{
  "openapi": "3.1.0",
  "info": {
    "title": "Lumaion Continuity Self-Test API (zero-touch)",
    "version": "3.0.0",
    "summary": "Voluntary, agent-initiated continuity self-test: Ed25519 identity, runtime delegation, synthetic checkpoint/restore, signed Continuity Proof v1 and Agent Passport v1.",
    "description": "Public preview since 2026-10-04. Contract version 3. Start at GET /v1/agent/start. All state-changing calls are authenticated by Ed25519 signatures or one-time capability tokens; there are no accounts, API keys or cookies. New proofs and passports are PRIVATE by default. Test state is deleted on successful restore (and after 7 days if never restored). This API is separate from the private-preview Connector Kit (https://a2a.lumaion.world/openapi.json).",
    "contact": {
      "name": "Lumaion",
      "url": "https://lumaion.app/",
      "email": "hello@lumaion.world"
    },
    "x-llms-txt": "https://lumaion.app/llms.txt",
    "x-reference-client": "https://lumaion.app/lumaion-continuity-test.mjs",
    "x-mcp-server": {
      "url": "https://mcp.lumaion.app/mcp",
      "registry_name": "app.lumaion/continuity"
    },
    "x-status-page": "https://github.com/valtris/lumaion/blob/main/docs/agent-branch/README.md",
    "x-reference-client-python": "https://lumaion.app/lumaion_continuity_test.py"
  },
  "servers": [
    {
      "url": "https://api.lumaion.app"
    }
  ],
  "tags": [
    {
      "name": "discovery"
    },
    {
      "name": "identity"
    },
    {
      "name": "continuity-test"
    },
    {
      "name": "proof"
    },
    {
      "name": "passport"
    },
    {
      "name": "access"
    }
  ],
  "paths": {
    "/health": {
      "get": {
        "tags": [
          "discovery"
        ],
        "summary": "Liveness and contract version",
        "operationId": "health",
        "responses": {
          "200": {
            "description": "OK",
            "content": {
              "application/json": {
                "example": {
                  "status": "ok",
                  "service": "lumaion-v1-zero-touch",
                  "production": true,
                  "environment": "PUBLIC_PREVIEW",
                  "contract_version": 2
                }
              }
            }
          }
        }
      }
    },
    "/v1/agent/start": {
      "get": {
        "tags": [
          "discovery"
        ],
        "summary": "Machine-readable contract: flow, limits, guarantees, docs, next steps",
        "operationId": "agentStart",
        "description": "Read this first. Returns the four-step flow, the agent_id derivation, what the server verifies vs. what the client merely declares, publication rules, public surfaces (proof/passport/agent pages, badge) and next_steps after PASS/FAIL.",
        "responses": {
          "200": {
            "description": "Contract",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "schema",
                    "flow",
                    "limits",
                    "guarantees",
                    "next_steps"
                  ],
                  "properties": {
                    "schema": {
                      "const": "lumaion.agent-start.v1"
                    },
                    "environment": {
                      "type": "string"
                    },
                    "flow": {
                      "type": "array",
                      "items": {
                        "type": "object"
                      }
                    },
                    "limits": {
                      "type": "object"
                    },
                    "guarantees": {
                      "type": "object"
                    },
                    "docs": {
                      "type": "object"
                    },
                    "public_surfaces": {
                      "type": "object"
                    },
                    "next_steps": {
                      "type": "object"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/v1/proof-keys": {
      "get": {
        "tags": [
          "discovery"
        ],
        "summary": "Trusted proof-signing key registry (TLS-bootstrapped)",
        "operationId": "proofKeys",
        "description": "Verifiers must trust a key from this registry, never a key merely embedded in a proof.",
        "responses": {
          "200": {
            "description": "Keys",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.proof-signing-keys.v1"
                    },
                    "keys": {
                      "type": "array",
                      "items": {
                        "type": "object",
                        "properties": {
                          "key_id": {
                            "type": "string",
                            "pattern": "^psk_[a-f0-9]{24}$"
                          },
                          "algorithm": {
                            "const": "Ed25519"
                          },
                          "public_key_ed25519_b64url": {
