Knowledge base
OpenAPI and integrator contract
Curated NAVCOM-ID OpenAPI 3: GET https://navcom.ai/oauth/openapi.json That document is the IdP contract: discovery, JWKS, authorize, token, userinfo, revoke, introspect, GET /oauth/v1/me, GET /oauth/v1/me/orgs, consent-gated resolve APIs, public avatar redirect, public app directory, and RP token inventory/revoke. Component schemas are pruned to those referenced by integrator paths. It does not include portal HTML, staff tools, login/OTP/password-reset, or the browser-extension snapshot APIs. Staff-only portal spec (logged-in staff): /openapi.json, Swagger UI /api-docs, ReDoc /api-redoc. Unauthenticated requests get 404. Do not publish that document. OIDC discovery also advertises the curated spec in the openapi field. Token auth methods: client_secret_post, client_secret_basic, private_key_jwt, none (public PKCE). Refresh tokens rotate. Privacy rules RPs must honor: - Hidden or redacted org slots are placeholders, not names. - discord_id is only present with the discord scope. - Email is never a synthetic @users.navcom.local address. - There is no client_credentials grant. Do not bulk-harvest identity. RSI avatars and public citizen cards: use SENTRY-API GET https://sentry.wildknightsquadron.com/api/v1/citizens/{handle}/profile/avatar_url NAVCOM-ID GET /oauth/v1/citizens/{handle}/avatar is public, no token, rate limited. It redirects to that URL and does not keep its own copy of SENTRY data. Identity resolve (authorization_code tokens only): GET /oauth/v1/me — scoped profile of the token subject GET /oauth/v1/resolve/rsi/{handle} — public SENTRY RSI card (never Discord) GET /oauth/v1/resolve/discord/{id} — RSI only if rsi+discord scopes AND the account discover toggle is on (default off) GET /oauth/v1/resolve/rsi/{handle}/discord — reverse lookup, same preference