Skip to content

Developer API reference

This is a catalog of published route shapes, not a blanket live-service claim. Current availability is authoritative only on /status.

For protocol, authentication, and client-compatibility evidence, use the separate MCP integration guide; a route catalog is not a client witness.

Observation — 2026-08-11

killinchu revision 83142da9 was AVAILABLE_AT_OBSERVATION at GET /api/killinchu/healthz (HTTP 200). a11oy revision f5c395e8 was provider RUNNING, but GET /healthz timed out at 20 s and 30 s: UNAVAILABLE. Hatun-MCP revision ebc78be2 was PAUSED; GET /readyz returned 503, quota 3/3: UNAVAILABLE. Do not infer authorization or client compatibility from a readiness probe.

Service catalog

ServiceBase hostReadiness routePublished route familiesCurrent state
a11oyhttps://szlholdings-a11oy.hf.space/healthz/api/a11oy/v1/*, /khipu/*, /mcp/UNAVAILABLE for readiness
killinchuhttps://szlholdings-killinchu.hf.space/api/killinchu/healthz/api/killinchu/v1/*, /khipu/*, /mcp/AVAILABLE_AT_OBSERVATION at the recorded probe only
Hatun-MCPhttps://szlholdings-hatun-mcp.hf.space/readyzserver card, Streamable HTTP MCPUNAVAILABLE; paused/quota blocked

https://a-11-oy.com is not treated as interchangeable with the a11oy Space in this reference: no custom-domain readiness/equivalence observation is carried by this release.

a11oy route shapes

MethodPathContract boundary
GET/healthzReadiness/liveness probe; timed out in the current observation.
GET/api/a11oy/v1/mcp/toolsREST tool discovery shape; not current-ready evidence.
POST/api/a11oy/v1/mcp/callGoverned tool-call shape; auth/response must be observed per deployment.
POST/khipu/signReceipt-envelope route shape; a route is not proof of a signer.
POST/khipu/verifyVerification route shape; do not expect verified:true without a fresh witness.
GET/khipu/pubkeyPublished key route shape; no current response is claimed.
GET/POST/mcp/Same-origin transport shape; client compatibility is separately unverified.

killinchu route shapes

MethodPathContract boundary
GET/api/killinchu/healthzThe only current successful public readiness probe in this release.
GET/api/killinchu/v1/honestHonesty disclosure route.
POST/api/killinchu/v1/remote-id/decodeDecoder route; input/result availability must be tested against the deployed revision.
POST/api/killinchu/v1/counter-uas/evaluateEvaluation route; output is decision support, not a safety or actuation authorization.
GET/api/killinchu/v1/lambdaLambda-gate definitions; Λ remains Conjecture 1.
GET/POST/mcp/Same-origin transport shape; no generic desktop-client support is claimed.

Authentication and receipt rules

No route in this document is an API-key issuance instruction. An unauthenticated HTTP 200 readiness result does not determine authorization for stateful routes. Hatun-MCP has historical API-key transport evidence, but it is paused and no authenticated current client session was witnessed. Use local, user-controlled credential flows only after a current operator path exists.

DSSE-PLACEHOLDER and UNSIGNED mean the receipt is not signed. A self-digest or hash chain can be independently recomputed for integrity, but cannot establish signer authenticity. Image signatures/provenance are separate immutable artifacts; see Compliance.

Roadmap

The standalone Provenance Anchor, Operator, Policy, GraphQL, and unified-SDK surfaces are ROADMAP / NOT DEPLOYED. Their previously documented routes and package names are not callable or installable claims.

Public claims link to source and evidence. SLSA L1 is the current stated supply-chain posture.