Skip to content

Overview

Sovereignty boundary readback + tenant-scoped config (get tenant; list + upsert entries routed to the env / secrets bindings). There is no /v1/tenants collection — the caller’s tenant is implicit from the bearer token. PATCH /config routes writes to SecretBinding when sensitive: true OR kind: "secret"; else to EnvBinding. GET /config merges both bindings at tenant scope; secret values are ALWAYS redacted here. The /config sub-routes mount when at least one of envBinding / secretsBinding is wired. Prefer /v1/env/* + /v1/secrets/* for new callers.