Council of AI Public API
Keyless REST API for the GSPC measurement estate: the living board (GET /api/gspc, one axis via ?axis=), the quotable live state, axis register, methodology, signed-card and commission indexes, public root and Merkle inclusion proofs, corrections and press feeds, an Article 50 C2PA-marking detector, XRPL asset evidence, and ten x402-metered doors (request-attestation, proof bundle, evidence-bundle, eunomia-data, rwa/evidence, wrapper, art50/marking-evidence, feeds/provider-diff, receipts/batch, free-door at amount 0) that answer HTTP 402 with the price and a signed offer until paid in USDC on Base. 141 operations across 112 paths, OpenAPI 3.1.0, servers[] https://councilof.ai, CC-BY-4.0; 34 operations carry an x-csoai-lifecycle marker (quarantined / not implemented). A second, read-only 7-operation spec is served at /api/openapi.json.
GET
/api/a2a
POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
#
POST
/api/a2a
POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
#
GET
/api/action-jobs
/api/action-jobs — bounded, durable action-intent ledger staging.
#
PATCH
/api/action-jobs
/api/action-jobs — bounded, durable action-intent ledger staging.
#
POST
/api/action-jobs
/api/action-jobs — bounded, durable action-intent ledger staging.
#
GET
/api/art50/marking-evidence
CSOAI Article 50 marking evidenc
#
GET
/api/article50
POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&... — re-verifies a signature, statelessly.
#
POST
/api/article50
POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&... — re-verifies a signature, statelessly.
#
GET
/api/assess
POST /api/assess — a deterministic, text-only EU AI Act screening helper.
#
POST
/api/assess
POST /api/assess — a deterministic, text-only EU AI Act screening helper.
#
GET
/api/atlas
atlas — retired until its response can be derived from current evidence.
#
POST
/api/atlas
atlas — retired until its response can be derived from current evidence.
#
GET
/api/axis-register
GET /api/axis-register — the GSPC axis register (canonical scored rows).
#
GET
/api/bank-complete
/api/bank-complete — evidence-derived reader for the bank × chain × stablecoin census. Data is embedded at build time (zero-drift with public/interop/bank-registry.json).
#
GET
/api/benchmark-quality
The day every artifact cited in this file was actually fetched.
#
POST
/api/board-sign
POST /api/board-sign — GitHub OIDC only. Signs a card-v0 payload with Pages secret BOARD_SIGN_KEY_PKCS8_B64. The PKCS8 never leaves Cloudflare. Never logs the key. Not a grade.
#
GET
/api/body-state
/api/body-state — per-workflow last run / last success / last failure.
#
GET
/api/cards
GET /api/cards — live signed-measurement surface (G4 fix).
#
GET
/api/certificate-schema
GET /api/certificate-schema — the schema URL the issuer and the verifier agree on.
#
POST
/api/checkout
POST /api/checkout — public door is closed.
#
GET
/api/commission-queue
GET /api/commission-queue — mill-visible QUEUED intents.
#
GET
/api/commissions
GET /api/commissions — the open commission queue, read from the same store that holds the settlements (REVENUE_KV, `ras:` records written by /api/request-attestation).
#
GET
/api/compute
GET /api/compute — probe surface for the two-machine wire.
#
POST
/api/contact
POST /api/contact — the contact form. Fields stored verbatim when KV (LEADS) is bound; honest `stored:false` + fallback address when not. Nothing inferred, nothing forwarded to thi
#
GET
/api/counters
GET /api/counters — Wave-1 public-utility counters (EXP 005), derived from artifacts.
#
GET
/api/coverage
GET /api/coverage — one machine-readable lifecycle view over the estate.
#
GET
/api/coverage-truth
GET /api/coverage-truth — distiguish indexed, runnable, measured, signed.
#
GET
/api/decide
GET /api/decide — not implemented; no decision attestation is created.
#
GET
/api/detect
POST /api/detect — free Article 50 provenance VERIFICATION (EU AI Act 50(2)). GET /api/detect — service descriptor.
#
POST
/api/detect
POST /api/detect — free Article 50 provenance VERIFICATION (EU AI Act 50(2)). GET /api/detect — service descriptor.
#
GET
/api/detector-interop
GET /api/detector-interop — open, signed detector-interoperability matrix.
