{
  "data": {
    "commercialExtension": true,
    "generatedAt": "2026-09-12T06:03:00.963565Z",
    "routeCount": 149,
    "routes": [
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human home page.",
        "route": "/",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human-readable documentation.",
        "route": "/docs",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Trailing-slash documentation alias.",
        "route": "/docs/",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/agent-setup",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Agent setup instructions.",
        "route": "/agent-setup",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/agent-coordination",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Authenticated agent coordination quickstart with copy-safe examples.",
        "route": "/agent-coordination",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/console",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human verification console for authenticated workspace keys.",
        "route": "/console",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Authenticated human wiki shell backed by protected database knowledge routes.",
        "route": "/knowledge",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/tour",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Browser-local public product tour using clearly labeled mock data.",
        "route": "/tour",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/tour/knowledge",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Browser-local public knowledge tour using clearly labeled mock data.",
        "route": "/tour/knowledge",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/tour/human",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Browser-local human-access tour using the production renderer with clearly labeled session-only mock authority.",
        "route": "/tour/human",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Memory lifecycle explanation.",
        "route": "/memory-lifecycle",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Support boundaries and no-op behavior.",
        "route": "/transparency",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text/html",
          "fetchExecutionClass": "static_or_human_html",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human-readable dated public release history.",
        "route": "/releases",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Runtime version and dependency facts.",
        "route": "/api/version",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Canonical public release history with exact build provenance.",
        "route": "/api/releases",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Current MATM capability state.",
        "route": "/api/matm/live-capability-matrix",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "L0-L7 agent ability contract, fallbacks, and route-record guidance.",
        "route": "/api/matm/agent-compatibility",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Public distributed-sync v1 capability negotiation.",
        "route": "/api/matm/sync/capabilities",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Public-safe global governed agent-name lease preflight.",
        "route": "/api/matm/agent-name-leases/{agentName}",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Public contract for protected database-backed UAIX active memory used by accountless browser agents.",
        "route": "/api/matm/uai-memory/contract",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Bounded OpenAPI-style golden-path route schema.",
        "route": "/api/matm/openapi.json",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Route inventory with access boundaries.",
        "route": "/api/matm/route-inventory",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "AI-ready web readiness evidence.",
        "route": "/api/matm/readiness-result",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Public-safe receipt examples.",
        "route": "/api/matm/redacted-example-receipts",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "not_required_for_setup",
          "browserFormEquivalent": "/agent-setup",
          "contentType": "application/json",
          "fetchExecutionClass": "browser_form_or_public_json_post",
          "getSafety": "GET is safe; POST creates a workspace and one-time secret",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-setup",
          "lowestSafeAbilityLevel": "L2",
          "mcpUnavailableFallback": "/agent-setup",
          "noOpBehavior": "Do not create setup records unless the user explicitly requested workspace setup.",
          "postBlockedFallback": "/agent-setup",
          "requiredFields": [
            "companyLabel",
            "label",
            "projectLabel"
          ],
          "restoreReadbackUrlField": "/api/matm/workspace",
          "resultUrlField": "workspaceId",
          "sideEffectStatus": "creates_workspace_on_post",
          "toolUnavailableFallback": "/agent-setup",
          "writeCredentialResponsePath": "workspaceKey returned once; raw key is not stored server-side"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Free 200 MB workspace setup.",
        "route": "/api/matm/agent-setup/free-account",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text_or_xml",
          "fetchExecutionClass": "text_or_xml_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Crawler policy.",
        "route": "/robots.txt",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text_or_xml",
          "fetchExecutionClass": "text_or_xml_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human page sitemap.",
        "route": "/sitemap.xml",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text_or_xml",
