{"openapi":"3.1.0","info":{"title":"mgmk shared context","version":"3.0.0","description":"Read and edit unlocked context through HTTP while a client holding a copy is connected. The server keeps readable HTTP data in request memory only; relay buffers contain ciphertext. Locked boards require a decrypting client."},"servers":[{"url":"https://mg.mk"}],"paths":{"/c/{code}":{"get":{"operationId":"readSharedContext","description":"Read unlocked context with ordinary HTTP. Accept text/plain, text/markdown or application/json. A live browser or local client supplies its copy; no readable server snapshot exists. Locked boards return 423.","parameters":[{"name":"code","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Readable context and agent instructions."},"423":{"description":"Locked: use a decrypting client."},"503":{"description":"No connected copy holder or delivery timed out."}}},"post":{"operationId":"editSharedContext","description":"Apply a small explicit edit to unlocked context through a connected participant. Use JSON with tool clipboard_append, clipboard_splice, clipboard_message, clipboard_find, clipboard_undo or clipboard_set. clientId is an unverified label; use an opId per edit. set requires confirmReplace:true. No readable request body is stored.","parameters":[{"name":"code","in":"path","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["tool"],"properties":{"tool":{"type":"string"},"clientId":{"type":"string"},"opId":{"type":"string"},"text":{"type":"string"},"at":{"type":"integer"},"delete":{"type":"integer"},"confirmReplace":{"type":"boolean"}}}}}},"responses":{"200":{"description":"Applied edit and current context."},"202":{"description":"Duplicate operation is pending; read before retrying."},"400":{"description":"Invalid operation or unsafe undo."},"413":{"description":"Edit exceeds 120 KB."},"423":{"description":"Locked: plaintext edits are disabled."},"503":{"description":"No connected copy holder or interrupted delivery; reuse opId."}}}},"/api/relay/{code}":{"post":{"operationId":"encryptedRelay","description":"Resolve a short address with describe. Open rooms admit a device signing its own write grant; protected rooms require invitation authority or approval. poll/send/offerKey/approve/settings require a server credential and a fresh single-use signed challenge. offerKey carries a recipient-encrypted key package, never plaintext keys.","parameters":[{"name":"code","in":"path","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RelayRequest"}}}},"responses":{"200":{"description":"Signed metadata, membership receipt or encrypted frames."},"400":{"description":"Invalid envelope."},"403":{"description":"Invalid, revoked or expired membership."},"409":{"description":"Address occupied or concurrent change; refresh before retrying."},"413":{"description":"Envelope exceeds 215 KB."},"429":{"description":"Quota exceeded; honor Retry-After."},"503":{"description":"Storage unavailable. Authentication fails closed."}}}}},"components":{"schemas":{"RelayRequest":{"type":"object","required":["op","payload"],"properties":{"op":{"type":"string","enum":["create","describe","join","requestApproval","challenge","poll","send","offerKey","httpClaim","httpReply","approve","settings"]},"boardId":{"type":"string","description":"Random board identity, independent of its reusable address. Optional for describe, which resolves a short room address."},"payload":{"type":"object","description":"Operation-specific signed metadata or authenticated ciphertext. See /developers and /privacy on this site."},"auth":{"type":"object","required":["device","challenge","credential","signature"],"properties":{"device":{"type":"string","description":"Compressed P-256 device signing public key, base64url."},"challenge":{"type":"string","description":"Fresh challenge issued for this operation and payload hash."},"credential":{"type":"object","description":"Server-signed receipt bound to the device, board, grant hash and expiry."},"signature":{"type":"string","description":"Device signature over the full challenge object."}}}}}}}}