Schemas
Reference
Schemas
Section titled “Schemas”Generated source hash: sha256:17da2cf4ee9ce00c2fa647574208559f354c4a7f29b3da22d3429eda1851c01f.
Audience
Section titled “Audience”- Developers validating manifests, mappings, policy, runtime records, release evidence, or settings.
- Test authors choosing fixture contracts.
- Security reviewers checking field names before approving public examples.
What is this?
Section titled “What is this?”This page is generated from contracts/jsonschema/. It summarizes schema titles, required-field counts, top-level property counts, and representative enum values. It does not replace the JSON files.
When do I use it?
Section titled “When do I use it?”Use it before writing docs, fixtures, or API clients that depend on exact contract files. Open the source schema for field-level validation rules.
What happens?
Section titled “What happens?”39schema files are scanned.- Required-field and property counts are generated from each JSON file.
- Representative enum values are shown to orient the reader; the source file remains authoritative.
| Source | Title | Type | Required fields | Top-level properties | Representative enums |
|---|---|---|---|---|---|
contracts/jsonschema/agent.schema.json | AgentManifest | object | 4 | 4 | low, medium, high, critical, service_account, user_delegated, agent_scoped, workload_mapped |
contracts/jsonschema/api-source.schema.json | APISourceManifest | object | 4 | 4 | localhost, metadata.google.internal, 169.254.169.254, healthy, degraded, unhealthy, unknown, not_configured |
contracts/jsonschema/api-tool-mapping.schema.json | APIToolMapping | object | 19 | 21 | low, medium, high, critical, application/json, application/x-www-form-urlencoded, multipart/form-data, GET |
contracts/jsonschema/auth-context.schema.json | AuthContextContract | object | 5 | 5 | jwt, service_identity, workload_identity, saml, RS256, RS384, RS512, PS256 |
contracts/jsonschema/authorization-server-profile.schema.json | AuthorizationServerProfileContract | object | 0 | 0 | RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 |
contracts/jsonschema/catalog-lite.schema.json | CatalogHttpContract | object | 6 | 6 | hidden, listed, connectable, low, medium, high, critical, mcp_server |
contracts/jsonschema/connector.schema.json | ConnectorManifest | object | 4 | 4 | submitted, under_review, approved, disabled, revoked, archived, rejected, mcp_server |
contracts/jsonschema/consumer-oauth-admin.schema.json | ConsumerOAuthAdminContract | object | 0 | 0 | mcp_server, api_source, virtual_server, token_exchange, authorization_code, draft, validating, active |
contracts/jsonschema/consumer-oauth-jwks-refresh-signal.schema.json | ConsumerOAuthJwksRefreshSignalBatch | object | 6 | 6 | |
contracts/jsonschema/consumer-oauth-migration-status.schema.json | ConsumerOAuthMigrationStatus | object | 0 | 0 | mcp_server, api_source, virtual_server, before_deadline, deadline_reached |
contracts/jsonschema/consumer-oauth-revocation-ack.schema.json | ConsumerOAuthRevocationAcknowledgementBatch | object | 7 | 7 | |
contracts/jsonschema/credential-binding.schema.json | CredentialBindingManifest | object | 4 | 4 | service_account, user_delegated, agent_scoped, workload_mapped, vault, aws, azure, gcp |
contracts/jsonschema/credential-broker.schema.json | CredentialBrokerResolutionContract | object | 2 | 2 | none, service_account, user_delegated, agent_scoped, workload_mapped, tool_call, api_adapter_call, health_probe |
contracts/jsonschema/hosted-audit-capture.schema.json | HostedAuditPayloadCaptureContract | object | 6 | 6 | active, expired, suspended, purged, suspend_capture, restore_capture, mark_abuse_review, hosted_payload_capture_active |
contracts/jsonschema/hosted-domain-membership.schema.json | HostedDomainMembershipContract | object | 6 | 6 | create_trial_with_provisional_domain, request_existing_org_access, public_domain_no_grouping, self_hosted_bypass, provisional, dac_exception, hosted_provisional_domain_association, hosted_same_domain_join_required |
contracts/jsonschema/hosted-email.schema.json | HostedEmailUserManagementContract | object | 5 | 5 | email_verification, invite, join_request_notification, join_approved, join_rejected, trial_expiry, hard_lock, upgrade_request |
contracts/jsonschema/hosted-org.schema.json | HostedOrgLifecycleContract | object | 4 | 4 | trial_active, trial_expired, active, locked, hosted_free_trial, hosted_team, hosted_business, hosted_enterprise |
contracts/jsonschema/hosted-runtime.schema.json | HostedRuntimeAllowlistedEndpointContract | object | 4 | 4 | https_api, https_mcp, pending_reachability, ready, denied, disabled, hosted_runtime_ready, hosted_runtime_reachable |
