Documentation
Implemented control-plane boundary
This page separates the APIs present in the release source from the broader product library. The source file docs/API_CONTRACTS.md is the canonical route-level contract; public roadmap pages do not extend it.
Present in the candidate source
Source implementation is not the same as a deployed or provider-verified production service. Those gates are reported separately.
Dashboard identity and workspaces
OIDC authorization code flow with PKCE, server-side sessions, workspace membership, invitations, role changes and recoverable account closure.
Projects and environments
Tenant-scoped projects, isolated test or production environments, audit events and dashboard reads backed by the control-plane API.
Stripe and Paddle connections
Customer-owned provider credentials, secret-store references, signed webhooks, checkout contracts, cancellation and reconciliation.
Catalog, usage and entitlements
Versioned products, plans, prices and mappings plus idempotent usage events and a single entitlement decision path.
Not a current contract
Roadmap and external release gates
- The SAML, SCIM, Sign-in UI, Abuse Checks, Secret Storage and Organization Setup libraries in the navigation are reference and roadmap material.
- Node.js, Python, Go, Ruby, PHP and Java packages are not published as current first-party SDK releases.
- Automated workspace-invitation email and Lemon Squeezy are not implemented contracts.
- Production deployment and live provider journeys require separate release evidence.
How to read this library
Treat navigation entries as design reference unless the capability also appears in the canonical API contract. Treat production availability as unmeasured unless the status surface identifies an exact deployed release and runtime proof.