Skip to content

Search docs

Jump between documentation pages.

Browse docs

daloyjs.dev API reference

This site runs a small public API for coding agents and tools: discovery catalogs, an OAuth token endpoint, the docs MCP server, and a markdown copy of every page. This page is generated from the same OpenAPI 3.1 document the site serves at /openapi.json, so the reference and the spec cannot drift apart.

How an agent uses the site API
  1. 01DiscoverGET /.well-known/api-catalog
  2. 02Get a tokenPOST /oauth/token (client_credentials)
  3. 03CallGET /api/v1 or POST /mcp with Bearer token
  4. 04Read pagesGET /md/{path} as markdown
Discovery and markdown pages are public. The versioned API and MCP accept a short-lived docs:read token from the public client_credentials grant; every response carries IETF RateLimit headers.

Authentication

Operations marked Requires a token need a bearer token, and Token optional ones accept one but also answer anonymously. Tokens come from the public client_credentials grant: there is no client secret, and the token only grants the read-only docs:read scope.

Get a tokenbash
curl -X POST https://daloyjs.dev/oauth/token \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data 'grant_type=client_credentials&scope=docs:read'

Versioning, deprecation headers and the sunset policy are covered in API lifecycle and API versioning.

Discovery

Catalogs agents should fetch first.

JSON index of DaloyJS website APIs (v1)

GET/api/v1Token optional

The catalog also publishes the whole versioning and deprecation policy under `versioning`, including every surface's status, successor, and sunset date.

Parameters

API-Version
"1" | "v1" | "1.0" | "1.0.0"
Default:-
headerPin the API major. Accepted: 1, v1, 1.0, 1.0.0. Any other value returns 400 unsupported_api_version instead of silently serving a different major.

Responses

  • 200Catalog of machine endpoints on this origin.application/json

    namerequired
    string
    Default:-
    descriptionrequired
    string
    Default:-
    versionrequired
    string
    Default:-
    versioning
    object
    Default:-
    linksrequired
    object
    Default:-
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 400The API-Version request header pinned a major this origin does not serve (code `unsupported_api_version`).application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.
  • defaultRFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).

Example request

bash
curl -X GET 'https://daloyjs.dev/api/v1' \
  -H "Authorization: Bearer $TOKEN"
GET /api/v1

Unversioned alias for the current major

GET/apiToken optional

Permanently redirects to /api/v1 so an agent never pins an unversioned path. The redirect carries rel="successor-version" and rel="latest-version" link relations.

Responses

  • 308Permanent redirect to the current major.

    Headers (3)
    Location
    string
    Default:-
    The versioned path, e.g. /api/v1.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Link
    string
    Default:-
    RFC 5829 rel="successor-version" and rel="latest-version".

Example request

bash
curl -X GET 'https://daloyjs.dev/api' \
  -H "Authorization: Bearer $TOKEN"
GET /api

DaloyJS website OpenAPI 3.1 document

GET/openapi.jsonToken optional

Responses

  • 200This OpenAPI document.application/json

    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.
  • defaultRFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).

Example request

bash
curl -X GET 'https://daloyjs.dev/openapi.json' \
  -H "Authorization: Bearer $TOKEN"
GET /openapi.json

RFC 9727 API catalog linkset

GET/.well-known/api-catalogToken optional

Responses

  • 200Linkset pointing at OpenAPI and the docs MCP.application/linkset+json

Example request

bash
curl -X GET 'https://daloyjs.dev/.well-known/api-catalog' \
  -H "Authorization: Bearer $TOKEN"
GET /.well-known/api-catalog

Curated Markdown index of the site for agents

GET/llms.txtToken optional

Responses

  • 200llms.txt v2 document.text/plain

    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/llms.txt' \
  -H "Authorization: Bearer $TOKEN"
GET /llms.txt

Docs MCP

Read-only Model Context Protocol for the documentation.

MCP Server Card for the docs MCP server (draft)

GET/.well-known/mcp/server-card.jsonToken optional

Discovery metadata for POST /mcp: transport, protocol version, capabilities, authentication, and the full tool list with input schemas. Follows the draft MCP Server Cards proposal (SEP-1649), which may change before it reaches a released MCP specification.

