API reference
KYE Protocol™ Cloud Partner-Plane API
18 operations · app-partner.yaml
Consultant / partner / trainer / auditor plane of the KYE™ Cloud™ dashboard — app.kyeprotocol.com/partner/ (Cloudflare Pages Functions backed by the kye-prod D1 database; consolidated from the retired dash.kyeprotocol.com surface, §07 §1a 2026-07-16).
Deny-by-default auth: /_middleware.js verifies the Clerk RS256 JWT against the Clerk JWKS, resolves the signed-in user to a row in the consultants table by email (migration 008), and attaches the consultant context to every /api/v1/partner/* request. Any verification failure returns 401. A signed-in user whose email is not on the consultants roster receives 403 not_enrolled (with an apply_url); a suspended consultant receives 403 consultant_suspended. Responses are scoped to the calling consultant / partner / trainer-org id.
Consultant
GET/api/v1/partner/meSigned-in consultant profile + KPIs
Returns the consultant's own roster row plus aggregate KPI counts computed as live scalar D1 queries — open leads (captured / qualified), active tenant links, unexpired certifications, and signed attributions.
Auth: Session (Clerk JWT)
Responses
200Profile + KPI counters401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/settingsRead the consultant's editable profile fields
Returns the full consultants row for the signed-in consultant (identity, contact, sectors / languages JSON, bio, links, status, certification level, timestamps).
Auth: Session (Clerk JWT)
Responses
200Current settings row401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)404Consultant row no longer present (consultant_not_found)
PATCH/api/v1/partner/settingsUpdate the consultant's editable profile fields
Parameterised D1 update of the consultants row. Only the whitelisted fields are writable from this surface; any other key in the body is ignored. String values are capped at 2000 characters; null clears a field. At least one editable field must be provided.
Auth: Session (Clerk JWT)
Request body (required)
| field | type | description |
|---|---|---|
display_name | string,null | |
phone | string,null | |
country | string,null | |
sectors_json | string,null | JSON-encoded array of sector slugs |
languages_json | string,null | JSON-encoded array of language codes |
bio | string,null | |
website | string,null | |
linkedin | string,null |
Responses
200Update applied400invalid_json, field_too_long, or no_editable_fields_provided401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/consultant-cardRead the consultant's signed Consultant Card™ envelope
Returns the latest signed kye.consultant_card.v1 envelope row for the signed-in consultant. Envelope signing happens server-side in the consultant-engine runtime; if no card row is provisioned yet the endpoint returns a minimal card view derived from the roster row with provisioned: false and a null envelope.
Auth: Session (Clerk JWT)
Responses
200Card view + signed envelope (envelope is null until provisioned)401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/tenantsTenants the signed-in consultant operates on
Rows from consultant_tenant_links (migration 008) for the calling consultant — invited / accepted / revoked link states plus aggregate counts. Scoped to the caller's consultant id by the partner-plane middleware; no cross-consultant reads.
Auth: Session (Clerk JWT)
Responses
200Link rows + counts for the calling consultant401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
Pipeline
GET/api/v1/partner/leadsLeads assigned to the signed-in consultant
Lists consultant_leads rows assigned to the caller, newest first. The status filter maps onto the underlying lead states (open = captured + qualified).
Auth: Session (Clerk JWT)
Parameters
| name | in | type | description |
|---|---|---|---|
status | query | string | |
limit | query | integer |
Responses
200Assigned leads400bad_status_filter — status not in open | qualified | converted | rejected | all401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/partner-leadsPartner lead pipeline (partners.html panel)
The partner-panel projection of the caller's assigned consultant_leads rows (migration 008), mapped to the pipeline table shape (customer / stage / region / vertical / opened / ACV). expected_acv_usd is taken from the partner's own registered deal for the same customer when one exists and is null otherwise — no value is ever invented.
Auth: Session (Clerk JWT)
Parameters
| name | in | type | description |
|---|---|---|---|
limit | query | integer |
Responses
200Partner lead pipeline, newest first401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/partner-payoutsPartner payout history (partners.html panel)
Quarterly revenue-share ACCRUALS derived from the caller's closed_won deal_registrations rows (share % fixed at registration time, constitution §10 §6). Status is always "accrued" — no disbursement ledger exists yet, so nothing is ever reported as paid. A partner with no closed-won deals receives an honest empty list.
Auth: Session (Clerk JWT)
Responses
200Per-quarter accruals, newest first401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/deal-registrationsList deals registered by the calling partner
Returns up to 200 kye.deal_registration.v1 rows owned by the calling partner, newest first.
Auth: Session (Clerk JWT)
Responses
200Registered deals401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
POST/api/v1/partner/deal-registrationsRegister a new deal
Persists a kye.deal_registration.v1 row tracked against the partner's signing kid with a default 30% revenue share. customer is required; stage must be one of the canonical pipeline stages.
