{"info":{"description":"Capability-based development runtime broker for authenticated Foundation CLI and hosted harness callers.","title":"Foundation credential broker","version":"0.0.0"},"openapi":"3.1.0","servers":[{"description":"Foundation credential broker API","url":"/api/v1"}],"components":{"schemas":{"CredentialServiceHealth":{"type":"object","properties":{"phase":{"type":"string","enum":["ready"]},"ready":{"type":"boolean","enum":[true]},"service":{"type":"string","enum":["foundation-credentials"]},"status":{"type":"string","enum":["ok"]}},"required":["phase","ready","service","status"]},"RuntimeAllocation":{"type":"object","properties":{"createdAt":{"type":"string","format":"date-time"},"expiresAt":{"type":"string","format":"date-time"},"githubRepositoryId":{"type":"string"},"id":{"type":"string","format":"uuid"},"provider":{"type":["string","null"]},"state":{"type":"string","enum":["requested","provisioning","active","expiring","revoking","revoked","failed","expired"]},"storeId":{"type":"string"},"updatedAt":{"type":"string","format":"date-time"}},"required":["createdAt","expiresAt","githubRepositoryId","id","provider","state","storeId","updatedAt"],"additionalProperties":false}},"parameters":{}},"paths":{"/health":{"get":{"description":"Reports that the credential service is ready.","operationId":"getCredentialServiceHealth","summary":"Get service health","tags":["Health"],"responses":{"200":{"description":"The credential service process is responding.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialServiceHealth"}}}}}}},"/runtime/doctor":{"post":{"description":"Reads the Development environment and models Neon variables without creating resources.","operationId":"inspectRepositoryRuntime","summary":"Inspect a repository development environment","tags":["Runtime"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false}},"required":["repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"The environment for strict validation with synthetic Neon values.","content":{"application/json":{"schema":{"type":"object","properties":{"targets":{"type":"array","items":{"type":"object","properties":{"environment":{"type":"object","additionalProperties":{"type":"string"}},"projectId":{"type":"string","pattern":"^prj_[A-Za-z0-9]+$"},"rootDirectories":{"type":"array","items":{"type":"string","minLength":1,"pattern":"^(?:\\.|(?![\\\\/])(?![A-Za-z]:[\\\\/])(?!.*(?:^|[\\\\/])\\.\\.(?:[\\\\/]|$))(?!.*[\\\\/]$).+)$"},"minItems":1},"syntheticVariables":{"type":"array","items":{"type":"string","pattern":"^[A-Za-z_][A-Za-z0-9_]*$"}}},"required":["environment","projectId","rootDirectories","syntheticVariables"],"additionalProperties":false},"minItems":1}},"required":["targets"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"409":{"description":"Configuration is invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"429":{"description":"The request was rate limited.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"503":{"description":"A provider is unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/runtime/database":{"post":{"description":"Replaces eligible Neon variables with new disposable database credentials and returns only those variables.","operationId":"resolveDatabaseCredentials","summary":"Resolve disposable Neon database credentials","tags":["Runtime"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"executionKey":{"type":"string","minLength":1,"maxLength":128},"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false},"requestedMinutes":{"type":"integer","minimum":1,"maximum":1440,"default":480}},"required":["executionKey","repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"Disposable Neon database credentials for each target.","content":{"application/json":{"schema":{"type":"object","properties":{"allocations":{"type":"array","items":{"type":"object","properties":{"expiresAt":{"type":"string","format":"date-time"},"id":{"type":"string","minLength":1},"storeId":{"type":"string","pattern":"^store_[A-Za-z0-9]+$"}},"required":["expiresAt","id","storeId"],"additionalProperties":false}},"targets":{"type":"array","items":{"type":"object","properties":{"environment":{"type":"object","additionalProperties":{"type":"string"}},"projectId":{"type":"string","pattern":"^prj_[A-Za-z0-9]+$"},"rootDirectories":{"type":"array","items":{"type":"string","minLength":1,"pattern":"^(?:\\.|(?![\\\\/])(?![A-Za-z]:[\\\\/])(?!.*(?:^|[\\\\/])\\.\\.(?:[\\\\/]|$))(?!.*[\\\\/]$).+)$"},"minItems":1}},"required":["environment","projectId","rootDirectories"],"additionalProperties":false}}},"required":["allocations","targets"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"409":{"description":"The database credentials could not be reconciled.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"429":{"description":"The allocation quota was exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"503":{"description":"A provider is temporarily unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/runtime":{"post":{"description":"Resolves every linked Vercel Development target and replaces eligible Neon variables with disposable credentials.","operationId":"resolveRepositoryRuntime","summary":"Resolve a repository development runtime","tags":["Runtime"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"executionKey":{"type":"string","minLength":1,"maxLength":128},"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false},"requestedMinutes":{"type":"integer","minimum":1,"maximum":1440,"default":480}},"required":["executionKey","repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"The complete in-memory repository runtime bundle.","content":{"application/json":{"schema":{"type":"object","properties":{"allocations":{"type":"array","items":{"type":"object","properties":{"expiresAt":{"type":"string","format":"date-time"},"id":{"type":"string","minLength":1},"storeId":{"type":"string","pattern":"^store_[A-Za-z0-9]+$"}},"required":["expiresAt","id","storeId"],"additionalProperties":false}},"targets":{"type":"array","items":{"type":"object","properties":{"environment":{"type":"object","additionalProperties":{"type":"string"}},"projectId":{"type":"string","pattern":"^prj_[A-Za-z0-9]+$"},"rootDirectories":{"type":"array","items":{"type":"string","minLength":1,"pattern":"^(?:\\.