Skip to main content

POST /api/zsp/unprotect

AU2: auth-gated like protect.

The zid used for the temporal HMAC stays body→env.zid resolution (backward compat — old envelopes were stamped with the zid they carry; forcing the session zid here would break them).

MethodPOST
Path/api/zsp/unprotect
Feature areaZSP spectral protect
TagOther
Authmachine key — Authorization: Bearer $ZEQ_KEY
Tierauthenticated (machine-control)

Parameters

This operation publishes no path, query or header parameters.

Request body

Optional. Content type: application/json.

The node publishes this body as a free-form JSON object — no field schema is exposed in openapi.json. Send the fields the summary above describes; the endpoint validates them and refuses rather than guessing.

Responses

StatusMeaning
200OK
400Bad request — a parameter or body field is missing or malformed
401Missing or invalid credentials
500Server error

400 body

FieldTypeRequiredDescription
okboolean — one of falseyes
errorstringnoHuman-readable message.
codestringnoStable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED.

401 body

FieldTypeRequiredDescription
okboolean — one of falseyes
errorstringnoHuman-readable message.
codestringnoStable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED.

500 body

FieldTypeRequiredDescription
okboolean — one of falseyes
errorstringnoHuman-readable message.
codestringnoStable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED.

Call it

curl -sS -X POST https://zeq.me/api/zsp/unprotect \
-H "Authorization: Bearer $ZEQ_KEY" \
-H "Content-Type: application/json" \
-d '{}'

Needs a machine key. Mint one: curl -sS -X POST https://zeq.me/api/demo-key/mint, then spin up your machine.


Generated from the live OpenAPI description (https://zeq.me/openapi.json, spec version 1.287.0) by scripts/generate-reference.mjs. Do not edit — this file is rewritten on every run.