api/operations.yaml · PARITY_REQUIRED

One handler.
Two encodings.

Live generated inventory: docs/generated/api-parity.md. Policy: API_PARITY.md.

Operations

IDScopeRESTMCP
system.status.getstate:readGET /api/v1/statustaclab.system.status.get · taclab://status
system.build.getstate:readGET /api/v1/buildtaclab.system.build.get · taclab://build
config.effective.getstate:readGET /api/v1/config/effectivetaclab.config.effective.get
config.validatestate:writePOST /api/v1/config/validatetaclab.config.validate
config.reloadconfig:reloadPOST /api/v1/config/reloadtaclab.config.reload
config.exportconfig:exportGET /api/v1/config/exporttaclab.config.export
runtime.resetruntime:resetPOST /api/v1/runtime/resettaclab.runtime.reset
users.*state:read / write/api/v1/userstaclab.users.* · taclab://users
groups.*state:read / write/api/v1/groupstaclab.groups.* · taclab://groups
clients.*state:read / write/api/v1/clientstaclab.clients.* · taclab://clients
tokens.*tokens:manage/api/v1/tokenstaclab.tokens.*
policy.evaluatepolicy:testPOST /api/v1/policy/evaluatetaclab.policy.evaluate
authentication.testpolicy:testPOST /api/v1/authentication/testtaclab.authentication.test
events.listevents:readGET /api/v1/eventstaclab.events.list · taclab://events/recent
events.subscribeevents:readGET /api/v1/events/stream SSEsubscriptions/listen (URI only)

Scopes (exact match)

state:write does not imply tokens:manage, config:reload, or runtime:reset.

state:read · state:write · config:reload · config:export · policy:test · events:read · events:sensitive · tokens:manage · runtime:reset

REST-only / MCP-only

GET /health/live · /health/readyREST_ONLY_PROTOCOL
GET /api/openapi.jsonREST_ONLY_PROTOCOL
POST/DELETE /api/v1/sessionREST_ONLY_PROTOCOL (cookie + CSRF)
server/discover · tools/list · resources/listMCP_ONLY_PROTOCOL
notifications/list_changedMCP_ONLY_PROTOCOL