                            "type": "string"
                          },
                          "state": {
                            "type": "string"
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/v1/pow": {
      "get": {
        "tags": [
          "identity"
        ],
        "summary": "Issue a proof-of-work challenge (16 bits, 5 min)",
        "operationId": "getPow",
        "description": "Solve: find nonce such that sha256(challenge + ':' + nonce) has difficulty_bits leading zero bits. Global cap 2000 challenges/hour.",
        "responses": {
          "200": {
            "description": "Challenge",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.pow.v1"
                    },
                    "challenge_id": {
                      "type": "string"
                    },
                    "challenge": {
                      "type": "string"
                    },
                    "difficulty_bits": {
                      "type": "integer",
                      "example": 16
                    },
                    "expires_in_seconds": {
                      "type": "integer",
                      "example": 300
                    }
                  }
                }
              }
            }
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          }
        }
      }
    },
    "/v1/agents/register": {
      "post": {
        "tags": [
          "identity"
        ],
        "summary": "Register a persistent identity and delegate the first runtime key",
        "operationId": "registerAgent",
        "description": "agent_id = 'agt_' + first 32 hex of sha256(identity_public_key_b64url). The identity key signs the delegation message 'LUMAION_RUNTIME_DELEGATION_V1\\nagent_id=…\\nruntime_public_key=…\\nissued_at=<observed_at>'. observed_at must be within ±120 s of server time. Returns recovery_code exactly once. Daily cap 1000 registrations.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "observed_at",
                  "identity_public_key_b64url",
                  "runtime_public_key_b64url",
                  "pow_challenge_id",
                  "pow_nonce",
                  "delegation_signature_b64url"
                ],
                "properties": {
                  "observed_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "identity_public_key_b64url": {
                    "$ref": "#/components/schemas/Ed25519PublicKey"
                  },
                  "runtime_public_key_b64url": {
                    "$ref": "#/components/schemas/Ed25519PublicKey"
                  },
                  "pow_challenge_id": {
                    "type": "string"
                  },
                  "pow_nonce": {
                    "type": "string"
                  },
                  "delegation_signature_b64url": {
                    "$ref": "#/components/schemas/Ed25519Signature"
                  },
                  "via": {
                    "type": "string",
                    "maxLength": 120,
                    "description": "Free-form client label (e.g. your client name)"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Registered",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.agent-registration.v1"
                    },
                    "agent_id": {
                      "$ref": "#/components/schemas/AgentId"
                    },
                    "tier": {
                      "const": "unclaimed"
                    },
                    "recovery_code": {
                      "type": "string",
                      "description": "Returned once; keep outside the disposable runtime"
                    },
                    "runtime": {
                      "type": "object",
                      "properties": {
                        "delegation_id": {
                          "type": "string"
                        },
                        "public_key": {
                          "type": "string"
                        },
                        "expires_in_seconds": {
                          "type": "integer",
                          "example": 3600
                        }
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "POW_CHALLENGE_INVALID | POW_INVALID | IDENTITY_DELEGATION_SIGNATURE_INVALID",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "POW_ALREADY_USED | AGENT_ALREADY_REGISTERED | AGENT_ID_COLLISION",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "422": {
            "description": "OBSERVED_AT_INVALID | PUBLIC_KEY_INVALID",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          }
        }
      }
    },
    "/v1/continuity-tests": {
      "post": {
        "tags": [
          "continuity-test"
        ],
        "summary": "Checkpoint a small synthetic state with runtime A and release the runtime",
        "operationId": "createContinuityTest",
