AUROS Protocol · Changelog
Changelog API
Historique des releases AUROS Protocol v1 — status, tooling, endpoints et headers. Feed machine : GET /api/v1/changelog (public, sans auth).
Releases
Anti-exit stack — home 2 portes, /start, Shield DB, nurture, pilotes
Home clarifiée (dossier | preuves), première victoire /start, reprise e-mail wizard, pont dossier→banque, persistance Shield Supabase, nurture dossiers, export partenaires CSV, pack HTML imprimable, waitlist Liquidity.
- Migrations 0046 shield_* + 0047 nurture_sent_at
- POST /api/wizard/resume-link · cron /api/cron/dossier-nurture
- GET /api/partners/payouts-export · pack?format=html
- Pages /start /pilots /liquidity
Shield — middleware, webhooks, banques, CFU auto-tap, Python
Adoption complète : withShieldTap/expressShieldTap, webhook shield.tap.created, landing banques + pack exemple, dashboard quota, export CFU ?shield=1, generation_source dans Evidence Pack, reseal/audit Premium, snippets agents, case study, welcome email, SDK Python.
- Middleware Next + Express + instrumentFetch
- GET /api/v1/shield/quota · audit · reseal
- Export CFU ?shield=1 + verify dans JSON/CSV
- Pages /developers/shield/{banks,dashboard,agents,case-study}
Shield — essai 1 clic + bouton console CFU
POST /api/v1/shield/demo sans clé, panneau Essayer sur /developers/shield, bouton Shield dans la console ChargeFlow, CLI init.
- Try panel : coller → preuve → verify auto
- Console CFU : Shield tap de l’export listé
- auros-shield init — snippets copy/paste
Shield v0.3 — ingest 1 ligne + Evidence Pack Premium
Intégration quasi invisible (curl brut + instrumentFetch) et Premium lourd : Evidence Pack CFU+taps pour banques/auditeurs dans un monde où le RWA est partout.
- POST /api/v1/shield/ingest — body brut, aucun schéma JSON
- instrumentFetch({ apiKey }) — wrap fetch sans rewrite métier
- POST /api/v1/shield/pack — Premium Evidence Pack (hash-only + bank_actions)
- SDK shieldIngest / shieldTap / shieldVerify / shieldPack (1.0.9)
AUROS Shield Proof Tap — freemium indispensable
Tap non invasif (hash only), verify contrepartie gratuit, 100 ancrages/mo free · Premium illimité + hybrid PQC + export.
- POST /api/v1/shield/tap · POST /api/v1/shield/verify · GET /api/v1/shield/receipts/:id
- GET /api/v1/shield/export (Premium)
- On-prem POST /v1/tap — package auros-shield 0.2.0
- Payload jamais stocké — seule la preuve est publique.
AUROS Shield — sous-couche crypto on-prem
Runtime installable chez le client : seal/verify CFU-attest, CBOM crypto, profils hybrid_pqc_ready — racine de confiance avant que ce soit obligatoire.
- Package @adrien1212balitrand/auros-shield (CLI + HTTP DMZ + Docker).
- GET /api/v1/shield/cbom — inventaire exemple cloud.
- Page /developers/shield · docs/AUROS-SHIELD.md.
- Honnête : HMAC aujourd'hui, PQC NIST en roadmap derrière la même enveloppe.
APIs institutionnelles + AUROS Power (low-carbon)
OpenAPI Watts, export CFU portfolio, generation_source (nucléaire inclus), page /developers/institutions et verticale /power — hors Green Verified.
- OpenAPI : /api/v1/watts/* + GET /api/v1/chargeflow/export.
- SDK chargeflowExport + generation_source sur Watts/ChargeFlow.
- Hub /power · guide /guides/low-carbon-power · glossaire energie-nucleaire-rwa · /comment-tokeniser/nucleaire.
- Score/checklist : asset_type low_carbon_power (indicatif).
Ownership de catégorie — /guides + intents
Hub /guides avec définitions canoniques (booking engine watts, CFU, RWA Intelligence, RTMS, low-carbon) et /guides/intents (Q&A citables) pour Google et recherche IA.
- 3 piliers × intents liés hub + outil + intents banques / Power.
- Glossaire : booking-engine-watts, chargeflow-cfu, rwa-intelligence-layer, energie-nucleaire-rwa.
- llms.txt + sitemap priorités guides.
SEO/GEO — visibilité Google + recherche IA sur tout AUROS
Catalogue ChargeFlow, FAQ Watts/ChargeFlow/Eau/Protocol, robots bots IA 2026, llms.txt + ai.txt, SearchAction RAG, IndexNow élargi, article blog Watts.
- Catalog chargeflow-pages (hub, fleets, console, flex, eau) + FAQ JSON-LD.
