API reference

KYE Protocol™ Cloud Partner-Plane API

18 operations · app-partner.yaml

Servers
https://app.kyeprotocol.com
Version
1.0.0
Source
app-partner.yaml

Consultant / partner / trainer / auditor plane of the KYE™ Cloud™ dashboard — app.kyeprotocol.com/partner/ (Cloudflare Pages Functions backed by the kye-prod D1 database; consolidated from the retired dash.kyeprotocol.com surface, §07 §1a 2026-07-16).

Deny-by-default auth: /_middleware.js verifies the Clerk RS256 JWT against the Clerk JWKS, resolves the signed-in user to a row in the consultants table by email (migration 008), and attaches the consultant context to every /api/v1/partner/* request. Any verification failure returns 401. A signed-in user whose email is not on the consultants roster receives 403 not_enrolled (with an apply_url); a suspended consultant receives 403 consultant_suspended. Responses are scoped to the calling consultant / partner / trainer-org id.

Consultant

GET/api/v1/partner/meSigned-in consultant profile + KPIs

Returns the consultant's own roster row plus aggregate KPI counts computed as live scalar D1 queries — open leads (captured / qualified), active tenant links, unexpired certifications, and signed attributions.

Auth: Session (Clerk JWT)

Responses

  • 200 Profile + KPI counters
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/settingsRead the consultant's editable profile fields

Returns the full consultants row for the signed-in consultant (identity, contact, sectors / languages JSON, bio, links, status, certification level, timestamps).

Auth: Session (Clerk JWT)

Responses

  • 200 Current settings row
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 404 Consultant row no longer present (consultant_not_found)
PATCH/api/v1/partner/settingsUpdate the consultant's editable profile fields

Parameterised D1 update of the consultants row. Only the whitelisted fields are writable from this surface; any other key in the body is ignored. String values are capped at 2000 characters; null clears a field. At least one editable field must be provided.

Auth: Session (Clerk JWT)

Request body (required)

fieldtypedescription
display_namestring,null
phonestring,null
countrystring,null
sectors_jsonstring,nullJSON-encoded array of sector slugs
languages_jsonstring,nullJSON-encoded array of language codes
biostring,null
websitestring,null
linkedinstring,null

Responses

  • 200 Update applied
  • 400 invalid_json, field_too_long, or no_editable_fields_provided
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/consultant-cardRead the consultant's signed Consultant Card™ envelope

Returns the latest signed kye.consultant_card.v1 envelope row for the signed-in consultant. Envelope signing happens server-side in the consultant-engine runtime; if no card row is provisioned yet the endpoint returns a minimal card view derived from the roster row with provisioned: false and a null envelope.

Auth: Session (Clerk JWT)

Responses

  • 200 Card view + signed envelope (envelope is null until provisioned)
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/tenantsTenants the signed-in consultant operates on

Rows from consultant_tenant_links (migration 008) for the calling consultant — invited / accepted / revoked link states plus aggregate counts. Scoped to the caller's consultant id by the partner-plane middleware; no cross-consultant reads.

Auth: Session (Clerk JWT)

Responses

  • 200 Link rows + counts for the calling consultant
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)

Pipeline

GET/api/v1/partner/leadsLeads assigned to the signed-in consultant

Lists consultant_leads rows assigned to the caller, newest first. The status filter maps onto the underlying lead states (open = captured + qualified).

Auth: Session (Clerk JWT)

Parameters

nameintypedescription
statusquerystring
limitqueryinteger

Responses

  • 200 Assigned leads
  • 400 bad_status_filter — status not in open | qualified | converted | rejected | all
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/partner-leadsPartner lead pipeline (partners.html panel)

The partner-panel projection of the caller's assigned consultant_leads rows (migration 008), mapped to the pipeline table shape (customer / stage / region / vertical / opened / ACV). expected_acv_usd is taken from the partner's own registered deal for the same customer when one exists and is null otherwise — no value is ever invented.

Auth: Session (Clerk JWT)

Parameters

nameintypedescription
limitqueryinteger

Responses

  • 200 Partner lead pipeline, newest first
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/partner-payoutsPartner payout history (partners.html panel)

Quarterly revenue-share ACCRUALS derived from the caller's closed_won deal_registrations rows (share % fixed at registration time, constitution §10 §6). Status is always "accrued" — no disbursement ledger exists yet, so nothing is ever reported as paid. A partner with no closed-won deals receives an honest empty list.

Auth: Session (Clerk JWT)

Responses

  • 200 Per-quarter accruals, newest first
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/deal-registrationsList deals registered by the calling partner

Returns up to 200 kye.deal_registration.v1 rows owned by the calling partner, newest first.

