Publication readiness

The current docs can serve as a baseline reference with route labels. Expanded external docs, SDKs, and production recipes need release evidence before they are promoted.

Current verdict

Baseline endpoint rendering can proceed. External-quality claims, SDK readiness, live side-effect recipes, and broad module coverage need publication review.

Who reviews publication readiness

ReviewerDecision
Product/API ownerConfirms the endpoint should exist as a public product contract and belongs in docs, SDKs, or onboarding flows.
Security and complianceChecks PHI exposure, authentication, authorization, tenant isolation, auditability, credentials, and sensitive examples.
Module engineering ownerConfirms the implementation matches the documented behavior, status codes, side effects, retries, and external-service assumptions.
Developer experience/docs ownerConfirms examples, Copy for LLM content, endpoint grouping, SDK inclusion, and try-out access are clear and safe for external users.

Gates

GateNameBlocks
E1Tenancy and actor contractQuickstart, examples, wrong-org guidance, audit/correlation docs
E2Side-effect policyLive, sandbox, queue, dry-run, and production recipe claims
E3Async and idempotency202, retry, polling, cancellation, and SDK retry helpers
E4Files and artifactsUploads, downloads, PDFs, reports, transcripts, EDI, and generated artifacts
E5PHI-safe DTOs and reportingBroad read/detail/report/export/analytics docs
E6Route registryPublic reference grouping, compatibility routes, try-out UX, and SDK inclusion
E7Credentials and webhooksCredential provisioning, callbacks, webhook subscriptions, and vendor webhook docs
E8Identifier policyCross-module workflow docs and SDK model examples
E9Release evidenceExpanded external docs, SDKs, and production readiness claims

Readiness by docs surface

SurfaceCurrentRequired
Generated OpenAPI JSON/YAMLBaseline source onlyRoute class metadata, reusable components, standard headers, examples checked for sensitive data, and fresh release evidence.
Scalar reference and endpoint pagesLimited baselineVisible route status, auth, side effects, async/idempotency, file policy, examples, and evidence per route.
QuickstartNeeds publication reviewA classified safe first endpoint with validated synthetic request and response examples.
Workflow guidesInternal draft onlyPlatform primitive links, endpoint status labels, and no live side-effect overclaims.
SDKsNeeds publication reviewRoute registry, reusable OpenAPI components, validated fixtures, release checks, and excluded unsafe routes.

Release evidence required

EvidencePurpose
Route registry diffClassifies every generated, compatibility, guest, worker, webhook, legacy, private, or internal route.
Fresh generated artifactsProves docs, endpoint pages, and OpenAPI came from the same release workspace.
wasp buildCatches Wasp generated-type and entity-list failures that Jest can miss.
HTTP contract testsCovers API-key tenancy, wrong-org behavior, safe errors, redaction, file ownership, idempotency, and webhook replay where applicable.
No-sensitive-data checksScans docs, examples, fixtures, snapshots, logs, and OpenAPI for PHI, secrets, raw payloads, storage keys, and signed URLs.
Known exception manifestRecords skipped routes, compatibility behavior, and approved publication exceptions.

Blocked claims

ClaimReason
SDK-ready public APIReusable OpenAPI components, route registry, examples, and release evidence are incomplete.
Production live execution recipesQueue-only, validate-only, dry-run, simulated, local, and metadata-only behavior must remain labeled.
Public file or artifact retrievalFile content class, scanning, retention, legal hold, ownership, and URL policy are unresolved.
Credential or webhook setupCredential lifecycle, masking, rotation, signing, replay, retry, and audit policy are not published.
Universal Idempotency-Key or rate-limit headersThe current OpenAPI baseline does not declare those global headers.
Stable tenant identifiers in responsesThe public organizationId/meta.organizationId response policy remains unresolved.