You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a72a726
Browse filesBrowse the repository at this point in the historyBrowse files
-**Type Safety**: 24 strongly-typed call patterns with built-in Go model validation
49
-
-**Streaming Architecture**: Memory-efficient processing with AES-GCM chunk encryption
49
+
-**Streaming Architecture**: Memory-efficient processing with AES-GCM chunk encryption (16KB default)
50
50
51
51
## Authentication & Security
52
52
53
53
All API endpoints require:
54
54
-**PoW Challenge**: Memory-hard proof-of-work with more than 206M parameter combinations
55
55
-**License Validation**: Cryptographic license verification with tier-based access control
56
-
-**End-to-End Encryption**: AES-GCM streaming encryption with 1KB chunks
56
+
-**End-to-End Encryption**: AES-128-GCM streaming encryption with 16KB chunks
57
57
-**Forward Secrecy**: Daily server key rotation with deterministic derivation
58
58
-**Data Anonymization**: Mandatory PII/secrets masking for all AI troubleshooting requests
59
59
@@ -95,16 +95,17 @@ Before using any API endpoints, ensure you understand and comply with all applic
95
95
2.**Function Generation**: SDK creates typed functions for each endpoint
96
96
3.**Data Anonymization**: Mandatory PII/secrets masking for support services
97
97
4.**PoW Challenge**: Automatic challenge solving before each request
98
-
5.**Request Signing**: Ed25519 signature generation with installation ID
99
-
6.**Encryption**: AES-GCM encryption of request/response bodies
100
-
7.**Type Validation**: Go models ensure data integrity throughout
98
+
5.**Request Signing**: AES-CBC signature (nonce + timestamp + content length + CRC32) with installation ID XOR-masking
99
+
6.**Key Exchange**: NaCL box (Curve25519) encrypts the ephemeral session key to the server
100
+
7.**Encryption**: AES-128-GCM streaming encryption of request/response bodies (16KB chunks)
101
+
8.**Type Validation**: Go models ensure data integrity throughout
101
102
102
103
### Core Components
103
104
104
105
-**Call Patterns**: 24 function types handle different request/response scenarios
105
106
-**Data Anonymizer**: Mandatory PII/secrets masking engine with 300+ pattern recognition
106
107
-**Transport Layer**: HTTP/2 with connection pooling and custom TLS configuration
107
-
-**Cryptographic Engine**: Ed25519 + AES-GCM for signatures and encryption
108
+
-**Cryptographic Engine**: NaCL box (Curve25519) for session-key exchange + AES-128-GCM for body encryption + AES-128-CBC for PoW request signatures; Ed25519 + SHA-512 used only for package-integrity validation (`models/signature.go`)
108
109
-**PoW Solver**: Memory-hard algorithm implementation with configurable timeout
109
110
-**License Manager**: Cryptographic license validation and tier enforcement
110
111
@@ -228,29 +229,49 @@ type TicketSettings struct {
228
229
229
230
## Error Handling
230
231
231
-
All endpoints return structured error responses:
232
+
All endpoints return structured error responses. The SDK parses them into typed Go errors:
232
233
233
234
```json
234
235
{
235
236
"status": "error",
236
-
"code": "RATE_LIMIT_EXCEEDED",
237
-
"message": "Request rate limit exceeded",
238
-
"details": {
239
-
"current_usage": "exceeded",
240
-
"limit": "tier_based",
241
-
"reset_time": "2025-09-17T15:30:00Z"
242
-
}
237
+
"code": "TooManyRequestsRPM"
243
238
}
244
239
```
245
240
246
-
Common error codes:
247
-
-`INVALID_LICENSE`: License validation failed
248
-
-`POW_REQUIRED`: Proof-of-work challenge not solved
|`TooManyRequestsRPH`|`*sdk.RateLimitError` (RPH) | No | Per-hour window — too long to auto-retry |
253
+
|`TooManyRequestsRPD`|`*sdk.RateLimitError` (RPD) | No | Per-day window — too long to auto-retry |
254
+
|`QuotaBlocked`|`*sdk.QuotaError` (Blocked) | Never | Endpoint unavailable for this license tier |
255
+
|`QuotaExceededDaily`|`*sdk.QuotaError` (Daily) | No (Retry-After) | Daily quota exhausted |
256
+
|`QuotaExceededMonthly`|`*sdk.QuotaError` (Monthly) | No (Retry-After) | Monthly quota exhausted |
257
+
258
+
### Retry-After Header
259
+
260
+
Rate-limit and quota responses carry a `Retry-After: <seconds>` header. The SDK embeds it in
261
+
`*RateLimitError.RetryAfter` and `*QuotaError.RetryAfter`. Use `sdk.RetryAfterOf(err)` to read it
262
+
from any error without type-asserting:
252
263
253
-
## SDK Integration
264
+
```go
265
+
ifwait:= sdk.RetryAfterOf(err); wait > 0 {
266
+
time.Sleep(wait) // server-suggested cooldown
267
+
}
268
+
```
269
+
270
+
`*RateLimitError` wraps temporary rate-limit sentinels (General/RPM are auto-retried by the SDK;
271
+
RPH/RPD are surfaced to the caller). `*QuotaError` wraps license-tier quota sentinels — all quota
272
+
errors are fatal and never auto-retried.
273
+
274
+
### SDK Integration
254
275
255
276
Use the VXControl Cloud SDK for seamless integration with the platform:
256
277
@@ -293,6 +314,29 @@ err := sdk.Build(configs,
293
314
)
294
315
```
295
316
317
+
### Endpoint Health Check
318
+
319
+
Use `sdk.Check()` to probe endpoint reachability and inspect allowed RPM **without making an actual API call**. Useful at startup or in health-check routines:
0 commit comments