- robots.ts : Claude-SearchBot, Perplexity-User, Applebot-Extended, Amazonbot, CCBot, Meta-External*, etc.
- /ai.txt + llms.txt enrichi (Watts, ChargeFlow, Eau, Copilot, citation policy).
- hreflang corrigé (fr + x-default, plus de faux en/es).
- Blog : /green/blog/auros-watts-booking-engine.
Watts hub live + inventaire depuis réserve + MCP 1.2.3
Hub /green/watts avec aperçu inventaire/secondaire en direct, match capacité depuis la réserve, nav Green Standards, outils MCP watts_get / list_offers / secondary_book.
- UI hub : compteurs + top offres/listings (demo API).
- Réserve : « Voir capacité ouverte » → POST offers/demo/match.
- Green Standards quick nav → AUROS Watts.
- MCP 1.2.3 : watts_get, watts_list_offers, watts_secondary_book.
AUROS Watts hub + MCP tools
Hub produit /green/watts et outils MCP watts_reserve/confirm/settle/offers/secondary (auros-mcp 1.2.2).
- UI hub brand-first · WattsFlowNav inclut Hub.
- MCP: watts_reserve, watts_confirm, watts_settle, watts_create_offer, watts_match_offers, watts_secondary_list.
Watts Reserve — nav, docs Protocol, SDK 1.0.7
WattsFlowNav, settle→secondaire, docs endpoint-watts-reserve, méthodes SDK watts* (1.0.7).
- UI flow Réserver · Inventaire · Secondaire + lien API.
- /developers/docs/endpoint-watts-reserve.
- @adrien1212balitrand/auros-protocol@1.0.7 — wattsReserve/confirm/settle/offers/secondary.
Watts Reserve étape 5 — secondaire + RWA prep
Listings secondaires à prix indicatif, intérêt non liant, lien compare_ref_id → /compare. Pas un marché réglementé.
- POST/GET /api/v1/watts/secondary (+ demo) · withdraw · interest.
- UI /green/chargeflow/secondary · table watt_secondary_listings.
- Pas d’auto-transfer CFU.
Watts Reserve étape 4 — inventaire capacité
Producteurs publient des fenêtres de capacité ; matching déterministe profil × offres. UI /green/chargeflow/inventory.
- POST/GET /api/v1/watts/offers (+ demo) · POST …/match · POST …/:id/withdraw.
- Table watt_capacity_offers.
- Pas d’auto-reserve — inventaire indicatif.
Watts Reserve étape 3 — settle / retire
POST settle à la livraison : retire la CFU liée, status settled. Pas d’auto-retire.
- POST /api/v1/watts/reserve/:id/settle (Premium) + /demo/settle.
- Champs delivery_ref / delivered volumes optionnels.
- UI demo : match → confirm → settle.
Watts Reserve étape 2 — confirm → mint CFU
POST confirm mint CFU-E/F liée à reservation_id (attributs + colonnes watt_reservations). UI demo match → confirm.
- POST /api/v1/watts/reserve/:id/confirm (Premium) + /demo/confirm.
- attributes.reservation_id sur CFU-E et CFU-F.
- Pas d’auto-mint — confirm explicite uniquement.
Watts Reserve étape 1 — reservation intents
Booking engine des watts : profil horaire × zone × carbone → match_score déterministe. Confirm = étape 2.
- POST /api/v1/watts/reserve (Premium) + /demo + GET /:id.
- UI /green/chargeflow/reserve · table watt_reservations.
- Docs docs/WATTS-RESERVE.md.
AUROS Copilot v1
Chat public /copilot + agents ops catalogue/contenu avec inbox approve/reject — pas d’auto-publish scores/CFU.
- POST /api/v1/copilot/chat — RAG ai-first, products, compare, ChargeFlow explain.
- Drafts internes avec revue humaine — pas d’auto-publish.
- Docs docs/COPILOT.md.
ChargeFlow partner connectors (Tesla / Total / OCPI)
Connecteurs sandbox+live Tesla Fleet, TotalEnergies OCPI, OCPI générique → CFU-E ; console sync ; SDK/MCP.
- GET /api/v1/chargeflow/partners · POST …/partners/sync (Premium).
- Sandbox fixtures 100 % fonctionnelles ; live avec credentials (non stockés).
- @adrien1212balitrand/auros-protocol@1.0.6 · auros-mcp@1.2.1.
- npm publish nécessite `npm login` (registry 401 sans auth).
- Pas de claim de partnership officiel constructeur.
ChargeFlow MCP tools + operator_id filter
Outils MCP list/mint/from-ocpi/get/retire ; GET /chargeflow?operator_id= ; SDK/MCP bumps.
- @adrien1212balitrand/auros-mcp@1.2.0 — chargeflow_* tools.
