Agents: request Accept: text/markdown or append /index.md.

# SliceRun HTTP API

Base URL: https://slicerun.pages.dev

Authenticate with `Authorization: Bearer <token>` from the OAuth token endpoint, or the `sr_session` cookie from the web app. Unauthenticated calls to protected routes return `401` with a `WWW-Authenticate` header pointing at RFC 9728 metadata.

## Privacy

`GET /api/jobs/{id}` returns:

- `visibility: full` for the posting shop, assigned driver, and admin
- `visibility: preview` for a candidate driver (pickup, fee, ready time — no drop-off or notes)
- `404` for everyone else, including a driver who was offered a job that someone else accepted

## Useful endpoints

- `GET /api/health` — public liveness
- `POST /api/jobs` — shop posts a job
- `GET /api/shop/jobs` / `GET /api/driver/jobs` — role-scoped lists
- `POST /api/jobs/{id}/accept|pickup|deliver|cancel`
- `GET /api/verification` — own status only
- `POST /oauth/register` / `GET /oauth/authorize` / `POST /oauth/token`

Full machine description: https://slicerun.pages.dev/openapi.json