# Hermes API Server run card

Never paste `API_SERVER_KEY` or an Authorization header value into this file.

## Ownership and scope

- API owner / backup owner:
- Calling service identity:
- Hermes profile ID and HERMES_HOME:
- Terminal backend and absolute cwd:
- Allowed Toolsets / Skills:
- Disallowed side effects:
- Approval owner:

## Network and credentials

- Host / port:
- Loopback, private network, or public exposure:
- Key storage location and rotation date; no value:
- CORS disabled or exact origins:
- TLS / reverse proxy owner if non-loopback:
- `max_concurrent_runs`:

## Contract discovered at runtime

- `/v1/capabilities` capture time:
- Advertised model alias:
- Chat / Responses / Runs features:
- Session key header support:
- Effective API toolsets:
- Unsupported input types:

## Evidence

- Missing bearer HTTP status:
- Wrong bearer HTTP status:
- Liveness result:
- Detailed readiness status and failed checks:
- Chat response ID / model / usage:
- Responses chain IDs and delete result:
- Run ID / terminal state / usage:
- Idempotency replay header and same run ID:
- Changed-payload conflict HTTP 409:
- Stop request and final cancelled evidence:
- Allowed / denied CORS origin evidence:
- Concurrency HTTP 429 evidence:

## Shutdown

- Calling system disabled at:
- Gateway stopped at:
- Port-close evidence:
- Key revoked/rotated at:
- Export archive SHA-256:
- Test profile deleted and default restored:
