/api/openapi.json and Swagger UI at /api/docs.
Send a root or scoped broker credential on authenticated server requests:
Connections
An access body may contain:
configuration contains non-secret input accepted by the trusted provider.
Provider selection always comes from the final path segment, never the body.
The provider list describes credential acquisition and input controls:
oauth or secret. Identity fields become path segments;
configuration fields become immutable, non-secret connection configuration;
scope fields become requested OAuth scopes.
Clients should render input_schema.fields.
Broker administration
Browser facade
When application auth is configured,/api/client exposes provider metadata,
connection metadata, authorization starts, write-only secret storage, and
disconnect. It rejects credential access, callbacks, and administration.
All application responses set Cache-Control: no-store. List and get responses
never include stored secrets, refresh tokens, OAuth client secrets, or bearer
values. Secret writes return only storage status.