Responses

  • 200The Server Card.application/json

    $schemarequired
    string<uri>
    Default:-
    versionrequired
    string
    Default:-
    protocolVersionrequired
    string
    Default:-
    serverInforequired
    object
    Default:-
    serverInfo.namerequired
    string
    Default:-
    serverInfo.title
    string
    Default:-
    serverInfo.versionrequired
    string
    Default:-
    description
    string
    Default:-
    iconUrl
    string<uri>
    Default:-
    documentationUrl
    string<uri>
    Default:-
    transportrequired
    object
    Default:-
    transport.typerequired
    "streamable-http"
    Default:-
    transport.endpointrequired
    string<uri>
    Default:-
    capabilitiesrequired
    object
    Default:-
    authentication
    object
    Default:-
    authentication.requiredrequired
    boolean
    Default:-
    authentication.schemesrequired
    string[]
    Default:-
    instructions
    string
    Default:-
    tools
    object[]
    Default:-
    tools[].namerequired
    string
    Default:-
    tools[].title
    string
    Default:-
    tools[].description
    string
    Default:-
    tools[].inputSchemarequired
    object
    Default:-
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/.well-known/mcp/server-card.json' \
  -H "Authorization: Bearer $TOKEN"
GET /.well-known/mcp/server-card.json

DaloyJS MCP server (JSON-RPC 2.0 over Streamable HTTP)

POST/mcpToken optional

Read-only tools: search_docs, get_doc, list_docs. Send JSON-RPC 2.0. GET on this URL returns 405 with a JSON hint. Bearer docs:read is optional.

Request body application/json

Responses

  • 200JSON-RPC result or error envelope.application/json

    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 400RFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 405RFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 413RFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X POST 'https://daloyjs.dev/mcp' \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  --data '{}'

OAuth

RFC 8414 authorization server and client_credentials token grant.

RFC 8414 OAuth 2.0 authorization-server metadata

GET/.well-known/oauth-authorization-serverToken optional

Responses

  • 200Authorization-server metadata JSON.application/json

Example request

bash
curl -X GET 'https://daloyjs.dev/.well-known/oauth-authorization-server' \
  -H "Authorization: Bearer $TOKEN"
GET /.well-known/oauth-authorization-server

RFC 9728 OAuth 2.0 protected-resource metadata

GET/.well-known/oauth-protected-resourceToken optional

Responses

  • 200Protected-resource metadata, including scopes_supported.application/json

Example request

bash
curl -X GET 'https://daloyjs.dev/.well-known/oauth-protected-resource' \
  -H "Authorization: Bearer $TOKEN"
GET /.well-known/oauth-protected-resource

OAuth 2.0 client_credentials token endpoint

POST/oauth/token

Public client. Send grant_type=client_credentials and optional scope=docs:read as application/x-www-form-urlencoded. No client_secret.

Request body application/x-www-form-urlencoded

grant_typerequired
"client_credentials"
Default:-
scope
"docs:read"
Default:-
client_id
string
Default:-

Responses

  • 200Access token response (RFC 6749 §5.1).application/json

    access_tokenrequired
    string
    Default:-
    token_typerequired
    "Bearer"
    Default:-
    expires_inrequired
    integer
    Default:-
    scoperequired
    "docs:read"
    Default:-
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 400OAuth error (RFC 6749 §5.2).application/json

    errorrequired
    string
    Default:-
    error_descriptionrequired
    string
    Default:-
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X POST 'https://daloyjs.dev/oauth/token' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data 'grant_type=client_credentials&scope=docs:read&client_id=…'

Authorization endpoint (client_credentials only)

GET/oauth/authorize

Advertised by the RFC 8414 metadata. This server implements no browser redirect flow, so it answers with an RFC 6749 §4.1.2.1 unsupported_response_type error pointing at the token endpoint. Probes get live JSON rather than an HTML 404.

Responses

  • 400OAuth error (RFC 6749 §5.2).application/json

    errorrequired
    string
    Default:-
    error_descriptionrequired
    string
    Default:-
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/oauth/authorize'
GET /oauth/authorize

OAuth 2.0 token introspection (RFC 7662)

POST/oauth/introspect

Confirm that a token minted by this origin is still active and which scope it carries. No client authentication: the only issued scope covers public documentation. Unknown or expired tokens return { active: false }.

