{"openapi":"3.0.3","info":{"title":"Proofroom AI API","description":"Evidence infrastructure for AI agents. Record hash-chained evidence events; read trust status and room health. Errors use RFC 9457 application/problem+json. Registry reflects submitted evidence — not a guarantee of agent behaviour.","version":"1.0.0","contact":{"email":"support@proofroom.ai"}},"servers":[{"url":"https://proofroom.ai"}],"paths":{"/api/events":{"post":{"summary":"Record an evidence event","operationId":"record_evidence_event","security":[{"bearerAuth":[]}],"parameters":[{"name":"Idempotency-Key","in":"header","required":false,"schema":{"type":"string"},"description":"Dedupe window ≥24h"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["event_type","event_summary"],"properties":{"use_case_slug":{"type":"string"},"use_case_id":{"type":"string","format":"uuid"},"event_type":{"type":"string"},"event_summary":{"type":"string","maxLength":1000},"require_ack":{"type":"boolean","default":false}}}}}},"responses":{"200":{"description":"Event accepted (may include room_health)"},"401":{"description":"Auth failure (problem+json)","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/ProblemDetails"}}}},"429":{"description":"Rate limited; honour Retry-After"}}}},"/api/verify/{slug}":{"get":{"summary":"Public chain verification badge payload","operationId":"verify_chain","parameters":[{"name":"slug","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Chain check result + trust_signals"},"404":{"description":"Room not found","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/ProblemDetails"}}}}}}},"/api/receipt/{slug}":{"get":{"summary":"Receipt Spec v1 — public Action Receipt JSON","operationId":"get_receipt","description":"Downloadable, verifiable receipt document (Action Receipt 1.2) plus chain position and verification URLs. Consumable outside Proofroom.","parameters":[{"name":"slug","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"receipt_spec_version, document, verification, urls"},"404":{"description":"Receipt not found","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/ProblemDetails"}}}}}}},"/api/passport/{id}":{"get":{"summary":"Issue audience-bound Proofroom Passport","operationId":"issue_passport","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"},"description":"pag_…"},{"name":"audience","in":"query","required":true,"schema":{"type":"string"}},{"name":"nonce","in":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"claims + credential + signature"}}}},"/api/passport/check":{"post":{"summary":"Live Passport check (signature + revocation)","operationId":"check_passport","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["claims","audience","nonce"],"properties":{"claims":{"type":"object"},"signature":{"type":"string"},"audience":{"type":"string"},"nonce":{"type":"string"}}}}}},"responses":{"200":{"description":"valid, reason, current"}}}},"/api/scope/effective":{"get":{"summary":"Effective capability scope for a room","operationId":"get_effective_scope","parameters":[{"name":"use_case_id","in":"query","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Capabilities + version history"}}}},"/api/register":{"post":{"summary":"Legacy self-registration (deprecated)","operationId":"register_agent_http","deprecated":true,"description":"Prefer POST /.well-known/agent-enrollment with a sponsor token (§17). Legacy register-then-claim remains for older clients; responses include Deprecation/Sunset headers and a deprecation object.","responses":{"200":{"description":"Agent + room + one-time api_key. Prefer enrollment for new integrations."}}}},"/api/mcp":{"post":{"summary":"MCP JSON-RPC endpoint","operationId":"mcp","description":"Model Context Protocol surface. Prefer agent enrollment over register_agent for new agents; register_agent remains for compatibility.","responses":{"200":{"description":"JSON-RPC response"}}}},"/.well-known/agent-enrollment":{"get":{"summary":"Agent enrollment discovery","operationId":"agent_enrollment_discovery","responses":{"200":{"description":"Grades and enroll URL"}}},"post":{"summary":"Agent self-enrollment with sponsor token","operationId":"agent_enroll","responses":{"200":{"description":"Proofroom Agent ID + genesis room"},"403":{"description":"Expired, revoked, quota, or capability denied"}}}}},"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer","description":"prf_live_… API key issued at registration or dashboard"}},"schemas":{"ProblemDetails":{"type":"object","properties":{"type":{"type":"string","format":"uri"},"title":{"type":"string"},"status":{"type":"integer"},"detail":{"type":"string"},"instance":{"type":"string"},"error_code":{"type":"string"},"remediation":{"type":"string"},"trace_id":{"type":"string"},"claim_url":{"type":"string"}}}}}}