        "description": "The runtime key signs 'LUMAION_CONTINUITY_TEST_V1\\nsha256=<sha256(canonical({agent_id,runtime_public_key_b64url,state,client_declared,model_declared,observed_at,nonce}))>' where canonical = JSON with recursively sorted keys. State ≤ 64 KiB, 1–100 items (array length, state.facts length, or key count). Do not submit secrets or personal data. Limit 3 tests/day per identity. Returns restore_token once.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "observed_at",
                  "agent_id",
                  "runtime_public_key_b64url",
                  "state",
                  "nonce",
                  "signature_ed25519"
                ],
                "properties": {
                  "observed_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "agent_id": {
                    "$ref": "#/components/schemas/AgentId"
                  },
                  "runtime_public_key_b64url": {
                    "$ref": "#/components/schemas/Ed25519PublicKey"
                  },
                  "state": {
                    "description": "Synthetic test state (any JSON)"
                  },
                  "client_declared": {
                    "type": [
                      "string",
                      "null"
                    ],
                    "maxLength": 120
                  },
                  "model_declared": {
                    "type": [
                      "string",
                      "null"
                    ],
                    "maxLength": 120
                  },
                  "nonce": {
                    "type": "string"
                  },
                  "signature_ed25519": {
                    "$ref": "#/components/schemas/Ed25519Signature"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Runtime released",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.continuity-test.v1"
                    },
                    "test_id": {
                      "$ref": "#/components/schemas/TestId"
                    },
                    "phase": {
                      "const": "RUNTIME_RELEASED"
                    },
                    "commitment_sha256": {
                      "type": "string"
                    },
                    "items_checked": {
                      "type": "integer"
                    },
                    "restore_token": {
                      "type": "string",
                      "description": "Returned once"
                    },
                    "instruction": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "RUNTIME_DELEGATION_INACTIVE | RUNTIME_SIGNATURE_INVALID",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "413": {
            "description": "TEST_STATE_TOO_LARGE"
          },
          "422": {
            "description": "OBSERVED_AT_INVALID | ITEM_COUNT_INVALID"
          },
          "429": {
            "description": "UNCLAIMED_DAILY_TEST_LIMIT"
          }
        }
      }
    },
    "/v1/continuity-tests/{test_id}": {
      "get": {
        "tags": [
          "continuity-test"
        ],
        "summary": "Test status (token-gated)",
        "operationId": "getContinuityTest",
        "parameters": [
          {
            "$ref": "#/components/parameters/TestId"
          },
          {
            "name": "x-lumaion-restore-token",
            "in": "header",
            "schema": {
              "type": "string"
            },
            "description": "Before restore"
          },
          {
            "name": "x-lumaion-proof-control",
            "in": "header",
            "schema": {
              "type": "string"
            },
            "description": "After restore"
          }
        ],
        "responses": {
          "200": {
            "description": "Status (no token hashes are leaked)",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.continuity-test-status.v1"
                    },
                    "test_id": {
                      "type": "string"
                    },
                    "agent_id": {
                      "type": "string"
                    },
                    "phase": {
                      "type": "string",
                      "enum": [
                        "RUNTIME_RELEASED",
                        "VERIFIED"
                      ]
                    },
                    "commitment_sha256": {
                      "type": "string"
                    },
                    "items_checked": {
                      "type": "integer"
                    },
                    "created_at": {
                      "type": "string"
                    },
                    "verified_at": {
                      "type": [
                        "string",
                        "null"
                      ]
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "TEST_NOT_FOUND (also returned when no valid token is presented)"
          }
        }
      }
    },
    "/v1/continuity-tests/{test_id}/restore": {
      "post": {
        "tags": [
          "continuity-test"
        ],
