Reference

API reference

Organization-scoped JSON API at https://api.fidacy.com. Choose the surface that matches the control you need: assessment, authority, evidence, coverage, or operations.

Conventions

  • ·Authentication: Authorization: Bearer fky_… or x-api-key.
  • ·Scopes: a missing credential returns 401; an insufficient scope returns 403.
  • ·Public verification: JWKS, Trust List, transparency and verification endpoints do not use tenant credentials.
  • ·OpenAPI: /openapi.json is the machine-readable core reference. This documentation includes newer operational endpoints that may not yet be represented there.

Assessment

EndpointScopePurpose
POST /v1/assessassess:writeEvaluate an AP2 payment mandate or supported agent action and return a signed verdict.
GET /v1/assessments, /:idassess:readRead stored assessments.
GET /v1/mandates, /:idassess:readRead assessed payment mandates.

Assessment decisions are lowercase approve, review or deny. A valid signature establishes what Fidacy signed, not that an external rail executed the effect.

Action Authority

EndpointScopePurpose
POST /v1/action-mandatesassess:writeCreate bounded authority for a subject, action, resource and time window.
POST /v1/action-mandates/:id/decisionsassess:writeIssue an uppercase ALLOW or DENY decision; ALLOW can include a single-use grant.
POST /v1/action-grants/redeemassess:writeAtomically redeem a grant inside a connected executor.
GET /v1/action-decisions/:id/incident-packaudit:readExport the evidence for one action decision.

See Action Authority for exact request contracts and enforcement limits.

Identity and policy

Endpoint familyScopePurpose
/v1/principals, /v1/agents, /v1/agents/:id/keysagents:read / agents:writeRegister accountable principals, agent identities and key bindings.
POST /v1/agents/verify-cardagents:writeVerify an A2A Agent Card and its key binding.
/v1/policies, /activate, /backtestpolicy:read / policy:writeCreate, activate and backtest policy versions.
/v1/eval-sets, /v1/evals, /v1/evals/runpolicy:read / policy:writeBuild labeled evaluation sets and run evaluations.

Evidence and coverage

Endpoint familyScopePurpose
GET /v1/audit, /audit/verify, /audit/exportaudit:readRead, verify and export tenant audit records.
/v1/artifacts and /v1/verify/artifactartifact:write or assess:write; public verifyRegister a local SHA-256 and later verify its receipt and anchor state.
/v1/sessionsaudit:read, assess:write, session:write or artifact:writeIngest and retrieve chain-verified agent sessions.
/v1/control-coverageaudit:read or assess:writeExpose live observer signals, historic gate proof and evidence gaps.
GET /v1/control-coverage/reportaudit:readExport signed Control Coverage evidence with explicit disclosures.

Operations

Endpoint familyScopePurpose
/v1/api-keyskeys:read / keys:writeCreate, list and revoke API keys.
/v1/webhook-endpointswebhooks:read / webhooks:writeRegister and inspect signed webhook delivery.
/v1/billingassess:read / assess:writeRead plan, create checkout and manage a spending cap.

Safe integration rules

Do not infer approval from availability. A 4xx is a request, authentication or scope problem; a 5xx means Fidacy could not complete that request. For a consequential side effect, stop or use an explicit human fallback. Only a matching, unexpired grant redemption proves the connected executor accepted the gate.