Endpoints
POST /v1/rpcfor request and response.GET /v1/ws(WebSocket upgrade) for subscriptions.
GET /healthz (process alive) and
GET /readyz (runtime ready). The authenticated health.* methods are separate.
Authentication
Send a bearer token on every HTTP request and on the WebSocket upgrade:Request and response envelope
data.code (a string, e.g. BUNDLE_MISMATCH), not on the numeric JSON-RPC
code. data also carries
details (per-code structured fields), retryable (a boolean), and correlation_id.
Pagination
List methods are cursor-based: passlimit (default 50, max 500 unless a method overrides it)
and cursor (omitted for the first page); the response returns next_cursor when more pages
exist. Offset pagination is not supported.
Idempotency
Mutating methods accept an optionalidempotency_key. The runtime stores the response keyed
by (method, token, key) for 24 hours. Replaying with the same key and body returns the
stored response; the same key with a different body returns IDEMPOTENCY_CONFLICT.
Versioning
The surface is under/v1/. Additive changes (new optional fields, new methods, new error
codes) stay in /v1/; breaking changes bump to /v2/. A deprecated /v1/ method stays
functional for at least one minor spec revision.
