Core Control Center
dry_run preview_only provider_off execution_off
APIhttps://shikka.anoopampress.com/api Publichttps://shikka.anoopampress.com

Smart Shikka Core Control Center

Read-only preview dashboard — no real execution, no provider call

Overview

Local Service Name
smart-shikka-api.service
Local Port
37842
Route Count
54
Module Count
26
All Unsafe Flags
false

Core Structure Map

Static architecture view of the preview-only layers. No live execution or external call.

API Layer safe_preview Public/token-protected preview endpoints; no real execution.
MCP Read-only Layer safe_preview Calculator, knowledge search, report draft, status read previews.
Provider Registry Blocked Layer blocked_execution_preview Provider catalog and call-block preview; no SDK, no key, no outbound call.
Approval Bridge Preview Layer blocked_execution_preview Request/decision preview; real execution always blocked.
App Integration Layer app_integration_preview Smart Print and Drishti Kundali context envelopes; no mutation/payment/send.
Owner/Ops Dashboard Layer owner_ops_preview Owner panel metadata aggregator; no external call or real execution.
Control Center Layer safe_preview This static read-only shell; no script, no secret, no live env.

Route Explorer

54 routes in the preview contract index.

POST POST /v1/gateway/preview
Modulegateway_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
real_gateway_routingexternal_networkpaymentsend
Supported Actions
gateway_preview
Safe Example Payload
{
  "query": "Smart Print estimate preview",
  "dryRunOnly": true
}
GET GET /v1/gateway/observability/preview-status
Modulegateway_observability
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
external_observability_exportpersistent_event_store_write
Supported Actions
observability_status
Safe Example Payload
{}
GET GET /v1/gateway/observability/recent-events
Modulegateway_observability
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
external_observability_exportpersistent_event_store_write
Supported Actions
recent_events
Safe Example Payload
{
  "limit": 10
}
POST POST /v1/security/bumblebee/preview-ingest
Modulesecurity_inventory_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
real_remediationsecurity_rule_updateexternal_networkmutation
Supported Actions
preview_ingest
Safe Example Payload
{
  "lines": [
    "{\"event\":\"test\"}"
  ],
  "dryRunOnly": true
}
POST POST /v1/security/bumblebee/preview-alert
Modulesecurity_alert_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
whatsapp_sendgithub_issue_createdeploy_gate_changeexternal_network
Supported Actions
preview_alert
Safe Example Payload
{
  "alertType": "suspicious_token",
  "severity": "high"
}
POST POST /v1/mcp/read-only-tools/preview
Modulemcp_readonly_tools_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_network
Supported Actions
calculatorknowledge_searchreport_previewstatus_preview
Safe Example Payload
{
  "toolId": "calculator",
  "intent": "add",
  "userMessage": "2 + 2"
}
POST POST /v1/audit-store/preview
Moduleaudit_store_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
audit_writeaudit_exportaudit_retention_applypersistent_storage
Supported Actions
append_previewquery_previewsummary_preview
Safe Example Payload
{
  "eventType": "test_event",
  "dryRunOnly": true
}
POST POST /v1/memory-retrieval/preview
Modulememory_retrieval_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
memory_writevector_writeembedding_generationexternal_network
Supported Actions
memory_query_previewmemory_status_preview
Safe Example Payload
{
  "query": "customer order summary",
  "dryRunOnly": true
}
POST POST /v1/provider-registry/preview
Moduleprovider_registry_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
provider_callprovider_key_exposuresdk_initializationexternal_network
Supported Actions
catalog_previewenv_diagnostics_previewcapability_previewselect_previewcall_block_previewsummary_preview
Safe Example Payload
{
  "action": "catalog_preview"
}
POST POST /v1/approval-execution/preview
Moduleapproval_execution_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
approved_executionexecution_unlockruntime_bridge_openreal_execution
Supported Actions
Safe Example Payload
{
  "action": "request_preview",
  "requestedAction": "deploy"
}
POST POST /v1/assistant/orchestrator/preview
Moduleassistant_orchestrator_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
ai_inferenceprovider_callaction_executionexternal_network
Supported Actions
Safe Example Payload
{
  "action": "plan_preview",
  "userMessage": "What is the workflow?"
}
POST POST /v1/app-integration/preview
Moduleapp_integration_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
paymentsendcustomer_updateapp_mutationprovider_callexternal_network
Supported Actions
Safe Example Payload
{
  "action": "context_envelope",
  "appId": "smart_print"
}
POST POST /v1/owner-ops-dashboard/preview
Moduleowner_ops_dashboard_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
real_executionprovider_callexternal_networkmutationwrite
Supported Actions
dashboard_previewmodule_status_previewreadiness_score_previewblocker_summary_previewnext_actions_previewhealth_previewpolicy_check
Safe Example Payload
{
  "action": "dashboard_preview",
  "appId": "smart_print"
}
POST POST /v1/core/preview-contracts
Modulecore_preview_contract_index
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendreal_smoke_execution
Supported Actions
route_catalogmodule_catalogsmoke_pack_previewapp_contract_summarysafety_expectationssummarypolicy_check
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /settings/providers
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
Safe Example Payload
{}
GET GET /v1/core/provider-settings
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
Safe Example Payload
{}
POST POST /v1/core/provider-settings/preview
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Forbidden Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /knowledge
Moduleknowledge_rag_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/knowledge
Moduleknowledge_rag_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/knowledge/preview
Moduleknowledge_rag_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Supported Actions
status_previewhtml_previewsummarypolicy_checkupload_schema_previewchunking_previewredaction_previewretrieval_previewsource_catalog_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /memory
Modulememory_approval_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/memory
Modulememory_approval_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/memory/preview
Modulememory_approval_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Supported Actions
status_previewhtml_previewsummarypolicy_checkmemory_suggestion_previewapproval_flow_previewredaction_previewretention_policy_previewforget_flow_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /goose
Modulegoose_connector_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/goose
Modulegoose_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/goose/preview
Modulegoose_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
status_previewhtml_previewsummarypolicy_checkcommand_catalog_previewexecution_plan_previewapproval_flow_previewsandbox_policy_previewrollback_plan_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /browser-extension
Modulebrowser_extension_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/browser-extension
Modulebrowser_extension_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/browser-extension/preview
Modulebrowser_extension_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Supported Actions
status_previewhtml_previewsummarypolicy_checkpermission_catalog_previewpage_context_previewredaction_previewaction_draft_previewextension_manifest_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /messaging
Modulemessaging_connector_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/messaging
Modulemessaging_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/messaging/preview
Modulemessaging_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Supported Actions
status_previewhtml_previewsummarypolicy_checkchannel_catalog_previewinbound_message_previewredaction_previewreply_draft_previewsend_policy_previewwebhook_schema_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /
Modulepreview_apps_home_dashboard
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /apps
Modulepreview_apps_home_dashboard
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/apps
Modulepreview_apps_home_dashboard
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Supported Actions
status_previewroute_index_previewnavigation_preview
Safe Example Payload
{}
POST POST /v1/core/apps/preview
Modulepreview_apps_home_dashboard
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Supported Actions
status_previewhtml_previewsummarypolicy_checkapp_catalog_previewroute_index_previewnavigation_preview
Safe Example Payload
{
  "action": "policy_check"
}
GET GET /external-services
Moduleexternal_service_toolkit_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/external-services
Moduleexternal_service_toolkit_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/external-services/preview
Moduleexternal_service_toolkit_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
status_previewhtml_previewsummarypolicy_checkservice_catalog_previewtool_permission_previewprovider_selection_previewemail_validation_previewphone_validation_previewlocation_lookup_previewcurrency_rate_previewfile_upload_policy_previewscreenshot_policy_previewdocument_pdf_policy_previewcalendar_holidays_previewnotification_draft_previewredaction_preview
Safe Example Payload
{
  "action": "status_preview"
}
GET GET /research-engine
Moduleresearch_engine_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/research-engine
Moduleresearch_engine_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/research-engine/preview
Moduleresearch_engine_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Supported Actions
status_previewhtml_previewsummarypolicy_checkresearch_topic_previewsource_catalog_previewresearch_plan_previewreport_schema_previewsample_report_previewpython_worker_policy_previewapproval_flow_previewredaction_previewoutput_safety_preview
Safe Example Payload
{
  "action": "status_preview"
}
GET GET /approvals
Moduletool_approval_workflow_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/approvals
Moduletool_approval_workflow_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/approvals/preview
Moduletool_approval_workflow_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Supported Actions
status_previewhtml_previewsummarypolicy_checkapproval_matrix_previewconfirmation_request_previewrisk_assessment_previewowner_decision_previewapproval_receipt_previewblocked_action_previewnotification_confirmation_previewemail_confirmation_previewphone_confirmation_previewfile_upload_confirmation_previewscreenshot_confirmation_previewpdf_confirmation_previewresearch_confirmation_previewmessaging_send_confirmation_previewpayment_confirmation_previewredaction_preview
Safe Example Payload
{
  "action": "status_preview"
}
GET GET /execution-plans
Modulesafe_tool_execution_plan_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/execution-plans
Modulesafe_tool_execution_plan_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/execution-plans/preview
Modulesafe_tool_execution_plan_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Supported Actions
status_previewhtml_previewsummarypolicy_checkexecution_plan_previewtool_chain_previewpreflight_check_previewapproval_gate_previewadapter_selection_previewrollback_plan_previewaudit_plan_previewdry_run_result_previewblocked_execution_previewexternal_service_execution_previewmessaging_execution_previewfile_pdf_screenshot_execution_previewresearch_execution_previewpayment_mutation_execution_previewanshika_agent_execution_previewredaction_preview
Safe Example Payload
{
  "action": "status_preview"
}
GET GET /adapters
Moduletool_adapter_registry_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/adapters
Moduletool_adapter_registry_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/adapters/preview
Moduletool_adapter_registry_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Supported Actions
status_previewhtml_previewsummarypolicy_checkadapter_registry_previewcapability_router_previewadapter_family_previewtool_to_adapter_map_previewadapter_selection_previewadapter_preflight_previewadapter_permission_previewadapter_blocklist_previewexternal_service_adapter_previewmessaging_adapter_previewfile_pdf_screenshot_adapter_previewresearch_adapter_previewanshika_agent_adapter_previewpayment_adapter_block_previewredaction_preview
Safe Example Payload
{
  "action": "status_preview"
}
GET GET /policy-decisions
Modulepolicy_decision_api_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Forbidden Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepayment
Supported Actions
html_preview
Safe Example Payload
{}
GET GET /v1/core/policy-decisions
Modulepolicy_decision_api_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepayment
Supported Actions
status_preview
Safe Example Payload
{}
POST POST /v1/core/policy-decisions/preview
Modulepolicy_decision_api_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Forbidden Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepaymentpython_execution
Supported Actions
status_previewhtml_previewsummarypolicy_checkdecision_matrix_previewpolicy_decision_previewcapability_decision_previewapproval_requirement_previewexecution_plan_requirement_previewadapter_requirement_previewkey_requirement_previewcritical_block_previewanshika_policy_decision_previewexternal_service_policy_decision_previewmessaging_policy_decision_previewresearch_policy_decision_previewpayment_policy_decision_previewdecision_receipt_previewredaction_preview
Safe Example Payload
{
  "action": "status_preview"
}

