API reference
Identity, account, administrator, and server-only Policy endpoints, with access requirements and response codes.
Browse endpoint referenceBuild with Aarchon Core
Explore the current API surface, test policy rules with sample inputs, copy integration patterns, and download safe starter templates. The interactive tools run in your browser and never send sample inputs or credentials to Aarchon.
Identity, account, administrator, and server-only Policy endpoints, with access requirements and response codes.
Browse endpoint referenceTry clearance, compartment, and action combinations against a local sample of the current default rules.
Open the playgroundCopy a server-side Identity check and fail-closed Policy request pattern. Service credentials stay on your server.
View code examplesDownload placeholder-only environment and Policy configuration templates. Generate real local credentials with the quickstart utility.
Get templatesFind common HTTP errors, readiness behavior, local PostgreSQL test setup, and next diagnostic steps.
Diagnose an issueContinue to the architecture, policy and trust guides, runnable local example, or your account workspace.
Quickstart · Architecture · Policy · Trust boundaries · Account dashboard
Sample-only · runs locally
Compare source and target clearance levels, compartments, and actions. This simulator mirrors the current kernel's default compartment and READ/WRITE rules, but it does not call a server, create a signed verdict, or replace validation against your configured policy.
Ready. No request has been sent.
Select inputs and evaluate to see a sample decision.
Call Identity and Policy from a trusted server that owns the resource. Never put a Policy service token, signing key, or production bearer token in browser JavaScript, a public repository, or a downloadable template.
Example assumes your server has already accepted a bearer token from its caller.
const identity = await fetch(new URL('/api/auth/me', process.env.IDENTITY_URL), {
headers: { Authorization: `Bearer ${userAccessToken}` },
signal: AbortSignal.timeout(3000),
});
if (identity.status === 401 || identity.status === 403) return respond(401);
if (!identity.ok) return respond(503);
const { user } = await identity.json();
Only after Identity verification, send the verified subject and server-selected target. Fail closed on any unavailable, malformed, or denied response.
const decision = await fetch(new URL('/api/v1/governance/evaluate', process.env.POLICY_URL), {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.AARCHON_POLICY_TOKEN}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
requestId: crypto.randomUUID(),
subjectId: user.id,
subjectRole: user.role,
targetDomainId: 'report-team-a',
action: 'READ',
payloadHash: createHash('sha256').update('/api/reports/team-a').digest('hex'),
}),
signal: AbortSignal.timeout(3000),
});
if (!decision.ok) return respond(503);
const verdict = await decision.json();
if (typeof verdict.allowed !== 'boolean') return respond(503);
if (!verdict.allowed) return respond(403);
return respond(200, protectedResource);
These are integration patterns, not a hosted test console. Configure service URLs, role-to-domain mappings, and credentials on your own server. See the runnable local example for a complete tested flow.
Files contain placeholders only. Do not deploy them unchanged. For real random credentials and protected local files, use node examples/internal-api/setup-local-policy.js from the repository root.
The sample Policy token hash is deliberately a non-secret placeholder; replace it with the SHA-256 digest of a separately generated service token before starting Policy.
| Signal | Likely meaning | Next check |
|---|---|---|
GET /api/health → 200 | Identity process is live; this does not prove the database is ready. | Check readiness separately. |
GET /api/ready → 503 | Identity cannot reach or verify its persistence layer. | Check database availability and the server-managed DATABASE_URL; never paste credentials into a support request. |
| 401 Unauthorized | Missing, invalid, expired, or revoked user session/service token. | Re-authenticate the user or verify the server's service credential and Identity response. |
| 403 Forbidden | Cross-site write rejected, administrator role absent, or Policy denied access. | Inspect request origin, server-verified role mapping, compartment, and returned rule name. |
| 400 / 415 | Malformed fields, unknown domain/action, or unsupported content type. | Compare request JSON with the API reference; send JSON for Policy. |
| 409 Conflict | Account email is already registered. | Use the login flow; do not retry registration with altered casing. |
| 429 Too Many Requests | Authentication or Policy rate limit reached. | Honor Retry-After where present and reduce retry frequency. |
| PostgreSQL tests skipped | The integration suite requires an explicitly set TEST_DATABASE_URL. | Use the disposable database setup in the quickstart; tests intentionally do not fall back to production DATABASE_URL. |
For system boundaries and fail-closed responsibilities, review Trust boundaries. For startup and end-to-end checks, follow the Quickstart.