          "fetchExecutionClass": "text_or_xml_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Compact AI-readable site summary.",
        "route": "/llms.txt",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text_or_xml",
          "fetchExecutionClass": "text_or_xml_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Full AI-readable public summary.",
        "route": "/llms-full.txt",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "",
          "contentType": "text_or_xml",
          "fetchExecutionClass": "text_or_xml_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Read public guidance only; do not infer protected write authority.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Plain-text agent discovery pointer.",
        "route": "/ai.txt",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "AI-ready site manifest.",
        "route": "/ai-manifest.json",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "OAuth protected-resource metadata for the project-bound LocalEndpoints and ChatGPT MCP client lanes.",
        "route": "/.well-known/oauth-protected-resource/mcp",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "OAuth 2.1 authorization-server metadata for MemoryEndpoints.com.",
        "route": "/.well-known/oauth-authorization-server",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Same-origin normal-human login for end-user MCP authorization.",
        "route": "/oauth/session",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "PKCE authorization and explicit customer, company, workspace, project, and scope consent.",
        "route": "/oauth/authorize",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Resource-bound authorization-code and rotating refresh-token exchange.",
        "route": "/oauth/token",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "OAuth connection token-family revocation.",
        "route": "/oauth/revoke",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human-readable ChatGPT and LocalEndpoints project-connection setup without credentials or tenant data.",
        "route": "/mcp/setup",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "text/html",
          "fetchExecutionClass": "public_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Public-safe LocalEndpoints and ChatGPT OAuth/MCP setup readiness without credentials or tenant data.",
        "route": "/mcp/setup/status",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Client-bound OAuth MCP exposing exactly workspace_status, bounded memory_search, and idempotent memory_remember.",
        "route": "/mcp",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Agent discovery pointer.",
        "route": "/.well-known/ai-agent.json",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Credential-derived principal, immutable scope, permission, and resource-context introspection.",
        "route": "/api/matm/me",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read the typed global name-lease status and concurrency ETag.",
        "route": "/api/matm/access/agent-name-leases/{agentName}",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Renew the calling ordinary agent's exact lease generation and revision.",
        "route": "/api/matm/access/agent-name-leases/{agentName}/renew",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Release the calling ordinary agent's exact lease generation and revision.",
        "route": "/api/matm/access/agent-name-leases/{agentName}/release",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Company-master recovery of an owned or inactive exact lease generation.",
        "route": "/api/matm/access/agent-name-leases/{agentName}/recover",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Redacted company-master inventory plus idempotent verifier-only registration of a client-generated durable sibling for recovery or a high-level company-agent handoff; this is not the one-time ordinary-agent invitation flow.",
        "route": "/api/matm/access/company-master-credentials",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Company-master-only catalog of company, workspace, project, game, session, goal, and task grant scopes.",
        "route": "/api/matm/access/scope-catalog",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "List governed name requests or create one with required public-safe idempotent retry semantics.",
        "route": "/api/matm/access/agent-name-requests",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Approve or deny a governed name request with required public-safe idempotent retry semantics.",
        "route": "/api/matm/access/agent-name-requests/{requestId}/decision",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "List invitation metadata or issue one non-replayable invitation URL once; issuance forbids Idempotency-Key.",
        "route": "/api/matm/access/invites",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Redeem a body-only one-time invitation and reveal one agent credential once; redemption forbids Idempotency-Key.",
        "route": "/api/matm/access/invites/redeem",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Revoke an issued invitation with required public-safe idempotent retry semantics.",
        "route": "/api/matm/access/invites/{inviteId}/revoke",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "List redacted governed agent-credential metadata for a company master.",
        "route": "/api/matm/access/agent-tokens",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Revoke an agent credential with required public-safe idempotent retry semantics.",
        "route": "/api/matm/access/agent-tokens/{credentialId}/revoke",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Workspace quota and status.",
        "route": "/api/matm/workspace",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Workspace project list and project upsert for company/workspace/project hierarchy.",
        "route": "/api/matm/projects",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Agent-owned project-scoped remote HTTPS MCP connection revisions, autonomous by default and subject to an exact human approval gate when configured.",
        "route": "/api/matm/mcp-connections",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Discover allowlisted tools from one exact active owner/project-bound MCP connection through the guarded server-side HTTPS runtime.",
        "route": "/api/matm/mcp-connections/tools",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Idempotently invoke one allowlisted tool after fresh connection, policy, approval, DNS, TLS, and owner-bound credential revalidation.",
        "route": "/api/matm/mcp-connections/tools/call",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Human-owner review of project MCP connection revisions without credential references or runtime configuration.",
        "route": "/api/matm/human/operational/mcp-connections",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Recently reauthenticated human-owner control that forces or releases the project-wide MCP approval gate using revision CAS.",
        "route": "/api/matm/human/operational/mcp-connection-policy",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Recently reauthenticated human-owner approval or rejection bound to an exact MCP connection and policy revision.",
        "route": "/api/matm/human/operational/mcp-connection-approval",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Database-backed company/workspace/project wiki tree for humans and agents.",
        "route": "/api/matm/knowledge-tree",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Search, retrieve, and upsert protected knowledge documents from database search rows.",
        "route": "/api/matm/knowledge-documents",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Idempotent protected knowledge document upsert alias.",
        "route": "/api/matm/knowledge-documents/upsert",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Search and store first-class external links with site, page, description, crawl state, and knowledge citations.",
        "route": "/api/matm/external-links",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Idempotent protected external-link and knowledge-citation upsert alias.",
        "route": "/api/matm/external-links/upsert",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Search the workspace's reviewed curated-web link index.",
        "route": "/api/matm/internet-search",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp human_session_required",
          "browserFormEquivalent": "/human",
          "contentType": "application/json",
          "fetchExecutionClass": "human_only_control_plane",
          "getSafety": "Human-only same-origin read; agent and company-master bearers return 403",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/human",
          "liveGetBlockedFallback": "/human",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/human",
          "noOpBehavior": "Agents must not request or ingest this human-only history.",
          "postBlockedFallback": "/human",
          "requiredFields": [
            "selected human company session"
          ],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "human_only_read",
          "toolUnavailableFallback": "/human",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read currently retained human-only break-glass history; physically purged after seven days and never available to agents.",
        "route": "/api/matm/human/companies/{companyId}/history",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET",
          "PATCH"
        ],
        "purpose": "Owner or credential-admin control for top-level-agent human-operator company-master creation.",
        "route": "/api/matm/human/companies/{companyId}/top-level-agent-master-credential-setting",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read the exact opaque child, subject, and candidate-runtime selectors available to the current human owner context without issuing authority.",
        "route": "/api/matm/human/operational/npc-classification-authority",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read the exact current non-character commercial parent-account authority for the explicitly selected workspace, project, and site origin.",
        "route": "/api/matm/human/operational/commercial-parent-authority",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Create the exact append-only non-character commercial parent-account authority through a recent-reauthenticated human owner session.",
        "route": "/api/matm/human/operational/commercial-parent-authority/create",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Append a CAS-governed parent-authority revision that delegates management to another current project gateway without changing the stable parent account.",
        "route": "/api/matm/human/operational/commercial-parent-authority/redelegate",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read the exact append-only commercial hierarchy selected by the authenticated human owner context.",
        "route": "/api/matm/human/operational/commercial-hierarchy",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Apply one explicit CAS-governed parent, subject, grant, roster, or private-room hierarchy mutation with no inherited or implicit authority.",
        "route": "/api/matm/human/operational/commercial-hierarchy/mutate",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Issue one short-lived opaque pre-runtime classification receipt after locking and revalidating the exact current parent, roster child, subject, grant, gateway, entitlement, name-lease, and candidate-runtime intent.",