Request body application/x-www-form-urlencoded

tokenrequired
string
Default:-
token_type_hint
"access_token"
Default:-

Responses

  • 200Introspection response (RFC 7662 §2.2).application/json

    activerequired
    boolean
    Default:-
    scope
    string
    Default:-
    token_type
    string
    Default:-
    iss
    string
    Default:-
    aud
    string
    Default:-
    iat
    integer
    Default:-
    exp
    integer
    Default:-
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 400OAuth error (RFC 6749 §5.2).application/json

    errorrequired
    string
    Default:-
    error_descriptionrequired
    string
    Default:-
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X POST 'https://daloyjs.dev/oauth/introspect' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data 'token=…&token_type_hint=access_token'

RFC 9728 §3.1 per-resource protected-resource metadata

GET/.well-known/oauth-protected-resource/{resource}Token optional

Metadata for one resource on this origin, located by inserting the resource path after the well-known prefix. MCP clients resolve /.well-known/oauth-protected-resource/mcp before attaching a token.

Parameters

resourcerequired
string
Default:-
pathResource path without the leading slash.

Responses

  • 200Protected-resource metadata, including scopes_supported.application/json

    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 404RFC 9457 problem+json with an error code and a recovery hint.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/.well-known/oauth-protected-resource/{resource}' \
  -H "Authorization: Bearer $TOKEN"

Markdown

Markdown representations of public pages, for agents that would rather not parse HTML.

Markdown representation of any public page

GET/md/{path}Token optional

Also reachable by appending `.md` to a page URL, or by sending `Accept: text/markdown` to the canonical URL. Responses set `Vary: Accept`.

Parameters

pathrequired
string
Default:-
pathPage path without the leading slash.

Responses

  • 200Markdown body of the page.text/markdown

    Headers (6)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
  • 404No such page. The Markdown body lists recovery entry points.text/markdown

  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/md/{path}' \
  -H "Authorization: Bearer $TOKEN"

Legacy Markdown handler for cached /docs/*.md destinations

GET/docs-md/{path}Token optionalDeprecated

Deprecated in favour of /md/docs/{path}. Every response carries an RFC 9745 Deprecation date and RFC 8288 deprecation / successor-version relations. No Sunset date is scheduled; one will be announced at least 180 days ahead. Policy: https://daloyjs.dev/docs/api-lifecycle.

Parameters

pathrequired
string
Default:-
pathDocs path without the leading slash.

Responses

  • 200Markdown body of the docs page.text/markdown

    Headers (9)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Deprecation
    string
    Default:-
    RFC 9745 structured-field Date marking when this surface was deprecated, e.g. @1756944000.
    Sunset
    string
    Default:-
    RFC 8594 IMF-fixdate for the scheduled retirement. Absent while no retirement is scheduled; never set less than 180 days ahead.
    Link
    string
    Default:-
    RFC 8288 relations: rel="deprecation", rel="sunset", rel="successor-version", rel="latest-version".
  • 404No such docs page.text/markdown

    Headers (9)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Deprecation
    string
    Default:-
    RFC 9745 structured-field Date marking when this surface was deprecated, e.g. @1756944000.
    Sunset
    string
    Default:-
    RFC 8594 IMF-fixdate for the scheduled retirement. Absent while no retirement is scheduled; never set less than 180 days ahead.
    Link
    string
    Default:-
    RFC 8288 relations: rel="deprecation", rel="sunset", rel="successor-version", rel="latest-version".
  • 429Quota exhausted. Honor Retry-After and retry. RateLimit remaining is 0.application/problem+json

    typerequired
    string<uri>
    Default:-
    titlerequired
    string
    Default:-
    statusrequired
    integer
    Default:-
    detailrequired
    string
    Default:-
    instance
    string
    Default:-
    coderequired
    string
    Default:-
    Machine-readable error code (snake_case).
    hintrequired
    string
    Default:-
    What the caller should do next to recover.
    Headers (7)
    RateLimit
    string
    Default:-
    IETF RateLimit header (draft-ietf-httpapi-ratelimit-headers). Example: "default";r=119;t=60
    RateLimit-Policy
    string
    Default:-
    Advertised quota. Default: "default";q=120;w=60
    RateLimit-Limit
    integer
    Default:-
    Maximum requests per window.
    RateLimit-Remaining
    integer
    Default:-
    Requests remaining in the current window.
    RateLimit-Reset
    integer
    Default:-
    Seconds until the current window resets.
    API-Version
    "1"
    Default:-
    Current URL-path major (1).
    Retry-After
    integer
    Default:-
    Seconds to wait before retrying.

Example request

bash
curl -X GET 'https://daloyjs.dev/docs-md/{path}' \
  -H "Authorization: Bearer $TOKEN"