{"service":"platphorm-codex","version":"0.5.0","domain":"codex.platphormnews.com","auth":{"sharedKey":"PLATPHORM_API_KEY","acceptedHeaders":["Authorization: Bearer $PLATPHORM_API_KEY","X-PlatPhorm-API-Key: $PLATPHORM_API_KEY"],"forbiddenKeyNamesPolicy":"Do not use service-specific platform key names; use PLATPHORM_API_KEY only."},"publicReadOnly":["cinematic Codex experience","chapter and slide catalog","tool catalog and screenshot-backed cards","health summaries","route and discovery summaries","discovery files","read-only MCP introspection"],"protectedActions":["POST /api/v1/tools/sync","POST /api/v1/tools/{slug}/screenshot/refresh","POST /api/v1/slides/sync","POST /api/v1/network/graph/sync","POST /api/v1/browserops/capture","POST /api/v1/inspect/tool/{slug}"],"screenshotCapturePolicy":"Public screenshots are safe static captures. Refreshing screenshots or triggering BrowserOps requires PLATPHORM_API_KEY.","trustedDomainPolicy":"Default trusted scope is *.platphormnews.com plus explicit graph-discovered partner domains; localhost, private, link-local, and metadata hosts are blocked for discovery and capture adapters.","routeStandard":["/api/health","/api/v1/health","/api/docs","/openapi.yaml","/llms.txt","/llms-full.txt","/llms-index.json","/robots.txt","/sitemap.xml","/sitemap-index.xml","/rss.xml","/feed.xml","/manifest.webmanifest","/.well-known/mcp.json","/.well-known/agents.json","/.well-known/ai-plugin.json","/.well-known/security.txt","/.well-known/trust.json","/api/mcp"],"vercelMetadataPolicy":"Safe Vercel headers may be captured; raw IPs, cookies, Authorization, X-PlatPhorm-API-Key, and request bodies are never stored in public artifacts.","tracePropagationPolicy":"Codex emits and propagates W3C traceparent/tracestate plus safe PlatPhorm trace headers for graph, screenshot, inspection, API, MCP, and discovery operations.","dataExposurePolicy":"Public views contain public-safe screenshots and metadata only. Private reports, protected screenshot data, and secrets are excluded.","securityContact":"security@platphormnews.com","requiredTrustLine":"Web dashboard, public-safe discovery, browser-based operations, trusted-domain discovery, standard route compliance, Vercel metadata capture, trace inspection, and agentic workflow discovery are intentionally supported for public read-only debugging and operator workflows. Mutating, administrative, ingestion, replay, fork, remediation, deployment, sync, test-triggering, reporting, and write actions require PLATPHORM_API_KEY. Codex exploration, public-safe platform storytelling, screenshot-backed tool discovery, and MCP Codex discovery remain public read-only capabilities. Screenshot refresh, catalog sync, and publishing are protected actions."}