# Delos > Delos Living LLC is a New York-based wellness real estate and technology company that applies building science to indoor environments across commercial, residential, hospitality, education, senior living and transportation. Delos founded the WELL Building Standard and co-founded the Well Living Lab with Mayo Clinic. Its connected product line — WellCube — pairs localized air purifiers with multi-sensor devices and is run from the "Cloud BE" / Darwin Cloud platform. Generated by API Evangelist on 2026-08-12. Delos publishes no llms.txt of its own: /llms.txt returns 404 on delos.com and wellcube.io, and the SPA hosts cloud.wellcube.io and app.wellcube.io answer 200 with an HTML shell for every path, which is not a document. This file is generated from apis.yml and the artifacts in this repository. ## APIs - [WellCube Cloud BE API](https://cloud.wellcube.io/api/v1/docs/): REST API behind the WellCube / Darwin Cloud platform — sessions, user product entitlements and invitations, installations and products with statistics, AWS product bundles, asynchronous device actions with job polling, and local-account linking, sharing, transfer and migration to federated AWS Cognito identity. Base URL https://cloud.wellcube.io/api/v1. 33 paths, 39 operations, OpenAPI 3.0.0, build version 11.13.9. ## Specs - [OpenAPI 3.0.0 — WellCube Cloud BE](openapi/delos-wellcube-cloud-be-openapi.yml): harvested verbatim from the live Swagger UI at https://cloud.wellcube.io/api/v1/docs/. Untouched original preserved at openapi/_original/delos-wellcube-cloud-be-openapi-original.json. - [OpenAPI Overlay](overlays/delos-wellcube-cloud-be-overlay.yaml): API Evangelist annotations — provenance, the three verified contract caveats, and consequence marking on the physical-command operation. ## How this API behaves Three properties an agent must know before calling it. All three were verified, not assumed. - **Every response is HTTP 200, including failures.** Verified live on 2026-08-12: an unauthenticated GET and a bad-credential login both returned a 200 status line with a failure body. The only outcome signal is `body.status` — `1` for success, `0` for failure. Anything that branches on HTTP status will read every error as a success. - **The contract declares no HTTP status codes at all.** Each of the 39 operations has one `default` response plus failure responses keyed by non-standard `x-`-prefixed strings (`x-permission-denied`, `x-not-exists`, `x-wrong-token`, …), which OpenAPI 3.0 does not permit. Match on `body.error.code` instead. - **There is no idempotency key.** 18 of the 39 operations write, several irreversibly. No rate-limit headers are returned either, so there is no throttling signal to back off on. ## Artifacts - [Authentication](authentication/delos-authentication.yml): one `Authorization` apiKey header applied globally; three token-issuing paths (password, limited-session with refresh, admin Cognito exchange); AWS Cognito user pool us-east-1_QNxQ6AqaQ with a live OIDC discovery document. - [Conventions](conventions/delos-conventions.yml): status-flag response envelope, limit/offset pagination, sortedBy/order sorting, UUID identifiers, submit-then-poll async, `Trace-Id` accepted via CORS but undocumented, no idempotency, no field expansion. - [Error codes](errors/delos-error-codes.yml): 14 reusable error components with pinned codes, mapped to all 19 response keys and to the operations that raise them, plus the undocumented `FORMAT_ERROR` observed live. - [Data model](data-model/delos-data-model.yml): 9 entities, 13 relationships, 3 implicit entities the spec references but never declares (User, Translator, Job). - [Conformance](conformance/delos-conformance.yml): what the API does and does not conform to, with evidence per standard. - [Lifecycle](lifecycle/delos-lifecycle.yml): no changelog, no status page, no SLA, no deprecation policy; the one deprecation signal is prose inside a response description. - [Packages](packages/delos-packages.yml): zero official API client libraries. Two first-party npm packages exist (mobile UI plugins, last published 2021 and 2023). - [Plans and pricing](plans/delos-plans-pricing.yml): no published pricing; sales-led with white-glove installation. - [Rate limits](rate-limits/delos-rate-limits.yml): none published, none observed. - [Well-known](well-known/delos-well-known.yml): every /.well-known/ path probed on four hosts; no document served. - [Event surface](asyncapi/delos-events.yml): a live WebSocket gateway exists (wss://ugw.wellcube.io/clients-socket) with no published contract. - [MCP candidate](mcp/delos-mcp.yml) and [tool crosswalk](mcp/delos-tool-crosswalk.yml): 39 candidate tools derived from the OpenAPI. Delos publishes no MCP server. - [Agent skills](skills/_index.yml): three generated skills grounded in real operationIds. - [Domain security](security/delos-domain-security.yml): TLS, HSTS, DNSSEC, CAA, SPF and DMARC probed per host and domain. ## Docs - [Swagger UI — the entire developer surface](https://cloud.wellcube.io/api/v1/docs/) - [WellCube platform overview](https://wellcube.io/platform) - [WellCube support (Zendesk; returns 403 to non-browser clients)](https://support.wellcube.io/hc/en-us) - [WellCube app login](https://app.wellcube.io/login) - [Delos company site](https://delos.com/) - [Delos blog](https://delos.com/blog/) - [Delos-tech GitHub organization](https://github.com/Delos-tech) - [Terms of use](https://wellcube.io/terms-of-use) - [Privacy policy](https://wellcube.io/privacy-policy) ## Optional - The API is not linked from any Delos marketing page. It was found by reading https://app.wellcube.io/config.js, the WellCube web app's public runtime configuration, which names the backend as https://cloud.wellcube.io/api/v1. - `docs.wellcube.io` resolves but serves an empty S3 bucket (`NoSuchKey` for index.html) — a documentation host provisioned and never filled. - The WellCube platform page advertises API integration with BMS/BAS, ESG reporting and workplace management platforms, but routes every enquiry through "Reach out to us" rather than to the callable contract. - This profile is maintained by API Evangelist and is not affiliated with or endorsed by Delos. See README.md.