| POST | /applications | Create an application |
| POST | /assurance-policies | Create an assurance policy |
| POST | /assurance-policies/update | Update policy with optimistic versioning |
| POST | /response-keys | Create a decision response key |
| POST | /response-keys/rotate | Rotate or compromise a response key |
| POST | /network-policies | Create a network policy |
| POST | /challenge-tags | Create a challenge tag |
| GET | /challenge-tags | List challenge tags |
| POST | /challenge-tags/update | Update challenge-tag configuration |
| POST | /challenge-tags/lifecycle | Suspend, activate, or retire a tag |
| POST | /connection-requests | Create a connection ceremony |
| POST | /connections/session | Exchange a one-use connection code |
| POST | /connections/remove | Remove a vendor relationship |
| POST | /entitlements/grant | Grant access to a challenge tag |
| POST | /entitlements/remove | Remove access to a challenge tag |
| POST | /challenges | Create a protected action |
| POST | /decisions/retrieve | Retrieve an encrypted decision |
| POST | /decisions/consume | Atomically consume a decision |
| POST | /forced-challenge-campaigns | Create a forced-challenge campaign |
| POST | /forced-challenge-campaigns/activate | Activate a scheduled campaign |
| POST | /webhooks | Register a webhook endpoint |
| GET | /events | List vendor events |
| GET | /audit | List sanitized audit events |