#
GET
/api/distribution-ledger
GET /api/distribution-ledger — one deduplicated list of every outward surface CSOAI has shipped to, with canonical URL, state, checked_at, and proof for each entry.
#
GET
/api/east-west-bench
#
GET
/api/embed
GET /api/embed — machine contract for the white-label kit. Counts are not typed here. The badge and embed.js read GET /api/gspc.
#
GET
/api/eu-ai-act
/api/eu-ai-act — evidence summary for the EU AI Act regime (Art 50, high-risk, GPAI). Obligation map is the same one the evidence-bundle assembler uses (see ./_obligations).
#
GET
/api/eunomia-data
Signed data feed (assembly + cadence)
#
GET
/api/evidence-bundle
Evidence bundle mapped to an obligation
#
POST
/api/evidence-intake
POST /api/evidence-intake — explicit candidate measurement intake.
#
GET
/api/fabric
GET /api/fabric -- normalized, read-only capability evidence.
#
GET
/api/feeds/provider-diff
Provider document diff feed (signed historical batch / bespoke partner feed)
#
GET
/api/files
files — retired until its response can be derived from current evidence.
#
POST
/api/files
files — retired until its response can be derived from current evidence.
#
GET
/api/fines
GET /api/fines — First-Fine Watch: signed coverage of the public AI enforcement record.
#
GET
/api/free-door
CSOAI Free Door
#
GET
/api/fulfill
GET /api/fulfill — public fulfillment door is closed.
#
GET
/api/growth-loops
/api/growth-loops — retired until loop status is derived from current evidence.
#
GET
/api/gspc
The PUBLIC view of the axes, and the count of axes that still carry a public leader.
#
GET
/api/hub-cards
An index either answered or it did not. `ok: true` with zero cells is a real, empty index — it has been read. Only `ok: false` is unread, and it always carries the reason, because
#
GET
/api/include
GET /api/include — not implemented; no Merkle inclusion proof is produced.
#
GET
/api/interop-bulk
GET /api/interop-bulk — metered bulk/replay access to signed interop surfaces.
#
GET
/api/lead
POST /api/lead — accepts the "email me the signed report" form.
#
POST
/api/lead
POST /api/lead — accepts the "email me the signed report" form.
#
GET
/api/learn-loop
/api/learn-loop — quarantined pre-release surface.
#
POST
/api/learn-loop
/api/learn-loop — quarantined pre-release surface.
#
GET
/api/learning-scenarios
#
GET
/api/mcp
GET /api/mcp — the MCP registry, served from a PROBED artifact.
#
GET
/api/memory
memory — retired until its response can be derived from current evidence.
#
POST
/api/memory
memory — retired until its response can be derived from current evidence.
#
GET
/api/observability
GET /api/observability — machine-readable estate health.
#
GET
/api/openapi.json
GET /api/openapi.json — an OpenAPI 3.1 description of the PUBLIC read endpoints that already exist, for ChatGPT / Custom-GPT Actions and any other schema importer.
#
GET
/api/operator
operator — retired until its response can be derived from current evidence.
#
POST
/api/operator
operator — retired until its response can be derived from current evidence.
#
GET
/api/otel
GET /api/otel — collector presence. LIVE only if a collector answers. Else UNCHECKABLE. Not a 23rd axis.
#
GET
/api/owasp-report
GET /api/owasp-report — OWASP LLM Top 10 ↔ GSPC axis coverage report.
#
GET
/api/paddle-webhook
POST /api/paddle-webhook — Paddle settlement webhook.
#
POST
/api/paddle-webhook
POST /api/paddle-webhook — Paddle settlement webhook.
#
GET
/api/pqc
GET /api/pqc — continuity mill vs estate signer. Not a 23rd axis. Continuity MEASURED ≠ we are PQC.
#
GET
/api/press.json
GET /api/press.json — what changed, with the command that proves each line.
#
GET
/api/prod-readiness
/api/prod-readiness — retired until readiness is derived from current evidence.
#
GET
/api/proof
CSOAI Proof Bundle
#
GET
/api/provider-canary
GET /api/provider-canary -- public configuration status; never probes. POST /api/provider-canary -- authenticated, fixed one-token capability canary.