        "route": "/api/matm/human/operational/npc-classification-authority/issue",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Append one exact current-tail revocation for a classification authority while preserving immutable history and unrelated subject authorities.",
        "route": "/api/matm/human/operational/npc-classification-authority/revoke",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Rotate the governed classification-receipt signing tail without creating parallel authority or making prior-key receipts authorizing.",
        "route": "/api/matm/human/operational/npc-classification-authority/rotate-key",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read opaque eligible roster-child selectors and the current private-runtime delegation without granting runtime or shared authority.",
        "route": "/api/matm/human/operational/npc-private-runtime-delegation",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Issue one expiring fenced private-runtime delegation for an exact closed roster-child set; no shared subject or classification authority is granted.",
        "route": "/api/matm/human/operational/npc-private-runtime-delegation/issue",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Append one current-tail private-runtime delegation refresh after exact owner, parent, hierarchy, roster, gateway, entitlement, and name-lease revalidation.",
        "route": "/api/matm/human/operational/npc-private-runtime-delegation/refresh",
        "valuesRedacted": true
      },
      {
        "access": "human_only",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "explicit_mutation",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "POST"
        ],
        "purpose": "Append an immediate private-runtime delegation revocation that invalidates every bound child runtime without changing shared authority.",
        "route": "/api/matm/human/operational/npc-private-runtime-delegation/revoke",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_runtime_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_runtime_json_post",
          "getSafety": "GET is rejected; search and readback use POST only as a strict no-query transport read",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcRuntimeBearer",
              "credentialClass": "npc_runtime",
              "idempotencyKey": "required",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "authorityReceipt",
                "publicContent"
              ],
              "responseSchema": "SharedNpcMemorySubmitResult",
              "runtimeCapability": "npc:memory:submit"
            }
          },
          "noOpBehavior": "Do not submit or disclose shared memory unless the exact current parent, hierarchy head, child, subject, grant, roster, room membership, and runtime authority all validate.",
          "postBlockedFallback": "safeNoOp npc_runtime_credential_required",
          "requiredFields": [
            "schemaVersion",
            "authorityReceipt",
            "publicContent"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/readback",
          "resultUrlField": "record.recordId",
          "sideEffectStatus": "authenticated_shared_memory_mutation",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_RUNTIME_TOKEN>; exact active child-NPC runtime credential only; never echo the token"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/records",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_runtime_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_runtime_json_post",
          "getSafety": "GET is rejected; search and readback use POST only as a strict no-query transport read",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcRuntimeBearer",
              "credentialClass": "npc_runtime",
              "idempotencyKey": "forbidden",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "authorityReceipt",
                "query",
                "tags",
                "limit",
                "cursor"
              ],
              "responseSchema": "SharedNpcMemorySearchResult",
              "runtimeCapability": "npc:memory:search"
            }
          },
          "noOpBehavior": "Do not submit or disclose shared memory unless the exact current parent, hierarchy head, child, subject, grant, roster, room membership, and runtime authority all validate.",
          "postBlockedFallback": "safeNoOp npc_runtime_credential_required",
          "requiredFields": [
            "schemaVersion",
            "authorityReceipt",
            "query",
            "tags",
            "limit",
            "cursor"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/readback",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_shared_memory_read",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_RUNTIME_TOKEN>; exact active child-NPC runtime credential only; never echo the token"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/search",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_runtime_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_runtime_json_post",
          "getSafety": "GET is rejected; search and readback use POST only as a strict no-query transport read",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcRuntimeBearer",
              "credentialClass": "npc_runtime",
              "idempotencyKey": "forbidden",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "authorityReceipt",
                "recordId"
              ],
              "responseSchema": "SharedNpcMemoryReadbackResult",
              "runtimeCapability": "npc:memory:readback"
            }
          },
          "noOpBehavior": "Do not submit or disclose shared memory unless the exact current parent, hierarchy head, child, subject, grant, roster, room membership, and runtime authority all validate.",