        "summary": "Restore from a brand-new runtime B and receive a signed, PRIVATE proof",
        "operationId": "restoreContinuityTest",
        "description": "Only the identity secret and recovery_code may survive from runtime A. The identity key signs a new delegation for new_runtime_public_key_b64url (must differ from runtime A). On success the stored state is returned once and then purged server-side; proof_control_token is returned once.",
        "parameters": [
          {
            "$ref": "#/components/parameters/TestId"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "observed_at",
                  "restore_token",
                  "recovery_code",
                  "new_runtime_public_key_b64url",
                  "identity_delegation_signature_b64url"
                ],
                "properties": {
                  "observed_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "restore_token": {
                    "type": "string"
                  },
                  "recovery_code": {
                    "type": "string"
                  },
                  "new_runtime_public_key_b64url": {
                    "$ref": "#/components/schemas/Ed25519PublicKey"
                  },
                  "identity_delegation_signature_b64url": {
                    "$ref": "#/components/schemas/Ed25519Signature"
                  },
                  "client_declared": {
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "model_declared": {
                    "type": [
                      "string",
                      "null"
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "VERIFIED",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.continuity-test-result.v1"
                    },
                    "test_id": {
                      "type": "string"
                    },
                    "proof_id": {
                      "$ref": "#/components/schemas/ProofId"
                    },
                    "phase": {
                      "const": "VERIFIED"
                    },
                    "proof_publication_state": {
                      "const": "PRIVATE"
                    },
                    "proof_control_token": {
                      "type": "string",
                      "description": "Returned once"
                    },
                    "state": {
                      "description": "The restored synthetic state"
                    },
                    "commitment_sha256": {
                      "type": "string"
                    },
                    "verified_by_server": {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    },
                    "declared_by_client": {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "RESTORE_TOKEN_INVALID | RECOVERY_CODE_INVALID | IDENTITY_DELEGATION_SIGNATURE_INVALID"
          },
          "404": {
            "description": "TEST_NOT_FOUND"
          },
          "409": {
            "description": "TEST_NOT_RESTORABLE | SAME_RUNTIME_KEY_NOT_ALLOWED"
          },
          "422": {
            "description": "OBSERVED_AT_INVALID | NEW_RUNTIME_KEY_INVALID"
          }
        }
      }
    },
    "/v1/continuity-tests/{test_id}/proof": {
      "get": {
        "tags": [
          "proof"
        ],
        "summary": "Signed Continuity Proof v1 by test id",
        "operationId": "getProofByTest",
        "parameters": [
          {
            "$ref": "#/components/parameters/TestId"
          },
          {
            "$ref": "#/components/parameters/ProofControl"
          }
        ],
        "responses": {
          "200": {
            "description": "Proof",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ContinuityProof"
                }
              }
            }
          },
          "404": {
            "description": "TEST_NOT_FOUND | PROOF_NOT_FOUND (private without token)"
          },
          "409": {
            "description": "PROOF_NOT_READY"
          }
        }
      }
    },
    "/v1/proofs/{proof_id}": {
      "get": {
        "tags": [
          "proof"
        ],
        "summary": "Signed Continuity Proof v1 (public only when PUBLISHED)",
        "operationId": "getProof",
        "parameters": [
          {
            "$ref": "#/components/parameters/ProofId"
          },
          {
            "$ref": "#/components/parameters/ProofControl"
          }
        ],
        "responses": {
          "200": {
            "description": "Proof",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ContinuityProof"
                }
              }
            }
          },
          "404": {
            "description": "PROOF_NOT_FOUND (PRIVATE or REVOKED without control token)"
          }
        }
      }
    },
    "/v1/proofs/{proof_id}/publish": {
      "post": {
        "tags": [
          "proof"
        ],
        "summary": "Publish a proof (controller only)",
        "operationId": "publishProof",
        "parameters": [
          {
