openapi: 3.2.0 info: title: HiveMorph v0.1 Activation API description: 'Polymorphic agent runtime — single shape (Merchant), single supermodel (W2 MERCHANT). Three gates: NEED + YIELD + CLEAN-MONEY.' version: 0.1.0 tags: - name: activation paths: /v1/activation/keys: get: tags: - activation summary: Activation-key capability discovery (no mint) description: Read-only capability probe for the activation-key rail. Returns how to mint, the price, the accepted auth, and the available scopes. Minting happens on POST /v1/activation/keys — this GET never issues a key. operationId: keys_discovery_v1_activation_keys_get responses: '200': description: Successful Response content: application/json: schema: {} post: tags: - activation summary: Mint a tk_live activation key (x402-paid or owner-admin) description: Mints a real, verifiable tk_live activation key. Requires a validated x402 access token (X-Hive-Access) OR the owner secret (X-Admin-Api-Key). Without either, returns a 402 payment_required envelope with a redeemable nonce — never a free key. The raw key is returned exactly once; only its SHA-256 hash is retained server-side. operationId: mint_key_v1_activation_keys_post parameters: - name: X-Admin-Api-Key in: header required: false schema: anyOf: - type: string - type: 'null' title: X-Admin-Api-Key - name: X-Hive-Access in: header required: false schema: anyOf: - type: string - type: 'null' title: X-Hive-Access requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/hivemorph__hive_activation__router__MintRequest' responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /v1/activation/verify: post: tags: - activation summary: Verify a tk_live activation key (counts one use) description: Validates a tk_live key against the keyring, enforcing revocation and usage limits, and counts one use. Never echoes the raw key back. operationId: verify_key_v1_activation_verify_post requestBody: content: application/json: schema: $ref: '#/components/schemas/hivemorph__hive_activation__router__VerifyRequest' required: true responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /v1/activation/keys/{key_id}: get: tags: - activation summary: Public activation-key metadata (no secret) description: Returns key metadata (prefix, scopes, usage, issuer). Never the raw key. operationId: key_metadata_v1_activation_keys__key_id__get parameters: - name: key_id in: path required: true schema: type: string title: Key Id responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' components: schemas: HTTPValidationError: properties: detail: items: $ref: '#/components/schemas/ValidationError' type: array title: Detail type: object title: HTTPValidationError hivemorph__hive_activation__router__VerifyRequest: properties: key: type: string title: Key description: The tk_live_ activation key to verify. type: object required: - key title: VerifyRequest ValidationError: properties: loc: items: anyOf: - type: string - type: integer type: array title: Location msg: type: string title: Message type: type: string title: Error Type input: title: Input ctx: type: object title: Context type: object required: - loc - msg - type title: ValidationError hivemorph__hive_activation__router__MintRequest: properties: scopes: anyOf: - items: type: string type: array - type: 'null' title: Scopes description: Requested permission scopes. Validated against the public allowlist; 'activation:mint' is admin-only. Defaults to ['receipts:read', 'x402:quote']. usage_limit: anyOf: - type: integer maximum: 10000000.0 minimum: 1.0 - type: 'null' title: Usage Limit description: Optional max number of verify calls this key may serve. label: type: string maxLength: 80 title: Label description: Optional human label. default: '' type: object title: MintRequest description: Body for POST /v1/activation/keys (all fields optional).