Skip to main content
Contract reference | MandateContract reference in the source-owned Mandate documentation.Mandatereferencemandatereferenceadopterdeveloperoperatorspecify

Contract reference

Open the interactive contract viewer. Search for a named type, entity, command, or event; follow relationships; inspect lifecycle diagrams; and share a link to a specific declaration.

The viewer reads ESS's ess-docs/1 projection. Its source and contract digests are visible on every page, with a downloadable projection. These describe the declared model. They do not establish implementation or runtime enforcement.

Read the generated reference​

The same specification generates a complete Markdown reference:

Semantic API projections​

ESS generates command-oriented OpenAPI references for the control plane, authorization service, STS, and worker.

Generated command routes are contract projections and are never served as product endpoints. The product routes are implemented separately, in mandate-server and mandate-proto, and the control plane serves six of them today: /v1/federation/login, /oauth/authorize, /oauth/token, /oauth/introspect, /oauth/jwks and /.well-known/oauth-authorization-server. Authorization-code redemption with S256 PKCE, introspection and the metadata and JWKS documents are implemented; token exchange, SCIM, SAML and the federation protocols a customer's administrator would call are not. Device authorization remains deferred.

Unsettled semantics remain visible​

Numeric epoch semantics, atomic membership contribution updates, lifecycle algorithms, and denial-audit behavior have explicit UNMAPPED entries and linked blockers. The unmapped register records the decisions and verification still required. A generated schema is not a substitute for those decisions.