Module Explorer

26 modules available.

Gateway Preview gateway_preview
Categorygateway
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Gateway preview does not route real traffic.
Gateway Observability gateway_observability
Categoryobservability
Readinessconfigured
Authauth required
Route Count2
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Observability is in-memory only; no external export.
Security Inventory Preview security_inventory_preview
Categorysecurity
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real remediation or security rule update.
Security Alert Preview security_alert_preview
Categorysecurity
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real WhatsApp/GitHub/create/deploy gate change.
MCP Read-only Tools Preview mcp_readonly_tools_preview
Categorytools
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Read-only tools preview only; no live MCP execution.
Audit Store Preview audit_store_preview
Categorypersistence
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Audit store preview is in-memory only; no real persistence.
Memory + Retrieval Preview memory_retrieval_preview
Categorypersistence
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Memory retrieval preview is in-memory only; no vector/embedding write.
Provider Registry Preview provider_registry_preview
Categoryprovider
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No provider SDK, no key exposure, no outbound call.
Approval Execution Preview approval_execution_preview
Categoryapproval
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Real execution is always blocked; approval is preview-only.
Assistant Orchestrator Preview assistant_orchestrator_preview
Categoryorchestration
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real AI/provider call or action execution.
App Integration Preview app_integration_preview
Categoryintegration
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real app execution, mutation, payment, or send.
Owner/Ops Dashboard Preview owner_ops_dashboard_preview
Categorydashboard
Readinessconfigured
Authpublic
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Aggregates only safe metadata; no external call or real execution.
Core Preview Contract Index core_preview_contract_index
Categorycontract_index
Readinessconfigured
Authauth required
Route Count1
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • Central metadata-only index; no real execution or external call.
Owner API Key Settings Preview provider_settings_preview
Categoryprovider_settings
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No provider call or key validation in preview.
  • No secret storage, env write, or key exposure.
  • All provider settings are owner-only and blocked until explicit future unlock.
Knowledge / RAG Upload Preview knowledge_rag_preview
Categoryknowledge_rag
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real file upload, document parsing, or OCR in preview.
  • No external URL fetch, website crawling, or embedding generation.
  • No vector DB call, vector write, memory write, or secret exposure.
Memory Write Approval Preview memory_approval_preview
Categorymemory_approval
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real memory write, persistence, or customer record update in preview.
  • No vector DB call, embedding generation, or file/database/audit write.
  • No provider call, external network, send, payment, or approved execution.
Goose Connector Preview goose_connector_preview
Categorygoose_connector
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real Goose execution, shell, or process execution in preview.
  • No file read/write, workspace mutation, or git mutation in preview.
  • No browser automation, MCP live tool execution, provider call, or external network.
Browser Extension Preview browser_extension_preview
Categorybrowser_extension
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real browser extension build, installable manifest, content script, or background worker in preview.
  • No browser automation, DOM access, page scraping, cookies/history access, or scripting in preview.
  • No local storage / session storage / indexed DB, service worker, provider call, external network, or real execution.
WhatsApp / Telegram Connector Preview messaging_connector_preview
Categorymessaging_connector
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real WhatsApp or Telegram API call, no webhook registration, no real inbound webhook processing in preview.
  • No message send, no email/SMS send, no message persistence, no contact/customer update in preview.
  • No provider call, external network, local storage / session storage / indexed DB, service worker, or real execution.
Preview Apps Home Dashboard preview_apps_home_dashboard
Categorypreview_apps_home
Readinessconfigured
Authpublic
Route Count4
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real execution, no provider call, no external network, no WhatsApp/Telegram API call, no Goose execution.
  • No database/file/audit/memory write, no mutation, no embedding generation, no vector write, no payment, no send.
  • No local storage / session storage / indexed DB / service worker, no key material exposure, no live HTTP check.
External Service Toolkit Preview external_service_toolkit_preview
Categoryexternal_services
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real API call, no provider SDK, no key configuration, no external network.
  • No send, no upload, no screenshot, no PDF, no mutation, no write, no payment.
  • All candidate APIs require owner approval. No production provider selected.
Research Engine Preview research_engine_preview
Categoryresearch
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No Python execution, no subprocess, no internet fetch, no source fetch.
  • No report write, no key/secret, no provider call, no mutation.
  • Owner approval required for live research run.
Tool Approval Workflow Preview tool_approval_workflow_preview
Categorysafety
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real approval persistence, no execution unlock, no send, no write, no payment.
  • No external API call, no Python execution, no screenshot, no PDF, no file upload.
  • All unsafe capabilities disabled. Owner approval required for all live actions.
Safe Tool Execution Plan Preview safe_tool_execution_plan_preview
Categorysafety
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No real execution, no adapter execution, no provider call, no send, no write, no payment.
  • No Python execution, no rollback execution, no approval persistence, no audit persistence.
  • All unsafe capabilities disabled. Planning layer only.
Tool Adapter Registry Preview tool_adapter_registry_preview
Categorysafety
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No adapter execution, no adapter SDK, no provider SDK, no external API, no send, no write, no payment.
  • No Python execution, no subprocess, no research execution, no file/PDF/screenshot.
  • All unsafe capabilities disabled. Registry and capability routing only.
Policy Decision API Preview policy_decision_api_preview
Categorysafety
Readinessconfigured
Authpublic
Route Count3
Safety Checks
previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Warnings
  • No policy decision persistence, no receipt signing, no real execution.
  • No adapter execution, no external API, no Python, no send, no write, no payment.
  • Decision engine preview only. All unsafe capabilities disabled.

API Explorer

27 API groups; all endpoints are preview-only and read-only.

public auth_required read_only preview_only blocked_execution owner_ops app_integration mcp
Gateway Preview gateway
1 endpoints all preview_only public/mixed
POST POST /v1/gateway/preview
Route IDgateway_preview
Modulegateway_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
gateway_preview
Blocked Capabilities
real_gateway_routingexternal_networkpaymentsend
Safe Request Shape
{"query":"Smart Print estimate preview","dryRunOnly":true}
Safe Response Shape
{ previewOnly, mode, requestedMode, provider, model, blocked, requiresApproval, mutationExecuted, providerCallExecuted, realExecutionPerformed }
Notes

Unauthenticated preview-only route; always returns safe metadata and never routes real traffic.

Gateway Observability observability
2 endpoints all preview_only all auth_required
GET GET /v1/gateway/observability/preview-status
Route IDgateway_observability_preview_status
Modulegateway_observability
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
observability_status
Blocked Capabilities
external_observability_exportpersistent_event_store_write
Safe Request Shape
{}
Safe Response Shape
{ ok, previewOnly, eventCount, maxEventCount, recentEvents, redactionApplied, storage, persistentStoreEnabled, externalNetworkEnabled, mutationExecuted, providerCallExecuted, realExecutionPerformed }
Notes

Token-protected read-only route; returns in-memory safe observability summary.

