Dashboard routes
Four routes exist for the private-beta dashboard at vulnpatch.dev and are reachable on the API host, so they are listed here to say what they are. They are not part of the public data contract: none is in openapi.json, the agent manifest does not name them, and each requires the caller's own GitHub token as a bearer credential. An agent should not call them.
POST /api/v1/access-request
GET /api/v1/access-request/:username
POST /api/v1/pr/validate
POST /api/v1/pr/fixAccess requests
POST /api/v1/access-request records a request for the private beta from the GitHub account the token belongs to, once per fourteen days. GET /api/v1/access-request/:username reports that account's own request: its status, when it was made and when another may be made. Asking about another account answers 403; asking without a token answers 401; GitHub not confirming who is asking answers 502.
Pull request tools
POST /api/v1/pr/validate checks a nixpkgs pull request for the common review findings, and POST /api/v1/pr/fix applies corrections to it, which includes a force push to the caller's branch. Both act on GitHub as the caller using the caller's token and answer 401 without one. They write to a third party's repository on the caller's behalf, which is why they stay out of the read-only public contract.
Retired
POST /api/v1/pr/signature forwarded a signing request to a bot worker that has been scrapped. It answers 410 with success: false and will not return.