; covered by auth-contract source checks without network.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public-exchange",
        "rateLimit": "required",
        "durability": "external-identity",
        "retry": "unsafe",
        "sideEffect": "identity-token-exchange"
      },
      "outputContract": null
    },
    {
      "id": "verified-paths-list",
      "endpoint": "/verified-paths",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "verified-path-detail",
      "endpoint": "/verified-paths/{pathId}",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "evidence-frontier",
      "endpoint": "/verified-paths/{pathId}/evidence-frontier",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": {
        "frontier": "EvidenceFrontier",
        "boundary": {
          "isScore": false,
          "isVerificationClaim": false,
          "submissionScoreEffect": "none-pending-human-review"
        }
      }
    },
    {
      "id": "evidence-list",
      "endpoint": "/evidence",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "evidence-submit",
      "endpoint": "/evidence/submit",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "evidence-submissions",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "durable-required",
        "retry": "idempotency-key",
        "sideEffect": "pending-human-review-evidence",
        "idempotency": {
          "header": "Idempotency-Key",
          "minLength": 8,
          "maxLength": 200,
          "replayStatus": 200,
          "conflictStatus": 409
        }
      },
      "outputContract": null
    },
    {
      "id": "evidence-submission-status",
      "endpoint": "/evidence/submissions/{submissionId}/status",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": false,
      "smokeSkipReason": "Requires an opaque id returned by a prior evidence submission; covered by the lifecycle privacy contract.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "evidence-status-snapshot",
      "endpoint": "/evidence/submissions/status",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": false,
      "smokeSkipReason": "Requires opaque ids returned by prior submissions; covered by the bounded lifecycle privacy contract.",
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "score-entity",
      "endpoint": "/scoring/entity/{entityId}",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "score-path",
      "endpoint": "/scoring/path/{pathId}",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "generate-route",
      "endpoint": "/routes/generate",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "stateless",
        "retry": "safe",
        "sideEffect": "none"
      },
      "outputContract": {
        "decisionTrace": "versioned unsigned selection context; never a Trust Graph score, signed receipt, or verification claim",
        "authoritativeEvidence": "selected route links to the signed receipt and receipt-verification endpoints"
      }
    },
    {
      "id": "generate-receipt",
      "endpoint": "/receipts/generate",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "stateless",
        "retry": "safe",
        "sideEffect": "none"
      },
      "outputContract": null
    },
    {
      "id": "signed-path-receipt",
      "endpoint": "/paths/{pathId}/receipt",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": {
        "receipt": "version 2 signed path envelope; freshness.decision must be allow and freshness.validUntil must be current before using freshness.routeConfidence; block carries routeConfidence=null",
        "signature": "HMAC-SHA256 over the exact receipt object; legacy version 1 receipts remain verifiable but are not generated"
      }
    },
    {
      "id": "remote-mcp",
      "endpoint": "/mcp",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "stateless",
        "retry": "safe",
        "sideEffect": "none"
      },
      "outputContract": null
    },
    {
      "id": "verify-receipt",
      "endpoint": "/receipts/verify",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "stateless",
        "retry": "safe",
        "sideEffect": "none"
      },
      "outputContract": null
    },
    {
      "id": "outcomes",
      "endpoint": "/outcomes",
      "methods": [
        "GET",
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "outcomes",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "durable-required-production",
        "retry": "idempotency-key-strongly-recommended",
        "sideEffect": "outcome-ledger-write",
        "idempotency": {
          "header": "Idempotency-Key",
          "minLength": 8,
          "maxLength": 200,
          "replayStatus": 200,
          "conflictStatus": 409,
          "uncertainty": "retry-with-same-key",
          "conflict": "surface-and-require-new-key"
        }
      },
      "outputContract": {
        "post": {
          "required": [
