{"estate":"cmykcloud","self":"https://cmykcloud.com/.well-known/estate","apps":[{"slug":"accounts","name":"Accounts","description":"One sign-in for every app, your profile, and the apps and OAuth clients admin.","base":"https://accounts.cmykcloud.com","documents":[{"name":"openid-configuration","path":"/.well-known/openid-configuration","url":"https://accounts.cmykcloud.com/.well-known/openid-configuration","description":"OpenID Provider metadata: the authorization, token, userinfo and end-session endpoints, supported scopes, and the JWKS location.","specification":"https://openid.net/specs/openid-connect-discovery-1_0.html"},{"name":"oauth-authorization-server","path":"/.well-known/oauth-authorization-server","url":"https://accounts.cmykcloud.com/.well-known/oauth-authorization-server","description":"OAuth 2.0 Authorization Server metadata. The same issuer described in OAuth’s own vocabulary, for clients that look here rather than at the OpenID document.","specification":"https://www.rfc-editor.org/rfc/rfc8414"},{"name":"jwks","path":"/.well-known/jwks","url":"https://accounts.cmykcloud.com/.well-known/jwks","description":"The public keys that verify tokens this issuer signed. Rotating keys appear here before they are used, so a verifier that refetches keeps working across a rotation.","specification":"https://www.rfc-editor.org/rfc/rfc7517"},{"name":"products","path":"/.well-known/products","url":"https://accounts.cmykcloud.com/.well-known/products","description":"The public product directory: apps an organisation can discover and request. Display fields only — never platform apps, grant-only products, client fields or metrics."},{"name":"capabilities","path":"/.well-known/capabilities","url":"https://accounts.cmykcloud.com/.well-known/capabilities","description":"The accounts capabilities manifest: every served RPC action with its input and output schema, the sign-in and sign-up pages, the events it publishes, and the app, feature and permission-code catalogue shapes. No user, session, credential, token or client table is catalogued. The same document answers on system.accounts.wellknown.capabilities.v1."}]},{"slug":"orgs","name":"Organizations","description":"Organisations, members, roles, branch and department structure, and join links.","base":"https://orgs.cmykcloud.com","documents":[{"name":"org-basics","path":"/.well-known/org-basics","url":"https://orgs.cmykcloud.com/.well-known/org-basics","description":"Public facts about the organisation that owns a custom domain. Rate limited, and it answers for public organisations only.","parameters":[{"name":"domain","required":true,"description":"The custom domain to look up. Without it the endpoint answers 400; for a domain no public organisation owns, 404."}]},{"name":"capabilities","path":"/.well-known/capabilities","url":"https://orgs.cmykcloud.com/.well-known/capabilities","description":"The orgs capabilities manifest: every served RPC action with its input and output schema, the public join-link page, the events it publishes, and the organisation, branch, node, group, team and role shapes with owner, creator, metadata and external-reference fields excluded. Membership rows are not catalogued. The same document answers on system.orgs.wellknown.capabilities.v1."}]},{"slug":"storage","name":"Storage","description":"Files for an org or a person, with quotas that warn before they block uploads.","base":"https://storage.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://storage.cmykcloud.com/.well-known/capabilities","description":"The storage capabilities manifest: every served RPC action with its input and output schema, the public share-link route, and the file and folder shapes it exposes with object keys and uploader ids excluded. The same document answers on system.storage.wellknown.capabilities.v1."}]},{"slug":"people","name":"People","description":"Everyone an organisation tracks — staff and external contacts alike.","base":"https://people.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://people.cmykcloud.com/.well-known/capabilities","description":"The people capabilities manifest: every served RPC action with its input and output schema, the events it publishes, and the person, tag and list shapes. Names, birthdays, contact points, addresses, notes, attachments and guardian invites are never catalogued. The same document answers on system.people.wellknown.capabilities.v1."}]},{"slug":"forms","name":"Forms","description":"Forms and responses, each form public, authenticated or members-only.","base":"https://forms.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://forms.cmykcloud.com/.well-known/capabilities","description":"The forms capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.forms.wellknown.capabilities.v1."}]},{"slug":"calendar","name":"Calendar","description":"Shared calendars, events, holidays and working days — with attendees and .ics import/export.","base":"https://calendar.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://calendar.cmykcloud.com/.well-known/capabilities","description":"The calendar capabilities manifest: every served RPC action with its input and output schema, the public calendar and feed routes, and the calendar, event and working-week shapes it exposes with share tokens and owner ids excluded. The same document answers on system.calendar.wellknown.capabilities.v1."}]},{"slug":"notifier","name":"Notifier","description":"Email, SMS and voice campaigns, with per-org balances and an itemised ledger.","base":"https://notifier.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://notifier.cmykcloud.com/.well-known/capabilities","description":"The notifier capabilities manifest: every served RPC action with its input and output schema, the public routes and inbound webhooks, the events it publishes, and the campaign, message and workflow shapes it exposes with tenant, recipient and provider columns excluded. The same document answers on system.notifier.wellknown.capabilities.v1."}]},{"slug":"web","name":"Web","description":"The root domain: marketing, docs, the app directory and the public forms.","base":"https://cmykcloud.com","documents":[{"name":"estate","path":"/.well-known/estate","url":"https://cmykcloud.com/.well-known/estate","description":"The machine-readable index of the well-known documents this estate advertises, grouped by the app that serves it. Start here to find the rest. A product the registry hides, such as a superadmin-only app, still serves its documents at its own address but is not listed."},{"name":"security.txt","path":"/.well-known/security.txt","url":"https://cmykcloud.com/.well-known/security.txt","description":"Where to report a vulnerability in any cmykcloud app, and the contact that answers.","specification":"https://www.rfc-editor.org/rfc/rfc9116"}]},{"slug":"audit","name":"Audit","description":"The ecosystem-wide, tamper-evident record of who changed what, and when.","base":"https://audit.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://audit.cmykcloud.com/.well-known/capabilities","description":"The audit capabilities manifest: every served RPC action with its input and output schema and the audit-event shape it exposes with actor, network and chain columns excluded. The same document answers on system.audit.wellknown.capabilities.v1."