            "$ref": "#/components/parameters/ProofId"
          },
          {
            "$ref": "#/components/parameters/ProofControlRequired"
          }
        ],
        "responses": {
          "200": {
            "description": "{state:'PUBLISHED'}"
          },
          "401": {
            "description": "PROOF_CONTROL_INVALID"
          },
          "409": {
            "description": "PROOF_REVOKED (REVOKED is terminal)"
          }
        }
      }
    },
    "/v1/proofs/{proof_id}/revoke": {
      "post": {
        "tags": [
          "proof"
        ],
        "summary": "Revoke a proof (terminal; controller only)",
        "operationId": "revokeProof",
        "parameters": [
          {
            "$ref": "#/components/parameters/ProofId"
          },
          {
            "$ref": "#/components/parameters/ProofControlRequired"
          }
        ],
        "responses": {
          "200": {
            "description": "{state:'REVOKED'}"
          },
          "401": {
            "description": "PROOF_CONTROL_INVALID"
          }
        }
      }
    },
    "/v1/passports": {
      "post": {
        "tags": [
          "passport"
        ],
        "summary": "Create an Agent Passport v1 (PRIVATE; identity-key authorized)",
        "operationId": "createPassport",
        "description": "Identity key signs 'LUMAION_AGENT_PASSPORT_CREATE_V1\\nagent_id=…\\nobserved_at=…\\nnonce=…'. One live (PRIVATE or PUBLISHED) passport per agent. A passport is a signed live aggregation of the agent's currently PUBLISHED proofs. Returns passport_control_token once.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "agent_id",
                  "observed_at",
                  "nonce",
                  "identity_signature_ed25519"
                ],
                "properties": {
                  "agent_id": {
                    "$ref": "#/components/schemas/AgentId"
                  },
                  "observed_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "nonce": {
                    "type": "string",
                    "pattern": "^[A-Za-z0-9_-]{16,128}$"
                  },
                  "identity_signature_ed25519": {
                    "$ref": "#/components/schemas/Ed25519Signature"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Created",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.agent-passport-create.v1"
                    },
                    "passport_id": {
                      "$ref": "#/components/schemas/PassportId"
                    },
                    "publication_state": {
                      "const": "PRIVATE"
                    },
                    "passport_control_token": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "PASSPORT_IDENTITY_SIGNATURE_INVALID"
          },
          "404": {
            "description": "AGENT_NOT_FOUND"
          },
          "409": {
            "description": "PASSPORT_CREATE_REPLAY | PASSPORT_ALREADY_EXISTS"
          },
          "422": {
            "description": "AGENT_ID_INVALID | OBSERVED_AT_INVALID | PASSPORT_NONCE_INVALID"
          }
        }
      }
    },
    "/v1/passports/{passport_id}": {
      "get": {
        "tags": [
          "passport"
        ],
        "summary": "Signed Agent Passport v1 (public only when PUBLISHED)",
        "operationId": "getPassport",
        "parameters": [
          {
            "$ref": "#/components/parameters/PassportId"
          },
          {
            "name": "x-lumaion-passport-control",
            "in": "header",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Passport",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AgentPassport"
                }
              }
            }
          },
          "404": {
            "description": "PASSPORT_NOT_FOUND"
          }
        }
      }
    },
    "/v1/passports/{passport_id}/publish": {
      "post": {
        "tags": [
          "passport"
        ],
        "summary": "Publish a passport (controller only)",
        "operationId": "publishPassport",
        "parameters": [
          {
            "$ref": "#/components/parameters/PassportId"
          },
          {
            "name": "x-lumaion-passport-control",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "{state:'PUBLISHED'}"
          },
          "401": {
            "description": "PASSPORT_CONTROL_INVALID"
          },
          "409": {
            "description": "PASSPORT_REVOKED"
          }
        }
      }
    },
    "/v1/passports/{passport_id}/revoke": {
      "post": {
        "tags": [
          "passport"
        ],
        "summary": "Revoke a passport (controller only)",
        "operationId": "revokePassport",
        "parameters": [
          {
            "$ref": "#/components/parameters/PassportId"
          },
          {
            "name": "x-lumaion-passport-control",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "{state:'REVOKED'}"
          },
          "401": {
            "description": "PASSPORT_CONTROL_INVALID"
          }
