Boundary API
Reports the platform's execution-boundary status: whether HTTP requests, provider calls, live execution, raw payloads, secret values, and customer identifiers are allowed in the current execution mode.
1 route
Response metadata: x-api-version, x-request-id, and traceresponse apply to normal routed responses and are omitted from the per-operation header tables below.
GET/api/boundary/status
audit access
Boundary status.
Permissions
| Access class | Credential | Scoping |
|---|---|---|
audit | An authenticated session or API bearer token is required. | The access class is enforced first; site and environment scopes narrow resources on scoped operations. |
HTTP request
GET https://<your-host>/api/boundary/status
Path parameters
This operation has no path parameters.
Query parameters
This operation has no query parameters.
Request headers
| Name | Type | Requirement | Description |
|---|---|---|---|
Authorization | string | Optional | Human credential alternative: supply one Bearer rys_... session token, ryk_... API token, or validated identity-provider JWT here. Do not combine it with X-Ryuki-Session-Id or the session cookie; conflicting carriers fail closed. |
X-Ryuki-Session-Id | string | Optional | Opaque rys_... session-token carrier used by the portal for mutations. Administrative session UUIDs cannot authenticate. Supply exactly one credential carrier per request. |
traceparent | string | Optional | Optional correlation input. When the second dash-separated segment has 32 characters, Ryuki reuses it as the request correlation identifier; this is not full W3C validation. |
Request body
This operation does not accept a request body.
Response
| Status | Description | Body |
|---|---|---|
200 | OK | BoundaryStatus |
200 response body
Structure: BoundaryStatus.
| Name | Type | Requirement | Description |
|---|---|---|---|
http_request_allowed | boolean | Required | Value of http_request_allowed returned in the response body. |
provider_calls_allowed | boolean | Required | Value of provider_calls_allowed returned in the response body. |
live_execution_allowed | boolean | Required | Value of live_execution_allowed returned in the response body. |
raw_payload_allowed | boolean | Required | Value of raw_payload_allowed returned in the response body. |
secret_values_allowed | boolean | Required | Value of secret_values_allowed returned in the response body. |
customer_identifiers_allowed | boolean | Required | Value of customer_identifiers_allowed returned in the response body. |
execution_mode | object (ExecutionMode) | Required | Value of execution_mode returned in the response body. |
Errors
JSON failures use one of the platform error envelopes and include the request correlation metadata when routing reaches the API middleware. See Errors for the exact shapes, authentication failures, retry guidance, and transport-level exceptions.
Examples
Request
curl --silent --show-error --globoff \
--request GET \
--header 'Authorization: Bearer <token>' \
'https://<your-host>/api/boundary/status'
Schematic response body
Illustrative shape generated from the extracted field types, not a recorded live response. Values are placeholders; null marks a field whose type could not be resolved.
Success status: 200
{
"http_request_allowed": false,
"provider_calls_allowed": false,
"live_execution_allowed": false,
"raw_payload_allowed": false,
"secret_values_allowed": false,
"customer_identifiers_allowed": false,
"execution_mode": {}
}