Skip to content
AutoCore1.0.0-rc.1 · Release Candidate
1.0.0-rc.1 · Release Candidate2 min read

OpenAPI Publication

The sanitized OpenAPI artifact and the runtime generation boundary.

Use the committed artifact for discovery and the deployed /docs surface only when explicitly enabled.

Source boundary

Source boundary: AutoCore current main 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60, checked against immutable v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f.

Runtime Swagger generation is present in apps/api/src/main.ts, is enabled outside production or with ENABLE_API_DOCS=true, and uses bearer plus autocore_rt cookie security schemes. The public artifact excludes operator-sensitive and internal-only routes and uses an example server.

CheckSource-backed expectation
ScopeThe public artifact is a documentation snapshot, not a production credential or deployment URL.
EvidenceUse placeholders, timestamps, release identity, route, status, and request ID where relevant.
Safe actionjq '.paths | length' public/autocore/api/1.0.0-rc.1/openapi.json
Stop conditionUnknown authorization, destructive impact, secret exposure, or conflicting evidence.

Verification

Run the safe check, record its result, and compare the outcome with the documented contract. If the result depends on external configuration or provider availability, mark it as configuration-dependent rather than claiming a product guarantee.

Code
jq '.paths | length' public/autocore/api/1.0.0-rc.1/openapi.json

Safety boundary

Examples are non-production and use placeholders. Do not deploy, reset, force a migration, create secrets, activate providers, replay sensitive work, or expose private data from this page.

Related articles