{
  "protocol": "HHTTPS — Human-verified HTTPS",
  "version": "0.5.0",
  "initiative": "iamhmn",
  "contact": "daniel.hannuschka@tweakz.de",
  "github": "github.com/dhannus/HHTTPS",
  "demo": "https://hhttps.org",
  "features": [
    "webauthn",
    "roles-esco-dynamic",
    "email-verification",
    "refresh-tokens",
    "token-revocation",
    "machine-tokens",
    "webhooks",
    "jwks",
    "discovery",
    "postgres-persistence"
  ],
  "security": {
    "algorithm": "ES256",
    "helmet": true,
    "rateLimiting": true,
    "revocation": true,
    "persistence": "postgres"
  },
  "stats": {
    "registeredPasskeys": 45,
    "activeTokens": 0,
    "activeRefreshTokens": 25,
    "activeSessions": 0,
    "revokedTokens": 65,
    "machineOperators": 27
  },
  "roles_model": "esco-dynamic",
  "base_identity": {
    "id": "citizen",
    "label": "Citizen",
    "icon": "🧑"
  },
  "endpoints": {
    "GET  /.well-known/hhttps-configuration": "Discovery",
    "GET  /.well-known/jwks.json": "Public key (JWKS)",
    "GET  /.well-known/openid-configuration": "OIDC discovery (scopes: openid, role, age_group, email)",
    "POST /hhttps/check": "★ Human/machine + role check",
    "GET  /hhttps/roles": "Role registry (ESCO-dynamic)",
    "POST /hhttps/session/start": "Create a method-neutral session (step 1; optional pseudonym)",
    "POST /hhttps/session/email/start": "Alias of session/start (legacy name)",
    "POST /hhttps/email/send": "Send the 6-digit verification code (step 2; email is the mandatory first method)",
    "POST /hhttps/email/confirm-code": "Confirm the code in the same tab → session bound to the identity anchor (step 3)",
    "GET  /hhttps/email/verify": "Confirm via magic link (same session only)",
    "POST /hhttps/webauthn/register/{start,finish}": "Passkey registration (requires sessionId with a verified email; 400 without sessionId, 403 without email)",
    "POST /hhttps/webauthn/auth/{start,finish}": "Passkey authentication (returning users)",
    "POST /hhttps/role/declare": "Issue HHTTPS token (requires a verified email; carries pseudonym + verified_methods)",
    "POST /hhttps/eid/upgrade": "EUDI Wallet upgrade (requires a verified email)",
    "POST /hhttps/age/upgrade": "Age upgrade via eudi-verifier (internal; requires a verified email — AK-27)",
    "POST /hhttps/age/direct": "Session-less age bootstrap DISABLED: always 403 email_verification_required (AK-28)",
    "GET  /hhttps/verify/github/start": "GitHub verification (requires a verified email)",
    "POST /hhttps/token/refresh": "Refresh access token",
    "GET  /hhttps/oauth/authorize": "OAuth/OIDC authorization (consent page)",
    "POST /hhttps/oauth/approve": "OAuth consent → authorization code",
    "POST /hhttps/oauth/token": "Code / refresh_token grant → id_token, access_token (scope email → email claim)",
    "GET  /hhttps/oauth/userinfo": "OIDC userinfo (preferred_username, verified_methods, *_verified, email with scope email)",
    "POST /hhttps/revoke": "Revoke token",
    "POST /hhttps/validate": "Validate token",
    "POST /hhttps/machine/{register,token}": "Machine token issuance",
    "GET/POST/DELETE /hhttps/webhooks": "Webhook management",
    "GET  /hhttps/stats": "Public aggregated stats"
  }
}