01
No private applicant data
Application answers remain behind staff authentication.
Public read-only endpoints for health, service discovery, network status, and community metadata. Private application, staff, and CAD operations stay on their own authenticated origins.
Versioned routes for Code Zero-owned integrations.
API availability, version, and timestamp.
Official Code Zero service directory.
Server-side checks against each service health file.
Public membership requirements and authentication metadata.
Public API responses should stay intentionally small.
Application answers remain behind staff authentication.
Member roleplay records remain behind CAD authentication.
Signed staff session details never leave Staff Operations.
OAuth secrets, bot tokens, and database credentials are never returned.