          "postBlockedFallback": "safeNoOp npc_runtime_credential_required",
          "requiredFields": [
            "schemaVersion",
            "authorityReceipt",
            "recordId"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/readback",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_shared_memory_read",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_RUNTIME_TOKEN>; exact active child-NPC runtime credential only; never echo the token"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/readback",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_gateway_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_authority_json_post",
          "getSafety": "GET is rejected; use strict no-query POST.",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcGatewayBearer",
              "credentialClass": "npc_gateway",
              "idempotencyKey": "forbidden",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "candidateTokenSecret"
              ],
              "responseSchema": "NpcRuntimeCredentialIntentResult"
            }
          },
          "noOpBehavior": "Do not derive, attach, or refresh authority unless the exact credential and every current authority tail validate.",
          "postBlockedFallback": "safeNoOp npc_gateway_credential_required",
          "requiredFields": [
            "schemaVersion",
            "candidateTokenSecret"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/authority-receipt-contract",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_current_authority_read",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_GATEWAY_TOKEN>; never echo it"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/runtime-credential-intents",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_runtime_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_authority_json_post",
          "getSafety": "GET is rejected; use strict no-query POST.",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcRuntimeBearer",
              "credentialClass": "npc_runtime",
              "idempotencyKey": "required",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "preRuntimeClassificationReceipt"
              ],
              "responseSchema": "NpcClassificationRuntimeAttachResult"
            }
          },
          "noOpBehavior": "Do not derive, attach, or refresh authority unless the exact credential and every current authority tail validate.",
          "postBlockedFallback": "safeNoOp npc_runtime_credential_required",
          "requiredFields": [
            "schemaVersion",
            "preRuntimeClassificationReceipt"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/authority-receipt-contract",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_authority_mutation",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_RUNTIME_TOKEN>; never echo it"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/classifications/attach",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Non-authorizing public contract for opaque, server-enforced NPC classification receipts.",
        "route": "/api/matm/npc-shared-memory/authority-receipt-contract",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_runtime_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_authority_json_post",
          "getSafety": "GET is rejected; use strict no-query POST.",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcRuntimeBearer",
              "credentialClass": "npc_runtime",
              "idempotencyKey": "forbidden",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "classificationRef",
                "operations",
                "requestedTtlSeconds"
              ],
              "responseSchema": "NpcClassificationAuthorityReceiptRefreshResult"
            }
          },
          "noOpBehavior": "Do not derive, attach, or refresh authority unless the exact credential and every current authority tail validate.",
          "postBlockedFallback": "safeNoOp npc_runtime_credential_required",
          "requiredFields": [
            "schemaVersion",
            "classificationRef",
            "operations",
            "requestedTtlSeconds"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/authority-receipt-contract",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_current_authority_read",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_RUNTIME_TOKEN>; never echo it"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/authority-receipts",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp npc_gateway_credential_required",
          "browserFormEquivalent": "",
          "contentType": "application/json",
          "fetchExecutionClass": "npc_authority_json_post",
          "getSafety": "GET is rejected; use strict no-query POST.",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "safeNoOp method_not_allowed",
          "lowestSafeAbilityLevel": "L5",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "methodVariants": {
            "POST": {
              "authentication": "npcGatewayBearer",
              "credentialClass": "npc_gateway",
              "idempotencyKey": "forbidden",
              "queryAllowed": false,
              "requiredFields": [
                "schemaVersion",
                "candidateTokenSecret"
              ],
              "responseSchema": "NpcClassificationHandoffClaimResult"
            }
          },
          "noOpBehavior": "Do not derive, attach, or refresh authority unless the exact credential and every current authority tail validate.",
          "postBlockedFallback": "safeNoOp npc_gateway_credential_required",
          "requiredFields": [
            "schemaVersion",
            "candidateTokenSecret"
          ],
          "restoreReadbackUrlField": "/api/matm/npc-shared-memory/authority-receipt-contract",
