{"openapi":"3.1.0","info":{"title":"Resilience Platform v1 security and routing contract","version":"2026-09-20","description":"Partial contract: runtime route and permission coverage. Not a complete payload schema or independent security attestation."},"servers":[{"url":"https:\/\/resilience.amartens.com"}],"paths":{"\/api\/v1\/compliance-status":{"get":{"summary":"GET \/api\/v1\/compliance-status","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-status\/cra":{"get":{"summary":"GET \/api\/v1\/compliance-status\/cra","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-status\/dora":{"get":{"summary":"GET \/api\/v1\/compliance-status\/dora","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-status\/iso-27001":{"get":{"summary":"GET \/api\/v1\/compliance-status\/iso-27001","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-status\/marisk":{"get":{"summary":"GET \/api\/v1\/compliance-status\/marisk","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-timeline":{"get":{"summary":"GET \/api\/v1\/compliance-timeline","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"platform-wide","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/compliance-timeline\/sync":{"post":{"summary":"POST \/api\/v1\/compliance-timeline\/sync","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"platform-wide","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/concentration-risk\/analyze":{"post":{"summary":"POST \/api\/v1\/concentration-risk\/analyze","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/concentration-risk\/breaches":{"get":{"summary":"GET \/api\/v1\/concentration-risk\/breaches","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/concentration-risk\/latest":{"get":{"summary":"GET \/api\/v1\/concentration-risk\/latest","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/concentration-risk\/thresholds":{"get":{"summary":"GET \/api\/v1\/concentration-risk\/thresholds","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}},"patch":{"summary":"PATCH \/api\/v1\/concentration-risk\/thresholds","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"requestBody":{"required":true,"content":{"application\/json":{"schema":{"type":"object","properties":{"provider_concentration_pct":{"type":"integer","minimum":1,"maximum":100},"sector_concentration_pct":{"type":"integer","minimum":1,"maximum":100},"regional_concentration_pct":{"type":"integer","minimum":1,"maximum":100},"technology_concentration_pct":{"type":"integer","minimum":1,"maximum":100},"review_frequency_days":{"type":"integer","minimum":30,"maximum":730},"enabled":{"type":["boolean","integer","string"],"enum":[true,false,0,1,"0","1"]}}}}}}}},"\/api\/v1\/dora\/measures":{"get":{"summary":"GET \/api\/v1\/dora\/measures","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/dora\/measures\/{id}":{"get":{"summary":"GET \/api\/v1\/dora\/measures\/{id}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"shared-reference-data","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"}}]}},"\/api\/v1\/findings":{"get":{"summary":"GET \/api\/v1\/findings","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/findings\/{id}":{"get":{"summary":"GET \/api\/v1\/findings\/{id}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"}}]}},"\/api\/v1\/keys":{"post":{"summary":"POST \/api\/v1\/keys","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"manage_keys","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"requestBody":{"required":true,"content":{"application\/json":{"schema":{"type":"object","required":["name"],"properties":{"name":{"type":"string","maxLength":255},"redirect_to":{"type":["string","null"],"enum":["profile","api-keys",null]}}}}}}}},"\/api\/v1\/programmes":{"get":{"summary":"GET \/api\/v1\/programmes","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/programmes\/{id}":{"get":{"summary":"GET \/api\/v1\/programmes\/{id}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"}}]}},"\/api\/v1\/test-cases":{"get":{"summary":"GET \/api\/v1\/test-cases","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/test-cases\/{id}":{"get":{"summary":"GET \/api\/v1\/test-cases\/{id}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"}}]}},"\/api\/v1\/vulnerability-scan\/latest":{"get":{"summary":"GET \/api\/v1\/vulnerability-scan\/latest","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"platform-wide","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}}},"\/api\/v1\/webhooks":{"get":{"summary":"GET \/api\/v1\/webhooks","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}}},"post":{"summary":"POST \/api\/v1\/webhooks","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"requestBody":{"required":true,"content":{"application\/json":{"schema":{"type":"object","properties":{"name":{"type":"string","maxLength":255},"channel":{"type":"string","enum":["slack","teams","email"]},"url":{"type":"string","format":"uri","maxLength":512,"description":"Must also pass the server-side channel destination allowlist."},"events":{"type":"array","minItems":1,"items":{"type":"string","enum":["finding.created","finding.status_changed","test_case.status_changed","deadline.approaching"]}}},"required":["name","channel","url","events"]}}}}}},"\/api\/v1\/webhooks\/{webhook}":{"get":{"summary":"GET \/api\/v1\/webhooks\/{webhook}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":null,"x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"webhook","in":"path","required":true,"schema":{"type":"string"}}]},"put":{"summary":"PUT \/api\/v1\/webhooks\/{webhook}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"webhook","in":"path","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application\/json":{"schema":{"type":"object","properties":{"name":{"type":"string","maxLength":255},"channel":{"type":"string","enum":["slack","teams","email"]},"url":{"type":"string","format":"uri","maxLength":512,"description":"Must also pass the server-side channel destination allowlist."},"events":{"type":"array","minItems":1,"items":{"type":"string","enum":["finding.created","finding.status_changed","test_case.status_changed","deadline.approaching"]}},"active":{"type":["boolean","integer","string"],"enum":[true,false,0,1,"0","1"]}}}}}}},"patch":{"summary":"PATCH \/api\/v1\/webhooks\/{webhook}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"webhook","in":"path","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application\/json":{"schema":{"type":"object","properties":{"name":{"type":"string","maxLength":255},"channel":{"type":"string","enum":["slack","teams","email"]},"url":{"type":"string","format":"uri","maxLength":512,"description":"Must also pass the server-side channel destination allowlist."},"events":{"type":"array","minItems":1,"items":{"type":"string","enum":["finding.created","finding.status_changed","test_case.status_changed","deadline.approaching"]}},"active":{"type":["boolean","integer","string"],"enum":[true,false,0,1,"0","1"]}}}}}}},"delete":{"summary":"DELETE \/api\/v1\/webhooks\/{webhook}","description":"Security and routing contract. Response payload schemas are not yet exhaustively specified. Tenant context is established by the API key. No API-wide idempotency, signed webhook delivery or complete business audit guarantee is asserted.","security":[{"BearerKey":[]},{"HeaderKey":[]}],"x-required-permission":"write","x-data-scope":"api-key-tenant","responses":{"2XX":{"description":"Successful operation; see endpoint documentation for payload."},"401":{"description":"Missing, invalid or expired API key."},"403":{"description":"Insufficient permission."},"404":{"description":"Resource unavailable in the applicable context."},"422":{"description":"Validation failed."},"429":{"description":"Rate limit exceeded."}},"parameters":[{"name":"webhook","in":"path","required":true,"schema":{"type":"string"}}]}}},"components":{"securitySchemes":{"BearerKey":{"type":"http","scheme":"bearer"},"HeaderKey":{"type":"apiKey","in":"header","name":"X-API-Key"}}}}