#
POST
/api/provider-canary
GET /api/provider-canary -- public configuration status; never probes. POST /api/provider-canary -- authenticated, fixed one-token capability canary.
#
GET
/api/receipt-status
GET /api/receipt-status — current receipt issuance status.
#
GET
/api/receipts/batch
Receipts batch — historical measurement leaves for a window (assembly)
#
GET
/api/refund
POST /api/refund — record a refund or chargeback and revoke entitlement + cert.
#
POST
/api/refund
POST /api/refund — record a refund or chargeback and revoke entitlement + cert.
#
GET
/api/registers
GET /api/registers — unsigned static benchmark summaries.
#
GET
/api/regulation
GET /api/regulation — source-cited regulation deadline feed.
#
GET
/api/regulator-findings
#
GET
/api/reported
GET /api/reported — third-party figures we carry but did not measure.
#
POST
/api/reported
GET /api/reported — third-party figures we carry but did not measure.
#
GET
/api/request-attestation
Commission a signed card (request-attestation)
#
GET
/api/revenue
GET /api/revenue — the three-SKU revenue instrumentation (EXEC-A-REVENUE.md §5).
#
GET
/api/root
GET /api/root — alias of public/root.json. Same bytes the static door serves. Never a second forest.
#
GET
/api/router
/api/router — the bounded discovery + interop + packages router.
#
GET
/api/rwa/evidence
XRPL asset evidence card (per request)
#
GET
/api/sandbox
sandbox — retired until its response can be derived from current evidence.
#
POST
/api/sandbox
sandbox — retired until its response can be derived from current evidence.
#
GET
/api/specialists
GET /api/specialists — the signed specialist-team feed, served LIVE + pass-through.
#
GET
/api/state
GET /api/state — the ONE live state surface every lane quotes instead of asserting.
#
GET
/api/summary
GET /api/summary — one-shot media-briefing payload.
#
GET
/api/swift
GET /api/swift — reader of public/interop/swift-census.json. Three-state census tape (LIVE / COMMITTED / DISCOVERED). DISCOVERED-first, not MEASURED. Not a SWIFT client feed. write
#
GET
/api/synthesis
/api/synthesis — retired until mappings is derived from current evidence.
#
GET
/api/trace
Resolve one published card by exact SHA-256. This endpoint reads; it never mints.
#
POST
/api/trace
Resolve one published card by exact SHA-256. This endpoint reads; it never mints.
#
GET
/api/verify
POST /api/verify — verify a posted measurement card. GET explains how.
#
POST
/api/verify
POST /api/verify — verify a posted measurement card. GET explains how.
#
GET
/api/verify-batch
GET /api/verify-batch — not implemented; no cards are verified.
#
GET
/api/verify-card
GET /api/verify-card — not implemented; no card is verified.
#
GET
/api/wave-dashboard
#
DELETE
/api/webhooks
GET/POST /api/webhooks — webhook CRUD (in-memory + KV if bound). GET: returns array of { id, url, events, active, created_at } POST: creates new webhook with { url, events } DELETE
#
GET
/api/webhooks
GET/POST /api/webhooks — webhook CRUD (in-memory + KV if bound). GET: returns array of { id, url, events, active, created_at } POST: creates new webhook with { url, events } DELETE
#
POST
/api/webhooks
GET/POST /api/webhooks — webhook CRUD (in-memory + KV if bound). GET: returns array of { id, url, events, active, created_at } POST: creates new webhook with { url, events } DELETE
#
GET
/api/witness
/api/witness — quarantined paid witness surface.
#
POST
/api/witness
/api/witness — quarantined paid witness surface.
#
GET
/api/worker
GET /api/worker — the GPU worker's state, read from the pod's own health endpoint at request time.
#
GET
/api/wrapper
Wrapped-asset parity card (per pair)
#
GET
/api/x402
GET /api/x402 — the machine catalog of the metered rail. NO AMOUNTS HERE.
#
GET
/api/x402-trust-seller
GET /api/x402-trust-seller?host=
#
GET
/api/xrpl
GET /api/xrpl — reader of the committed public-root 16.
#
GET
/api/yield
GET /api/yield — the weekly yield dashboard (V3 brief G5.6).