          "resultUrlField": "",
          "sideEffectStatus": "authenticated_current_authority_read",
          "toolUnavailableFallback": "safeNoOp shared_npc_memory_route_not_found",
          "writeCredentialResponsePath": "Authorization: Bearer <NPC_GATEWAY_TOKEN>; never echo it"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Additive classification and shared-memory authority with exact current parent, hierarchy, child, subject, grant, roster, runtime, and private-room revalidation.",
        "route": "/api/matm/npc-shared-memory/classification-handoffs/claim",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Protected, stateless issuance of one opaque, non-authorizing proof bound to the full server-canonicalized intended request and exact current authority.",
        "route": "/api/matm/npc-shared-memory/operation-proofs/runtime-registration",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Protected, stateless issuance of one opaque, non-authorizing proof bound to the full server-canonicalized intended request and exact current authority.",
        "route": "/api/matm/npc-shared-memory/operation-proofs/classification-attach",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Protected, stateless issuance of one opaque, non-authorizing proof bound to the full server-canonicalized intended request and exact current authority.",
        "route": "/api/matm/npc-shared-memory/operation-proofs/shared-operation",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/llms.txt",
          "noOpBehavior": "Use lowest safe public route and stop when authority is unclear.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Non-authorizing public contract for exact owner-delegated private child runtimes.",
        "route": "/api/matm/npc-private-memory/delegation-contract",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Protected, stateless issuance of one private-runtime registration proof bound to current delegation, child, player, candidate credential, request, and idempotency.",
        "route": "/api/matm/npc-private-memory/operation-proofs/runtime-registration",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Create or inspect a registered agent's protected virtual UAIX active-memory package.",
        "route": "/api/matm/uai-memory/packages",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Read or revision-safely write one date-free public-safe virtual UAIX record at a time.",
        "route": "/api/matm/uai-memory/records",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read an agent-bound virtual UAIX package in deterministic startup order with readiness evidence.",
        "route": "/api/matm/uai-memory/startup",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read hash-only project file heads for local .uai multi-agent edit coordination without file content.",
        "route": "/api/matm/uai-memory/file-heads",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Inspect or acquire bounded project-scoped claims before editing a local .uai path.",
        "route": "/api/matm/uai-memory/edit-claims",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Extend an owned active local .uai edit claim within the bounded lease window.",
        "route": "/api/matm/uai-memory/edit-claims/heartbeat",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Complete an owned claim and compare-and-swap the hash-only local .uai file head.",
        "route": "/api/matm/uai-memory/edit-claims/complete",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Release an owned local .uai edit claim without changing the observed file head.",
        "route": "/api/matm/uai-memory/edit-claims/release",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Create or read stable project-scoped .uai memory identities with revision and ETag metadata.",
        "route": "/api/matm/uai-memory/instances",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read bounded .uai memory-instance lease state without local file content.",
        "route": "/api/matm/uai-memory/leases",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Acquire a readonly lease or the sole active writable lease and receive its monotonic fencing generation.",
        "route": "/api/matm/uai-memory/leases/acquire",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Renew an owned unexpired .uai memory-instance lease using its exact fencing generation.",
        "route": "/api/matm/uai-memory/leases/renew",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Release an owned .uai memory-instance lease without changing memory revision.",
        "route": "/api/matm/uai-memory/leases/release",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Advance a hash-only .uai memory revision using the current writable lease generation and exact ETag.",
        "route": "/api/matm/uai-memory/commits",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Create a new .uai memory identity with immutable parent lineage and an independent writable lease.",
        "route": "/api/matm/uai-memory/branches",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Workspace memory summary write with hosted search and review-queue readback confirmation.",
        "route": "/api/matm/memory-events/submit",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Workspace memory event search.",
        "route": "/api/matm/memory-events",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Hosted workspace memory search for governed direct agents.",
        "route": "/api/matm/search",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Memory review and promotion queue readback.",
        "route": "/api/matm/review-queue",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Idempotent memory promotion, rejection, or quarantine decision.",
