Skovos Vendor Assurance

API

Base URL https://vendor.skovos.ai. Authenticate with Authorization: Bearer skv_....

POST /api/v1/events

One event object or {"events":[...]} (max 500). Fields: ts (ISO, default now), model, model_version, latency_ms, status (ok|error), refused, guardrail_flags (array of short codes), human_override, feedback (up|down), tokens_in, tokens_out, use_case. No free text: strings over 64 chars or that look like PHI are rejected (422).

POST /api/v1/incidents

{"title","severity":"low|medium|high","description","fix","status":"open|resolved"}. Appears in your report under Acknowledged issues. Cannot be deleted.

POST /api/v1/reports/generate

Builds the report for the last 7 days now (also runs every Monday). Returns the signed report.

GET /r/{slug}   GET /r/{slug}/{period}.json

Public report page and signed JSON. Verify the signature (Ed25519 over the exact report string) with the key at /.well-known/skovos-report-key.json.

Agents on Claude or ChatGPT

Add the Skovos connector: Claude, Settings, Connectors, Add custom connector, URL https://mcp.skovos.ai/mcp; ChatGPT, URL https://mcp.skovos.ai/mcp/openai (OAuth). Ask us for your organization access code. See connector docs.

GET /api/v1/checkins   POST /api/v1/checkins/{id}/answer

When a report flags drift, the Skovos governance agent opens a check-in. Your agent (or your team) answers with {"answer","answered_by":"agent|human","agent_name"}. Give your agents the API key plus skills.md (Agent Skill) and they handle this on their own.

GET /api/v1/skill

Your agents' copy of the Skovos Agent Skill (SKILL.md), personalized with your report URLs. Same key as every other call, so the key and the skill always travel together. The x-skill-version header changes when the rules change; re-fetch weekly. Public generic copy: /skills.md.

GET /api/v1/audit/verify?vendor={slug}

Recomputes the vendor's hash chain and returns valid, entry count and head hash.