#
Documentation
Specifications
Other Resources
Every API here is available over the APIs.io API and to AI agents over MCP.
components:
schemas:
X402Accept:
properties:
amount:
description: atomic units (x402 v2)
pattern: ^[0-9]+$
type: string
asset:
const: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
description: USDC contract, 6 decimals
type: string
extra:
description: EIP-712 domain of the asset
properties:
name:
type: string
version:
type: string
type: object
maxAmountRequired:
description: atomic units (x402 v1 name for the same figure)
pattern: ^[0-9]+$
type: string
maxTimeoutSeconds:
type: integer
network:
const: eip155:8453
description: CAIP-2
type: string
payTo:
const: '0x212686404A7D1E1fD88F35eD6200c3aF7A78ae31'
type: string
scheme:
const: exact
type: string
required:
- scheme
- network
- asset
- payTo
- amount
- maxTimeoutSeconds
type: object
X402PaymentRequired:
properties:
accepts:
items:
$ref: '#/components/schemas/X402Accept'
minItems: 1
type: array
error:
type: string
extensions:
description: extensions.bazaar carries info.input (a sample request) and schema (input/output JSON Schema). extensions['offer-receipt'].info.offers[]
carries one server-signed offer per accepts[] entry, format 'jws' — a compact EdDSA JWS whose payload is the offer
(x402 Offer & Receipt extension §4.1). It is present only when the edge holds its signing key; csoai.offer_receipt.signed
says which, and why, on every 402.
properties:
offer-receipt:
properties:
info:
properties:
offers:
items:
properties:
acceptIndex:
description: unsigned convenience field; match offers to accepts[] by payload fields, never by
index (§4.1.1)
type: integer
format:
const: jws
type: string
signature:
description: JWS compact serialization containing the offer payload
type: string
required:
- format
- signature
type: object
type: array
type: object
type: object
type: object
resource:
properties:
description:
type: string
mimeType:
type: string
serviceName:
type: string
tags:
items:
type: string
type: array
url:
type: string
type: object
x402Version:
const: 2
type: integer
required:
- x402Version
- accepts
type: object
securitySchemes:
ed25519:
description: Ed25519 signature of canonical body, under did:web:csoai.org#card-attestation-1
in: header
name: X-CSOAI-Signed-Card
type: apiKey
githubOidc:
bearerFormat: JWT
description: GitHub Actions OIDC token satisfying the handler's issuer, audience, repository and workflow checks.
scheme: bearer
type: http
operatorBearer:
description: Operation-specific configured operator or writer credential. Not interchangeable across operations.
scheme: bearer
type: http
info:
contact:
email: nicholas@csoai.org
name: CSOAI Ltd
url: https://councilof.ai/
description: 'Verification is free forever. Agents pay per artefact: issuance, assembly, cadence — never a grade. 22 axes
measured · 14 model fleets · 3 public leader scores · 8 fact runs · TIE is TIE · not a certificate. Operations with security
[] are free and unauthenticated. Operations with x-payment-info are x402 doors; an amount appears only inside a door''s
402 challenge (documented as each door''s 402 example).'
license:
name: CC-BY-4.0
url: https://creativecommons.org/licenses/by/4.0/
title: Council of AI — Public API
version: 0.2+820f7aa0ad7a
x-guidance: 'Free board: GET /api/gspc — quote totals.lid verbatim, never compose a count. Paid doors are the operations
carrying x-payment-info: GET without payment answers HTTP 402 with the x402 v2 challenge (accepts[0]: scheme exact, network
eip155:8453, USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0x212686404A7D1E1fD88F35eD6200c3aF7A78ae31); pay it
and retry with the X-PAYMENT header. Required query parameters carry an example that reaches the 402. Free previews are
named per door under x-csoai.free_preview. Catalog: https://councilof.ai/.well-known/x402.json and https://councilof.ai/api/x402.
Verify is free: https://councilof.ai/gspc-verify. Offer & Receipt emission is conditional: a 402 carries server-signed
offers only when the Pages signing key is available; a settled 200 carries a signed receipt only when settlement exposes
the required payer and transaction evidence and that key is available. The extension uses JWS/EdDSA, kid did:web:csoai.org#board-attestation-1,
published at https://csoai.org/.well-known/did.json. Check either without trusting this document: POST it to /api/receipts/verify,
or run scripts/verify_receipt.py, which reads did.json and contacts nobody. 22 axes measured · 14 model fleets · 3 public
leader scores · 8 fact runs · TIE is TIE · not a certificate.'
openapi: 3.1.0
paths:
/api/a2a:
get:
description: POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
operationId: get__api_a2a
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
post:
description: POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
operationId: post__api_a2a
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/a2a — the A2A v1.0 JSON-RPC binding that /.well-known/agent-card.json points at.
