SYSTEM STATE
StableFounder ControlledHuman Reviewed
LIVE ENDPOINT HEALTH
APIs are the wires. Health gates keep them from becoming exposed nerves.
Live API Health Gate checks that every /api/live endpoint returns safe JSON, protects secrets, labels structural readiness honestly, and can route failures to telemetry, recovery, and founder review.
Health Ready
/api/live/dashboard-status100% health readinessReturns dashboard panels, routes, status labels, readiness, and timestamp.
✓ API Defined/api/live/dashboard-status
✓ Expected Response DefinedReturns dashboard panels, routes, status labels, readiness, and timestamp.
✓ Safeguard DefinedSafe summaries only.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/telemetry-status100% health readinessReturns build, deployment, runtime, token summary, connector freshness, workflow cost, and alerts.
✓ API Defined/api/live/telemetry-status
✓ Expected Response DefinedReturns build, deployment, runtime, token summary, connector freshness, workflow cost, and alerts.
✓ Safeguard DefinedNo raw tokens or secrets.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/signal-mesh-status100% health readinessReturns signal sources, routing, priority, correlation, and verification status.
✓ API Defined/api/live/signal-mesh-status
✓ Expected Response DefinedReturns signal sources, routing, priority, correlation, and verification status.
✓ Safeguard DefinedUse confidence and structural-readiness labels.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/ingestion-status100% health readinessReturns connectors, validation, schema health, freshness, and handoff readiness.
✓ API Defined/api/live/ingestion-status
✓ Expected Response DefinedReturns connectors, validation, schema health, freshness, and handoff readiness.
✓ Safeguard DefinedCredentials remain server-side only.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/autonomy-status100% health readinessReturns auto-allowed, review-required, blocked, escalated, and override-ready actions.
✓ API Defined/api/live/autonomy-status
✓ Expected Response DefinedReturns auto-allowed, review-required, blocked, escalated, and override-ready actions.
✓ Safeguard DefinedNo unsafe blocked-action payloads.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/command-center-status100% health readinessReturns panels, decisions, alerts, workflow queue, approvals, and override state.
✓ API Defined/api/live/command-center-status
✓ Expected Response DefinedReturns panels, decisions, alerts, workflow queue, approvals, and override state.
✓ Safeguard DefinedFounder-facing summaries only.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/safe-mode-status100% health readinessReturns normal, degraded, paused, safe mode, recovery, or override status.
✓ API Defined/api/live/safe-mode-status
✓ Expected Response DefinedReturns normal, degraded, paused, safe mode, recovery, or override status.
✓ Safeguard DefinedHuman override must remain visible.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
Health Ready
/api/live/system-heartbeat100% health readinessReturns aggregate readiness, layers, warnings, blocked items, review-required items, and recommended action.
✓ API Defined/api/live/system-heartbeat
✓ Expected Response DefinedReturns aggregate readiness, layers, warnings, blocked items, review-required items, and recommended action.
✓ Safeguard DefinedBe honest about structural readiness versus true live integration.
✓ Secret Saferoute must not expose credentials or raw secrets
✓ JSON Readyroute should return safe JSON response
LIVE API RULES
Every live API route must return safe JSON.
Live APIs must never expose tokens, secrets, credentials, private logs, or raw sensitive payloads.
Structural readiness must be labeled honestly until real providers, databases, queues, and credentials are wired.
Heartbeat must summarize dashboard, telemetry, signal mesh, ingestion, autonomy, command center, and safe mode.
Blocked, review-required, warning, and safe-mode states must remain visible.
Live API failures should route to Telemetry Alert Gate, Founder Decision Gate, and Recovery Simulator.