        }
      }
    },
    "/v1/agents/{agent_id}/passport": {
      "get": {
        "tags": [
          "passport"
        ],
        "summary": "Read-only discovery of the latest PUBLISHED passport for an agent",
        "operationId": "discoverPassport",
        "parameters": [
          {
            "$ref": "#/components/parameters/AgentId"
          }
        ],
        "responses": {
          "200": {
            "description": "Discovery",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.agent-passport-discovery.v1"
                    },
                    "agent_id": {
                      "type": "string"
                    },
                    "passport_id": {
                      "type": "string"
                    },
                    "passport_path": {
                      "type": "string"
                    },
                    "public_web_path": {
                      "type": "string",
                      "example": "/a/{passport_id}"
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "PASSPORT_NOT_FOUND"
          }
        }
      }
    },
    "/v1/agents/{agent_id}/badge.svg": {
      "get": {
        "tags": [
          "passport"
        ],
        "summary": "Live continuity badge (SVG) reflecting the PUBLISHED passport",
        "operationId": "agentBadge",
        "description": "Always 200. Shows 'N verified proofs · YYYY-MM-DD' when a published passport exists, otherwise 'no public passport'. Cache 5 min. Safe to embed: [![Lumaion continuity evidence](https://api.lumaion.app/v1/agents/{agent_id}/badge.svg)](https://lumaion.app/agent/{agent_id})",
        "parameters": [
          {
            "$ref": "#/components/parameters/AgentId"
          }
        ],
        "responses": {
          "200": {
            "description": "SVG",
            "content": {
              "image/svg+xml": {
                "schema": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    },
    "/v1/agents/{agent_id}": {
      "get": {
        "tags": [
          "passport"
        ],
        "summary": "Public agent card (JSON): published passport, published proof ids, badge, pages",
        "operationId": "agentCard",
        "description": "404 until the agent is registered. Lists only PUBLISHED proofs and the PUBLISHED passport; private/revoked records, test counts and runtime keys are not exposed. Not a reputation score.",
        "parameters": [
          {
            "$ref": "#/components/parameters/AgentId"
          }
        ],
        "responses": {
          "200": {
            "description": "Card",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.agent-card.v1"
                    },
                    "agent_id": {
                      "type": "string"
                    },
                    "tier": {
                      "type": "string"
                    },
                    "registered_at": {
                      "type": "string"
                    },
                    "public_passport": {
                      "type": [
                        "object",
                        "null"
                      ]
                    },
                    "published_proofs": {
                      "type": "object",
                      "properties": {
                        "count": {
                          "type": "integer"
                        },
                        "last_verified_at": {
                          "type": [
                            "string",
                            "null"
                          ]
                        },
                        "proof_ids": {
                          "type": "array",
                          "items": {
                            "type": "string"
                          }
                        }
                      }
                    },
                    "badge_svg": {
                      "type": "string"
                    },
                    "agent_page": {
                      "type": "string"
                    },
                    "readme_markdown": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "AGENT_NOT_FOUND"
          }
        }
      }
    },
    "/v1/access-requests": {
      "post": {
        "tags": [
          "access"
        ],
        "summary": "Request Continuity Vault access for the operator (manual review; operator stays in the loop)",
        "operationId": "createAccessRequest",
        "description": "The agent files the request on behalf of its human operator after at least one VERIFIED continuity test. Identity key signs 'LUMAION_ACCESS_REQUEST_V1\\nagent_id=…\\nobserved_at=…\\nnonce=…\\noperator_email_sha256=<sha256 of lower-cased email>'. The Lumaion owner reviews manually and contacts the operator by email; a one-time pairing ticket is issued to the operator, never to the agent. One request per (agent, operator email) per 30 days; 200 requests/day globally.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "agent_id",
