Surfil
// api platform

A small, signed, versioned edge API

The Surfil edge is a compact REST surface - entitlement, devices, receipts, credits and audit - with signed batches, idempotency keys, and outputs you can verify offline. Read the contract before you write a line.

~/acme/api · the edge API
$ curl -H "authorization: Bearer …" api.surfil.com/v1/receipts
✓ 200 · signed · epoch 7 · Ed25519
$ surfil verify receipt.md
✓ VALID (offline · no account)
# every response is metadata + a signature, never source
Endpoints

Five groups, one signed surface

Each endpoint returns metadata and a signature, never source. The set is deliberately small - every route maps to a real product concept.

Entitlement

What a device is licensed for. The edge checks entitlement before any metered operation runs.

Devices

Enroll, list and revoke devices; each holds its own Ed25519 signing identity, revocable fail-closed.

Receipts

Fetch and verify the signed value-outputs - savings, benchmarks, attestations - your operations produced.

Credits

Balance and atomic, idempotent decrements. Order: window credits, then monthly, then paid, then granted.

Audit

The append-only, hash-chained record of admin and metered actions, exportable for independent review.

How requests work

Versioned, signed, idempotent

REST over HTTPS

Plain, versioned REST/HTTPS endpoints - no bespoke SDK required to call them, though one is on the way.

Signed batches

The device speaks to the edge over mTLS with signed metadata batches - event data, never raw source.

Idempotent by key

Credit decrements carry idempotency keys in D1, so a retried or replayed request never double-charges.

OpenAPI-documented

Endpoints are versioned and OpenAPI-described, so an evaluator can read the contract before writing code.

Auth

No passwords in the path

Devices authorize with the RFC 8628 device flow and carry their own signing identity; enterprises bring their own IdP.

Device flow (RFC 8628)

Developers authorize a device with the standard device flow - no password is ever typed into a form.

Ed25519 device tokens

Each device carries its own signing identity; revocation is enforced fail-closed at the edge, immediately.

OIDC SSO

Enterprise sign-in flows through your identity provider, with sessions and revocations traced to directory identity.

ⓘ This page is the shape of the API. The full per-endpoint reference and the OpenAPI spec grow in the docs as each endpoint stabilizes - the contract is versioned, so evaluators can track it.

Read the contract, then talk to us

The endpoints, auth model and signing are documented and versioned. Bring an integration question or an architecture review - both start from the same signed surface.