openapi: 3.2.0 info: title: Cape Partners — Sniffer Agent Confidentiality API version: 1.0.0 description: Machine-readable API backing the Cape Partners M&A deal-flow workspace (click, humans). contact: name: Cape Partners url: https://www.capepartners.fr servers: - url: https://www.capepartners.fr description: Production (www) via Cloudflare - url: https://sniffer.capepartners.fr description: Workspace host - url: http://localhost:3000 description: Local dev tags: - name: Confidentiality paths: /api/nda/sign: security: - SessionToken: [] post: summary: Record/request the NDA for a session. tags: - Confidentiality responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/NdaSignResponse' '400': description: Invalid session or missing signer_name content: application/json: schema: type: object description: Invalid session identifier properties: error: type: string required: - error requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/NdaSignRequest' operationId: postApiNdaSign x-operation-id-source: derived /api/nda/text: get: summary: Return the full Cape Partners Terms of Service (plain text), the single… tags: - Confidentiality responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/NdaTextResponse' operationId: getApiNdaText x-operation-id-source: derived /api/tos/text: get: summary: Return the full Cape Partners Terms of Service (plain text). tags: - Confidentiality responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/NdaTextResponse' operationId: getApiTosText x-operation-id-source: derived components: schemas: NdaSignResponse: type: object properties: ok: type: boolean session_id: type: string nda_signed: type: boolean NdaTextResponse: type: object properties: name: type: string text: type: string NdaSignRequest: type: object properties: session_id: type: string format: uuid signer_name: type: string signerName: type: string company: type: string signedAt: type: string signed_at: type: string required: - session_id - signer_name securitySchemes: SessionToken: type: apiKey in: header name: X-Session-Id description: 'The workspace session UUID is a capability token carried in the URL PATH (not this header — shown here only because OpenAPI securitySchemes cannot model a path parameter as a credential). A valid request must present a well-formed UUID-v4 in the path segment {session_id} AND a first-party Origin/Referer (or none). Requests carrying a known-foreign Origin/Referer are refused 403. Per-IP rate limiting applies. All responses carry Referrer-Policy: strict-origin-when-cross-origin.' NdaSigned: type: apiKey in: header name: X-Nda-Signed description: 'Precondition (not a literal header): a server-side NDA signature for {session_id} must be recorded in the nda_signatures table via POST /api/nda/sign before NDA-gated resources (/api/matched-names, /api/infomemo/*) will serve data. Recorded signatures are enforced server-side (helper `nda_signed`), not by trusting a client header.'