This contract, served by the running instance (password-protected)
The embedded copy of this OpenAPI document — backs the reference UI above. Same Basic Auth gate as /docs.
View as MarkdownAuthorization
docsBasic Gates /docs and /docs/openapi.yaml only. Credentials come from the DOCS_USER/DOCS_PASSWORD env vars; if either is unset the routes are not registered at all (404), never served open.
In: header
Response Body
text/plain
curl -X GET "https://example.com/docs/openapi.yaml""string"API reference UI (password-protected)
Scalar API reference for the running instance, gated by HTTP Basic Auth (DOCS_USER/DOCS_PASSWORD) — not linked from any product surface. Unlike tasks/links, auth is the platform's identity boundary, so this route is only registered at all when both env vars are set; an unconfigured deployment 404s here instead of serving it open.
Create an account with email + password
Creates an account with email_verified: false and emails a confirmation link (best-effort). No session is issued until the address is proven (202 verification_required): the owner opens the link, then signs in with the password. A password sign-in before that is refused with 403 email_unverified and a fresh link is sent. Domain auto-join/discovery is withheld until the address is confirmed.