This contract, served by the running instance (password-protected)
The embedded copy of this OpenAPI document — backs the reference UI above and is handy for local codegen against a running instance. Same Basic Auth gate as /docs.
View as MarkdownAuthorization
docsBasic Gates /docs, /docs/openapi.yaml, and /debug/webhooks/stats. Credentials come from the DOCS_USER/DOCS_PASSWORD env vars; if either is unset the routes are not registered at all (404), never served open.
In: header
Response Body
text/plain
curl -X GET "https://example.com/docs/openapi.yaml""string"API reference UI (password-protected)
Scalar API reference for the running instance, gated by HTTP Basic Auth (DOCS_USER/DOCS_PASSWORD) — not linked from any product surface. The route is only registered at all when both env vars are set; an unconfigured deployment 404s here instead of serving it open.
Webhook dispatcher observability snapshot (password-protected)
Operator-facing, not tenant-facing: aggregate, cross-tenant webhook delivery health (pending count, oldest pending age, outcome counters, latency, worker utilization, per-destination-host failure rate) for this process's dispatcher. Gated by the same Basic Auth as /docs, never the per-tenant v1 auth group, since this is cross-tenant volume/health data no single authenticated caller's own webhooks should reveal.