}]},{"slug":"adms","name":"ADMS","description":"Attendance devices on the wall — enrolment, punches and device health.","base":"https://adms.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://adms.cmykcloud.com/.well-known/capabilities","description":"The adms capabilities manifest: every served RPC action with its input and output schema, the device protocols it accepts, the events it publishes, and the device and punch shapes it exposes with credentials, addresses and raw device lines excluded. The same document answers on system.adms.wellknown.capabilities.v1."}]},{"slug":"attendance","name":"Attendance","description":"The attendance engine — who was present, late, absent or on leave, judged against configurable policies, with overtime and notification rules.","base":"https://attendance.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://attendance.cmykcloud.com/.well-known/capabilities","description":"The attendance capabilities manifest: its own RPC action with its input and output schema (the reserved marks contract has no caller and is not advertised), the day-judged event, and the policy, group, leave-type and day-result shapes with policy bodies, raw evidence, reasons and acting user ids excluded. The same document answers on system.attendance.wellknown.capabilities.v1."}]},{"slug":"school","name":"School","description":"School management — academic years, classes and sections, enrolment and admissions, student and staff records, guardians and routines.","base":"https://school.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://school.cmykcloud.com/.well-known/capabilities","description":"The school capabilities manifest: every served RPC action with its input and output schema, the events it publishes, and the academic-year, class, group, subject, classroom, section, subject-offering, period and exam shapes. Student, staff, guardian, marks and fee records are never catalogued. The same document answers on system.school.wellknown.capabilities.v1."}]},{"slug":"teacher","name":"Teacher","description":"The teacher portal — your classes, your routine and the rosters of the sections you teach.","base":"https://teacher.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://teacher.cmykcloud.com/.well-known/capabilities","description":"The teacher capabilities manifest: its own RPC action with its input and output schema. The portal owns no table and publishes no event — what a teacher sees is school’s answer, asked afresh on every request. The same document answers on system.teacher.wellknown.capabilities.v1."}]},{"slug":"student","name":"Student","description":"The student portal — your class, your section and your week at school.","base":"https://student.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://student.cmykcloud.com/.well-known/capabilities","description":"The student capabilities manifest: its own RPC action with its input and output schema. The portal owns no table and publishes no event — what a student sees is school’s answer, asked afresh on every request. The same document answers on system.student.wellknown.capabilities.v1."}]},{"slug":"guardian","name":"Guardian","description":"The guardian portal — your children’s classes and weeks at every school that invited you.","base":"https://guardian.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://guardian.cmykcloud.com/.well-known/capabilities","description":"The guardian capabilities manifest: its own RPC action with its input and output schema, and the public invite route a school hands a guardian. The portal owns no table and publishes no event. The same document answers on system.guardian.wellknown.capabilities.v1."}]},{"slug":"billing","name":"Billing","description":"Your organisation’s wallet, usage, VAT invoices and payments for every cmykcloud app.","base":"https://billing.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://billing.cmykcloud.com/.well-known/capabilities","description":"The billing capabilities manifest: its own RPC action with its input and output schema (the reserved wallet contracts have no caller and are not advertised), the product and meter model shapes, and its events, billing.invoice.finalized among them. No price, contract, wallet, hold, invoice, payment or ledger table is catalogued as a model. The same document answers on system.billing.wellknown.capabilities.v1."}]},{"slug":"rules","name":"Rules","description":"Your organisation’s decision tables — versioned, tested and published, then evaluated for every app that asks.","base":"https://rules.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://rules.cmykcloud.com/.well-known/capabilities","description":"The rules capabilities manifest: every served RPC action with its input and output schema, and the decision and decision-version shapes it exposes with the owning organisation, the authoring user and the decision content excluded. The same document answers on system.rules.wellknown.capabilities.v1."}]},{"slug":"mail","name":"Mail","description":"Your personal mailbox and your organisations’ shared addresses — threads, labels, filters and attachments.","base":"https://mail.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://mail.cmykcloud.com/.well-known/capabilities","description":"The mail capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.mail.wellknown.capabilities.v1."}]},{"slug":"support","name":"Support","description":"Help when you need it — open a ticket, follow every reply, and hear back by email.","base":"https://support.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://support.cmykcloud.com/.well-known/capabilities","description":"The support capabilities manifest: every served RPC action with its input and output schema, the public routes, and the row shapes it exposes with sensitive columns excluded. The same document answers on system.support.wellknown.capabilities.v1."}]},{"slug":"my","name":"My Portal","description":"Your portal — your profile, your classes or students, and your children’s school life in one place.","base":"https://my.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://my.cmykcloud.com/.well-known/capabilities","description":"The my capabilities manifest: its own RPC action with its input and output schema. The portal owns no table yet and publishes no event — what you see is accounts, people and school answers, asked afresh on every request. The same document answers on system.my.wellknown.capabilities.v1."}]},{"slug":"website-builder","name":"Website builder","description":"Every org’s public website — pages, notices, news, gallery and settings, managed per site.","base":"https://builder.cmykcloud.com","documents":[{"name":"capabilities","path":"/.well-known/capabilities","url":"https://builder.cmykcloud.com/.well-known/capabilities","description":"The website-builder capabilities manifest: its own RPC action with its input and output schema. The builder owns no table and publishes no event — what it renders is managed per site, asked afresh on every request. The same document answers on system.website-builder.wellknown.capabilities.v1."}]}]}