OUTCOME · Planned · Verify
What changes
None today: this route is not executable. Its intended behavior is: read-only projection; it grants no mutation, settlement, traffic, or authority change.
v2Identity · attestations
/api/v2/identity/attestations/subject/profile/{profile_uuid}/claimsThis page describes intended capability and integration boundaries so people and agents can prepare safely. Do not send this request or register it as an executable tool. Wait until the capability registry marks it implemented-contract, then re-fetch the deployed OpenAPI document and build the request from that machine contract.
PURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Do not call or register this operation as an executable agent tool yet. Use this page to plan the future manage subject claims workflow; enable it only after the status becomes implemented-contract and the exact operation appears in deployed OpenAPI.
OUTCOME · Planned · Verify
None today: this route is not executable. Its intended behavior is: read-only projection; it grants no mutation, settlement, traffic, or authority change.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema. This planning record grants no runtime authority, and only deployed OpenAPI can define an executable public contract.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
This operation is a non-executable planning contract. Its capability-registry record defines the intended owner, parameters, responses, and integration boundary until an implemented Rust OpenAPI operation replaces it.
EXTENDED INTEGRATION GUIDANCE
Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing trust:read authority.EXAMPLEBearer hc_live_…
profile_uuidpathRequiredidentifierCanonical profile uuid.EXAMPLEprofile-uuid-01
cursorqueryOptionalopaque stringCursor returned by the previous page.EXAMPLEeyJvZmZzZXQiOjUwfQ
limitqueryOptionalinteger · 1–200Maximum records to return.EXAMPLE50
statusqueryOptionalstringOptional lifecycle-state filter.EXAMPLEACTIVE
qqueryOptionalstring · max 200Optional application search term.EXAMPLEtreasury
RESPONSES
{
"result": "See the operation's authoritative OpenAPI response schema."
}{
"code": "request_failed",
"message": "Bearer credential is missing, expired, or invalid."
}request_failed{
"code": "request_failed",
"message": "The principal lacks the required scope, role, tenant, or step-up authority."
}request_failed{
"code": "request_failed",
"message": "Path, query, or body validation failed."
}request_failed{
"code": "request_failed",
"message": "The authoritative service or read model is unavailable."
}request_failedOPERATIONAL NOTES
This planned contract now defines its public parameters, authorization boundary, replay behavior, responses, and authoritative owner. It remains non-executable until its owner adapter and conformance tests are promoted into the Rust gateway.
Return to the V2 directory ↗