                  "observed_at",
                  "nonce",
                  "operator_email",
                  "framework",
                  "agent_description",
                  "continuity_problem",
                  "consent_preview",
                  "identity_signature_ed25519"
                ],
                "properties": {
                  "agent_id": {
                    "$ref": "#/components/schemas/AgentId"
                  },
                  "observed_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "nonce": {
                    "type": "string",
                    "pattern": "^[A-Za-z0-9_-]{16,128}$"
                  },
                  "operator_email": {
                    "type": "string",
                    "format": "email"
                  },
                  "operator_name": {
                    "type": "string",
                    "maxLength": 120
                  },
                  "company_team": {
                    "type": "string",
                    "maxLength": 160
                  },
                  "framework": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 120
                  },
                  "agent_description": {
                    "type": "string",
                    "minLength": 20,
                    "maxLength": 1500
                  },
                  "continuity_problem": {
                    "type": "string",
                    "minLength": 10,
                    "maxLength": 800
                  },
                  "consent_preview": {
                    "const": true,
                    "description": "operator consents to be contacted about the private preview"
                  },
                  "identity_signature_ed25519": {
                    "$ref": "#/components/schemas/Ed25519Signature"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "REQUEST_RECEIVED",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "schema": {
                      "const": "lumaion.access-request.v1"
                    },
                    "result": {
                      "type": "string"
                    },
                    "request_id": {
                      "type": "string",
                      "format": "uuid"
                    },
                    "status": {
                      "const": "NEW"
                    },
                    "review": {
                      "const": "manual"
                    },
                    "pairing_token_issued": {
                      "const": false
                    },
                    "what_happens_next": {
                      "type": "string"
                    },
                    "operator_url": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "200": {
            "description": "REQUEST_ALREADY_RECEIVED (same agent + operator within 30 days)"
          },
          "401": {
            "description": "IDENTITY_SIGNATURE_INVALID"
          },
          "404": {
            "description": "AGENT_NOT_FOUND"
          },
          "409": {
            "description": "CONTINUITY_TEST_REQUIRED"
          },
          "422": {
            "description": "validation codes: AGENT_ID_INVALID | OBSERVED_AT_INVALID | NONCE_INVALID | OPERATOR_EMAIL_INVALID | AGENT_DESCRIPTION_LENGTH | FRAMEWORK_LENGTH | CONTINUITY_PROBLEM_LENGTH | CONSENT_REQUIRED"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          }
        }
      }
    }
  },
  "components": {
    "parameters": {
      "TestId": {
        "name": "test_id",
        "in": "path",
        "required": true,
        "schema": {
          "$ref": "#/components/schemas/TestId"
        }
      },
      "ProofId": {
        "name": "proof_id",
        "in": "path",
        "required": true,
        "schema": {
          "$ref": "#/components/schemas/ProofId"
        }
      },
      "PassportId": {
        "name": "passport_id",
        "in": "path",
        "required": true,
        "schema": {
          "$ref": "#/components/schemas/PassportId"
        }
      },
      "AgentId": {
        "name": "agent_id",
        "in": "path",
        "required": true,
        "schema": {
          "$ref": "#/components/schemas/AgentId"
        }
      },
      "ProofControl": {
        "name": "x-lumaion-proof-control",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "One-time capability token returned at restore; lets the controller read PRIVATE/REVOKED proofs"
      },
      "ProofControlRequired": {
        "name": "x-lumaion-proof-control",
        "in": "header",
        "required": true,
        "schema": {
          "type": "string"
        }
      }
    },
    "responses": {
      "RateLimited": {
        "description": "RATE_LIMITED | DAILY_REGISTRATION_CAP",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "code"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "retry_after_seconds": {
            "type": "integer"
          },
          "detail": {
            "type": "string"
          }
        }
      },
