The same authority checks, through a different door.
A bounded API surface over the same application services, with antiforgery protection on mutations.
How it works
The optional versioned API runs in the existing web host and calls the same application services, using an ordinary authenticated session, current grants and workspace checks. Routes cover selected requirement, source, material, evidence, analysis, product, export, release and feedback operations.
Boundaries
Cross-origin access and an API-key bypass are not part of this contract. Other interface capabilities do not imply matching public routes.
Same-host versioned API
Element
Platform & access
Versioning
Expected versions
Human decision
No key bypass
Status
Implemented