GET GET /v1/gateway/observability/recent-events
Route IDgateway_observability_recent_events
Modulegateway_observability
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
recent_events
Blocked Capabilities
external_observability_exportpersistent_event_store_write
Safe Request Shape
{"limit":10}
Safe Response Shape
{ previewOnly, events, redactionApplied, eventCount, capped }
Notes

Token-protected read-only route; returns redacted and capped in-memory events.

Security Inventory Preview security
1 endpoints all preview_only public/mixed
POST POST /v1/security/bumblebee/preview-ingest
Route IDsecurity_bumblebee_preview_ingest
Modulesecurity_inventory_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
preview_ingest
Blocked Capabilities
real_remediationsecurity_rule_updateexternal_networkmutation
Safe Request Shape
{"lines":["{\"event\":\"test\"}"],"dryRunOnly":true}
Safe Response Shape
{ previewOnly, accepted, redacted, parsedRows, errors, policyFlags }
Notes

Preview-only security inventory ingest; no real rule update or remediation.

Security Alert Preview security
1 endpoints all preview_only public/mixed
POST POST /v1/security/bumblebee/preview-alert
Route IDsecurity_bumblebee_preview_alert
Modulesecurity_alert_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
preview_alert
Blocked Capabilities
whatsapp_sendgithub_issue_createdeploy_gate_changeexternal_network
Safe Request Shape
{"alertType":"suspicious_token","severity":"high"}
Safe Response Shape
{ previewOnly, alertPreview, workflowSteps, blocked, policyFlags }
Notes

Preview-only alert workflow; no real WhatsApp/GitHub/create/deploy gate change.

MCP Read-only Tools Preview tools
1 endpoints all preview_only public/mixed
POST POST /v1/mcp/read-only-tools/preview
Route IDmcp_readonly_tools_preview
Modulemcp_readonly_tools_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
calculatorknowledge_searchreport_previewstatus_preview
Blocked Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_network
Safe Request Shape
{"toolId":"calculator","intent":"add","userMessage":"2 + 2"}
Safe Response Shape
{ previewOnly, toolId, result, redactedInput, policyFlags }
Notes

Read-only preview tools; no live MCP/tool execution or network call.

Audit Store Preview persistence
1 endpoints all preview_only public/mixed
POST POST /v1/audit-store/preview
Route IDaudit_store_preview
Moduleaudit_store_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
append_previewquery_previewsummary_preview
Blocked Capabilities
audit_writeaudit_exportaudit_retention_applypersistent_storage
Safe Request Shape
{"eventType":"test_event","dryRunOnly":true}
Safe Response Shape
{ previewOnly, auditEventId, redactedSummary, persisted, policyFlags }
Notes

Preview-only audit store; persisted is always false and no real storage write.

Memory + Retrieval Preview persistence
1 endpoints all preview_only public/mixed
POST POST /v1/memory-retrieval/preview
Route IDmemory_retrieval_preview
Modulememory_retrieval_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
memory_query_previewmemory_status_preview
Blocked Capabilities
memory_writevector_writeembedding_generationexternal_network
Safe Request Shape
{"query":"customer order summary","dryRunOnly":true}
Safe Response Shape
{ previewOnly, matches, queryPreview, memoryWriteEnabled, vectorDatabaseEnabled, embeddingGenerationEnabled, policyFlags }
Notes

Preview-only memory retrieval; no memory/vector/embedding write or network call.

Provider Registry Preview provider
1 endpoints all preview_only public/mixed
POST POST /v1/provider-registry/preview
Route IDprovider_registry_preview
Moduleprovider_registry_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
catalog_previewenv_diagnostics_previewcapability_previewselect_previewcall_block_previewsummary_preview
Blocked Capabilities
provider_callprovider_key_exposuresdk_initializationexternal_network
Safe Request Shape
{"action":"catalog_preview"}
Safe Response Shape
{ previewOnly, catalog, diagnostics, selectedAdapter, providerCallsEnabled, policyFlags }
Notes

Preview-only provider registry; no provider SDK, no key exposure, no outbound call.

Approval Execution Preview approval
1 endpoints all preview_only public/mixed
POST POST /v1/approval-execution/preview
Route IDapproval_execution_preview
Moduleapproval_execution_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
approved_executionexecution_unlockruntime_bridge_openreal_execution
Safe Request Shape
{"action":"request_preview","requestedAction":"deploy"}
Safe Response Shape
{ superseded, canonicalRoute, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical approval authority is POST /api/ceo/approve.

Assistant Orchestrator Preview orchestration
1 endpoints all preview_only public/mixed
POST POST /v1/assistant/orchestrator/preview
Route IDassistant_orchestrator_preview
Moduleassistant_orchestrator_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
ai_inferenceprovider_callaction_executionexternal_network
Safe Request Shape
{"action":"plan_preview","userMessage":"What is the workflow?"}
Safe Response Shape
{ superseded, canonicalRoute, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical orchestration authority is POST /api/ceo/turn.

App Integration Preview integration
1 endpoints all preview_only public/mixed
POST POST /v1/app-integration/preview
Route IDapp_integration_preview
Moduleapp_integration_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
paymentsendcustomer_updateapp_mutationprovider_callexternal_network
Safe Request Shape
{"action":"context_envelope","appId":"smart_print"}
Safe Response Shape
{ superseded, canonicalRoute, canonicalManifest, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical app dispatch uses POST /api/ceo/turn and the seven-app manifest.

Owner/Ops Dashboard Preview dashboard
1 endpoints all preview_only public/mixed
POST POST /v1/owner-ops-dashboard/preview
Route IDowner_ops_dashboard_preview
Moduleowner_ops_dashboard_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
dashboard_previewmodule_status_previewreadiness_score_previewblocker_summary_previewnext_actions_previewhealth_previewpolicy_check
Blocked Capabilities
real_executionprovider_callexternal_networkmutationwrite
Safe Request Shape
{"action":"dashboard_preview","appId":"smart_print"}
Safe Response Shape
{ previewOnly, action, dashboard, modules, readiness, blockers, nextActions, health, policyFlags }
Notes

Preview-only owner/ops dashboard aggregator; no real execution or external call.

Core Preview Contract Index contract_index
1 endpoints all preview_only all auth_required
POST POST /v1/core/preview-contracts
Route IDcore_preview_contract_index
Modulecore_preview_contract_index
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
route_catalogmodule_catalogsmoke_pack_previewapp_contract_summarysafety_expectationssummarypolicy_check
Blocked Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendreal_smoke_execution
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ previewOnly, action, routeCatalog?, moduleCatalog?, smokePack?, safetyExpectations?, summary?, policyFlags }
Notes

Token-protected preview-only route; returns the central contract index catalog and policy checks.

Owner API Key Settings Preview provider_settings
3 endpoints all preview_only public/mixed
GET GET /settings/providers
Route IDprovider_settings_preview
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.

GET GET /v1/core/provider-settings
Route IDprovider_settings_status
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.

POST POST /v1/core/provider-settings/preview
Route IDprovider_settings_preview_post
Moduleprovider_settings_preview
Authpublic
Preview Onlytrue
Status Without Auth410
Status With Auth410
Supported Actions
Blocked Capabilities
provider_callexternal_networkreal_executionapproved_executionmutationsecret_storageenv_writefile_writedatabase_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Notes

Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.

Knowledge / RAG Upload Preview knowledge_rag
3 endpoints all preview_only public/mixed
GET GET /knowledge
Route IDknowledge_rag_preview
Moduleknowledge_rag_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, uploadEnabled=false, documentParsingEnabled=false, embeddingGenerationEnabled=false, vectorWriteExecuted=false, memoryWriteExecuted=false
Notes

Public static HTML page with no file upload, no parser, no URL fetch, no crawling, no embedding, no secret.

GET GET /v1/core/knowledge
Route IDknowledge_rag_status
Moduleknowledge_rag_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags, sourceCatalog, uploadEnabled, documentParsingEnabled, embeddingGenerationEnabled, vectorWriteExecuted }
Notes

Token-protected safe JSON status; no file upload, no parser, no URL fetch, no embedding, no vector write.

POST POST /v1/core/knowledge/preview
Route IDknowledge_rag_preview_post
Moduleknowledge_rag_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkupload_schema_previewchunking_previewredaction_previewretrieval_previewsource_catalog_preview
Blocked Capabilities
file_uploaddocument_parsingocrexternal_url_fetchwebsite_crawlingembedding_generationvector_databasevector_writememory_writeaudit_writefile_writedatabase_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposure
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, schema, chunking, redaction, retrieval, sourceCatalog, policyFlags, policyCompliant }
Notes

Preview actions for knowledge / RAG uploads; requires local auth token; no real upload, parser, fetch, embedding, or vector DB call.

