Small interfaces. Clear boundaries.
Use the existing event path. Keep credentials on the server.
Available in the internal beta
Event intake
POST /api/v1/lines/{publicLineId}/eventsScoped Bearer key or signed HMAC intake; stable Idempotency-Key; bounded JSON payload.
Authorized retrieval
GET /api/v1/events/{eventId}GET /api/v1/events/{eventId}/contentRead scope, tenant, Line and retention checks apply. A write key does not grant read access.
Interface direction
Record, synchronization, verification and SDK surfaces are proposed boundaries, not additional live APIs. Device trust and vault discovery are not implemented.
The additive signal.event.v1 metadata contract describes event identity, time, source, optional context and state. It does not replace immutable arkosom.record.v1 notes.