---
title: "KYE™ Data Governance Pack™ API | API reference"
description: "KYE™ Data Governance Pack™ API: 7 operations from data-governance.openapi.yaml, a published KYE Protocol™ OpenAPI contract."
url: https://kyeprotocol.com/developers/api/data-governance/
lang: en
source: "KYE Protocol"
---

> KYE™ Data Governance Pack™ API: 7 operations from data-governance.openapi.yaml, a published KYE Protocol™ OpenAPI contract.

API reference

# KYE™ Data Governance Pack™ API

7 operations · `data-governance.openapi.yaml`

**Servers**

`https://gateway.kyeprotocol.com` `http://127.0.0.1:8787`

**Version**

1.0.0

**Source**

[data-governance.openapi.yaml](https://kyeprotocol.com/developers/api/data-governance.openapi.yaml)

Public API for the KYE™ Data Governance Pack™ (constitution §31). Customers register `kye.data_use_manifest.v1` and `kye.data_asset.v1` records via these endpoints; the records are then loaded by the `data_use` PDP stage at decision-time and by the `kye-dsar-evidence-agent` at DSAR-assembly time.

Persistence: writes flow through the gateway to the D1 tables created by migration `021_data_governance_pack.sql`: - `data_use_manifests` - `data_assets` - `data_access_events` (append-only, written by the data\_use stage — NOT exposed by these endpoints)

Audit chain: every successful registration emits a canonical event (`data_use_manifest.registered`, `data_use_manifest.revoked`, `data_asset.registered`).

Base path: `/v1/`

data-use-manifests 4 data-assets 3

## data-use-manifests

GET `/v1/data-use-manifests` List data\_use\_manifests

**Auth:** bearerAuth

### Parameters

| name | in | type | description |
| --- | --- | --- | --- |
| `tenant_id` | query | string |  |
| `subject` | query | string |  |
| `active` | query | boolean | When true, filter to manifests where not\_before ≤ now ≤ not\_after AND revoked\_at is unset. |

### Responses

- `200` List of manifests with count

POST `/v1/data-use-manifests` Register a data\_use\_manifest

Registers a `kye.data_use_manifest.v1` record. The manifest declares what data the named subject (an agent / service / role / user) may touch, for what purpose, under what restrictions, and for how long. The PDP's data\_use stage loads the active manifest at decision-time and binds the requested action against it.

**Auth:** bearerAuth

### Request body (required)

| field | type | description |
| --- | --- | --- |
| `manifest_id` **required** | string |  |
| `tenant_id` | string |  |
| `issuer` **required** | string |  |
| `subject` **required** | string |  |
| `purposes` **required** | array |  |
| `permitted_actions` **required** | array |  |
| `asset_selectors` **required** | array |  |
| `permitted_classifications` | array |  |
| `permitted_jurisdictions` | array |  |
| `transfer_safeguards` | array |  |
| `retention` | object |  |
| `data_subject_basis` | string |  |
| `special_category_basis` | string |  |
| `issued_at` **required** | string |  |
| `not_before` **required** | string |  |
| `not_after` | string |  |
| `signature` **required** | object |  |

### Responses

- `201` Manifest registered
- `400` Missing required field
- `401` Unauthorised

GET `/v1/data-use-manifests/{manifest_id}` Read a single data\_use\_manifest

**Auth:** bearerAuth

### Parameters

| name | in | type | description |
| --- | --- | --- | --- |
| `manifest_id` **required** | path | string |  |

### Responses

- `200` Manifest record
- `404` Manifest not found

POST `/v1/data-use-manifests/{manifest_id}/revoke` Revoke a data\_use\_manifest

Sets `revoked_at = now()`. Subsequent decisions against this manifest deny with reason code `manifest_revoked`. Idempotent — a second revoke returns 200 with `note: already_revoked`.

**Auth:** bearerAuth

### Parameters

| name | in | type | description |
| --- | --- | --- | --- |
| `manifest_id` **required** | path | string |  |

### Responses

- `200` Manifest revoked (or already revoked)
- `404` Manifest not found

## data-assets

GET `/v1/data-assets` List data\_assets

**Auth:** bearerAuth

### Parameters

| name | in | type | description |
| --- | --- | --- | --- |
| `tenant_id` | query | string |  |
| `classification` | query | string |  |
| `owner` | query | string |  |

### Responses

- `200` List of assets with count

POST `/v1/data-assets` Register a data\_asset

Registers a `kye.data_asset.v1` record. The asset describes a data location (DB table / object-store path / API endpoint / CKAN dataset / message-bus topic / vector store collection / file / stream) and its classification, per-field PII inventory, retention default, and lineage parents.

**Invariant:** when `classification ∈ {personal_data, special_category_data}`, `data_subject_ref_field` is REQUIRED — so the DSAR agent can join evidence rows back to a subject.

**Auth:** bearerAuth

### Request body (required)

| field | type | description |
| --- | --- | --- |
| `asset_id` **required** | string |  |
| `tenant_id` | string |  |
| `owner` **required** | string |  |
| `asset_kind` **required** | string | One of db\_table, object\_store\_path, api\_endpoint, ckan\_dataset, message\_topic, vector\_collection, file, stream |
| `location` **required** | object |  |
| `classification` **required** | string |  |
| `pii_inventory` | array |  |
| `labels` | object |  |
| `default_retention_days` | integer |  |
| `data_subject_ref_field` | string |  |
| `lineage_parents` | array |  |

### Responses

- `201` Asset registered
- `400` Missing required field — code: \`missing\_required\_field\` OR \`data\_subject\_ref\_field\_required\_for\_personal\_data\`

GET `/v1/data-assets/{asset_id}` Read a single data\_asset

**Auth:** bearerAuth

### Parameters

| name | in | type | description |
| --- | --- | --- | --- |
| `asset_id` **required** | path | string |  |

### Responses

- `200` Asset record
- `404` Asset not found