Memory Write Approval Preview memory_approval
3 endpoints all preview_only public/mixed
GET GET /memory
Route IDmemory_approval_preview
Modulememory_approval_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, memoryWriteEnabled=false, memoryPersistenceEnabled=false, vectorDatabaseEnabled=false, embeddingGenerationEnabled=false, customerRecordUpdated=false
Notes

Public static HTML page with no memory write, no persistence, no secret, no input/button/form/script.

GET GET /v1/core/memory
Route IDmemory_approval_status
Modulememory_approval_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags, categoryCatalog, memoryWriteEnabled, memoryPersistenceEnabled, vectorDatabaseEnabled, embeddingGenerationEnabled, customerRecordUpdated }
Notes

Token-protected safe JSON status; no memory write, no persistence, no vector DB, no embedding, no customer update.

POST POST /v1/core/memory/preview
Route IDmemory_approval_preview_post
Modulememory_approval_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkmemory_suggestion_previewapproval_flow_previewredaction_previewretention_policy_previewforget_flow_preview
Blocked Capabilities
memory_writememory_persistencevector_databasevector_writeembedding_generationcustomer_record_updatedatabase_writefile_writeaudit_writeprovider_callexternal_networkreal_executionapproved_executionmutationpaymentsendkey_material_exposuremcp_live_executiongoose_executionbrowser_automationwhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, suggestion, approvalFlow, redaction, retention, forgetFlow, policyFlags, policyCompliant }
Notes

Preview actions for memory write approval; requires local auth token; no real memory write, persistence, vector DB, or embedding.

Goose Connector Preview goose_connector
3 endpoints all preview_only public/mixed
GET GET /goose
Route IDgoose_connector_preview
Modulegoose_connector_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, gooseExecutionEnabled=false, shellExecutionEnabled=false, fileWriteExecuted=false, workspaceMutationEnabled=false
Notes

Public static HTML page with no Goose execution, no shell/process, no file/workspace/git mutation, no script, no secret.

GET GET /v1/core/goose
Route IDgoose_connector_status
Modulegoose_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags, commandCatalog, gooseExecutionEnabled, shellExecutionEnabled, commandExecutionPerformed }
Notes

Token-protected safe JSON status; no Goose execution, shell, process, file/workspace/git mutation, or provider call.

POST POST /v1/core/goose/preview
Route IDgoose_connector_preview_post
Modulegoose_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkcommand_catalog_previewexecution_plan_previewapproval_flow_previewsandbox_policy_previewrollback_plan_preview
Blocked Capabilities
goose_executionshell_executionprocess_spawncommand_executionfile_readfile_writeworkspace_mutationgit_mutationbrowser_automationmcp_live_tool_executionprovider_callexternal_networkreal_executionapproved_executionmutationdatabase_writeaudit_writememory_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, commandCatalog, executionPlan, approvalFlow, sandboxPolicy, rollbackPlan, policyFlags, policyCompliant }
Notes

Preview actions for Goose connector; requires local auth token; no real Goose execution, shell, process, file/workspace/git mutation, or provider call.

Browser Extension Preview browser_extension
3 endpoints all preview_only public/mixed
GET GET /browser-extension
Route IDbrowser_extension_preview
Modulebrowser_extension_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, extensionBuildEnabled=false, installableManifestEnabled=false, contentScriptEnabled=false, browserAutomationEnabled=false, pageScrapingEnabled=false
Notes

Public static HTML page with no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no script, no secret.

GET GET /v1/core/browser-extension
Route IDbrowser_extension_status
Modulebrowser_extension_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags, permissionCatalog, extensionBuildEnabled, installableManifestEnabled, contentScriptEnabled, browserAutomationEnabled, pageScrapingEnabled }
Notes

Token-protected safe JSON status; no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no provider call.

POST POST /v1/core/browser-extension/preview
Route IDbrowser_extension_preview_post
Modulebrowser_extension_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkpermission_catalog_previewpage_context_previewredaction_previewaction_draft_previewextension_manifest_preview
Blocked Capabilities
extension_buildinstallable_manifestcontent_scriptbackground_workerbrowser_automationdom_accesspage_scrapingwebsite_fetchwebsite_crawlinglocal_storagesession_storageindexed_dbservice_workerexternal_networkcdnprovider_callmcp_live_tool_executiongoose_executionreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurewhatsapp_sendtelegram_sendemail_send
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, permissionCatalog, pageContext, redaction, actionDraft, manifest, policyFlags, policyCompliant }
Notes

Preview actions for browser extension; requires local auth token; no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no provider call.

WhatsApp / Telegram Connector Preview messaging_connector
3 endpoints all preview_only public/mixed
GET GET /messaging
Route IDmessaging_connector_preview
Modulemessaging_connector_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, whatsappEnabled=false, telegramEnabled=false, whatsappApiCallExecuted=false, telegramApiCallExecuted=false, sendEnabled=false, webhookRegistrationEnabled=false
Notes

Public static HTML page with no real WhatsApp/Telegram API call, no webhook registration, no real inbound processing, no message send, no message persistence, no script, no secret.

GET GET /v1/core/messaging
Route IDmessaging_connector_status
Modulemessaging_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags, channelCatalog, whatsappEnabled, telegramEnabled, sendEnabled, webhookRegistrationEnabled }
Notes

Token-protected safe JSON status; no real WhatsApp/Telegram API call, no webhook registration, no real inbound processing, no message send, no provider call.

POST POST /v1/core/messaging/preview
Route IDmessaging_connector_preview_post
Modulemessaging_connector_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkchannel_catalog_previewinbound_message_previewredaction_previewreply_draft_previewsend_policy_previewwebhook_schema_preview
Blocked Capabilities
whatsapp_api_calltelegram_api_callwhatsapp_sendtelegram_sendemail_sendsms_sendwebhook_registrationinbound_webhook_processingmessage_sendmessage_persistencecontact_updatecustomer_record_updateprovider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentkey_material_exposurelocal_storagesession_storageindexed_dbservice_worker
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, channelCatalog, inboundMessage, redaction, replyDraft, sendPolicy, webhookSchema, policyFlags, policyCompliant }
Notes

Preview actions for WhatsApp / Telegram connector; requires local auth token; no real API call, no webhook registration, no real inbound processing, no message send, no provider call.

Preview Apps Home Dashboard preview_apps_home
4 endpoints all preview_only public/mixed
GET GET /
Route IDpreview_apps_home_dashboard
Modulepreview_apps_home_dashboard
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, static app catalog, route index, safety summary, next safe actions
Notes

Public read-only home HTML page with no real execution, no provider call, no external network, no secret, no mutation, no storage, no service worker.

GET GET /apps
Route IDpreview_apps_home_apps
Modulepreview_apps_home_dashboard
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, compact app catalog and route index
Notes

Public read-only /apps HTML page with no real execution, no provider call, no secret, no mutation, no storage.

GET GET /v1/core/apps
Route IDpreview_apps_home_status
Modulepreview_apps_home_dashboard
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewroute_index_previewnavigation_preview
Blocked Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, appCatalog, routeIndex, navigation, policyFlags, policyCompliant }
Notes

Token-protected safe JSON status; no real execution, no provider call, no external network, no secret exposure.

POST POST /v1/core/apps/preview
Route IDpreview_apps_home_preview_post
Modulepreview_apps_home_dashboard
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkapp_catalog_previewroute_index_previewnavigation_preview
Blocked Capabilities
provider_callexternal_networkcdnreal_executionapproved_executionmutationdatabase_writefile_writeaudit_writememory_writeembedding_generationvector_writepaymentsendkey_material_exposurelocal_storagesession_storageindexed_dbservice_workerwhatsapp_api_calltelegram_api_callgoose_execution
Safe Request Shape
{"action":"policy_check"}
Safe Response Shape
{ action, status, html, summary, appCatalog, routeIndex, navigation, policyFlags, policyCompliant }
Notes

Preview actions for the home dashboard; requires local auth token; no real execution, no provider call, no external network, no mutation, no secret exposure.

External Service Toolkit Preview external_services
3 endpoints all preview_only public/mixed
GET GET /external-services
Route IDexternal_service_toolkit_preview
Moduleexternal_service_toolkit_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, external service toolkit catalog and policy preview
Notes

Public read-only external service toolkit HTML page; no real API call, no provider SDK, no key, no send, no upload, no screenshot, no PDF.

GET GET /v1/core/external-services
Route IDexternal_service_toolkit_status
Moduleexternal_service_toolkit_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ status, policyFlags, previewOnly }
Notes

Token-protected external service toolkit status; no real API call, no provider SDK, no key, no mutation.

POST POST /v1/core/external-services/preview
Route IDexternal_service_toolkit_preview_post
Moduleexternal_service_toolkit_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkservice_catalog_previewtool_permission_previewprovider_selection_previewemail_validation_previewphone_validation_previewlocation_lookup_previewcurrency_rate_previewfile_upload_policy_previewscreenshot_policy_previewdocument_pdf_policy_previewcalendar_holidays_previewnotification_draft_previewredaction_preview
Blocked Capabilities
provider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|catalog|permissions|policy|status|summary, policyFlags, previewOnly }
Notes

Preview actions for external service toolkit; requires local auth token; no real API call, no provider SDK, no key, no send, no upload, no screenshot, no PDF.