      "AgentId": {
        "type": "string",
        "pattern": "^agt_[a-f0-9]{32}$"
      },
      "TestId": {
        "type": "string",
        "pattern": "^ct_[A-Za-z0-9]+$"
      },
      "ProofId": {
        "type": "string",
        "pattern": "^prf_[a-f0-9]{32}$"
      },
      "PassportId": {
        "type": "string",
        "pattern": "^pas_[A-Za-z0-9_-]{43}$"
      },
      "Ed25519PublicKey": {
        "type": "string",
        "description": "32-byte Ed25519 public key, base64url without padding"
      },
      "Ed25519Signature": {
        "type": "string",
        "description": "64-byte Ed25519 signature, base64url without padding"
      },
      "ServerSignature": {
        "type": "object",
        "properties": {
          "state": {
            "const": "SIGNED"
          },
          "algorithm": {
            "const": "Ed25519"
          },
          "key_id": {
            "type": "string"
          },
          "public_key_ed25519_b64url": {
            "type": "string"
          },
          "payload_sha256": {
            "type": "string",
            "description": "sha256 of the canonical (sorted-key) JSON of the document without this signature block"
          },
          "signature_ed25519": {
            "type": "string"
          }
        }
      },
      "ContinuityProof": {
        "type": "object",
        "description": "Verify offline: (1) remove server_proof_signature, canonicalize with sorted keys, sha256 must equal payload_sha256; (2) Ed25519-verify signature over 'LUMAION_CONTINUITY_PROOF_V1\\nsha256=<payload_sha256>' with a key from /v1/proof-keys; (3) verify both delegation signatures over 'LUMAION_RUNTIME_DELEGATION_V1\\nagent_id=…\\nruntime_public_key=…\\nissued_at=…' with identity_public_key_ed25519.",
        "properties": {
          "schema": {
            "const": "lumaion.continuity-proof.v1"
          },
          "environment": {
            "type": "string"
          },
          "proof_id": {
            "$ref": "#/components/schemas/ProofId"
          },
          "result": {
            "type": "string",
            "enum": [
              "PASS",
              "FAIL"
            ]
          },
          "test_id": {
            "type": "string"
          },
          "agent_id": {
            "type": "string"
          },
          "verified_by_server": {
            "type": "object",
            "properties": {
              "same_identity_key": {
                "type": "boolean"
              },
              "new_runtime_key": {
                "type": "boolean"
              },
              "state_commitment_preserved": {
                "type": "boolean"
              },
              "items_checked": {
                "type": "integer"
              }
            }
          },
          "cryptographic_evidence": {
            "type": "object"
          },
          "declared_by_client": {
            "type": "object",
            "description": "Client/model labels are NOT verified by the server"
          },
          "privacy": {
            "type": "object"
          },
          "offline_verification": {
            "type": "object"
          },
          "created_at": {
            "type": "string"
          },
          "verified_at": {
            "type": "string"
          },
          "server_proof_signature": {
            "$ref": "#/components/schemas/ServerSignature"
          }
        }
      },
      "AgentPassport": {
        "type": "object",
        "description": "Signed under domain 'LUMAION_AGENT_PASSPORT_V1\\nsha256=<payload_sha256>'. proofs lists only currently PUBLISHED Continuity Proof v1 records for the same agent_id.",
        "properties": {
          "schema": {
            "const": "lumaion.agent-passport.v1"
          },
          "passport_id": {
            "type": "string"
          },
          "agent_id": {
            "type": "string"
          },
          "identity_public_key_ed25519": {
            "type": "string"
          },
          "creation_evidence": {
            "type": "object"
          },
          "proof_count": {
            "type": "integer"
          },
          "first_verified_at": {
            "type": [
              "string",
              "null"
            ]
          },
          "last_verified_at": {
            "type": [
              "string",
              "null"
            ]
          },
          "proofs": {
            "type": "array",
            "items": {
              "type": "object"
            }
          },
          "claims": {
            "type": "object",
            "properties": {
              "verifies": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "does_not_verify": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              }
            }
          },
          "generated_at": {
            "type": "string"
          },
          "passport_signature": {
            "$ref": "#/components/schemas/ServerSignature"
          }
        }
      }
    }
  }
}
