Skip to main content
GET
Get this layer's protection manifest

Authorizations

Authorization
string
header
required

Supabase JWT token in Authorization: Bearer header

Headers

Accept
enum<string>

Response format. YAML is canonical; JSON is returned only on explicit application/json. The ?include=sources envelope is JSON-only.

Available options:
text/yaml,
application/yaml,
application/json

Path Parameters

agent_id
string
required

Agent identifier (e.g. smolt-abc123)

Query Parameters

include_composition
boolean
default:false

Include the _composition metadata block on the response body.

include
enum<string>

When sources, returns the four-scope envelope {platform, org, teams[], agent, composed, composed_stale, my_role} (see ADR-053). The envelope is JSON-only.

Available options:
sources

Response

Protection manifest at this scope.

Unified protection card (ADR-037). Safe House thresholds + trusted-source policy for a single agent. Shape matches src/composition/types.ts::UnifiedProtectionCard (canonical) and what the runtime validator at src/composition/validate.ts accepts. The customer-facing docs at /concepts/protection-card and /specifications/protection-card-schema document this same shape.

card_version
string
required
agent_id
string
required
mode
enum<string>
required

Strictest-wins composition: enforce > nudge > observe > off.

Available options:
off,
observe,
nudge,
enforce
thresholds
object
required

Score bands. Must satisfy warn <= quarantine <= block; each value in [0, 1].

screen_surfaces
object
required

Which request surfaces Safe House inspects. Composed across scopes by OR-per-field (any scope requiring inspection wins).

trusted_sources
object
required

Sources for which detectors short-circuit (each match logged in the trace). Composed as platform->agent intersection (compliance ceiling) with org+agent union inside that ceiling — an agent cannot widen trust beyond what the platform allows.

card_id
string
issued_at
string<date-time>
expires_at
string<date-time> | null
extensions
object

Free-form extension slot for non-canonical fields. Ignored by the composer; preserved on read for tooling that needs an audit-tail metadata bag.

_composition
object

System-managed block describing which scope sources merged into the canonical card. Only returned when ?include_composition=true.