API reference
KYE™ Data Governance Pack™ API
7 operations · data-governance.openapi.yaml
Public API for the KYE™ Data Governance Pack™ (constitution §31). Customers register kye.data_use_manifest.v1 and kye.data_asset.v1 records via these endpoints; the records are then loaded by the data_use PDP stage at decision-time and by the kye-dsar-evidence-agent at DSAR-assembly time.
Persistence: writes flow through the gateway to the D1 tables created by migration 021_data_governance_pack.sql: - data_use_manifests - data_assets - data_access_events (append-only, written by the data_use stage — NOT exposed by these endpoints)
Audit chain: every successful registration emits a canonical event (data_use_manifest.registered, data_use_manifest.revoked, data_asset.registered).
Base path: /v1/
data-use-manifests
GET/v1/data-use-manifestsList data_use_manifests
Auth: bearerAuth
Parameters
| name | in | type | description |
|---|---|---|---|
tenant_id | query | string | |
subject | query | string | |
active | query | boolean | When true, filter to manifests where not_before ≤ now ≤ not_after AND revoked_at is unset. |
Responses
200List of manifests with count
POST/v1/data-use-manifestsRegister a data_use_manifest
Registers a kye.data_use_manifest.v1 record. The manifest declares what data the named subject (an agent / service / role / user) may touch, for what purpose, under what restrictions, and for how long. The PDP's data_use stage loads the active manifest at decision-time and binds the requested action against it.
Auth: bearerAuth
Request body (required)
| field | type | description |
|---|---|---|
manifest_id required | string | |
tenant_id | string | |
issuer required | string | |
subject required | string | |
purposes required | array | |
permitted_actions required | array | |
asset_selectors required | array | |
permitted_classifications | array | |
permitted_jurisdictions | array | |
transfer_safeguards | array | |
retention | object | |
data_subject_basis | string | |
special_category_basis | string | |
issued_at required | string | |
not_before required | string | |
not_after | string | |
signature required | object |
Responses
201Manifest registered400Missing required field401Unauthorised
GET/v1/data-use-manifests/{manifest_id}Read a single data_use_manifest
Auth: bearerAuth
Parameters
| name | in | type | description |
|---|---|---|---|
manifest_id required | path | string |
Responses
200Manifest record404Manifest not found
POST/v1/data-use-manifests/{manifest_id}/revokeRevoke a data_use_manifest
Sets revoked_at = now(). Subsequent decisions against this manifest deny with reason code manifest_revoked. Idempotent — a second revoke returns 200 with note: already_revoked.
Auth: bearerAuth
Parameters
| name | in | type | description |
|---|---|---|---|
manifest_id required | path | string |
Responses
200Manifest revoked (or already revoked)404Manifest not found
data-assets
GET/v1/data-assetsList data_assets
Auth: bearerAuth
Parameters
| name | in | type | description |
|---|---|---|---|
tenant_id | query | string | |
classification | query | string | |
owner | query | string |
Responses
200List of assets with count
POST/v1/data-assetsRegister a data_asset
Registers a kye.data_asset.v1 record. The asset describes a data location (DB table / object-store path / API endpoint / CKAN dataset / message-bus topic / vector store collection / file / stream) and its classification, per-field PII inventory, retention default, and lineage parents.
Invariant: when classification ∈ {personal_data, special_category_data}, data_subject_ref_field is REQUIRED — so the DSAR agent can join evidence rows back to a subject.
Auth: bearerAuth
Request body (required)
| field | type | description |
|---|---|---|
asset_id required | string | |
tenant_id | string | |
owner required | string | |
asset_kind required | string | One of db_table, object_store_path, api_endpoint, ckan_dataset, message_topic, vector_collection, file, stream |
location required | object | |
classification required | string | |
pii_inventory | array | |
labels | object | |
default_retention_days | integer | |
data_subject_ref_field | string | |
lineage_parents | array |
Responses
201Asset registered400Missing required field — code: `missing_required_field` OR `data_subject_ref_field_required_for_personal_data`
GET/v1/data-assets/{asset_id}Read a single data_asset
Auth: bearerAuth
Parameters
| name | in | type | description |
|---|---|---|---|
asset_id required | path | string |
Responses
200Asset record404Asset not found