cAPI / Covenant

Connection should carry accountability, not bypass it.

cAPI is Veklom's governed connection layer between capability surfaces. It discovers and carries calls across service boundaries while keeping consequence authority and durable evidence anchored in the systems that actually own them.

Current classification
Mixed verification
MIXED

The canonical cAPI repository exposes a typed governed pipeline and local runtime on port 3003, including request, state, discovery, policy composition, audit and evidence-forwarding surfaces. Some seeded/demo runtime behavior in that repo should not be confused with external production proof.

Architectural role
Cross-service governed connection fabric
Owns
01Cross-service capability discovery and connection orchestration.
02Connection-level policy, request signing and replay-aware handling where implemented in the cAPI runtime.
03Local audit/evidence records for cAPI-observed calls and forwarding status into PGL when configured.
04A stable interlink layer so application integrations do not need to own Veklom authority logic themselves.
Boundary

Power stays narrow on purpose.

CAPPO remains the constitutional consequence-authority boundary.
A cAPI connection or local receipt does not automatically prove the external provider performed the claimed consequence.
PGL/Gnomledger remains the durable provenance store and VLink remains the low-friction portable connection primitive.
Interfaces

The surface should tell you where the truth comes from.

Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.

Canonical local port
3003
Governed request
POST /api/request
Discovery
GET /api/discover/{identity}
Audit / evidence
GET /api/audit · PGL forwarding when configured
Claim boundary

cAPI can truthfully show what it observed, signed and forwarded. The site must not upgrade seeded traffic, a successful connection or a local ledger entry into proof of an external real-world consequence without provider-side readback.