Policies
Alpha access, errors, stability, and data retention.
This page records the policies that apply to the /api/v1alpha1 DeepFrame API.
Alpha Access
The Public API Alpha - the alpha key type for the DeepFrame API - is an opt-in surface. A platform admin must explicitly enable it for the workspace before the API allows alpha traffic. The request must also use an active key of this type with the required route permission. Standard API keys cannot call alpha routes.
When the key is valid but the workspace is not opted in, the API returns a 403 forbidden problem. A key without alpha access remains a 404 resource-not-found result. These responses are application/problem+json.
Error Catalog And Retryability
Every /api/v1alpha1 error uses application/problem+json and contains type, title, status, detail, instance, and request_id. The type URI is the stable error contract. The detail text may change.
| Status | Catalog summary | Retry guidance |
|---|---|---|
| 400 | bad-request, validation-error, invalid-cursor, or ssrf-blocked | No. Correct the request or use a fresh cursor or URL. |
| 401 | unauthorized | No. Correct or replace the key. |
| 402 | quota-exceeded | No. Wait for a quota or plan change. |
| 403 | forbidden, including workspace alpha opt-in denial | No. Correct the permission, billing state, trial state, or workspace opt-in. |
| 404 | resource-not-found | No. Verify the resource, workspace, and key alpha access. |
| 409 | conflict or idempotency-in-flight | Only after the resource state changes; for idempotency-in-flight, wait and retry the same payload. |
| 422 | unprocessable-entity or idempotency-payload-mismatch | No. Correct the input or use the original payload with the same key. |
| 429 | rate-limit-exceeded | Yes. Honor Retry-After and the X-RateLimit-* headers before retrying. |
| 500 | internal-error | Only when the operation is idempotent and safe to repeat. |
| 503 | service-unavailable | Yes. Use bounded exponential backoff with jitter. |
Branch on the type URI, not on detail or status alone. Do not retry a 4xx response other than 429 without changing the request or state.
Alpha Stability
/api/v1alpha1 is an alpha channel. This alpha revision has no compatibility promise. Breaking changes ship as /api/v1alpha2, and a prior alpha revision may receive a 30-day sunset through the Deprecation and Sunset headers.
The API reference and response behavior are generated from the same OpenAPI contract. Log Deprecation and Sunset when they appear.
Data Retention
Stored profiles, report templates, and runs use archive-not-delete retention. Profile and report-template versions are append-only. Archiving a head blocks new runs and hides the resource from default listings, but preserves every version so past runs, answers, and reports resolve the exact version that produced them.
Tenant offboarding purge is a separate owner-authorized operation. It is not performed by an alpha DELETE call and must not be inferred from resource archival.