# CertaRail generated API collections

These artifacts are generated from canonical api/openapi/certarail.v1.yaml at API version 0.29.0. Do not edit generated collection files by hand.

Source SHA-256: b99b1fed7c86e352cb1ee818ba5ce8e74200dc70e7a6ab1ea25258b3795e633c

## Downloads

- certrail.sandbox.postman.v2.1.json — Postman Collection v2.1 with a numbered guided lifecycle and the full canonical API catalog.
- certrail.local.postman_environment.json — secret-safe Postman LOCAL environment.
- certrail.sandbox.bruno.opencollection.yml — bundled OpenCollection 1.0.0 YAML for Bruno.
- certrail.sandbox.http — generated editor/CLI request catalog for every canonical operation.

## Run the guided lifecycle

1. Import the Postman collection plus environment, or import the bundled Bruno OpenCollection.
2. Select Local, then set sandbox_credential in local secret storage and credential_expires_at to its ISO-8601 expiry. The collection does not issue credentials.
3. Confirm tenant_id matches the tenant bound to that credential.
4. Run Guided sandbox lifecycle from 01 through 12 in order.
5. Inspect the decision, exact replay, expected 409 changed-payload conflict, evidence lookup, signed webhook test, verifier result, and inbox evidence.
6. Keep both cleanup requests enabled. They revoke the mutable Webhook Inbox and checkout fixture created by the run.

The collection does not persist or log the one-time checkout session token or webhook signing secret. Decision and evidence records are immutable and are not deleted by cleanup. LOCAL sandbox observations do not prove provider calls, money or asset movement, custody, or Production readiness.