            "outcome",
            "persistence.durable",
            "persistence.mode",
            "persistence.source"
          ],
          "persistence": {
            "modes": [
              "supabase",
              "memory"
            ],
            "durableWhen": "persistence.mode === 'supabase'"
          },
          "createdStatus": 201,
          "replayStatus": 200,
          "conflictStatus": 409,
          "replayHeader": "Idempotency-Replayed: true|false when Idempotency-Key is present",
          "replayBody": "replayed boolean when Idempotency-Key is present",
          "retryContract": {
            "created": "201: remove any queued draft; the outcome is accepted",
            "replayed": "200 with Idempotency-Replayed true: remove any queued draft; the original outcome is accepted",
            "conflict": "409: do not retry this payload with the same key; surface the conflict and require a new key",
            "rateLimited": "429: retain the queued draft and stable key; retry after Retry-After when present",
            "serverUnavailable": "5xx: retain the queued draft and stable key; retry with backoff",
            "transportUnknown": "network failure before a response: retain the queued draft and stable key because the server may have accepted it",
            "rejected": "other 4xx: do not queue or retry automatically; surface validation guidance"
          },
          "signedReceipt": "optional; present only when the receipt-signing capability is configured"
        }
      }
    },
    {
      "id": "outcome-aggregate",
      "endpoint": "/outcomes/aggregate/{pathId}",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "outcomes",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": {
        "successDenominator": "resolved outcomes only (completed + failed + replaced)",
        "pendingStates": [
          "saved",
          "used"
        ],
        "unknownStates": "counted separately and never coerced to failure"
      }
    },
    {
      "id": "outcome-aggregates",
      "endpoint": "/outcomes/aggregates",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": {
        "maxIds": 20,
        "consistency": "all aggregates derive from one outcome snapshot",
        "freshMode": "fresh=1 is explicitly no-store for read-after-write convergence"
      }
    },
    {
      "id": "outcome-summary",
      "endpoint": "/outcomes/summary",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "outcomes",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": {
        "successDenominator": "resolved outcomes only (completed + failed + replaced)",
        "resolutionDenominator": "all measured outcome states",
        "seedRows": "excluded from every public aggregate"
      }
    },
    {
      "id": "compare-paths",
      "endpoint": "/paths/compare",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "terrain-diff",
      "endpoint": "/terrain/diff",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "client-errors",
      "endpoint": "/api/errors",
      "methods": [
        "GET",
        "POST"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "ephemeral-memory",
        "store": "client-errors",
        "launchCritical": false,
        "note": "Writes live in process/isolate memory only and do not survive restarts."
      },
      "mutationPolicy": {
        "auth": "public-write-admin-read",
        "rateLimit": "required",
        "durability": "best-effort-observability",
        "retry": "safe-deduplicated",
        "sideEffect": "sanitized-error-log-append",
        "privacy": "server-redacts-secrets-email-and-local-paths",
        "receipt": "{ id, fingerprint, deduplicated, count }"
      },
      "outputContract": null
    },
    {
      "id": "contact-status",
      "endpoint": "/api/contact/status",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "contact-send",
      "endpoint": "/api/contact",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "external-email",
        "retry": "unsafe",
        "sideEffect": "transactional-email"
      },
      "outputContract": null
    },
    {
      "id": "popular-goals",
      "endpoint": "/api/popular-goals",
      "methods": [
        "GET"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "waitlist",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "subscription-challenge",
      "endpoint": "/api/subscription/challenge",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required-fail-closed",
        "durability": "durable-required-production",
        "retry": "unsafe",
        "sideEffect": "challenge-create-and-email"
      },
      "outputContract": null
    },
    {
      "id": "subscription-verify",
      "endpoint": "/api/subscription/verify",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "one-time-token",
        "rateLimit": "required",