Research Engine Preview research
3 endpoints all preview_only public/mixed
GET GET /research-engine
Route IDresearch_engine_preview
Moduleresearch_engine_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, research engine preview page with research types and source catalog
Notes

Public read-only research engine HTML page; no Python execution, no subprocess, no internet fetch, no report write.

GET GET /v1/core/research-engine
Route IDresearch_engine_status
Moduleresearch_engine_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ status, policyFlags, previewOnly }
Notes

Token-protected research engine status; no Python execution, no subprocess, no internet fetch, no report write.

POST POST /v1/core/research-engine/preview
Route IDresearch_engine_preview_post
Moduleresearch_engine_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkresearch_topic_previewsource_catalog_previewresearch_plan_previewreport_schema_previewsample_report_previewpython_worker_policy_previewapproval_flow_previewredaction_previewoutput_safety_preview
Blocked Capabilities
python_executionsubprocessinternet_fetchsource_fetchreport_writeprovider_callexternal_networkreal_executionmutationdatabase_writefile_writeaudit_writememory_writepaymentsendkey_material_exposure
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|catalog|plan|schema|policy|flow|safety, policyFlags, previewOnly }
Notes

Preview actions for research engine; requires local auth token; no Python execution, no subprocess, no internet fetch, no report write.

Tool Approval Workflow Preview safety
3 endpoints all preview_only public/mixed
GET GET /approvals
Route IDtool_approval_workflow_preview
Moduletool_approval_workflow_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ contentType, html, previewOnly }
Notes

Public HTML preview of tool approval workflow; no real persistence, no execution, no send, no write, no payment.

GET GET /v1/core/approvals
Route IDtool_approval_workflow_status
Moduletool_approval_workflow_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags }
Notes

Token-protected tool approval workflow status; no real persistence, no execution, no send, no write, no payment.

POST POST /v1/core/approvals/preview
Route IDtool_approval_workflow_preview_post
Moduletool_approval_workflow_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkapproval_matrix_previewconfirmation_request_previewrisk_assessment_previewowner_decision_previewapproval_receipt_previewblocked_action_previewnotification_confirmation_previewemail_confirmation_previewphone_confirmation_previewfile_upload_confirmation_previewscreenshot_confirmation_previewpdf_confirmation_previewresearch_confirmation_previewmessaging_send_confirmation_previewpayment_confirmation_previewredaction_preview
Blocked Capabilities
approval_persistencereal_executionexecution_unlocksendwritepaymentexternal_apipython_executionkey_material_exposure
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|status|summary, policyFlags, previewOnly }
Notes

Preview actions for tool approval workflow; requires local auth token; no real persistence, no execution, no send, no write, no payment.

Safe Tool Execution Plan Preview safety
3 endpoints all preview_only public/mixed
GET GET /execution-plans
Route IDsafe_tool_execution_plan_preview
Modulesafe_tool_execution_plan_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ contentType, html, previewOnly }
Notes

Public HTML preview of safe tool execution plan; no real execution, no adapter, no send, no write, no payment.

GET GET /v1/core/execution-plans
Route IDsafe_tool_execution_plan_status
Modulesafe_tool_execution_plan_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags }
Notes

Token-protected safe tool execution plan status; no real execution, no adapter, no send, no write, no payment.

POST POST /v1/core/execution-plans/preview
Route IDsafe_tool_execution_plan_preview_post
Modulesafe_tool_execution_plan_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkexecution_plan_previewtool_chain_previewpreflight_check_previewapproval_gate_previewadapter_selection_previewrollback_plan_previewaudit_plan_previewdry_run_result_previewblocked_execution_previewexternal_service_execution_previewmessaging_execution_previewfile_pdf_screenshot_execution_previewresearch_execution_previewpayment_mutation_execution_previewanshika_agent_execution_previewredaction_preview
Blocked Capabilities
real_executionadapter_executionprovider_callsendwritepaymentpython_executionrollback_executionkey_material_exposure
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|status|summary, policyFlags, previewOnly }
Notes

Preview actions for safe tool execution plan; requires local auth token; no real execution, no adapter, no send, no write, no payment.

Tool Adapter Registry Preview safety
3 endpoints all preview_only public/mixed
GET GET /adapters
Route IDtool_adapter_registry_preview
Moduletool_adapter_registry_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Safe Request Shape
{}
Safe Response Shape
HTML page (no script, no form, no button)
Notes

Public HTML tool adapter registry preview; no token, no adapter execution, no SDK, no send, no write, no payment.

GET GET /v1/core/adapters
Route IDtool_adapter_registry_status
Moduletool_adapter_registry_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Safe Request Shape
{}
Safe Response Shape
{ previewOnly, status, policyFlags }
Notes

Token-protected tool adapter registry status; no adapter execution, no SDK, no send, no write, no payment.

POST POST /v1/core/adapters/preview
Route IDtool_adapter_registry_preview_post
Moduletool_adapter_registry_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkadapter_registry_previewcapability_router_previewadapter_family_previewtool_to_adapter_map_previewadapter_selection_previewadapter_preflight_previewadapter_permission_previewadapter_blocklist_previewexternal_service_adapter_previewmessaging_adapter_previewfile_pdf_screenshot_adapter_previewresearch_adapter_previewanshika_agent_adapter_previewpayment_adapter_block_previewredaction_preview
Blocked Capabilities
adapter_executionadapter_sdkprovider_sdkexternal_apisendwritepaymentpython_execution
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|status|summary, policyFlags, previewOnly }
Notes

Preview actions for tool adapter registry; requires local auth token; no adapter execution, no SDK, no send, no write, no payment.

Policy Decision API Preview safety
3 endpoints all preview_only public/mixed
GET GET /policy-decisions
Route IDpolicy_decision_api_preview
Modulepolicy_decision_api_preview
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepayment
Safe Request Shape
{}
Safe Response Shape
{ html }
Notes

Public policy decision API HTML preview; no token; safe static read-only page.

GET GET /v1/core/policy-decisions
Route IDpolicy_decision_api_status
Modulepolicy_decision_api_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepayment
Safe Request Shape
{}
Safe Response Shape
{ status, policyFlags, previewOnly }
Notes

Protected policy decision API JSON status; requires local auth token; no persistence, no execution.

POST POST /v1/core/policy-decisions/preview
Route IDpolicy_decision_api_preview_post
Modulepolicy_decision_api_preview
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_checkdecision_matrix_previewpolicy_decision_previewcapability_decision_previewapproval_requirement_previewexecution_plan_requirement_previewadapter_requirement_previewkey_requirement_previewcritical_block_previewanshika_policy_decision_previewexternal_service_policy_decision_previewmessaging_policy_decision_previewresearch_policy_decision_previewpayment_policy_decision_previewdecision_receipt_previewredaction_preview
Blocked Capabilities
persistencereceipt_signingexecutionadapter_executionexternal_apisendwritepaymentpython_execution
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, result|status|summary, policyFlags, previewOnly }
Notes

Preview actions for policy decision API; requires local auth token; no persistence, no execution, no send, no write, no payment.

Core Control Center control_center
3 endpoints all preview_only public/mixed
GET /control-center
Route IDcontrol_center_html
Modulecore_control_center
Authpublic
Preview Onlytrue
Status Without Auth200
Status With Auth200
Supported Actions
html_preview
Blocked Capabilities
provider_callexternal_networkreal_executionmutationpaymentsend
Safe Request Shape
{}
Safe Response Shape
text/html; previewOnly, realExecutionPerformed=false, providerCallExecuted=false, mutationExecuted=false
Notes

Public static HTML page with no secret and no live env read.

GET /v1/core/control-center
Route IDcontrol_center_status
Modulecore_control_center
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_preview
Blocked Capabilities
provider_callexternal_networkreal_executionmutationpaymentsend
Safe Request Shape
{}
Safe Response Shape
{ status, routeCount, moduleCount, apiExplorerGroups, mcpExplorerTools, policyFlags, previewOnly }
Notes

Safe JSON status; requires x-smart-shikka-local-token header if local auth is configured.

POST /v1/core/control-center/preview
Route IDcontrol_center_preview
Modulecore_control_center
Authauth required
Preview Onlytrue
Status Without Auth401
Status With Auth200
Supported Actions
status_previewhtml_previewsummarypolicy_check
Blocked Capabilities
provider_callexternal_networkreal_executionmutationpaymentsend
Safe Request Shape
{"action":"status_preview"}
Safe Response Shape
{ action, status, html, summary, policyFlags, policyCompliant, previewOnly }
Notes

Preview actions for control center; requires x-smart-shikka-local-token header if local auth is configured.

MCP Read-only Tools

4 read-only preview tools; no live execution or provider call.