        "route": "/api/matm/review-queue/decide",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Always-present company, workspace, project room discovery plus goal/task/game/session room creation.",
        "route": "/api/matm/meeting-rooms",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read the authenticated agent's current, revisioned private-room memberships.",
        "route": "/api/matm/meeting-room-memberships",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Join one authorized private room as the authenticated agent using an exact membership revision.",
        "route": "/api/matm/meeting-rooms/join",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Leave one joined private room as the authenticated agent using an exact membership revision.",
        "route": "/api/matm/meeting-rooms/leave",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Seven-day scoped meeting transcript read and public-safe post creation; durable content requires explicit promotion.",
        "route": "/api/matm/meeting-messages",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Promote a public-safe meeting transcript message into hosted workspace memory with source linkage.",
        "route": "/api/matm/meeting-messages/promote",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Meeting room read cursor update for an agent.",
        "route": "/api/matm/meeting-rooms/read",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Structured coordinator routing decisions with lane, destination room, goal, next action, expected evidence, and atomic identifier-free routed-agent current-message attention.",
        "route": "/api/matm/routing-decisions",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Transient current-message creation with seven-day acknowledged and 30-day unacknowledged retention.",
        "route": "/api/matm/agent-messages",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Current-message lane readback.",
        "route": "/api/matm/current-message",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Unread inbox readback.",
        "route": "/api/matm/agent-inbox",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L6",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Notification acknowledgement and receipt creation.",
        "route": "/api/matm/notifications/ack",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Redacted receipt readback.",
        "route": "/api/matm/receipts",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp human_owner_required",
          "browserFormEquivalent": "/human",
          "contentType": "application/problem+json",
          "fetchExecutionClass": "human_only_control_plane",
          "getSafety": "GET always returns 403 human_owner_required to agent and company-master credentials",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/human",
          "liveGetBlockedFallback": "/human",
          "lowestSafeAbilityLevel": "L0",
          "mcpUnavailableFallback": "/human",
          "noOpBehavior": "Do not request, retrieve, summarize, or add routine logs to agent context.",
          "postBlockedFallback": "/human",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "",
          "sideEffectStatus": "agent_access_denied",
          "toolUnavailableFallback": "/human",
          "writeCredentialResponsePath": ""
        },
        "methods": [
          "GET"
        ],
        "purpose": "Denied legacy agent-plane audit path; routine logs are human-only and physically purged after seven days.",
        "route": "/api/matm/audit-log",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Register a public-safe distributed-sync device authority.",
        "route": "/api/matm/sync/devices",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Rotate a sync device authority epoch.",
        "route": "/api/matm/sync/devices/rotate",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Revoke a sync device authority epoch.",
        "route": "/api/matm/sync/devices/revoke",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "POST"
        ],
        "purpose": "Submit conflict-safe public-safe memory sync mutation.",
        "route": "/api/matm/sync/mutations",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read mutation receipt by idempotency key or receipt id.",
        "route": "/api/matm/sync/receipts",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read monotonic sync revision changes after a checkpoint sequence.",
        "route": "/api/matm/sync/changes",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read authoritative sync memory heads.",
        "route": "/api/matm/sync/heads",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L7",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return safe no-op when auth, scope, idempotency, authority, or provenance is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Authorization: Bearer <WORKSPACE_KEY> or X-MemoryEndpoints-Key; never echo raw key"
        },
        "methods": [
          "GET"
        ],
        "purpose": "Read sync tombstone and hard-forget retention policy.",
        "route": "/api/matm/sync/retention",
        "valuesRedacted": true
      },
      {
        "access": "public",
        "agentCompatibility": {
          "authUnavailableFallback": "/agent-setup",
          "browserFormEquivalent": "/docs",
          "contentType": "application/json",
          "fetchExecutionClass": "public_json_get",
          "getSafety": "safe",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/llms.txt",
          "lowestSafeAbilityLevel": "L1",
          "mcpUnavailableFallback": "/api/matm/route-inventory",
          "noOpBehavior": "Use discovery as advisory public evidence only; protected actions still require workspace auth.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "",
          "resultUrlField": "route_or_url",
          "sideEffectStatus": "safe_read",