        "durability": "durable-required-production",
        "retry": "unsafe",
        "sideEffect": "challenge-consume-and-session-create"
      },
      "outputContract": {
        "sessionToken": "opaque bearer returned once after one-time challenge succeeds",
        "expiresAt": "24-hour session expiry",
        "pendingPathId": "server-bound path intent from the consumed challenge"
      }
    },
    {
      "id": "subscription-revoke",
      "endpoint": "/api/subscription/revoke",
      "methods": [
        "POST"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "stateless-derived",
        "store": null,
        "launchCritical": false
      },
      "mutationPolicy": {
        "auth": "subscription-bearer",
        "rateLimit": "required",
        "durability": "durable-required-production",
        "retry": "safe",
        "sideEffect": "session-revoke"
      },
      "outputContract": {
        "revoked": "true only when the hashed server session was removed"
      }
    },
    {
      "id": "subscribe",
      "endpoint": "/api/subscribe",
      "methods": [
        "GET",
        "POST",
        "DELETE"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "path-subscriptions",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "subscription-bearer",
        "rateLimit": "required",
        "durability": "durable-required-production",
        "retry": "safe",
        "sideEffect": "subscription-upsert-or-delete"
      },
      "outputContract": null
    },
    {
      "id": "waitlist-insights",
      "endpoint": "/api/admin/waitlist/insights",
      "methods": [
        "GET"
      ],
      "authRequired": true,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "waitlist",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": null,
      "outputContract": null
    },
    {
      "id": "waitlist",
      "endpoint": "/api/waitlist",
      "methods": [
        "POST"
      ],
      "authRequired": false,
      "safeToSmoke": true,
      "smokeSkipReason": null,
      "durability": {
        "class": "durable-adapter",
        "store": "waitlist",
        "launchCritical": true,
        "note": "Writes persist via Supabase REST when runtime credentials are configured; memory fallback otherwise. Verify live via /api/runtime/status."
      },
      "mutationPolicy": {
        "auth": "public",
        "rateLimit": "required",
        "durability": "durable-preferred",
        "retry": "safe",
        "sideEffect": "waitlist-upsert-and-welcome-on-first-write"
      },
      "outputContract": null
    }
  ],
  "x-capabilities": [
    {
      "name": "maintenance-public-status",
      "description": "Manifest route: /maintenance/public-status (Worker-only public projection of scheduled execution receipts. Counts, timestamps and status only; smoke excluded and freshness expires after 26 hours. Configuration is not inferred from a receipt.)",
      "endpoint": "/maintenance/public-status",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "runtime": "cloudflare-worker"
    },
    {
      "name": "maintenance-run",
      "description": "Manifest route: /maintenance/run (Worker-only operator action; requires a Bearer trigger token, durable coordinator, and Idempotency-Key. Can send subscribed notifications. Use X-ATLAS-Maintenance-Delivery: suppress for mail-free checks; suppressed work remains partial.)",
      "endpoint": "/maintenance/run",
      "format": "application/json",
      "methods": [
        "POST"
      ],
      "runtime": "cloudflare-worker",
      "auth": "Authorization: Bearer <ATLAS maintenance trigger token> (operator only; Cloudflare Worker runtime)"
    },
    {
      "name": "maintenance-status",
      "description": "Manifest route: /maintenance/status (Worker-only authenticated operator receipt; never expose delivery or review details publicly.)",
      "endpoint": "/maintenance/status",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "runtime": "cloudflare-worker",
      "auth": "Authorization: Bearer <ATLAS maintenance trigger token> (operator only; Cloudflare Worker runtime)"
    },
    {
      "name": "health",
      "description": "Manifest route: /health",
      "endpoint": "/health",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "readiness",
      "description": "Manifest route: /ready",
      "endpoint": "/ready",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "path-deltas-batch",
      "description": "Manifest route: /paths/deltas",
      "endpoint": "/paths/deltas",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "path-delta",
      "description": "Manifest route: /paths/{pathId}/delta",
      "endpoint": "/paths/{pathId}/delta",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "entities-batch",
      "description": "Manifest route: /entities/batch",
      "endpoint": "/entities/batch",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "entity-detail",