- @adrien1212balitrand/auros-protocol@1.0.5 — listChargeflow operator_id.
- npm publish nécessite `npm login` sur le scope (non connecté ici).
Console ChargeFlow — import OCPI/CSV
Panneau d'import JSON sur /green/chargeflow/console vers POST /from-ocpi.
- Exemple CDR + CSV, mint CFU-E, rafraîchissement de la liste.
ChargeFlow OCPI/CSV stub → CFU-E
POST /api/v1/chargeflow/from-ocpi — mappe CDRs OCPI-like et lignes CSV vers mint CFU-E (offline, max 50).
- Pas de client OCPI live — stub pour exports flottes/CPO.
- SDK createChargeflowFromOcpi · docs endpoint-chargeflow-ocpi.
ChargeFlow webhooks + console export
Événements chargeflow.unit.minted / retired, export CSV/JSON depuis la console opérateur.
- Webhooks Premium par clé API — mint E/W/F et retire (pas de demo).
- Console /green/chargeflow/console — download CSV et JSON de la liste filtrée.
ChargeFlow ops — list, console, batch, SDK 1.0.2
GET /api/v1/chargeflow, batch E/W/F, console opérateur, npm @adrien1212balitrand/auros-protocol@1.0.2.
- Liste Premium filtrée kind/status + UI /green/chargeflow/console (retire).
- POST /api/v1/chargeflow/batch · /w/batch · /f/batch (max 50, succès partiel).
- SDK listChargeflow + createChargeflow*Batch.
CFU-F flex + SDK ChargeFlow + tunnel fleets
POST /api/v1/chargeflow/f, méthodes SDK create/get/verify/retire, landing /green/chargeflow/fleets.
- CFU-F : fenêtre kW + HMAC auros-cfu-f:v1: + Watt companion.
- SDK @adrien1212balitrand/auros-protocol — ChargeFlow E/W/F.
- Tunnel commercial flottes/CPO sans claim Tesla.
ChargeFlow v0.1 — unicité, retirement & CFU-W
Anti double-count serveur, POST retire, OpenAPI ChargeFlow, et mint CFU-W (m³ + H₂O) sur la même table.
- 409 si unité active déjà présente pour (kind, clé, operator, external_ref).
- POST /api/v1/chargeflow/{id}/retire — status=retired sans re-signer le hash.
- POST /api/v1/chargeflow/w · UI /eau/chargeflow · HMAC auros-cfu-w:v1:.
AUROS ChargeFlow CFU-E v0
POST /api/v1/chargeflow — enregistre une session kWh en CFU-E (hash + HMAC + Watt), verify public et page /chargeflow/{id}.
- Standard public docs/CHARGEFLOW-STANDARD.md — off-chain only, pas de smart contract.
- Gate Protocol Premium (même SKU que attest). Demo sandbox : POST /api/v1/chargeflow/demo.
- UI pitch /green/chargeflow · docs developers endpoint-chargeflow.
Readiness Attestation API v1
POST /api/v1/attest — hash SHA-256 canonique + HMAC, vérification publique GET /api/v1/attest/verify et page /attest/{id}.
- Snapshot sans branding ni PII (score, grade, MiCA, gaps, sections).
- Vérif par id ou hash+sig (stateless).
- Signature serveur via clé dédiée (configuration interne).
Custom scoring weights & profiles
Pondérations personnalisables sur POST /api/v1/score et /score/batch — profils real_estate_fund et credit_fund (premium).
- Champs optionnels `profile` et `weights` (5 dimensions, somme 100 %).
- Réponse inclut meta.weights_applied, weights_source, weights_normalized.
- Clé demo / free : poids par défaut uniquement — custom → 403 premium_required.
Roadmap #14
White-label PDF dossier
Branding client sur les dossiers premium — logo HTTPS, couleur primaire, masquage AUROS.
- POST /api/v1/dossier — branding.company_name, logo_url, primary_color, hide_auros_branding.
- PDF généré avec en-tête client et footer « Powered by AUROS » optionnel.
Roadmap #13
GET /api/v1/benchmarks
Benchmarks sectoriels RWA — médiane APY, quartiles P25/P75 et nombre de produits par catégorie, avec repli statique curaté si le hub live est sparse.
- GET /api/v1/benchmarks — auth Bearer, paramètre requis `category` (bonds|stablecoins|real_estate|private_credit|commodities).
- Filtre optionnel `jurisdiction` (match partiel, ex. EU, US, Luxembourg).
- Métriques calculées depuis le hub `/compare` ; fallback statique si < 3 produits avec rendement positif.
- Réponse : median_apy, p25_apy, p75_apy, product_count, as_of + disclaimer standard.