Auth: Session (Clerk JWT)

Responses

  • 200 Registered deals
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
POST/api/v1/partner/deal-registrationsRegister a new deal

Persists a kye.deal_registration.v1 row tracked against the partner's signing kid with a default 30% revenue share. customer is required; stage must be one of the canonical pipeline stages.

Auth: Session (Clerk JWT)

Request body (required)

fieldtypedescription
customer requiredstring
stage requiredstringOne of qualifying, scoping, contracting, closed_won, closed_lost
expected_closestringExpected close date (free-form ISO date string)
expected_acvnumberExpected annual contract value
notesstring

Responses

  • 200 Deal registered
  • 400 customer_required or invalid_stage
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project

Marketplace

GET/api/v1/partner/marketplace-listingsMarketplace listings owned by the caller

Lists the kye.{rule_pack,sector_pack,widget}_listing.v1 rows the calling partner / consultant owns — pricing, sectors, revenue-share split, publication status. Optionally filtered by listing kind.

Auth: Session (Clerk JWT)

Parameters

nameintypedescription
kindquerystring

Responses

  • 200 Owned listings (up to 200)
  • 400 invalid_kind — kind not in rule_pack | sector_pack | widget
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project

Evidence

GET/api/v1/partner/attributionsSigned attributions on evidence packs

Lists consultant_attributions rows for the signed-in consultant — each a signed attribution placed on a customer evidence pack (tenant_id, evidence_pack_id, attested_by / attested_at, signature alg + kid), newest first.

Auth: Session (Clerk JWT)

Parameters

nameintypedescription
limitqueryinteger

Responses

  • 200 Signed attributions
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/certificationsCertifications held by the signed-in consultant

Lists consultant_certifications rows with a derived active flag computed from the not_before / not_after validity window at request time, plus total / active counts.

Auth: Session (Clerk JWT)

Responses

  • 200 Certification history
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/reportsSigned reports the partner-plane user has access to

KYE™ Reporting Engine™ partner-plane view. Returns signed kye.report.v1 envelope rows on tenants the consultant is attributed to (access derives from consultant_attributions — a consultant who attested an evidence pack can read reports on that tenant). Optionally filtered by regulatory framework. Report synthesis itself is patent-track and not disclosed here.

Auth: Session (Clerk JWT)

Parameters

nameintypedescription
frameworkquerystringExact-match filter on the report's regulatory framework

Responses

  • 200 Accessible report envelopes (up to 200, newest sealed first)
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project

Replay

GET/api/v1/partner/replay-runsRecent Replay-Proof™ verifications by this user

Lists the last 100 replay-verify calls the caller has made via the partner console (decision id, verdict, signer kid, reason, timestamp).

Auth: Session (Clerk JWT)

Responses

  • 200 Verification history
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
POST/api/v1/partner/replay-verifyVerify a KYE-anchored artefact

Two clearly-separated verdict layers. (1) DISCLOSED — real Ed25519 signature verification of a { payload, signature: { alg: EdDSA, kid, sig } } envelope against the published self-audit JWKS (kyeprotocol.com/trust/self-audit-jwks.json); the §0.4 "Replay-Proof™ derivable from public keys alone" contract. (2) DEFERRED — offline replay reconstruction is patent-track; when the KYE_REPLAY_ENGINE service binding is present the call is proxied, otherwise that layer alone reports replay: deferred. Every call is recorded as a replay_runs row for the caller.

Auth: Session (Clerk JWT)

Request body (required)

fieldtypedescription
inputstringA signed envelope as a JSON string (verified against the JWKS), or a kye:decision:... id (routed to the replay layer).
livestring"latest" or a YYYY-MM-DD date — fetches and verifies the published LIVE self-audit bundle for that day.

Responses

  • 200 Verification result (both layers reported separately)
  • 400 empty_input, invalid_envelope_json, unrecognised_input, or live not "latest" / YYYY-MM-DD
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 502 The published LIVE self-audit bundle could not be fetched or was not JSON
  • 503 D1 binding KYE_DB is not configured on the Pages project

Training

GET/api/v1/partner/training-cohortsCohorts owned by the calling trainer-org

Lists up to 200 training cohorts owned by the caller with enrolled / passed counters. Signed completion records are surfaced separately via /api/v1/training-completions.

Auth: Session (Clerk JWT)

Responses

  • 200 Trainer-owned cohorts
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/training-completionsSigned training completion records

Lists up to 200 kye.training.completion.v1 envelope rows the trainer-org has sealed — partner_user_id, cohort_id, verdict (pass / fail / pending), score, sealed_at + signed_by_kid.

Auth: Session (Clerk JWT)

Responses

  • 200 Sealed completion records
  • 401 Missing bearer token, or JWT verification failed (signature / issuer / expiry)
  • 403 Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
  • 503 D1 binding KYE_DB is not configured on the Pages project