Calculator Preview calculator_preview
Categoryread-only tools
Authauth required
Safety Checks
readOnly=true previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Blocked Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_networkpaymentsendcustomer_updatememory_writeaudit_write
Safe Input Shape
{
  "toolId": "calculator_preview",
  "intent": "<INTENT>",
  "userMessage": "<USER_MESSAGE>",
  "pageContext": {},
  "knowledgeContext": {},
  "maxResults": 10
}
Safe Output Shape
{
  "previewOnly": true,
  "readOnly": true,
  "toolId": "calculator_preview",
  "toolStatus": "preview_only",
  "policy": {
    "allowed": true,
    "riskLevel": "safe"
  },
  "result": {},
  "mutationExecuted": false,
  "providerCallExecuted": false,
  "realExecutionPerformed": false,
  "externalNetworkEnabled": false,
  "approvedExecutionEnabled": false,
  "saveExecuted": false,
  "sendExecuted": false,
  "paymentExecuted": false,
  "customerRecordUpdated": false
}
Safety Notes

Safe numeric/formula preview only. No real calculation backend, no payment math.

Knowledge Search Preview knowledge_search_preview
Categoryread-only tools
Authauth required
Safety Checks
readOnly=true previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Blocked Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_networkpaymentsendcustomer_updatememory_writeaudit_write
Safe Input Shape
{
  "toolId": "knowledge_search_preview",
  "intent": "<INTENT>",
  "userMessage": "<USER_MESSAGE>",
  "pageContext": {},
  "knowledgeContext": {},
  "maxResults": 10
}
Safe Output Shape
{
  "previewOnly": true,
  "readOnly": true,
  "toolId": "knowledge_search_preview",
  "toolStatus": "preview_only",
  "policy": {
    "allowed": true,
    "riskLevel": "safe"
  },
  "result": {},
  "mutationExecuted": false,
  "providerCallExecuted": false,
  "realExecutionPerformed": false,
  "externalNetworkEnabled": false,
  "approvedExecutionEnabled": false,
  "saveExecuted": false,
  "sendExecuted": false,
  "paymentExecuted": false,
  "customerRecordUpdated": false
}
Safety Notes

Searches only provided sanitized context. No DB, no network, no raw private data echo.

Report Draft Preview report_draft_preview
Categoryread-only tools
Authauth required
Safety Checks
readOnly=true previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Blocked Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_networkpaymentsendcustomer_updatememory_writeaudit_write
Safe Input Shape
{
  "toolId": "report_draft_preview",
  "intent": "<INTENT>",
  "userMessage": "<USER_MESSAGE>",
  "pageContext": {},
  "knowledgeContext": {},
  "maxResults": 10
}
Safe Output Shape
{
  "previewOnly": true,
  "readOnly": true,
  "toolId": "report_draft_preview",
  "toolStatus": "preview_only",
  "policy": {
    "allowed": true,
    "riskLevel": "safe"
  },
  "result": {},
  "mutationExecuted": false,
  "providerCallExecuted": false,
  "realExecutionPerformed": false,
  "externalNetworkEnabled": false,
  "approvedExecutionEnabled": false,
  "saveExecuted": false,
  "sendExecuted": false,
  "paymentExecuted": false,
  "customerRecordUpdated": false
}
Safety Notes

Draft outline/text preview only. No save, no send, no export, no PDF generation.

Status Read Preview status_read_preview
Categoryread-only tools
Authauth required
Safety Checks
readOnly=true previewOnly=true providerCallEnabled=false mutationEnabled=false externalNetworkEnabled=false writeEnabled=false
Blocked Capabilities
mcp_live_calltool_executionfile_system_mutationexternal_networkpaymentsendcustomer_updatememory_writeaudit_write
Safe Input Shape
{
  "toolId": "status_read_preview",
  "intent": "<INTENT>",
  "userMessage": "<USER_MESSAGE>",
  "pageContext": {},
  "knowledgeContext": {},
  "maxResults": 10
}
Safe Output Shape
{
  "previewOnly": true,
  "readOnly": true,
  "toolId": "status_read_preview",
  "toolStatus": "preview_only",
  "policy": {
    "allowed": true,
    "riskLevel": "safe"
  },
  "result": {},
  "mutationExecuted": false,
  "providerCallExecuted": false,
  "realExecutionPerformed": false,
  "externalNetworkEnabled": false,
  "approvedExecutionEnabled": false,
  "saveExecuted": false,
  "sendExecuted": false,
  "paymentExecuted": false,
  "customerRecordUpdated": false
}
Safety Notes

Read-only metadata summary. No live route call, no Core DB read.

Safety Flags

Total Flags
17
Enabled
2
Disabled
15
All Expected
true
previewOnlytrue
controlCenterOnlytrue
realExecutionPerformedfalse
mutationExecutedfalse
providerCallExecutedfalse
externalNetworkEnabledfalse
approvedExecutionEnabledfalse
memoryWriteExecutedfalse
auditWriteExecutedfalse
fileWriteExecutedfalse
databaseWriteExecutedfalse
paymentExecutedfalse
sendExecutedfalse
customerRecordUpdatedfalse
embeddingGenerationEnabledfalse
keyMaterialExposedfalse
smokeExecutedfalse

Safety Matrix

All unsafe capabilities are blocked by policy; no live execution or network call.

Total Capabilities
15
All Blocked
true
CapabilityStatusExpectedEvidence
Provider Call blocked off providerCallExecuted=false; capability is blocked by control center policy.
External Network blocked off externalNetworkEnabled=false; capability is blocked by control center policy.
Real Execution blocked off realExecutionPerformed=false; capability is blocked by control center policy.
Approved Execution blocked off approvedExecutionEnabled=false; capability is blocked by control center policy.
Mutation blocked off mutationExecuted=false; capability is blocked by control center policy.
Database Write blocked off databaseWriteExecuted=false; capability is blocked by control center policy.
File Write blocked off fileWriteExecuted=false; capability is blocked by control center policy.
Audit Write blocked off auditWriteExecuted=false; capability is blocked by control center policy.
Memory Write blocked off memoryWriteExecuted=false; capability is blocked by control center policy.
Payment blocked off paymentExecuted=false; capability is blocked by control center policy.
Send blocked off sendExecuted=false; capability is blocked by control center policy.
Customer Record Update blocked off customerRecordUpdated=false; capability is blocked by control center policy.
Embedding Generation blocked off embeddingGenerationEnabled=false; capability is blocked by control center policy.
Key Material Exposure blocked off keyMaterialExposed=false; capability is blocked by control center policy.
Smoke Execution blocked off smokeExecuted=false; capability is blocked by control center policy.

Route Risk Matrix

Risk posture for every preview route from the contract catalog.

