{"trustCenter": "FedRAMP 20x Class A certification data", "authentication": {"type": "OAuth2 bearer token (AWS Cognito, GovCloud)", "grant": "client_credentials (machine-to-machine)", "issuer": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_3daN7M624", "requiredScope": "alira-trust-center/certification-data.read", "header": "Authorization: Bearer <access_token>", "enforcement": "enforced", "localFakeIssuer": false, "note": "Access is provisioned as a Cognito app client per agency. Tokens are obtained directly from Cognito without contacting us, so sharing is uninterrupted per CDS-TRC-USH."}, "browserSignIn": {"domain": "sw-alira-trust.auth.us-east-1.amazoncognito.com", "clientId": "2h6ledqdlntapd0nn85bo72dl3", "redirectUri": "https://trust.skywarditsolutions.com/", "scopes": ["openid", "alira-trust-center/certification-data.read"]}, "public": ["/", "/api/fedramp/package-overview.json", "/api/meta", "/api/public", "/index.html"], "endpoints": [{"path": "/api/meta", "public": true, "returns": "this document"}, {"path": "/api/public", "public": true, "rule": "CDS-CSO-PUB", "returns": "the sixteen publicly-required items, and which of them are not published yet"}, {"path": "/api/fedramp/package-overview.json", "public": true, "rule": "CPO-CSO-OVR", "schema": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json"}, {"path": "/api/fedramp/security-decision-record.json", "public": false, "rule": "SDR-CSO-FRR", "schema": "https://fedramp.gov/schemas/fedramp-security-decision-record-schema-2026-06-24.json"}, {"path": "/api/fedramp/ongoing-certification-report.json", "public": false, "rule": "CCM-OCR-AVL", "schema": "https://fedramp.gov/schemas/fedramp-ongoing-certification-report-schema-2026-06-24.json"}, {"path": "/api/overview", "public": false, "returns": "all rules with status, grouped by family"}, {"path": "/api/materials", "public": false, "rule": "FRC-CLA-EAM", "returns": "the five external assessment materials the rule names, and a link to each one provided"}, {"path": "/materials/{materialId}", "public": false, "rule": "FRC-CLA-EAM", "returns": "the material itself, for entries explicitly marked servable. Every download is recorded in the recipient register before the bytes are sent."}, {"path": "/api/recipient-register", "public": false, "returns": "who has received each served document. Requires the inventory scope."}, {"path": "/api/rule/{ruleId}", "public": false, "returns": "one rule with its controls and evidence"}, {"path": "/api/control/{ruleId}/{controlId}", "public": false, "returns": "NIST requirement, fetcher runs, evidence list"}, {"path": "/api/file?path={repoRelativePath}", "public": false, "returns": "one evidence JSON, parsed"}, {"path": "/evidence/{repoRelativePath}", "public": false, "returns": "one evidence artifact, raw"}, {"path": "/api/access-inventory", "public": false, "rule": "CDS-TRC-AAI", "returns": "who has accessed certification data", "requiresScope": "alira-trust-center/access-inventory.read"}], "humanReadable": "/", "rules": {"CDS-TRC-PAC": "documented programmatic access \u2014 this document", "CDS-TRC-USH": "uninterrupted sharing \u2014 tokens, not approvals", "CDS-TRC-ACL": "access logging \u2014 every request recorded", "CDS-TRC-AAI": "access inventory \u2014 /api/access-inventory", "CDS-CSO-PUB": "public data \u2014 see `public` above"}}