Auth: Session (Clerk JWT)
Request body (required)
| field | type | description |
|---|---|---|
customer required | string | |
stage required | string | One of qualifying, scoping, contracting, closed_won, closed_lost |
expected_close | string | Expected close date (free-form ISO date string) |
expected_acv | number | Expected annual contract value |
notes | string |
Responses
200Deal registered400customer_required or invalid_stage401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
Marketplace
GET/api/v1/partner/marketplace-listingsMarketplace listings owned by the caller
Lists the kye.{rule_pack,sector_pack,widget}_listing.v1 rows the calling partner / consultant owns — pricing, sectors, revenue-share split, publication status. Optionally filtered by listing kind.
Auth: Session (Clerk JWT)
Parameters
| name | in | type | description |
|---|---|---|---|
kind | query | string |
Responses
200Owned listings (up to 200)400invalid_kind — kind not in rule_pack | sector_pack | widget401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
Evidence
GET/api/v1/partner/attributionsSigned attributions on evidence packs
Lists consultant_attributions rows for the signed-in consultant — each a signed attribution placed on a customer evidence pack (tenant_id, evidence_pack_id, attested_by / attested_at, signature alg + kid), newest first.
Auth: Session (Clerk JWT)
Parameters
| name | in | type | description |
|---|---|---|---|
limit | query | integer |
Responses
200Signed attributions401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/certificationsCertifications held by the signed-in consultant
Lists consultant_certifications rows with a derived active flag computed from the not_before / not_after validity window at request time, plus total / active counts.
Auth: Session (Clerk JWT)
Responses
200Certification history401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)
GET/api/v1/partner/reportsSigned reports the partner-plane user has access to
KYE™ Reporting Engine™ partner-plane view. Returns signed kye.report.v1 envelope rows on tenants the consultant is attributed to (access derives from consultant_attributions — a consultant who attested an evidence pack can read reports on that tenant). Optionally filtered by regulatory framework. Report synthesis itself is patent-track and not disclosed here.
Auth: Session (Clerk JWT)
Parameters
| name | in | type | description |
|---|---|---|---|
framework | query | string | Exact-match filter on the report's regulatory framework |
Responses
200Accessible report envelopes (up to 200, newest sealed first)401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
Replay
GET/api/v1/partner/replay-runsRecent Replay-Proof™ verifications by this user
Lists the last 100 replay-verify calls the caller has made via the partner console (decision id, verdict, signer kid, reason, timestamp).
Auth: Session (Clerk JWT)
Responses
200Verification history401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
POST/api/v1/partner/replay-verifyVerify a KYE-anchored artefact
Two clearly-separated verdict layers. (1) DISCLOSED — real Ed25519 signature verification of a { payload, signature: { alg: EdDSA, kid, sig } } envelope against the published self-audit JWKS (kyeprotocol.com/trust/self-audit-jwks.json); the §0.4 "Replay-Proof™ derivable from public keys alone" contract. (2) DEFERRED — offline replay reconstruction is patent-track; when the KYE_REPLAY_ENGINE service binding is present the call is proxied, otherwise that layer alone reports replay: deferred. Every call is recorded as a replay_runs row for the caller.
Auth: Session (Clerk JWT)
Request body (required)
| field | type | description |
|---|---|---|
input | string | A signed envelope as a JSON string (verified against the JWKS), or a kye:decision:... id (routed to the replay layer). |
live | string | "latest" or a YYYY-MM-DD date — fetches and verifies the published LIVE self-audit bundle for that day. |
Responses
200Verification result (both layers reported separately)400empty_input, invalid_envelope_json, unrecognised_input, or live not "latest" / YYYY-MM-DD401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)502The published LIVE self-audit bundle could not be fetched or was not JSON503D1 binding KYE_DB is not configured on the Pages project
Training
GET/api/v1/partner/training-cohortsCohorts owned by the calling trainer-org
Lists up to 200 training cohorts owned by the caller with enrolled / passed counters. Signed completion records are surfaced separately via /api/v1/training-completions.
Auth: Session (Clerk JWT)
Responses
200Trainer-owned cohorts401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project
GET/api/v1/partner/training-completionsSigned training completion records
Lists up to 200 kye.training.completion.v1 envelope rows the trainer-org has sealed — partner_user_id, cohort_id, verdict (pass / fail / pending), score, sealed_at + signed_by_kid.
Auth: Session (Clerk JWT)
Responses
200Sealed completion records401Missing bearer token, or JWT verification failed (signature / issuer / expiry)403Signed in but not on the consultants roster (not_enrolled) or suspended (consultant_suspended)503D1 binding KYE_DB is not configured on the Pages project