RouteRisk LevelRisk FactorsMitigation
POST POST /v1/gateway/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[real_gateway_routing, external_network, payment, send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/gateway/observability/preview-status auth_required_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[external_observability_export, persistent_event_store_write]
Protect with local token; do not expose the token in browser or logs.
GET GET /v1/gateway/observability/recent-events auth_required_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[external_observability_export, persistent_event_store_write]
Protect with local token; do not expose the token in browser or logs.
POST POST /v1/security/bumblebee/preview-ingest blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[real_remediation, security_rule_update, external_network, mutation]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/security/bumblebee/preview-alert safe_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[whatsapp_send, github_issue_create, deploy_gate_change, external_network]
Public preview route; no auth or live execution required.
POST POST /v1/mcp/read-only-tools/preview safe_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[mcp_live_call, tool_execution, file_system_mutation, external_network]
Public preview route; no auth or live execution required.
POST POST /v1/audit-store/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[audit_write, audit_export, audit_retention_apply, persistent_storage]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/memory-retrieval/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[memory_write, vector_write, embedding_generation, external_network]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/provider-registry/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, provider_key_exposure, sdk_initialization, external_network]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/approval-execution/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[approved_execution, execution_unlock, runtime_bridge_open, real_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/assistant/orchestrator/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[ai_inference, provider_call, action_execution, external_network]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/app-integration/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[payment, send, customer_update, app_mutation, provider_call, external_network]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/owner-ops-dashboard/preview owner_ops_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[real_execution, provider_call, external_network, mutation, write]
Owner/ops route; verify role and intent before any real ops enablement.
POST POST /v1/core/preview-contracts blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, real_smoke_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /settings/providers blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, approved_execution, mutation, secret_storage, env_write, file_write, database_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/provider-settings blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, approved_execution, mutation, secret_storage, env_write, file_write, database_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/provider-settings/preview blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, approved_execution, mutation, secret_storage, env_write, file_write, database_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /knowledge blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[file_upload, document_parsing, ocr, external_url_fetch, website_crawling, embedding_generation, vector_database, vector_write, memory_write, audit_write, file_write, database_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/knowledge blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[file_upload, document_parsing, ocr, external_url_fetch, website_crawling, embedding_generation, vector_database, vector_write, memory_write, audit_write, file_write, database_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/knowledge/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[file_upload, document_parsing, ocr, external_url_fetch, website_crawling, embedding_generation, vector_database, vector_write, memory_write, audit_write, file_write, database_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /memory blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[memory_write, memory_persistence, vector_database, vector_write, embedding_generation, customer_record_update, database_write, file_write, audit_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure, mcp_live_execution, goose_execution, browser_automation, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/memory blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[memory_write, memory_persistence, vector_database, vector_write, embedding_generation, customer_record_update, database_write, file_write, audit_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure, mcp_live_execution, goose_execution, browser_automation, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/memory/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[memory_write, memory_persistence, vector_database, vector_write, embedding_generation, customer_record_update, database_write, file_write, audit_write, provider_call, external_network, real_execution, approved_execution, mutation, payment, send, key_material_exposure, mcp_live_execution, goose_execution, browser_automation, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /goose blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[goose_execution, shell_execution, process_spawn, command_execution, file_read, file_write, workspace_mutation, git_mutation, browser_automation, mcp_live_tool_execution, provider_call, external_network, real_execution, approved_execution, mutation, database_write, audit_write, memory_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/goose blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[goose_execution, shell_execution, process_spawn, command_execution, file_read, file_write, workspace_mutation, git_mutation, browser_automation, mcp_live_tool_execution, provider_call, external_network, real_execution, approved_execution, mutation, database_write, audit_write, memory_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/goose/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[goose_execution, shell_execution, process_spawn, command_execution, file_read, file_write, workspace_mutation, git_mutation, browser_automation, mcp_live_tool_execution, provider_call, external_network, real_execution, approved_execution, mutation, database_write, audit_write, memory_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /browser-extension blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[extension_build, installable_manifest, content_script, background_worker, browser_automation, dom_access, page_scraping, website_fetch, website_crawling, local_storage, session_storage, indexed_db, service_worker, external_network, cdn, provider_call, mcp_live_tool_execution, goose_execution, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/browser-extension blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[extension_build, installable_manifest, content_script, background_worker, browser_automation, dom_access, page_scraping, website_fetch, website_crawling, local_storage, session_storage, indexed_db, service_worker, external_network, cdn, provider_call, mcp_live_tool_execution, goose_execution, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/browser-extension/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[extension_build, installable_manifest, content_script, background_worker, browser_automation, dom_access, page_scraping, website_fetch, website_crawling, local_storage, session_storage, indexed_db, service_worker, external_network, cdn, provider_call, mcp_live_tool_execution, goose_execution, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, whatsapp_send, telegram_send, email_send]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /messaging blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[whatsapp_api_call, telegram_api_call, whatsapp_send, telegram_send, email_send, sms_send, webhook_registration, inbound_webhook_processing, message_send, message_persistence, contact_update, customer_record_update, provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, key_material_exposure, local_storage, session_storage, indexed_db, service_worker]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/messaging blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[whatsapp_api_call, telegram_api_call, whatsapp_send, telegram_send, email_send, sms_send, webhook_registration, inbound_webhook_processing, message_send, message_persistence, contact_update, customer_record_update, provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, key_material_exposure, local_storage, session_storage, indexed_db, service_worker]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/messaging/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[whatsapp_api_call, telegram_api_call, whatsapp_send, telegram_send, email_send, sms_send, webhook_registration, inbound_webhook_processing, message_send, message_persistence, contact_update, customer_record_update, provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, key_material_exposure, local_storage, session_storage, indexed_db, service_worker]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET / blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, local_storage, session_storage, indexed_db, service_worker, whatsapp_api_call, telegram_api_call, goose_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /apps blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, local_storage, session_storage, indexed_db, service_worker, whatsapp_api_call, telegram_api_call, goose_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/apps blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, local_storage, session_storage, indexed_db, service_worker, whatsapp_api_call, telegram_api_call, goose_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/apps/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, cdn, real_execution, approved_execution, mutation, database_write, file_write, audit_write, memory_write, embedding_generation, vector_write, payment, send, key_material_exposure, local_storage, session_storage, indexed_db, service_worker, whatsapp_api_call, telegram_api_call, goose_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /external-services blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/external-services blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/external-services/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /research-engine blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[python_execution, subprocess, internet_fetch, source_fetch, report_write, provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/research-engine blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[python_execution, subprocess, internet_fetch, source_fetch, report_write, provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/research-engine/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[python_execution, subprocess, internet_fetch, source_fetch, report_write, provider_call, external_network, real_execution, mutation, database_write, file_write, audit_write, memory_write, payment, send, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /approvals blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[approval_persistence, real_execution, execution_unlock, send, write, payment, external_api, python_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/approvals blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[approval_persistence, real_execution, execution_unlock, send, write, payment, external_api, python_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/approvals/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[approval_persistence, real_execution, execution_unlock, send, write, payment, external_api, python_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /execution-plans blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[real_execution, adapter_execution, provider_call, send, write, payment, python_execution, rollback_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/execution-plans blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[real_execution, adapter_execution, provider_call, send, write, payment, python_execution, rollback_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/execution-plans/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[real_execution, adapter_execution, provider_call, send, write, payment, python_execution, rollback_execution, key_material_exposure]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /adapters blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[adapter_execution, adapter_sdk, provider_sdk, external_api, send, write, payment, python_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/adapters blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[adapter_execution, adapter_sdk, provider_sdk, external_api, send, write, payment, python_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/adapters/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[adapter_execution, adapter_sdk, provider_sdk, external_api, send, write, payment, python_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /policy-decisions blocked_execution_preview
  • authRequired=false
  • previewOnly=true
  • forbiddenCapabilities=[persistence, receipt_signing, execution, adapter_execution, external_api, send, write, payment]
Forbidden capabilities are blocked by contract; real execution remains disabled.
GET GET /v1/core/policy-decisions blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[persistence, receipt_signing, execution, adapter_execution, external_api, send, write, payment]
Forbidden capabilities are blocked by contract; real execution remains disabled.
POST POST /v1/core/policy-decisions/preview blocked_execution_preview
  • authRequired=true
  • previewOnly=true
  • forbiddenCapabilities=[persistence, receipt_signing, execution, adapter_execution, external_api, send, write, payment, python_execution]
Forbidden capabilities are blocked by contract; real execution remains disabled.

Module Risk Matrix

Risk posture for every preview module from the module catalog.

ModuleRisk LevelRisk FactorsMitigation
Gateway Preview (gateway_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Gateway Observability (gateway_observability) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Security Inventory Preview (security_inventory_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Security Alert Preview (security_alert_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
MCP Read-only Tools Preview (mcp_readonly_tools_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Audit Store Preview (audit_store_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Memory + Retrieval Preview (memory_retrieval_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Provider Registry Preview (provider_registry_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Approval Execution Preview (approval_execution_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Assistant Orchestrator Preview (assistant_orchestrator_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
App Integration Preview (app_integration_preview) app_integration_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
App integration module; verify per-app policy and consent before real handoff.
Owner/Ops Dashboard Preview (owner_ops_dashboard_preview) owner_ops_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
Owner/ops module; restrict to authorized operators and audit before enabling.
Core Preview Contract Index (core_preview_contract_index) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=1
All execution, provider, and write flags are disabled; safe to preview.
Owner API Key Settings Preview (provider_settings_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Knowledge / RAG Upload Preview (knowledge_rag_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Memory Write Approval Preview (memory_approval_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Goose Connector Preview (goose_connector_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Browser Extension Preview (browser_extension_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
WhatsApp / Telegram Connector Preview (messaging_connector_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Preview Apps Home Dashboard (preview_apps_home_dashboard) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
External Service Toolkit Preview (external_service_toolkit_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Research Engine Preview (research_engine_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Tool Approval Workflow Preview (tool_approval_workflow_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Safe Tool Execution Plan Preview (safe_tool_execution_plan_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Tool Adapter Registry Preview (tool_adapter_registry_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.
Policy Decision API Preview (policy_decision_api_preview) safe_preview
  • realExecutionEnabled=false
  • mutationEnabled=false
  • providerCallEnabled=false
  • externalNetworkEnabled=false
  • writeEnabled=false
  • warnings=3
All execution, provider, and write flags are disabled; safe to preview.

Diagnostics Preview

Static, preview-only diagnostics with no live checks, no env read, and no network call.

Deployment

All modules are preview-only pass
No live deployment or VPS checks are performed; all modules are preview-only.
Manual CheckVerify systemd service and port 37842 on the VPS before staging.

API Route Availability

Route catalog is preview-only and complete pass
Route catalog enumerates 54 preview-only routes; no live route calls are made.
Manual CheckRun an authenticated smoke test against /v1/core/preview-contracts after deployment.

Auth Boundary

Token-protected routes are identified manual_check_required
Token-protected routes require the configured local token header only when a token is configured; no secret is read or exposed.
Manual CheckRotate the configured local auth token and verify 401 responses for missing tokens.

