PARTNER CONTRACT / SANDBOX

Give your agent an answer—not a face.

A deterministic capability firewall sits between retailer intent and YouCam execution. The LLM may ask. It never chooses provider parameters or approves consent.

Run the contract

THE PAYLOAD DIFF

Push a request. Receive the minimum.

01 / PARTNER REQUESTCANONICALIZED
POST /v1/partner/requests
{
  "subjectId": "11111111-1111-4111-8111-111111111111",
  "purpose": "Preview Jacket 142 once",
  "expiresAt": "2026-08-16T23:59:00.000Z",
  "request": {
    "capability": "VTO_RENDER_ONLY",
    "input": {
      "sku": "JACKET-142",
      "assetSha256": "b9803b0908340e9b70f24d78d0fa8e3c82aa6cd7a1469e925c63db4ae97971e4",
      "category": "upper_body"
    }
  }
}
02 / PARTNER DISCLOSUREALLOWLISTED
GET /v1/partner/requests/:id/disclosure · 200 OK
{
  "requestId": "018f…",
  "status": "COMPLETED",
  "disclosure": { "tryOnCompleted": true }
}
ALWAYS ABSENTsource_imagerender_urlprovider_task_idskin_scoresfile_id

ONE DURABLE CONTROL PLANE

A seven-step ceremony.

  1. 01Authenticate partner

    Hash-scoped API key, actor binding, and registered origin.

  2. 02Push request

    Purpose, capability, catalog digest, expiry, unit quote.

  3. 03Ask the person

    Top-level MirrorKey consent with recent user presence.

  4. 04Consume once

    Atomic transition prevents replay and parallel double use.

  5. 05Execute privately

    The browser unlocks the IndexedDB VTO Key, records a client-reported digest/size, and live mode PUTs the same bytes to one exact signed YouCam origin. Mock mode sends none.

  6. 06Project output

    Strict schema discards every field the requester did not receive.

  7. 07Clean + evidence

    Durable deletion retry produces subject-only signed confirmation or explicit unverified-absence evidence.

LIVE MODE PRECONDITIONFAIL CLOSED

No credential? No worker? No live button.

The public web build defaults to a visibly synthetic local fixture. Live startup is rejected unless all secrets, allowed origins, durable database state, signed webhooks, field encryption, and workers are configured. Browser upload also requires one exact YouCam upload origin in CSP plus verified provider-bucket CORS. The control plane never substitutes a mock result for a live failure; the web experience may open a separately labeled local fixture.

YOUCAM_MODE=live
YOUCAM_API_KEY=••••••••
YOUCAM_WEBHOOK_SECRET=whsec_••••
DATABASE_PATH=/data/mirrorkey.db
DATA_ENCRYPTION_KEY_B64=••••••••
RECEIPT_SIGNING_PRIVATE_KEY_B64=••••••••
DURABLE_WORKER_ENABLED=true
MIRRORKEY_DEMO_YOUCAM_UPLOAD_ORIGIN=https://yce-….amazonaws.com
DEMOSAFE TO EXPLORELIVEDISABLED UNTIL GATES PASS