Versioning

All endpoints are under /api/v1. Future breaking changes will use /api/v2. The API version is part of the URL path, not a header.

Clients must tolerate additional response fields and preserve unknown evidence/status values as unknown rather than interpreting them as success. Do not depend on JSON key order, incidental list order, error-message wording, or undocumented fields. Existing documented fields and behavior form the compatibility contract; security fixes may tighten invalid-input handling. Release notes must identify relevant compatibility changes. Endpoints explicitly marked experimental or legacy carry the limitations stated in their sections.

The OpenAPI subset is a coverage boundary for machine-readable documentation, not a declaration that the remaining documented endpoints are unsupported. WebSocket protocols and terminal streams are outside that subset.