|(?![\\\\/])(?![A-Za-z]:[\\\\/])(?!.*(?:^|[\\\\/])\\.\\.(?:[\\\\/]|$))(?!.*[\\\\/]$).+)$"},"minItems":1}},"required":["environment","projectId","rootDirectories"],"additionalProperties":false},"minItems":1}},"required":["allocations","targets"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"409":{"description":"The runtime could not be reconciled.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"429":{"description":"The allocation quota was exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"503":{"description":"A provider is temporarily unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/allocations/{allocationId}":{"get":{"description":"Returns the sanitized state of one caller-owned disposable resource allocation.","operationId":"getRuntimeAllocation","summary":"Inspect a runtime allocation","tags":["Allocations"],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"allocationId","in":"path"}],"responses":{"200":{"description":"The caller-owned allocation state.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RuntimeAllocation"}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"404":{"description":"Allocation not found.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"409":{"description":"The allocation could not be inspected.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"503":{"description":"A provider is temporarily unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}},"delete":{"description":"Releases one caller-owned disposable resource allocation and its provider artifacts.","operationId":"releaseRuntimeAllocation","summary":"Release a runtime allocation","tags":["Allocations"],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"allocationId","in":"path"}],"responses":{"200":{"description":"The allocation has been released.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"state":{"type":"string","enum":["revoked"]}},"required":["id","state"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"404":{"description":"Allocation not found.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"409":{"description":"The allocation could not be released.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"503":{"description":"A provider is temporarily unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/auth/workload/bootstrap":{"post":{"description":"Issues a repository-bound Codex setup credential to an authorized developer.","operationId":"provisionCodexBootstrap","summary":"Provision a Codex bootstrap credential","tags":["Workload authentication"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false}},"required":["repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"A repository-bound Codex setup credential.","content":{"application/json":{"schema":{"type":"object","properties":{"credential":{"type":"string","minLength":1},"expiresAt":{"type":"string","format":"date-time"}},"required":["credential","expiresAt"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"500":{"description":"Credential creation failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/auth/workload/session":{"post":{"description":"Exchanges the setup-only Codex bootstrap credential for a short-lived, repository-bound materialization session.","operationId":"exchangeCodexBootstrap","summary":"Exchange a Codex bootstrap credential","tags":["Workload authentication"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false}},"required":["repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"A short-lived broker materialization session.","content":{"application/json":{"schema":{"type":"object","properties":{"expiresAt":{"type":"string","format":"date-time"},"token":{"type":"string","minLength":1}},"required":["expiresAt","token"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"500":{"description":"Session creation failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}},"/auth/registry/session":{"post":{"description":"Exchanges an authorized setup identity for a short-lived package registry session with repository audit context.","operationId":"createRegistrySession","summary":"Create a package registry session","tags":["Registry authentication"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"repository":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":100},"owner":{"type":"string","pattern":"^(?!-)(?!.*--)[A-Za-z\\d-]{1,39}(?<!-)$"}},"required":["name","owner"],"additionalProperties":false}},"required":["repository"],"additionalProperties":false}}}},"responses":{"200":{"description":"A short-lived package registry session.","content":{"application/json":{"schema":{"type":"object","properties":{"expiresAt":{"type":"string","format":"date-time"},"registry":{"type":"string","format":"uri"},"token":{"type":"string","minLength":1}},"required":["expiresAt","registry","token"],"additionalProperties":false}}}},"401":{"description":"Authentication failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"403":{"description":"Authorization failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}},"500":{"description":"Session creation failed.","content":{"application/json":{"schema":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"additionalProperties":false}}}}}}}},"webhooks":{}}