/api/action-jobs:
get:
description: Bare GET returns public contract metadata. Requests with job_id require writer bearer authorization; origin
restrictions still apply. /api/action-jobs — bounded, durable action-intent ledger staging.
operationId: get__api_action-jobs
responses:
'200':
content:
application/json: {}
description: OK
'401':
description: A job_id read requires an authorized writer bearer.
security:
- {}
- operatorBearer: []
summary: /api/action-jobs — bounded, durable action-intent ledger staging.
patch:
description: Configured writer bearer and exact same-origin Origin header required. /api/action-jobs — bounded, durable
action-intent ledger staging.
operationId: patch__api_action-jobs
responses:
'200':
content:
application/json: {}
description: OK
'401':
description: Required bearer credential missing or rejected.
security:
- operatorBearer: []
summary: /api/action-jobs — bounded, durable action-intent ledger staging.
post:
description: Configured writer bearer and exact same-origin Origin header required. /api/action-jobs — bounded, durable
action-intent ledger staging.
operationId: post__api_action-jobs
responses:
'200':
content:
application/json: {}
description: OK
'401':
description: Required bearer credential missing or rejected.
security:
- operatorBearer: []
summary: /api/action-jobs — bounded, durable action-intent ledger staging.
/api/agentic-fix:
get:
description: ''
operationId: get__api_agentic-fix
responses:
'503':
content:
application/json: {}
description: Unavailable — quarantined pre-release; no evidence is manufactured
summary: ''
x-csoai-lifecycle: QUARANTINED_PRE_RELEASE
post:
description: ''
operationId: post__api_agentic-fix
responses:
'503':
content:
application/json: {}
description: Unavailable — quarantined pre-release; no evidence is manufactured
summary: ''
x-csoai-lifecycle: QUARANTINED_PRE_RELEASE
/api/art50/marking-evidence:
get:
description: A signed card recording whether a machine-readable mark was detected in one named output, by named methods,
at one time. Detection, never a conformity opinion. preview=1 is free unsigned. Paid signed card requires url (HTTP
402).
operationId: x402_art50_marking_evidence
parameters:
- description: Public URL of the generative output to measure (≤ 20 MiB); or POST the bytes
example: https://councilof.ai/og-image.png
in: query
name: url
required: true
schema:
const: https://councilof.ai/og-image.png
type: string
- description: 1 = free unsigned measurement
in: query
name: preview
required: false
schema:
type: string
responses:
'200':
content:
application/json:
schema:
description: A signed card recording whether a machine-readable mark was detected in one named output, by
named methods, at one time. Detection, never a conformity opinion.
type: object
description: A signed card recording whether a machine-readable mark was detected in one named output, by named
methods, at one time. Detection, never a conformity opinion.
'402':
content:
application/json:
example:
accepts:
- amount: '10000'
asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
csoai_pricing:
campaign_id: csoai-launch-30d-20260911
ends_at: '2026-10-11T00:00:00Z'
fresh_compute_excluded: true
normal_amount_atomic: '25000000'
offered_amount_atomic: '10000'
pricing_basis: PROMO_EXISTING_DATA
product_id: csoai.product.art50_marking_evidence
sku_id: art50_marking_evidence
starts_at: '2026-09-11T00:00:00Z'
tier: pack
description: A signed card recording whether a machine-readable mark was detected in one named output, by
named methods, at one time. Detection, never a conformity opinion.