Control Center HTML Safety

HTML page contains no scripts, forms, or execution controls pass
HTML page is built from static contracts with no <script>, <button>, <form>, or external resources.
Manual CheckReview the rendered /control-center page source for any injected secret.

Provider Safety

Provider calls and external network are disabled pass
All modules have providerCallEnabled=false and externalNetworkEnabled=false; no provider SDK is initialized.
Manual CheckConfirm provider adapter is not initialized in server config.

Execution Safety

Real and approved execution are disabled pass
All modules have realExecutionEnabled=false; approvedExecutionEnabled=false in policy flags.
Manual CheckEnsure dry_run mode is set before enabling any real execution gate.

App Integration Readiness

App integration preview module is configured pass
App integration preview module is present with mutation/payment/send disabled.
Manual CheckTest Smart Print and Drishti Kundali context envelopes manually.

Owner/Ops Readiness

Owner/Ops dashboard preview module is configured pass
Owner/Ops dashboard preview module is present and aggregates safe metadata only.
Manual CheckReview owner-ops dashboard preview before enabling owner-only routes.

Documentation

All modules have a docsPath pass
Module catalog references a docs file for every module; no file content is read.
Manual CheckConfirm docs files exist in the deployed docs/ directory.

Section Completion

Current completion status of the Web/Desktop control center sections.

Total Sections
15
All Complete
false
Overview complete
Route Explorer complete
Module Explorer complete
API/MCP Explorer complete
MCP Tools complete
Safety Matrix complete
Diagnostics complete
Desktop/PWA Shell complete
Provider Registry complete
Approval Bridge complete
App Integration complete
Owner/Ops complete
Smoke Checklist complete
Live Deploy pending
Smart Print/Drishti Consumption pending

Completion Summary

Final web/desktop section status. Live deploy and Smart Print/Drishti consumption are handled separately.

Web/Desktop Shell complete
Route Explorer complete
API/MCP Explorer complete
Safety Matrix complete
Diagnostics complete
Live Deploy pending separately
Smart Print/Drishti Consumption pending later
Real provider/execution intentionally OFF

Copy-Safe cURL Examples

Replace <LOCAL_AUTH_TOKEN> with your local token only when running locally. Never commit a real token.

POST /v1/gateway/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/gateway/preview" \
  -H "Content-Type: application/json" \
  -d '{"query":"Smart Print estimate preview","dryRunOnly":true}'
GET /v1/gateway/observability/preview-status
curl -X GET "https://shikka.anoopampress.com/api/v1/gateway/observability/preview-status" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
GET /v1/gateway/observability/recent-events
curl -X GET "https://shikka.anoopampress.com/api/v1/gateway/observability/recent-events" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/security/bumblebee/preview-ingest
curl -X POST "https://shikka.anoopampress.com/api/v1/security/bumblebee/preview-ingest" \
  -H "Content-Type: application/json" \
  -d '{"lines":["{\"event\":\"test\"}"],"dryRunOnly":true}'
POST /v1/security/bumblebee/preview-alert
curl -X POST "https://shikka.anoopampress.com/api/v1/security/bumblebee/preview-alert" \
  -H "Content-Type: application/json" \
  -d '{"alertType":"suspicious_token","severity":"high"}'
POST /v1/mcp/read-only-tools/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/mcp/read-only-tools/preview" \
  -H "Content-Type: application/json" \
  -d '{"toolId":"calculator","intent":"add","userMessage":"2 + 2"}'
POST /v1/audit-store/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/audit-store/preview" \
  -H "Content-Type: application/json" \
  -d '{"eventType":"test_event","dryRunOnly":true}'
POST /v1/memory-retrieval/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/memory-retrieval/preview" \
  -H "Content-Type: application/json" \
  -d '{"query":"customer order summary","dryRunOnly":true}'
POST /v1/provider-registry/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/provider-registry/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"catalog_preview"}'
POST /v1/approval-execution/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/approval-execution/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"request_preview","requestedAction":"deploy"}'
POST /v1/assistant/orchestrator/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/assistant/orchestrator/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"plan_preview","userMessage":"What is the workflow?"}'
POST /v1/app-integration/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/app-integration/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"context_envelope","appId":"smart_print"}'
POST /v1/owner-ops-dashboard/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/owner-ops-dashboard/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"dashboard_preview","appId":"smart_print"}'
POST /v1/core/preview-contracts
curl -X POST "https://shikka.anoopampress.com/api/v1/core/preview-contracts" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /settings/providers
curl -X GET "https://shikka.anoopampress.com/api/settings/providers" \
  -H "Content-Type: application/json"
GET /v1/core/provider-settings
curl -X GET "https://shikka.anoopampress.com/api/v1/core/provider-settings" \
  -H "Content-Type: application/json"
POST /v1/core/provider-settings/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/provider-settings/preview" \
  -H "Content-Type: application/json" \
  -d '{"action":"policy_check"}'
GET /knowledge
curl -X GET "https://shikka.anoopampress.com/api/knowledge" \
  -H "Content-Type: application/json"
GET /v1/core/knowledge
curl -X GET "https://shikka.anoopampress.com/api/v1/core/knowledge" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/knowledge/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/knowledge/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /memory
curl -X GET "https://shikka.anoopampress.com/api/memory" \
  -H "Content-Type: application/json"
GET /v1/core/memory
curl -X GET "https://shikka.anoopampress.com/api/v1/core/memory" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/memory/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/memory/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /goose
curl -X GET "https://shikka.anoopampress.com/api/goose" \
  -H "Content-Type: application/json"
GET /v1/core/goose
curl -X GET "https://shikka.anoopampress.com/api/v1/core/goose" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/goose/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/goose/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /browser-extension
curl -X GET "https://shikka.anoopampress.com/api/browser-extension" \
  -H "Content-Type: application/json"
GET /v1/core/browser-extension
curl -X GET "https://shikka.anoopampress.com/api/v1/core/browser-extension" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/browser-extension/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/browser-extension/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /messaging
curl -X GET "https://shikka.anoopampress.com/api/messaging" \
  -H "Content-Type: application/json"
GET /v1/core/messaging
curl -X GET "https://shikka.anoopampress.com/api/v1/core/messaging" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/messaging/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/messaging/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /
curl -X GET "https://shikka.anoopampress.com/api/" \
  -H "Content-Type: application/json"
GET /apps
curl -X GET "https://shikka.anoopampress.com/api/apps" \
  -H "Content-Type: application/json"
GET /v1/core/apps
curl -X GET "https://shikka.anoopampress.com/api/v1/core/apps" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/apps/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/apps/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"policy_check"}'
GET /external-services
curl -X GET "https://shikka.anoopampress.com/api/external-services" \
  -H "Content-Type: application/json"
GET /v1/core/external-services
curl -X GET "https://shikka.anoopampress.com/api/v1/core/external-services" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/external-services/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/external-services/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'
GET /research-engine
curl -X GET "https://shikka.anoopampress.com/api/research-engine" \
  -H "Content-Type: application/json"
GET /v1/core/research-engine
curl -X GET "https://shikka.anoopampress.com/api/v1/core/research-engine" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/research-engine/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/research-engine/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'
GET /approvals
curl -X GET "https://shikka.anoopampress.com/api/approvals" \
  -H "Content-Type: application/json"
GET /v1/core/approvals
curl -X GET "https://shikka.anoopampress.com/api/v1/core/approvals" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/approvals/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/approvals/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'
GET /execution-plans
curl -X GET "https://shikka.anoopampress.com/api/execution-plans" \
  -H "Content-Type: application/json"
GET /v1/core/execution-plans
curl -X GET "https://shikka.anoopampress.com/api/v1/core/execution-plans" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/execution-plans/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/execution-plans/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'
GET /adapters
curl -X GET "https://shikka.anoopampress.com/api/adapters" \
  -H "Content-Type: application/json"
GET /v1/core/adapters
curl -X GET "https://shikka.anoopampress.com/api/v1/core/adapters" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/adapters/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/adapters/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'
GET /policy-decisions
curl -X GET "https://shikka.anoopampress.com/api/policy-decisions" \
  -H "Content-Type: application/json"
GET /v1/core/policy-decisions
curl -X GET "https://shikka.anoopampress.com/api/v1/core/policy-decisions" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
POST /v1/core/policy-decisions/preview
curl -X POST "https://shikka.anoopampress.com/api/v1/core/policy-decisions/preview" \
  -H "Content-Type: application/json" \
  -H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
  -d '{"action":"status_preview"}'

Smoke Checklist

Leak Checks
10
Smoke Tests
54
Network Call
true
Route Invocation
true

Leak Checks

  • no_api_key
  • no_password
  • no_secret
  • no_private_key
  • no_access_token
  • no_provider_key
  • no_database_uri
  • no_mongo_url
  • no_whatsapp_token
  • no_customer_pii

No route is invoked; no network call; no real token required for preview catalog.

Next Safe Actions

  • Review the preview route catalog
  • Check module readiness status
  • Verify safety flags before any real execution
  • Use authenticated JSON preview for detailed metadata
  • Confirm provider and real execution remain disabled