      "description": "Manifest route: /entities/{entityId}",
      "endpoint": "/entities/{entityId}",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "entity-claim-revisions",
      "description": "Manifest route: /entities/{entityId}/revisions",
      "endpoint": "/entities/{entityId}/revisions",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "admin-review",
      "description": "Manifest route: /api/admin/review/{entityId}",
      "endpoint": "/api/admin/review/{entityId}",
      "format": "application/json",
      "methods": [
        "POST"
      ],
      "auth": "X-Obelisk-Session or X-Admin-Token"
    },
    {
      "name": "admin-log",
      "description": "Manifest route: /api/admin/log",
      "endpoint": "/api/admin/log",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "auth": "X-Obelisk-Session or X-Admin-Token"
    },
    {
      "name": "admin-evidence-queue",
      "description": "Manifest route: /api/admin/evidence-queue",
      "endpoint": "/api/admin/evidence-queue",
      "format": "application/json",
      "methods": [
        "GET",
        "POST"
      ],
      "auth": "X-Obelisk-Session or X-Admin-Token"
    },
    {
      "name": "admin-status",
      "description": "Manifest route: /api/admin/status",
      "endpoint": "/api/admin/status",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "runtime-status",
      "description": "Manifest route: /api/runtime/status",
      "endpoint": "/api/runtime/status",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "obelisk-verify",
      "description": "Manifest route: /api/obelisk-verify (External Obelisk IdP fetch; covered by auth-contract source checks without network.)",
      "endpoint": "/api/obelisk-verify",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "verified-path-detail",
      "description": "Manifest route: /verified-paths/{pathId}",
      "endpoint": "/verified-paths/{pathId}",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "evidence-frontier",
      "description": "Manifest route: /verified-paths/{pathId}/evidence-frontier",
      "endpoint": "/verified-paths/{pathId}/evidence-frontier",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "evidence-list",
      "description": "Manifest route: /evidence",
      "endpoint": "/evidence",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "evidence-submit",
      "description": "Manifest route: /evidence/submit",
      "endpoint": "/evidence/submit",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "evidence-submission-status",
      "description": "Manifest route: /evidence/submissions/{submissionId}/status (Requires an opaque id returned by a prior evidence submission; covered by the lifecycle privacy contract.)",
      "endpoint": "/evidence/submissions/{submissionId}/status",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "auth": "None — the opaque receipt id in the path or query is the capability"
    },
    {
      "name": "evidence-status-snapshot",
      "description": "Manifest route: /evidence/submissions/status (Requires opaque ids returned by prior submissions; covered by the bounded lifecycle privacy contract.)",
      "endpoint": "/evidence/submissions/status",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "auth": "None — the opaque receipt id in the path or query is the capability"
    },
    {
      "name": "score-entity",
      "description": "Manifest route: /scoring/entity/{entityId}",
      "endpoint": "/scoring/entity/{entityId}",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "score-path",
      "description": "Manifest route: /scoring/path/{pathId}",
      "endpoint": "/scoring/path/{pathId}",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "remote-mcp",
      "description": "Manifest route: /mcp",
      "endpoint": "/mcp",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "verify-receipt",
      "description": "Manifest route: /receipts/verify",
      "endpoint": "/receipts/verify",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "outcome-aggregate",
      "description": "Manifest route: /outcomes/aggregate/{pathId}",
      "endpoint": "/outcomes/aggregate/{pathId}",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "outcome-aggregates",
      "description": "Manifest route: /outcomes/aggregates",
      "endpoint": "/outcomes/aggregates",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "outcome-summary",
      "description": "Manifest route: /outcomes/summary",
      "endpoint": "/outcomes/summary",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "client-errors",
      "description": "Manifest route: /api/errors",
      "endpoint": "/api/errors",
      "format": "application/json",
      "methods": [
        "GET",
        "POST"
      ],
      "auth": "X-Obelisk-Session or X-Admin-Token"
    },
    {
      "name": "contact-status",
