Reference
API reference
Organization-scoped JSON API at https://api.fidacy.com. Choose the surface that matches the control you need: assessment, authority, evidence, coverage, or operations.
Conventions
- ·Authentication:
Authorization: Bearer fky_…orx-api-key. - ·Scopes: a missing credential returns
401; an insufficient scope returns403. - ·Public verification: JWKS, Trust List, transparency and verification endpoints do not use tenant credentials.
- ·OpenAPI: /openapi.json is the machine-readable core reference. This documentation includes newer operational endpoints that may not yet be represented there.
Assessment
| Endpoint | Scope | Purpose |
|---|---|---|
POST /v1/assess | assess:write | Evaluate an AP2 payment mandate or supported agent action and return a signed verdict. |
GET /v1/assessments, /:id | assess:read | Read stored assessments. |
GET /v1/mandates, /:id | assess:read | Read assessed payment mandates. |
Assessment decisions are lowercase approve, review or deny. A valid signature establishes what Fidacy signed, not that an external rail executed the effect.
Action Authority
| Endpoint | Scope | Purpose |
|---|---|---|
POST /v1/action-mandates | assess:write | Create bounded authority for a subject, action, resource and time window. |
POST /v1/action-mandates/:id/decisions | assess:write | Issue an uppercase ALLOW or DENY decision; ALLOW can include a single-use grant. |
POST /v1/action-grants/redeem | assess:write | Atomically redeem a grant inside a connected executor. |
GET /v1/action-decisions/:id/incident-pack | audit:read | Export the evidence for one action decision. |
See Action Authority for exact request contracts and enforcement limits.
Identity and policy
| Endpoint family | Scope | Purpose |
|---|---|---|
/v1/principals, /v1/agents, /v1/agents/:id/keys | agents:read / agents:write | Register accountable principals, agent identities and key bindings. |
POST /v1/agents/verify-card | agents:write | Verify an A2A Agent Card and its key binding. |
/v1/policies, /activate, /backtest | policy:read / policy:write | Create, activate and backtest policy versions. |
/v1/eval-sets, /v1/evals, /v1/evals/run | policy:read / policy:write | Build labeled evaluation sets and run evaluations. |
Evidence and coverage
| Endpoint family | Scope | Purpose |
|---|---|---|
GET /v1/audit, /audit/verify, /audit/export | audit:read | Read, verify and export tenant audit records. |
/v1/artifacts and /v1/verify/artifact | artifact:write or assess:write; public verify | Register a local SHA-256 and later verify its receipt and anchor state. |
/v1/sessions | audit:read, assess:write, session:write or artifact:write | Ingest and retrieve chain-verified agent sessions. |
/v1/control-coverage | audit:read or assess:write | Expose live observer signals, historic gate proof and evidence gaps. |
GET /v1/control-coverage/report | audit:read | Export signed Control Coverage evidence with explicit disclosures. |
Operations
| Endpoint family | Scope | Purpose |
|---|---|---|
/v1/api-keys | keys:read / keys:write | Create, list and revoke API keys. |
/v1/webhook-endpoints | webhooks:read / webhooks:write | Register and inspect signed webhook delivery. |
/v1/billing | assess:read / assess:write | Read plan, create checkout and manage a spending cap. |
Safe integration rules
Do not infer approval from availability. A
4xx is a request, authentication or scope problem; a 5xx means Fidacy could not complete that request. For a consequential side effect, stop or use an explicit human fallback. Only a matching, unexpired grant redemption proves the connected executor accepted the gate.