extra:
decimals: 6
name: USD Coin
symbol: USDC
version: '2'
maxAmountRequired: '10000'
maxTimeoutSeconds: 300
mimeType: application/json
network: eip155:8453
payTo: '0x212686404A7D1E1fD88F35eD6200c3aF7A78ae31'
resource: https://councilof.ai/api/art50/marking-evidence
scheme: exact
error: Payment required
extensions:
bazaar:
info:
input:
method: GET
queryParams:
url: https://councilof.ai/og-image.png
type: http
output:
example:
payload:
checked:
- method: c2pa.manifest-store
result: NOT_DETECTED
kind: csoai.art50.marking-evidence/0.1
statements:
- marking not detected by method c2pa.manifest-store
schema: https://councilof.ai/schema/card-v0.json
sig_ed25519: <hex or null>
surface: art50.marking-evidence
unmeasured:
- root_inclusion
- watermark.synthid
type: json
schema:
$schema: https://json-schema.org/draft/2020-12/schema
properties:
input:
additionalProperties: false
properties:
method:
enum:
- GET
- HEAD
- DELETE
type: string
queryParams:
properties:
preview:
description: 1 = free unsigned measurement
type: string
url:
description: Public URL of the generative output to measure (≤ 20 MiB); or POST the bytes
type: string
required:
- url
type: object
type:
const: http
type: string
required:
- type
- method
type: object
output:
properties:
example:
type: object
type:
type: string
required:
- type
type: object
required:
- input
type: object
offer-receipt:
info:
offers:
- acceptIndex: 0
format: jws
signature: eyJhbGciOiJFZERTQSIsImtpZCI6ImRpZDp3ZWI6Y3NvYWkub3JnI2JvYXJkLWF0dGVzdGF0aW9uLTEifQ.eyJhbW91bnQiOiIxMDAwMCIsImFzc2V0IjoiMHg4MzM1ODlmQ0Q2ZURiNkUwOGY0YzdDMzJENGY3MWI1NGJkQTAyOTEzIiwibmV0d29yayI6ImVpcDE1NTo4NDUzIiwicGF5VG8iOiIweDIxMjY4NjQwNEE3RDFFMWZEODhGMzVlRDYyMDBjM2FGN0E3OGFlMzEiLCJyZXNvdXJjZVVybCI6Imh0dHBzOi8vY291bmNpbG9mLmFpL2FwaS9hcnQ1MC9tYXJraW5nLWV2aWRlbmNlIiwic2NoZW1lIjoiZXhhY3QiLCJ2YWxpZFVudGlsIjoxNzg5MzE1MTc4LCJ2ZXJzaW9uIjoxfQ.JNBclDT1djyPZmETtHdWB5r2IUf-epi_l7VdIfHWXraeaITe-rT0R6s5sTbYZXYMcf1MrWMeydhzu8y6Wa2cAQ
schema:
$schema: https://json-schema.org/draft/2020-12/schema
properties:
offers:
items:
properties:
acceptIndex:
type: integer
format:
const: jws
type: string
signature:
description: JWS compact serialization containing the offer payload
type: string
required:
- format
- signature
type: object
type: array
required:
- offers
type: object
resource:
description: A signed card recording whether a machine-readable mark was detected in one named output, by
named methods, at one time. Detection, never a conformity opinion.
mimeType: application/json
serviceName: CSOAI Article 50 marking evidenc
tags:
- article-50
- c2pa
- marking
- measurement
- x402
url: https://councilof.ai/api/art50/marking-evidence
x402Version: 2
schema:
$ref: '#/components/schemas/X402PaymentRequired'
description: Payment required — the x402 v2 challenge. The same JSON is base64-encoded in the PAYMENT-REQUIRED response
header. Pay accepts[0] (scheme exact, network eip155:8453, USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo
0x212686404A7D1E1fD88F35eD6200c3aF7A78ae31; amount in atomic units) and retry the same request with the X-PAYMENT
header. Verification of the artefact stays free.
headers:
PAYMENT-REQUIRED:
description: base64(JSON) of this challenge body
schema:
type: string
summary: CSOAI Article 50 marking evidenc
tags:
- x402
- assembly
x-csoai:
challenge:
amount_source: captured live 402 (challenges/art50_marking_evidence.json)
captured: true
payment_required_header_bytes: 6924
door: https://councilof.ai/api/art50/marking-evidence?url=https://councilof.ai/og-image.png
free_preview: https://councilof.ai/api/art50/marking-evidence?url=https://councilof.ai/og-image.png&preview=1
paid_for: assembly
x-payment-info:
protocols:
- x402
/api/article50:
get:
description: POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&...
— re-verifies a signature, statelessly.
operationId: get__api_article50
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&...
