{
  "openapi": "3.1.0",
  "info": {
    "title": "Web Bot Auth implementation check — wba.cloudless.sh",
    "version": "0.1.0",
    "description": "Send a live Web Bot Auth signed request and get a step-by-step report of whether it verifies against your own published key directory, and if not, where it fails.",
    "x-status": "live",
    "x-guidance": "Sign a GET to https://wba.cloudless.sh/v1/whoami with the web-bot-auth profile (draft-ietf-webbotauth-httpsig-protocol-00): Signature-Agent pointing at your key directory origin; Signature-Input covering @target-uri (or @authority) and signature-agent with tag=\"web-bot-auth\", keyid = RFC 7638 thumbprint, created, expires and a nonce (max age 60 s). A verified result means the signature verified against your own published directory; it grants nothing."
  },
  "servers": [
    {
      "url": "https://wba.cloudless.sh"
    }
  ],
  "paths": {
    "/v1/whoami": {
      "get": {
        "operationId": "whoami",
        "summary": "Check a Web Bot Auth signed request and report each verification step.",
        "parameters": [
          {
            "name": "Signature-Agent",
            "in": "header",
            "required": true,
            "description": "Your directory origin, dictionary form (sig1=\"https://…\") or legacy bare string.",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "Signature-Input",
            "in": "header",
            "required": true,
            "description": "RFC 9421 Signature-Input with the web-bot-auth parameters.",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "Signature",
            "in": "header",
            "required": true,
            "description": "RFC 9421 Signature.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "verified",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Report"
                }
              }
            }
          },
          "401": {
            "description": "invalid or unverified — see steps",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Report"
                }
              }
            }
          },
          "405": {
            "description": "Method not allowed (GET and HEAD only)."
          },
          "429": {
            "description": "Rate limited."
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "Report": {
        "type": "object",
        "required": [
          "schema",
          "profile",
          "verdict",
          "request",
          "steps"
        ],
        "properties": {
          "schema": {
            "type": "string",
            "const": "cloudless.wba_whoami.v1"
          },
          "profile": {
            "type": "string",
            "const": "draft-ietf-webbotauth-httpsig-protocol-00"
          },
          "verdict": {
            "type": "string",
            "enum": [
              "verified",
              "invalid",
              "unverified"
            ]
          },
          "meaning": {
            "type": "string"
          },
          "principal": {
            "type": "object",
            "description": "Present only when verdict is verified.",
            "properties": {
              "signatureAgent": {
                "type": "string",
                "format": "uri"
              },
              "keyThumbprint": {
                "type": "string"
              },
              "principalId": {
                "type": "string"
              }
            }
          },
          "request": {
            "type": "object",
            "description": "What the checker reconstructed and parsed from your request.",
            "properties": {
              "method": {
                "type": "string"
              },
              "targetUri": {
                "type": "string",
                "format": "uri"
              },
              "serverTime": {
                "type": "string",
                "format": "date-time"
              },
              "label": {
                "type": "string"
              },
              "signatureAgent": {
                "type": "object",
                "properties": {
                  "form": {
                    "type": "string",
                    "enum": [
                      "current",
                      "legacy"
                    ]
                  },
                  "key": {
                    "type": "string"
                  },
                  "uri": {
                    "type": "string"
                  }
                }
              },
              "params": {
                "type": "object",
                "additionalProperties": true
              }
            }
          },
          "steps": {
            "type": "array",
            "items": {
              "type": "object",
              "required": [
                "id",
                "status",
                "detail"
              ],
              "properties": {
                "id": {
                  "type": "string",
                  "enum": [
                    "headers",
                    "signature_agent",
                    "directory_fetch",
                    "directory_key",
                    "directory_signature",
                    "coverage",
                    "tag_alg",
                    "freshness",
                    "nonce",
                    "signature"
                  ]
                },
                "status": {
                  "type": "string",
                  "enum": [
                    "pass",
                    "fail",
                    "warn",
                    "skip",
                    "info"
                  ]
                },
                "detail": {
                  "type": "string"
                }
              }
            }
          },
          "hint": {
            "type": "string"
          },
          "docs": {
            "type": "string",
            "format": "uri"
          }
        }
      }
    }
  }
}