Skip to main content
GET
Get this layer's alignment manifest

Authorizations

Authorization
string
header
required

Supabase JWT token in Authorization: Bearer header

Headers

Accept
enum<string>

Response format. YAML is canonical; JSON is returned only on explicit application/json. The ?include=sources envelope is JSON-only.

Available options:
text/yaml,
application/yaml,
application/json

Path Parameters

agent_id
string
required

Agent identifier (e.g. smolt-abc123)

Query Parameters

include_composition
boolean
default:false

Include the _composition metadata block on the response body.

include
enum<string>

When sources, returns the four-scope envelope {platform, org, teams[], agent, composed, composed_stale, my_role} (see ADR-053). The envelope is JSON-only.

Available options:
sources

Response

Alignment manifest at this scope.

OUTPUT-only variant of UnifiedAlignmentCard for the COMPOSED card the server emits on GET /v1/alignment/{scope}/{id}, /effective, and the composed field of preview-compose. Identical to UnifiedAlignmentCard except principal is optional (a default / org-scope composed card has no agent principal) and values.declared / autonomy.bounded_actions may be empty (a fresh card declares nothing yet). The strict UnifiedAlignmentCard remains the authoring/request contract.

card_version
string
required

Card schema version (required, non-empty). Current canonical value: unified/2026-04-26.

Minimum string length: 1
autonomy_mode
enum<string>
required

ADR-039 master switch for the action-policing pipeline (autonomy constraints). Required at the top level post-cutover; the legacy enforcement.mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
integrity_mode
enum<string>
required

ADR-039 master switch for the values/conscience pipeline (integrity constraints). Required at the top level post-cutover; the legacy integrity.enforcement_mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
agent_id
string
required

Target agent id. On PUT, server overwrites to match the URL path.

values
object
required
autonomy
object
required
audit
object
required
card_id
string

Card row id. Server-assigned on PUT (ac-{uuid}).

issued_at
string<date-time>
expires_at
string<date-time> | null
principal
object

Required object describing whose authority the agent acts under (ADR-039 Decision 10).

conscience
object
capabilities
object
enforcement
object

Optional ADR-039 Decision-3 user-facing knobs for unmapped-tool handling. The legacy mode, unmapped_tool_action and fail_open keys are REJECTED by the validator (mode → top-level autonomy_mode; fail_open → gateway env config).

extensions
object
_composition
object

System-managed block describing which scope sources merged into the canonical card. Only returned when ?include_composition=true.

content_hash
string

Response-only: content hash of the composed card (sha256:<hex>), injected by the GET/PUT response. Server-assigned — do not send on a PUT.

version
integer

Response-only: monotonic card version, injected by the GET/PUT response. Server-assigned — do not send on a PUT.