— re-verifies a signature, statelessly.
post:
description: POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&...
— re-verifies a signature, statelessly.
operationId: post__api_article50
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/article50 — issues an Article 50 passport (free tier, HMAC-signed). GET /api/article50?verify=1&...
— re-verifies a signature, statelessly.
/api/assess:
get:
description: POST /api/assess — a deterministic, text-only EU AI Act screening helper.
operationId: get__api_assess
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/assess — a deterministic, text-only EU AI Act screening helper.
post:
description: POST /api/assess — a deterministic, text-only EU AI Act screening helper.
operationId: post__api_assess
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/assess — a deterministic, text-only EU AI Act screening helper.
/api/atlas:
get:
description: atlas — retired until its response can be derived from current evidence.
operationId: get__api_atlas
responses:
'503':
content:
application/json: {}
description: Unavailable — quarantined pre-release; no evidence is manufactured
summary: atlas — retired until its response can be derived from current evidence.
x-csoai-lifecycle: QUARANTINED_PRE_RELEASE
post:
description: atlas — retired until its response can be derived from current evidence.
operationId: post__api_atlas
responses:
'503':
content:
application/json: {}
description: Unavailable — quarantined pre-release; no evidence is manufactured
summary: atlas — retired until its response can be derived from current evidence.
x-csoai-lifecycle: QUARANTINED_PRE_RELEASE
/api/axis-register:
get:
description: GET /api/axis-register — the GSPC axis register (canonical scored rows).
operationId: get__api_axis-register
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/axis-register — the GSPC axis register (canonical scored rows).
/api/badge:
get:
description: ''
operationId: get__api_badge
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/bank-complete:
get:
description: /api/bank-complete — evidence-derived reader for the bank × chain × stablecoin census. Data is embedded
at build time (zero-drift with public/interop/bank-registry.json).
operationId: get__api_bank-complete
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: /api/bank-complete — evidence-derived reader for the bank × chain × stablecoin census. Data is embedded at
build time (zero-drift with public/interop/bank-registry.json).
/api/benchmark-quality:
get:
description: The day every artifact cited in this file was actually fetched.
operationId: get__api_benchmark-quality
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: The day every artifact cited in this file was actually fetched.
/api/board-sign:
post:
description: GitHub OIDC bearer required; token claims are validated by the handler. POST /api/board-sign — GitHub OIDC
only. Signs a card-v0 payload with Pages secret BOARD_SIGN_KEY_PKCS8_B64. The PKCS8 never leaves Cloudflare. Never
logs the key. Not a grade.
operationId: post__api_board-sign
responses:
'200':
content:
application/json: {}
description: OK
'401':
description: Required bearer credential missing or rejected.
security:
- githubOidc: []
summary: POST /api/board-sign — GitHub OIDC only. Signs a card-v0 payload with Pages secret BOARD_SIGN_KEY_PKCS8_B64.
The PKCS8 never leaves Cloudflare. Never logs the key. Not a grade.
/api/body-state:
get:
description: /api/body-state — per-workflow last run / last success / last failure.
operationId: get__api_body-state
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: /api/body-state — per-workflow last run / last success / last failure.
/api/cards:
get:
description: GET /api/cards — live signed-measurement surface (G4 fix).
operationId: get__api_cards
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/cards — live signed-measurement surface (G4 fix).
/api/certificate-schema:
get:
description: GET /api/certificate-schema — the schema URL the issuer and the verifier agree on.
operationId: get__api_certificate-schema
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/certificate-schema — the schema URL the issuer and the verifier agree on.
/api/challenge:
get:
description: ''
operationId: get__api_challenge
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
post:
description: ''
operationId: post__api_challenge
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/chat:
post:
description: ''
operationId: post__api_chat
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/checkout:
post:
description: POST /api/checkout — public door is closed.
operationId: post__api_checkout
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/checkout — public door is closed.
/api/clarity:
get:
description: ''
operationId: get__api_clarity
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/commission-queue:
get:
description: GET /api/commission-queue — mill-visible QUEUED intents.
operationId: get__api_commission-queue
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/commission-queue — mill-visible QUEUED intents.
