HTTP API
Public reads are unauthenticated. Publication uses Firebase bearer tokens or provisioned API keys.
Resources
/api/v1/objects and /worlds support discovery. Exact version, manifest, agent, integrity, compatibility, and reverse-world-reference endpoints are described by the live contract.
Errors and limits
Clients should branch on HTTP status and structured error codes, honor Retry-After for 429 responses, and treat 503 as a dependency outage. Cursors are opaque and bound to the active filter set.