Capability OS
Authenticated tenant and workspace APIs are issued by BYOS. Browser traffic stays same-origin through the control plane so cookies and session validation do not depend on a separate CORS contract.
The API directory describes where each Veklom responsibility actually lives. It is intentionally not a giant undifferentiated REST catalog: authority, runtime, evidence, measurement and connection are separate because their trust boundaries are separate.
Authenticated tenant and workspace APIs are issued by BYOS. Browser traffic stays same-origin through the control plane so cookies and session validation do not depend on a separate CORS contract.
CAPPO owns the governed execution decision. Public product flows should reach this boundary instead of recreating authorization in the frontend.
cAPI and VLink connect systems without making a connection identifier equal authority.
Gnomledger/PGL persists provenance. EEE packages a single already-governed execution into a portable signed artifact.
VNP exposes evidence-labelled network and API telemetry. Missing measurements stay unverified instead of receiving a synthetic score.
LockerPhycer exposes its security/identity host boundary separately from BYOS and CAPPO.