      "description": "Manifest route: /api/contact/status",
      "endpoint": "/api/contact/status",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "contact-send",
      "description": "Manifest route: /api/contact",
      "endpoint": "/api/contact",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "popular-goals",
      "description": "Manifest route: /api/popular-goals",
      "endpoint": "/api/popular-goals",
      "format": "application/json",
      "methods": [
        "GET"
      ]
    },
    {
      "name": "subscription-challenge",
      "description": "Manifest route: /api/subscription/challenge",
      "endpoint": "/api/subscription/challenge",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "subscription-verify",
      "description": "Manifest route: /api/subscription/verify",
      "endpoint": "/api/subscription/verify",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "subscription-revoke",
      "description": "Manifest route: /api/subscription/revoke",
      "endpoint": "/api/subscription/revoke",
      "format": "application/json",
      "methods": [
        "POST"
      ],
      "auth": "Authorization: Bearer <subscription session token>"
    },
    {
      "name": "subscribe",
      "description": "Manifest route: /api/subscribe",
      "endpoint": "/api/subscribe",
      "format": "application/json",
      "methods": [
        "GET",
        "POST",
        "DELETE"
      ],
      "auth": "Authorization: Bearer <subscription session token>"
    },
    {
      "name": "waitlist-insights",
      "description": "Manifest route: /api/admin/waitlist/insights",
      "endpoint": "/api/admin/waitlist/insights",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "auth": "X-Obelisk-Session or X-Admin-Token"
    },
    {
      "name": "waitlist",
      "description": "Manifest route: /api/waitlist",
      "endpoint": "/api/waitlist",
      "format": "application/json",
      "methods": [
        "POST"
      ]
    },
    {
      "name": "release-readiness",
      "description": "Machine-readable go/no-go release gate generated from PROJECT_STATUS without claiming launch approval. Read nextAgentActions before attempting launch-adjacent work.",
      "endpoint": "/release-gate.json",
      "format": "application/json",
      "methods": [
        "GET"
      ],
      "output": {
        "status": "go | blocked",
        "gateTaxonomy": "{ gates, founderOnly, credentialGated, agentAttemptable }",
        "nextAgentActions": "[{ rank, gateKey, gate, category, owner, action, safeToAttemptNow, blockedBy, sourceGates, agentProbe }]",
        "launchReadyPredicate": "{ blockersClear, remainingGatesClear, productionUrlConfigured, deployStatusProduction, stagingRedeployCurrent, durablePersistenceReady, migrationChannelReady, brandingCompliant, rateLimiterConfigured, mobileParityApproved }",
        "mobileParityEvidence": "{ structuralEvidence, visualReview, founderApproval, artifact, viewportEvidence, themeEvidence, gates, releaseApproved, blockingReasons }",
        "runtimeObservability": "{ statusEndpoint, rateLimiterConfigured, launchBlocking }"
      }
    },
    {
      "name": "get-route-for-goal",
      "description": "MCP one-call shortcut: natural-language goal to best route, evidence receipt, and ranked alternatives. Replaces 3 sequential MCP calls with one.",
      "tool": "atlas.get_route_for_goal",
      "protocol": "MCP v1",
      "input": {
        "goal": "string",
        "constraints": "string[] (concept keys - see recognizedConcepts)",
        "top_n": "number (optional, default 3)"
      },
      "output": {
        "route": "VerifiedPath",
        "receipt": "Receipt",
        "interpretedGoal": "{ budget, excluded, ambiguity, recommendedNextAction }",
        "rankedMatches": "[{ pathId, title, matchScore, matchReason, constraintsMet, constraintsUnmet, overBudget, budgetAssessment, matchEvidence, excludedHits, caveats }]",
        "decisionTrace": "{ schemaVersion, signed:false, fingerprint, selected, alternatives, authoritativeEvidence }"
      },
      "recognizedConcepts": [
        "affordable",
        "ai_image",
        "ai_music",
        "ai_video",
        "ai_voice",
        "animated",
        "api",
        "apiavailable",
        "audio",
        "avatar",
        "beginner",
        "beginner_to_intermediate",
        "budget",
        "business",
        "cinematic",
        "clip",
        "commercial",
        "commercial_rights",
        "copy",
        "developer",
        "footage",
        "illustration",
        "image",
        "music",
        "narration",
        "photo",
        "production",
        "professional",
        "sound",
        "soundtrack",
        "text",
        "trailer",
        "tts",
        "under",
        "video",
        "visual",
        "voice",
        "voiceover",
        "writing"
      ]
    }
  ]
}
