Skip to content

Policies

Alpha access, errors, stability, and data retention.

This page records the policies that apply to the /api/v1alpha1 DeepFrame API.

Alpha Access

The Public API Alpha - the alpha key type for the DeepFrame API - is an opt-in surface. A platform admin must explicitly enable it for the workspace before the API allows alpha traffic. The request must also use an active key of this type with the required route permission. Standard API keys cannot call alpha routes.

When the key is valid but the workspace is not opted in, the API returns a 403 forbidden problem. A key without alpha access remains a 404 resource-not-found result. These responses are application/problem+json.

Error Catalog And Retryability

Every /api/v1alpha1 error uses application/problem+json and contains type, title, status, detail, instance, and request_id. The type URI is the stable error contract. The detail text may change.

StatusCatalog summaryRetry guidance
400bad-request, validation-error, invalid-cursor, or ssrf-blockedNo. Correct the request or use a fresh cursor or URL.
401unauthorizedNo. Correct or replace the key.
402quota-exceededNo. Wait for a quota or plan change.
403forbidden, including workspace alpha opt-in denialNo. Correct the permission, billing state, trial state, or workspace opt-in.
404resource-not-foundNo. Verify the resource, workspace, and key alpha access.
409conflict or idempotency-in-flightOnly after the resource state changes; for idempotency-in-flight, wait and retry the same payload.
422unprocessable-entity or idempotency-payload-mismatchNo. Correct the input or use the original payload with the same key.
429rate-limit-exceededYes. Honor Retry-After and the X-RateLimit-* headers before retrying.
500internal-errorOnly when the operation is idempotent and safe to repeat.
503service-unavailableYes. Use bounded exponential backoff with jitter.

Branch on the type URI, not on detail or status alone. Do not retry a 4xx response other than 429 without changing the request or state.

Alpha Stability

/api/v1alpha1 is an alpha channel. This alpha revision has no compatibility promise. Breaking changes ship as /api/v1alpha2, and a prior alpha revision may receive a 30-day sunset through the Deprecation and Sunset headers.

The API reference and response behavior are generated from the same OpenAPI contract. Log Deprecation and Sunset when they appear.

Data Retention

Stored profiles, report templates, and runs use archive-not-delete retention. Profile and report-template versions are append-only. Archiving a head blocks new runs and hides the resource from default listings, but preserves every version so past runs, answers, and reports resolve the exact version that produced them.

Tenant offboarding purge is a separate owner-authorized operation. It is not performed by an alpha DELETE call and must not be inferred from resource archival.

On this page