{
  "schema": "docsloth-registry-publish/1",
  "origin": "https://registry.docsloth.dev",
  "generated_at": "2026-10-05T06:04:50.829Z",
  "contract_version": "1",
  "package_format": {
    "manifest": "component-package.json",
    "kinds": [
      "block",
      "theme",
      "adapter",
      "plugin"
    ],
    "plugin_note": "kind: plugin is refused until a host sandbox with explicit capability grants exists."
  },
  "http": {
    "method": "POST",
    "path": "/v1/packages",
    "auth": "Authorization: Bearer <token> (from --token or DOCSLOTH_TOKEN); the token is never stored in the manifest, the registry or stdout.",
    "body": {
      "manifest": "the package manifest",
      "files": "{ \"<path>\": \"<base64>\" }"
    },
    "success": "2xx { ok: true, digest: \"sha256:…\", unchanged: true|false }",
    "conflict": "409 (or any non-2xx) refuses a name+version republished with different bytes (DSL1705); an identical republish is a no-op."
  },
  "directory_registry": {
    "command": "docsloth component publish --dir <package> --registry <dir>",
    "output": "index.json + packages/<name>/<version>/{manifest.json,files/…}"
  },
  "catalog_entries": 57,
  "static_api": {
    "index": "https://registry.docsloth.dev/api/v1/index.json",
    "search": "https://registry.docsloth.dev/api/v1/search.json",
    "versions": "https://registry.docsloth.dev/api/v1/versions.json"
  },
  "notes": [
    "This site is static: /api/v1/publish.json documents the contract; it does not accept publishes.",
    "Publishing auth, the hosted write path and the custom domain are cloud-side (owner / registry team), not generated here.",
    "The catalog these endpoints serve is packages/contracts/component-catalog.json; there is no second database."
  ]
}
