Developer surface

One system. Explicit boundaries.

The API directory describes where each Veklom responsibility actually lives. It is intentionally not a giant undifferentiated REST catalog: authority, runtime, evidence, measurement and connection are separate because their trust boundaries are separate.

API domain

Capability OS

↗

Authenticated tenant and workspace APIs are issued by BYOS. Browser traffic stays same-origin through the control plane so cookies and session validation do not depend on a separate CORS contract.

/api/v1/auth/*
/api/v1/*
BYOS /health
BYOS /ready
API domain

Consequence authority

↗

CAPPO owns the governed execution decision. Public product flows should reach this boundary instead of recreating authorization in the frontend.

POST /v1/exec
/api/v1/cappo/*
execution evidence lookup
API domain

Connection

↗

cAPI and VLink connect systems without making a connection identifier equal authority.

cAPI :3003
VLink /.well-known/vlink.json
VLink /vlinks/{id}/v1
POST /receipts/verify
API domain

Evidence

↗

Gnomledger/PGL persists provenance. EEE packages a single already-governed execution into a portable signed artifact.

POST /api/v1/ledger/events
GET /api/v1/ledger/agents/{id}/verify
EEE offline verifier
API domain

Measurement

↗

VNP exposes evidence-labelled network and API telemetry. Missing measurements stay unverified instead of receiving a synthetic score.

GET /v1/vnp/methodology
GET /v1/vnp/metrics
/v1/vnp/beacon/routes
API domain

Host boundary

↗

LockerPhycer exposes its security/identity host boundary separately from BYOS and CAPPO.

LockerPhycer :8092
GET /health
local /docs when running
Rules of the API

The browser is not the authority kernel.

01Authentication and workspace state come from BYOS.
02Consequence authorization comes from CAPPO.
03Host-sensitive execution boundaries stay in LockerPhycer.
04Durable evidence belongs in PGL/Gnomledger; portable execution evidence belongs in EEE.
05Connection identifiers and transport routes never mint wider authority.