Roadmap #12
MCP server for AUROS Protocol
Package @adrien1212balitrand/auros-mcp — 8 outils MCP (score, products, compare, …) pour Cursor et Claude Desktop.
- Tools : score, score_batch, products, jurisdictions, checklist, compare, regulatory_feed, status.
- Auth via env AUROS_API_KEY (clé démo auros_pk_test_demo par défaut).
- Thin wrapper sur https://getauros.com/api/v1/* — aucune route HTTP nouvelle.
- Config Cursor/Claude Desktop documentée — npx @adrien1212balitrand/auros-mcp.
Roadmap #11
Webhook replay, dead letter queue & delivery logs
Journal des livraisons webhook, retry exponentiel (5 tentatives), dead letter et endpoints replay — visible sur le dashboard développeurs.
- Table protocol_webhook_deliveries — statuts pending, delivered, failed, dead_letter.
- GET /api/v1/webhooks/:id/deliveries — liste paginée des tentatives.
- POST /api/v1/webhooks/:id/replay et POST /api/v1/webhooks/deliveries/:delivery_id/replay — relance manuelle (premium).
- Cron /api/cron/protocol-monitor étendu — retry automatique avec backoff 1m → 4h.
- Section Webhook deliveries sur /developers/dashboard (tier premium).
Roadmap #9
GET /api/v1/regulatory/feed
Feed réglementaire curaté ESMA/AMF/BaFin — 18 références MiCA, webhook `regulatory.update`, abonnements par juridiction.
- GET /api/v1/regulatory/feed — premium, filtres jurisdiction/tag/since/limit.
- POST /api/v1/regulatory/subscribe — alertes feed par juridiction + tags mica/esma/amf/bafin.
- Webhook `regulatory.update` — cron /api/cron/protocol-monitor ou trigger manuel.
- v1 = feed statique curaté ; v2 = polling live ESMA/AMF/BaFin.
Roadmap #10
POST /api/v1/score/batch
Score jusqu'à 20 actifs en un appel — succès partiel par item, quota 1 unité par batch (pas par item).
- Corps : `{ "items": [ { description | champs structurés }, … ], "record_history"?: boolean }`.
- Chaque item retourne `score_id` + résultat complet ou `{ ok: false, error }` sans faire échouer le batch.
- SDK TypeScript/Python : `client.scoreBatch()` / `score_batch()`.
- Compte comme 1 requête quota mensuel (100/mois free tier) — documenté OpenAPI et docs auth.
Roadmap #8
Python SDK on PyPI
Package `auros-protocol` v1.0.0 publié sur PyPI — client httpx typé pour score, products, jurisdictions, checklist, compare et status.
- Installation : pip install auros-protocol.
- Méthodes miroir du SDK TypeScript pour les endpoints publics v1.
- Clé démo auros_pk_test_demo documentée dans le README PyPI.
Roadmap #6
Rate limit response headers
Headers X-RateLimit-Limit, X-RateLimit-Remaining et X-RateLimit-Reset sur toutes les réponses /api/v1/* authentifiées et routes limitées par IP.
- Visibilité quota mensuel par clé (100 req/mois free, 50 demo) sans parser le corps 429.
- Burst IP (30/min) et création de clé (5/h/IP) exposent les mêmes headers avec fenêtre glissante.
- X-RateLimit-Reset : timestamp Unix — début du mois UTC suivant pour le quota clé.
Roadmap #5
POST /api/v1/compare
Comparaison side-by-side de 2–4 produits RWA — par IDs explicites ou filtres (category, yield, risk tier, jurisdiction).
- Réponse avec comparison.highlights (best/worst par métrique, logique /compare).
- SDK TypeScript/Python : client.compare().
- Auth Bearer requise ; headers protocol standard sur chaque réponse.
Roadmap #3
Postman collection v2.1
Collection Postman publique couvrant tous les endpoints AUROS Protocol v1 — import direct, variables baseUrl et apiKey.
- Fichier statique /auros-postman.json (sans auth).
- Exemples score, products, compare, jurisdictions, checklist, keys et endpoints premium.
Roadmap #2
Status page & X-Response-Time
Page statut publique /status et endpoint JSON GET /api/v1/status — probes scoring, catalogue, juridictions et stockage clés.
- Header X-Response-Time sur toutes les routes /api/v1/* (via protocolRoute).
- Payload JSON : services, version protocol, commit déployé, timestamp.
Roadmap #1
X-AUROS-Logo response header
Header X-AUROS-Logo: https://getauros.com/auros-logo.svg sur toutes les réponses API v1, OpenAPI x-logo et docs auth.
- Complète X-AUROS-Protocol-Version sur chaque réponse protocolJson.
- Référence publique pour intégrateurs et attributions UI.
Roadmap #4