Browse the public endpoints intended for applications, agents, and protected resources. Filter by workflow and authentication boundary, then move into a quickstart or SDK when you are ready to integrate.
Common integration handlingSchemas are in the published specification
2xx — request accepted
401 — token missing or invalid
403 — tenant or authority refused
409 — state or parameter conflict
This page documents the public integration surface only. Administrative and operational routes are intentionally excluded. Confirm request and response schemas in the published specification before production integration.
The enforcement path
Follow every endpoint above from identity to evidence.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
01IdentityWho or what is acting
02IntentSigned purpose and limits
03PolicyDeterministic evaluation
04ApprovalA named human when required
05ExecutionSingle-use grant, redeemed at the resource