API reference

KYE™ Data Governance Pack™ API

7 operations · data-governance.openapi.yaml

Servers
https://gateway.kyeprotocol.com http://127.0.0.1:8787
Version
1.0.0
Source
data-governance.openapi.yaml

Public API for the KYE™ Data Governance Pack™ (constitution §31). Customers register kye.data_use_manifest.v1 and kye.data_asset.v1 records via these endpoints; the records are then loaded by the data_use PDP stage at decision-time and by the kye-dsar-evidence-agent at DSAR-assembly time.

Persistence: writes flow through the gateway to the D1 tables created by migration 021_data_governance_pack.sql: - data_use_manifests - data_assets - data_access_events (append-only, written by the data_use stage — NOT exposed by these endpoints)

Audit chain: every successful registration emits a canonical event (data_use_manifest.registered, data_use_manifest.revoked, data_asset.registered).

Base path: /v1/

data-use-manifests

GET/v1/data-use-manifestsList data_use_manifests

Auth: bearerAuth

Parameters

nameintypedescription
tenant_idquerystring
subjectquerystring
activequerybooleanWhen true, filter to manifests where not_before ≤ now ≤ not_after AND revoked_at is unset.

Responses

  • 200 List of manifests with count
POST/v1/data-use-manifestsRegister a data_use_manifest

Registers a kye.data_use_manifest.v1 record. The manifest declares what data the named subject (an agent / service / role / user) may touch, for what purpose, under what restrictions, and for how long. The PDP's data_use stage loads the active manifest at decision-time and binds the requested action against it.

Auth: bearerAuth

Request body (required)

fieldtypedescription
manifest_id requiredstring
tenant_idstring
issuer requiredstring
subject requiredstring
purposes requiredarray
permitted_actions requiredarray
asset_selectors requiredarray
permitted_classificationsarray
permitted_jurisdictionsarray
transfer_safeguardsarray
retentionobject
data_subject_basisstring
special_category_basisstring
issued_at requiredstring
not_before requiredstring
not_afterstring
signature requiredobject

Responses

  • 201 Manifest registered
  • 400 Missing required field
  • 401 Unauthorised
GET/v1/data-use-manifests/{manifest_id}Read a single data_use_manifest

Auth: bearerAuth

Parameters

nameintypedescription
manifest_id requiredpathstring

Responses

  • 200 Manifest record
  • 404 Manifest not found
POST/v1/data-use-manifests/{manifest_id}/revokeRevoke a data_use_manifest

Sets revoked_at = now(). Subsequent decisions against this manifest deny with reason code manifest_revoked. Idempotent — a second revoke returns 200 with note: already_revoked.

Auth: bearerAuth

Parameters

nameintypedescription
manifest_id requiredpathstring

Responses

  • 200 Manifest revoked (or already revoked)
  • 404 Manifest not found

data-assets

GET/v1/data-assetsList data_assets

Auth: bearerAuth

Parameters

nameintypedescription
tenant_idquerystring
classificationquerystring
ownerquerystring

Responses

  • 200 List of assets with count
POST/v1/data-assetsRegister a data_asset

Registers a kye.data_asset.v1 record. The asset describes a data location (DB table / object-store path / API endpoint / CKAN dataset / message-bus topic / vector store collection / file / stream) and its classification, per-field PII inventory, retention default, and lineage parents.

Invariant: when classification ∈ {personal_data, special_category_data}, data_subject_ref_field is REQUIRED — so the DSAR agent can join evidence rows back to a subject.

Auth: bearerAuth

Request body (required)

fieldtypedescription
asset_id requiredstring
tenant_idstring
owner requiredstring
asset_kind requiredstringOne of db_table, object_store_path, api_endpoint, ckan_dataset, message_topic, vector_collection, file, stream
location requiredobject
classification requiredstring
pii_inventoryarray
labelsobject
default_retention_daysinteger
data_subject_ref_fieldstring
lineage_parentsarray

Responses

  • 201 Asset registered
  • 400 Missing required field — code: `missing_required_field` OR `data_subject_ref_field_required_for_personal_data`
GET/v1/data-assets/{asset_id}Read a single data_asset

Auth: bearerAuth

Parameters

nameintypedescription
asset_id requiredpathstring

Responses

  • 200 Asset record
  • 404 Asset not found