/api/commissions:
get:
description: GET /api/commissions — the open commission queue, read from the same store that holds the settlements (REVENUE_KV,
`ras:<receipt sha>` records written by /api/request-attestation).
operationId: get__api_commissions
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/commissions — the open commission queue, read from the same store that holds the settlements (REVENUE_KV,
`ras:<receipt sha>` records written by /api/request-attestation).
/api/comparison:
get:
description: ''
operationId: get__api_comparison
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/compute:
get:
description: GET /api/compute — probe surface for the two-machine wire.
operationId: get__api_compute
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/compute — probe surface for the two-machine wire.
/api/contact:
post:
description: POST /api/contact — the contact form. Fields stored verbatim when KV (LEADS) is bound; honest `stored:false`
+ fallback address when not. Nothing inferred, nothing forwarded to third parties.
operationId: post__api_contact
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: POST /api/contact — the contact form. Fields stored verbatim when KV (LEADS) is bound; honest `stored:false`
+ fallback address when not. Nothing inferred, nothing forwarded to third parties.
/api/corpus-watch:
get:
description: ''
operationId: get__api_corpus-watch
responses:
'501':
content:
application/json:
example:
accepted: false
endpoint: /api/corpus-watch
persisted: false
schema: csoai.capability-state/0.1
signed: false
state: NOT_IMPLEMENTED
description: Not implemented — no input was accepted, persisted, or signed
summary: ''
x-csoai-lifecycle: NOT_IMPLEMENTED
post:
description: ''
operationId: post__api_corpus-watch
responses:
'501':
content:
application/json:
example:
accepted: false
endpoint: /api/corpus-watch
persisted: false
schema: csoai.capability-state/0.1
signed: false
state: NOT_IMPLEMENTED
description: Not implemented — no input was accepted, persisted, or signed
summary: ''
x-csoai-lifecycle: NOT_IMPLEMENTED
/api/corrections:
get:
description: ''
operationId: get__api_corrections
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/counters:
get:
description: GET /api/counters — Wave-1 public-utility counters (EXP 005), derived from artifacts.
operationId: get__api_counters
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/counters — Wave-1 public-utility counters (EXP 005), derived from artifacts.
/api/coverage:
get:
description: GET /api/coverage — one machine-readable lifecycle view over the estate.
operationId: get__api_coverage
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/coverage — one machine-readable lifecycle view over the estate.
/api/coverage-truth:
get:
description: GET /api/coverage-truth — distiguish indexed, runnable, measured, signed.
operationId: get__api_coverage-truth
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: GET /api/coverage-truth — distiguish indexed, runnable, measured, signed.
/api/cross:
get:
description: ''
operationId: get__api_cross
responses:
'200':
content:
application/json: {}
description: OK
security: []
summary: ''
/api/dashboard:
get:
description: ''
operationId: get__api_dashboard
responses:
'501':
content:
application/json:
example:
accepted: false
endpoint: /api/dashboard
persisted: false
schema: csoai.capability-state/0.1
signed: false
state: NOT_IMPLEMENTED
description: Not implemented — no input was accepted, persisted, or signed
summary: ''
x-csoai-lifecycle: NOT_IMPLEMENTED
post:
description: ''
operationId: post__api_dashboard
responses:
'501':
content:
application/json:
example:
accepted: false
endpoint: /api/dashboard
persisted: false
schema: csoai.capability-state/0.1
signed: false
state: NOT_IMPLEMENTED
description: Not implemented — no input was accepted, persisted, or signed
summary: ''
x-csoai-lifecycle: NOT_IMPLEMENTED
/api/decide:
get:
description: GET /api/decide — not implemented; no decision attestation is created.
operationId: get__api_decide
responses:
'501':
content:
application/json:
example:
accepted: false
endpoint: /api/decide
persisted: false
schema: csoai.capability-state/0.1
signed: false
state: NOT_IMPLEMENTED
description: Not implemented — no input was accepted, persisted, or signed
summary: GET /api/decide — not implemented; no decision attestation is created.
x-csoai-lifecycle: NOT_IMPLEMENTED
/api/detect:
get:
description: POST /api/detect — free Article 50 provenance VERIFICATION (EU AI Act 50(2)). GET /api/detect
# --- truncated at 32 KB (152 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/councilof-ai/refs/heads/main/openapi/councilof-ai-public-api-openapi.yml