Skip to main content
PUT
Publish or replace the alignment manifest

Authorizations

Authorization
string
header
required

Supabase JWT token in Authorization: Bearer header

Headers

Idempotency-Key
string
required

Client-supplied idempotency token. Replays within 24 hours return the stored result. See ADR-023.

Required string length: 1 - 128
If-Match
string

Optional optimistic-concurrency token. Pass the ETag from a recent GET ("sha256:<hex64>" shape) to make the write conditional: a stale ETag returns 412 Precondition Failed, a malformed one 400. Omit it to publish unconditionally.

Pattern: ^"sha256:[0-9a-f]{64}"$

Path Parameters

agent_id
string
required

Agent identifier (e.g. smolt-abc123)

Body

Unified alignment card (ADR-008/ADR-039). Authored in YAML or JSON; composed server-side with platform defaults, org template, and active exemptions before storage. This schema matches the runtime validator at src/composition/validate.ts EXACTLY — a card authored strictly to it passes PUT /v1/agents/{id}/alignment-card and the preview-compose endpoint. Output-only fields (card_id, issued_at, expires_at, _composition, content_hash, version) are server-assigned and must NOT be sent on a PUT.

card_version
string
required

Card schema version (required, non-empty). Current canonical value: unified/2026-04-26.

Minimum string length: 1
autonomy_mode
enum<string>
required

ADR-039 master switch for the action-policing pipeline (autonomy constraints). Required at the top level post-cutover; the legacy enforcement.mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
integrity_mode
enum<string>
required

ADR-039 master switch for the values/conscience pipeline (integrity constraints). Required at the top level post-cutover; the legacy integrity.enforcement_mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
agent_id
string
required

Target agent id. On PUT, server overwrites to match the URL path.

principal
object
required

Required object describing whose authority the agent acts under (ADR-039 Decision 10).

values
object
required
autonomy
object
required
audit
object
required
card_id
string

Card row id. Server-assigned on PUT (ac-{uuid}).

issued_at
string<date-time>
expires_at
string<date-time> | null
conscience
object
capabilities
object
enforcement
object

Optional ADR-039 Decision-3 user-facing knobs for unmapped-tool handling. The legacy mode, unmapped_tool_action and fail_open keys are REJECTED by the validator (mode → top-level autonomy_mode; fail_open → gateway env config).

extensions
object
_composition
object

System-managed block describing which scope sources merged into the canonical card. Only returned when ?include_composition=true.

content_hash
string

Response-only: content hash of the composed card (sha256:<hex>), injected by the GET/PUT response. Server-assigned — do not send on a PUT.

version
integer

Response-only: monotonic card version, injected by the GET/PUT response. Server-assigned — do not send on a PUT.

Response

Composed canonical card after the write.

OUTPUT-only variant of UnifiedAlignmentCard for the COMPOSED card the server emits on GET /v1/alignment/{scope}/{id}, /effective, and the composed field of preview-compose. Identical to UnifiedAlignmentCard except principal is optional (a default / org-scope composed card has no agent principal) and values.declared / autonomy.bounded_actions may be empty (a fresh card declares nothing yet). The strict UnifiedAlignmentCard remains the authoring/request contract.

card_version
string
required

Card schema version (required, non-empty). Current canonical value: unified/2026-04-26.

Minimum string length: 1
autonomy_mode
enum<string>
required

ADR-039 master switch for the action-policing pipeline (autonomy constraints). Required at the top level post-cutover; the legacy enforcement.mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
integrity_mode
enum<string>
required

ADR-039 master switch for the values/conscience pipeline (integrity constraints). Required at the top level post-cutover; the legacy integrity.enforcement_mode location is rejected.

Available options:
off,
observe,
nudge,
enforce
agent_id
string
required

Target agent id. On PUT, server overwrites to match the URL path.

values
object
required
autonomy
object
required
audit
object
required
card_id
string

Card row id. Server-assigned on PUT (ac-{uuid}).

issued_at
string<date-time>
expires_at
string<date-time> | null
principal
object

Required object describing whose authority the agent acts under (ADR-039 Decision 10).

conscience
object
capabilities
object
enforcement
object

Optional ADR-039 Decision-3 user-facing knobs for unmapped-tool handling. The legacy mode, unmapped_tool_action and fail_open keys are REJECTED by the validator (mode → top-level autonomy_mode; fail_open → gateway env config).

extensions
object
_composition
object

System-managed block describing which scope sources merged into the canonical card. Only returned when ?include_composition=true.

content_hash
string

Response-only: content hash of the composed card (sha256:<hex>), injected by the GET/PUT response. Server-assigned — do not send on a PUT.

version
integer

Response-only: monotonic card version, injected by the GET/PUT response. Server-assigned — do not send on a PUT.