OUTCOME · Planned · Discover
What changes
None today: this route is not executable. Its intended behavior is: read-only projection; it grants no mutation, settlement, traffic, or authority change.
v2Public entropy
/api/v2/entropy/transit-keysThis page describes intended capability and integration boundaries so people and agents can prepare safely. Do not send this request or register it as an executable tool. Wait until the capability registry marks it implemented-contract, then re-fetch the deployed OpenAPI document and build the request from that machine contract.
PURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Do not call or register this operation as an executable agent tool yet. Use this page to plan the future transit keys workflow; enable it only after the status becomes implemented-contract and the exact operation appears in deployed OpenAPI.
OUTCOME · Planned · Discover
None today: this route is not executable. Its intended behavior is: read-only projection; it grants no mutation, settlement, traffic, or authority change.
WHY IT MATTERS
ISOLATION + AUTHORITY
Caller authorization, nonce, requested byte count, physical source, source key, signed envelope, consumer conditioning, application randomness model, and downstream cryptographic use remain distinct. A valid source signature proves envelope provenance and integrity, not fitness for every cryptographic protocol or permission to perform a downstream action. This planning record grants no runtime authority, and only deployed OpenAPI can define an executable public contract.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
This operation is a non-executable planning contract. Its capability-registry record defines the intended owner, parameters, responses, and integration boundary until an implemented Rust OpenAPI operation replaces it.
EXTENDED INTEGRATION GUIDANCE
Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing entropy:read authority.EXAMPLEBearer hc_live_…
cursorqueryOptionalopaque account-key cursorCursor returned by the preceding subject-scoped key page.EXAMPLEeyJvZmZzZXQiOjUwfQ
limitqueryOptionalinteger · 1–200Maximum public-key records to return; defaults to 50.EXAMPLE50
statusqueryOptionalACTIVE | ROTATING | REVOKEDExact future account-key lifecycle filter.EXAMPLEACTIVE
RESPONSES
{
"result": "See the operation's authoritative OpenAPI response schema."
}{
"code": "request_failed",
"message": "Bearer credential is missing, expired, or invalid."
}request_failed{
"code": "request_failed",
"message": "The principal lacks the required scope, role, tenant, or step-up authority."
}request_failed{
"code": "request_failed",
"message": "Path, query, or body validation failed."
}request_failed{
"code": "request_failed",
"message": "The authoritative service or read model is unavailable."
}request_failedOPERATIONAL NOTES
This planned contract now defines its public parameters, authorization boundary, replay behavior, responses, and authoritative owner. It remains non-executable until its owner adapter and conformance tests are promoted into the Rust gateway.
Return to the V2 directory ↗