4
AUTHORIZED RUNTIME INTERFACE DISCOVERY
Gaps remainIncumbent API inventory
Record endpoints, schemas, auth class, pagination, idempotency and export behavior from normal authorized operator traffic.
Read-only evidence collection only. Store credential references/classes—not secret values. Do not bypass authentication, scan unrelated hosts or probe endpoints outside customer authorization.
4
4
2
Runtime API inventory
Evidence is based on authorized product use, not guessed endpoint names.
| Endpoint | Domain | Auth class | Idempotency | Schema | Evidence |
|---|---|---|---|---|---|
GET https://authorized-demo.invalid/api/meters/{id} | meter | session | supported | schema://meter-v1 | 1 |
GET https://authorized-demo.invalid/api/readings | telemetry | api_key_ref | supported | schema://reading-v2 | 1 |
POST https://authorized-demo.invalid/api/recharge | recharge | unknown | unknown | missing | 1 |
POST https://authorized-demo.invalid/api/valve | control | session | unknown | schema://command-v1 | 1 |
Inventory issues
gap
api-recharge:auth_unknown
gap
api-recharge:response_schema_missing
gap
api-recharge:idempotency_unknown
gap
api-command:idempotency_unknown
Migration use
1ObserveCapture authorized request/response schemas and correlation IDs.
2ClassifyIdentity, meter, telemetry, recharge, vending, control, reports and configuration.
3ContractTranslate verified behavior into adapter contracts and fixture tests.
4ExitRequire exportability and documented failure behavior before cutover.