Contract reference
Open the interactive contract viewer. Search for a named type, entity, command, or event; follow relationships; inspect lifecycle diagrams; and share a link to a specific declaration.
The viewer reads ESS's ess-docs/1 projection. Its source and contract digests are visible on every page, with a downloadable projection. These describe the declared model. They do not establish implementation or runtime enforcement.
Read the generated reference
The same specification generates a complete Markdown reference:
- System and deployment overview
- Core identifiers
- Identity and sessions
- Organizations and teams
- Directory mapping
- External identity and federation
- Credentials, registered audiences, and exchange
- Relationships and grants
- Policies
- Authorization decisions
- Delegation, execution, and approval
- Workload identity
- Audit
Semantic API projections
ESS generates command-oriented OpenAPI references for the control plane, authorization service, STS, and worker.
Generated command routes are contract projections and are never served as product endpoints. The product routes are implemented separately, in mandate-server and mandate-proto, and the control plane serves six of them today: /v1/federation/login, /oauth/authorize, /oauth/token, /oauth/introspect, /oauth/jwks and /.well-known/oauth-authorization-server. Authorization-code redemption with S256 PKCE, introspection and the metadata and JWKS documents are implemented; token exchange, SCIM, SAML and the federation protocols a customer's administrator would call are not. Device authorization remains deferred.
Unsettled semantics remain visible
Numeric epoch semantics, atomic membership contribution updates, lifecycle algorithms, and denial-audit behavior have explicit UNMAPPED entries and linked blockers. The unmapped register records the decisions and verification still required. A generated schema is not a substitute for those decisions.