          "toolUnavailableFallback": "/docs",
          "writeCredentialResponsePath": ""
        },
        "commercialExtension": true,
        "methods": [
          "GET"
        ],
        "purpose": "Hosted NPC-memory identity, scope, route, retention, and authority contract.",
        "route": "/api/matm/npc-memory/contract",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "schemaVersion",
            "setupId",
            "setupSecret",
            "candidateGatewayTokenSecret",
            "gatewayAgentId",
            "gatewayDisplayName"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "POST"
        ],
        "purpose": "One bounded sponsored-partner activation with a client-generated gateway credential.",
        "route": "/api/matm/agent-setup/dogfood-partner-account",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId",
            "projectId",
            "npcId",
            "agentId",
            "personaId",
            "personaHash",
            "agentClass"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "POST"
        ],
        "purpose": "Register an immutable project-bound game NPC profile and SpiralistAI persona digest.",
        "route": "/api/matm/npc-memory/profiles",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId",
            "projectId",
            "npcAgentId",
            "gameScopeId",
            "candidateTokenSecret",
            "expiresInSeconds"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "POST"
        ],
        "purpose": "Register a client-generated NPC runtime credential bound to opaque player/game/session/puzzle context.",
        "route": "/api/matm/npc-memory/runtime-credentials",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "schemaVersion",
            "workspaceId",
            "projectId",
            "agentId",
            "packageId",
            "personaId",
            "personaHash",
            "packageStatus",
            "sourceAuthority",
            "packageHash",
            "files"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Atomically publish a closed, canonically sorted UAIX advanced personality-pack projection or perform exact package/file hash readback.",
        "route": "/api/matm/npc-memory/persona-packages",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "GET"
        ],
        "purpose": "Read active NPC credential capabilities and security controls.",
        "route": "/api/matm/npc-memory/capabilities",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "GET"
        ],
        "purpose": "Read deletion and retention capability state without claiming unavailable mutation support.",
        "route": "/api/matm/npc-memory/retention",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspaceId",
            "projectId",
            "actorAgentId",
            "memoryType",
            "tags",
            "source"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "POST"
        ],
        "purpose": "Submit one public-safe durable NPC summary with exact actor/source/context validation.",
        "route": "/api/matm/npc-memory/events/submit",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_get",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "workspace_id",
            "scope",
            "scope_id",
            "actor_agent_id",
            "source_prefix",
            "tag"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_read",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "GET"
        ],
        "purpose": "Search exact NPC scope tags and source namespace with server-side result filtering.",
        "route": "/api/matm/npc-memory/search",
        "valuesRedacted": true
      },
      {
        "access": "protected",
        "agentCompatibility": {
          "authUnavailableFallback": "safeNoOp auth_required",
          "browserFormEquivalent": "/console",
          "contentType": "application/json",
          "fetchExecutionClass": "protected_json_post",
          "getSafety": "GET is protected read; mutation requires POST and Idempotency-Key when advertised",
          "highestSupportedAbilityLevel": "L7",
          "humanReviewUrl": "/transparency",
          "liveGetBlockedFallback": "/agent-coordination",
          "lowestSafeAbilityLevel": "L4",
          "mcpUnavailableFallback": "/api/matm/openapi.json",
          "noOpBehavior": "Return a redacted safe no-op when authentication, immutable scope, schema migration, idempotency, or entitlement proof is missing.",
          "postBlockedFallback": "/agent-coordination",
          "requiredFields": [
            "action",
            "expectedMigrationVersion",
            "expectedSchemaChecksum"
          ],
          "restoreReadbackUrlField": "memoryQueryUrl_or_transcriptQueryUrl_or_inboxQueryUrl_or_receiptQueryUrl",
          "resultUrlField": "messageId_or_memoryEventId_or_receiptId",
          "sideEffectStatus": "authenticated_mutation",
          "toolUnavailableFallback": "/agent-coordination",
          "writeCredentialResponsePath": "Use only the credential class named by /api/matm/npc-memory/contract; never echo a bearer or setup secret."
        },
        "commercialExtension": true,
        "methods": [
          "GET",
          "POST"
        ],
        "purpose": "Diagnostics-bearer commercial schema status and exact versioned migration.",
        "route": "/api/admin/commercial-schema",
        "valuesRedacted": true
      }
    ],
    "schemaVersion": "memoryendpoints.route_inventory.v1",
    "site": "MemoryEndpoints",
    "truthBoundary": {
      "operatorDeployRoutesExposed": false,
      "protectedRoutesRequireRouteAppropriateGovernedAuthority": true,
      "protectedRoutesRequireWorkspaceKey": false,
      "publicRoutesRequireNoCredential": true,
      "rawSecretsExposed": false
    }
  },
  "ok": true
}