contracts/jsonschema/hosted-social-auth.schema.json | HostedSocialAuthContract | object | 5 | 5 | google, microsoft, github, signup, login, active, membership_pending, hosted_social_provider_ready |
contracts/jsonschema/license.schema.json | LicenseStatusContract | object | 1 | 3 | valid, expired, missing, offline_grace, license_valid, license_expired, license_missing, license_offline_grace |
contracts/jsonschema/mcp-compatibility-profile.schema.json | MCPCompatibilityProfile | object | 0 | 0 | 2024-11-05, 2025-03-26, 2025-06-18, 2025-11-25, 2026-07-28, legacy_initialized, modern_stateless, streamable_http |
contracts/jsonschema/mcp-resource-auth-binding.schema.json | McpResourceAuthBindingContract | object | 0 | 0 | mcp_server, api_source, virtual_server, static_only, mixed, oauth_only, compatible, approved_only |
contracts/jsonschema/mcp-server.schema.json | MCPServerManifest | object | 4 | 4 | low, medium, high, critical, registered, disabled, deprecated, service_account |
contracts/jsonschema/policy-simulation.schema.json | PolicySimulationContract | object | 2 | 2 | none, service_account, user_delegated, agent_scoped, workload_mapped, allow, deny |
contracts/jsonschema/policy.schema.json | PolicyManifest | object | 4 | 4 | draft, published, superseded, disabled, allow, deny, DiscoverTool, CallTool |
contracts/jsonschema/private-route-decision.schema.json | PrivateRouteDecisionContract | object | 2 | 2 | mcp_server, api_operation, direct_private_endpoint, outbound_connector, denied, allow, deny, mtls |
contracts/jsonschema/release-candidate-evidence.schema.json | M9 Release Candidate Evidence | object | 5 | 5 | linked, pass, justified |
contracts/jsonschema/release-evidence-bundle.schema.json | M8 Release Evidence Bundle | object | 5 | 5 | cosign, sbom, release_evidence_bundle, helm_chart, oci_image, spdx-json, cyclonedx-json |
contracts/jsonschema/revocation-event-v2.schema.json | ConsumerOAuthRevocationEventContract | object | 10 | 10 | authentication, policy, discovery, upstream_credentials |
contracts/jsonschema/revocation-event.schema.json | RevocationEventContract | object | 12 | 13 | agent_disabled, credential_revoked, connector_disabled, policy_superseded, client_surface_disabled, server_disabled, api_source_disabled, operation_disabled |
contracts/jsonschema/runtime-audit-export-v3.schema.json | ConsumerOAuthRuntimeAuditExportContract | object | 6 | 6 | succeeded, upstream_http_error, upstream_failure, deadline_exceeded, outcome_unknown, null, received, authentication |
contracts/jsonschema/runtime-audit-export-v4.schema.json | ConsumerOAuthRuntimeAuditExportV4Contract | object | 6 | 6 | succeeded, upstream_http_error, upstream_failure, deadline_exceeded, outcome_unknown, null, received, authentication |
contracts/jsonschema/runtime-discovery.schema.json | RuntimeDiscoveryContract | object | 2 | 2 | low, medium, high, critical, none, service_account, user_delegated, agent_scoped |
contracts/jsonschema/runtime-projection.schema.json | RuntimeProjectionContract | object | 0 | 0 | disabled, observe, enforce, gateway.runtime.audit-export/v3, gateway.runtime.audit-export/v4, gateway.consumer-oauth.runtime/v7, gateway.consumer-oauth.runtime/v8, RS256 |
contracts/jsonschema/runtime-tool-call.schema.json | RuntimeToolCallContract | object | 2 | 2 | not_logged, redacted, none, policy_denied, manifest_denied_candidate, schema_invalid, unregistered_server, unknown_tool |
contracts/jsonschema/session-lifecycle-v2.schema.json | ConsumerOAuthSessionLifecycleContract | object | 13 | 13 | pending, active, reconnecting, draining, terminated, revoked, expired, failed |
contracts/jsonschema/session-lifecycle-v3.schema.json | ConsumerOAuthSessionLifecycleV3Contract | object | 13 | 13 | pending, active, reconnecting, draining, terminated, revoked, expired, failed |
contracts/jsonschema/session-lifecycle.schema.json | SessionLifecycleContract | object | 5 | 5 | pending, active, reconnecting, draining, terminated, revoked, expired, failed |
contracts/jsonschema/telemetry-siem-config.schema.json | TelemetryAndSiemConfig | object | 0 | 0 | read, create, update, test, disable, healthy, degraded, failed |
What can go wrong?
Section titled “What can go wrong?”- A docs page invents fields instead of linking the schema.
- A schema is removed while generated reference output is stale.
- Public docs paste raw payloads from private fixtures. Use field names and safe IDs instead.
- A generated schema summary is treated as a validation substitute. The source JSON is the validator target.
Source truth
Section titled “Source truth”- Read Audit Events for the generated audit-event schema summary.
- Read Admin API for control-plane routes.
- Read Evals for fixture contract expectations.
Type set in Geist, Source Serif 4, and Departure Mono.