{
  "schema": "varexis-index-automatic-api/1",
  "capabilities": "/api/index/capabilities",
  "portal": "/index-access",
  "activation": "Use automatic_checkout_active from the capabilities endpoint. Presence of this contract does not mean paid checkout is active.",
  "scope": "Automatic delivery of reviewed published routes and version-bound source snapshots. The free preview shows the answer and limitations before payment. Bespoke claim assessment, fresh research and protected evidence are excluded.",
  "authentication": {
    "scheme": "Bearer",
    "key_format": "vxi_ followed by a cryptographically random 32-byte value encoded as base64url without padding (43 characters)",
    "creation": "The caller generates and securely retains its key before creating checkout. The server stores only its SHA-256 hash. One key identifies one purchase; subscription keys also authorise subsequent queries.",
    "transport": "Authorization header only. Never put keys in URLs, source control or request bodies.",
    "recovery": "Retain your key before paying. Automatic email-based recovery is not provided."
  },
  "flow": [
    {
      "step": 1,
      "method": "GET",
      "url": "/api/index/capabilities",
      "purpose": "Check availability and select a published route."
    },
    {
      "step": 2,
      "method": "POST",
      "url": "/api/index/preview",
      "authentication": false,
      "body": {
        "route_id": "A route_id from capabilities"
      },
      "purpose": "Inspect the full free answer, source snapshot and snapshot_sha256. Unknown or altered questions are refused before payment."
    },
    {
      "step": 3,
      "method": "POST",
      "url": "/api/index/checkout",
      "authentication": true,
      "body": {
        "route_id": "The previewed route",
        "service_id": "single_request",
        "snapshot_sha256": "The preview's hash",
        "accept_terms": true
      },
      "purpose": "Receive a Stripe checkout URL for the existing product. Obtain the owner's spending authority and retain the access key. Retries with the same key and scope reuse one order."
    },
    {
      "step": 4,
      "method": "GET",
      "url": "/api/index/result",
      "authentication": true,
      "purpose": "After payment, retrieve the saved JSON answer or receipt using the same key. Stripe verification occurs server-side. Pending payment returns pending; no email submission is needed."
    },
    {
      "step": 5,
      "method": "POST",
      "url": "/api/index/query",
      "authentication": true,
      "headers": {
        "Idempotency-Key": "A unique 16–100 character request reference"
      },
      "body": {
        "route_id": "A published route"
      },
      "purpose": "For an active subscription, retrieve and save another source snapshot. Developer/API permits 100 new queries per paid subscription period. Retries with the same request reference do not consume another query."
    }
  ],
  "products": {
    "single_request": {
      "net_gbp": 5,
      "recurring": false
    },
    "evidence_receipt": {
      "net_gbp": 19,
      "recurring": false,
      "receipt": "Delivery time, source hashes and snapshot binding; not digitally signed or an independent assurance."
    },
    "research_subscription": {
      "net_gbp": 29,
      "recurring": "monthly",
      "includes": "Reviewed route exports and saved retrievals; operational rate limits apply."
    },
    "developer_api": {
      "net_gbp": 149,
      "recurring": "monthly",
      "included_queries": 100
    }
  },
  "other_endpoints": {
    "saved_results": {
      "method": "GET",
      "url": "/api/index/history",
      "authentication": true,
      "limit": 100
    },
    "cancel_renewal": {
      "method": "POST",
      "url": "/api/index/cancel",
      "authentication": true
    }
  },
  "limits": {
    "request_body_bytes": 16384,
    "requests_per_minute_per_key": 60,
    "requests_per_minute_per_source_ip": 60,
    "checkout_attempts_per_minute_per_key": 6
  },
  "payment_boundary": "Stripe-hosted checkout may require a person or an authorised payment-capable agent. After subscription setup, the key can retrieve covered results directly within its allowance. This service does not implement x402 or autonomous wallet payments.",
  "existing_payment_links": "Existing Stripe links remain the launch purchase route. Purchases made outside the automatic checkout endpoint do not automatically acquire a request key or question linkage.",
  "evidence_boundary": "Public and paid retrieval share the same public source IDs. Prepared operator packs are not additional private experimental evidence. Payments never unlock raw logs, thresholds, private paths, protected mechanisms or proprietary source code."
}
