POST /api/contracts/simulate
C3 (2026-06-13): accept a machine API key (Bearer zsm_*) as well as a session, so a CI pipeline can lint → simulate → deploy with one credential.
The inline dry-run only uses the caller zid as a created_by fallback; the
| Method | POST |
| Path | /api/contracts/simulate |
| Feature area | Contracts |
| Tag | Contracts |
| Auth | machine key — Authorization: Bearer $ZEQ_KEY |
| Tier | authenticated (machine-control) |
Parameters
This operation publishes no path, query or header parameters.
Request body
Optional. Content type: application/json.
The node publishes this body as a free-form JSON object — no field schema is exposed in openapi.json.
Send the fields the summary above describes; the endpoint validates them and refuses rather than guessing.
Responses
| Status | Meaning |
|---|---|
200 | OK |
400 | Bad request — a parameter or body field is missing or malformed |
401 | Missing or invalid credentials |
403 | Forbidden — authenticated, but not permitted for this resource |
404 | Not found |
400 body
| Field | Type | Required | Description |
|---|---|---|---|
ok | boolean — one of false | yes | — |
error | string | no | Human-readable message. |
code | string | no | Stable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED. |
401 body
| Field | Type | Required | Description |
|---|---|---|---|
ok | boolean — one of false | yes | — |
error | string | no | Human-readable message. |
code | string | no | Stable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED. |
403 body
| Field | Type | Required | Description |
|---|---|---|---|
ok | boolean — one of false | yes | — |
error | string | no | Human-readable message. |
code | string | no | Stable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED. |
404 body
| Field | Type | Required | Description |
|---|---|---|---|
ok | boolean — one of false | yes | — |
error | string | no | Human-readable message. |
code | string | no | Stable machine-readable code, e.g. ADMIN_REQUIRED, INVALID_ZID, ZID_NOT_LINKED. |
Call it
curl -sS -X POST https://zeq.me/api/contracts/simulate \
-H "Authorization: Bearer $ZEQ_KEY" \
-H "Content-Type: application/json" \
-d '{}'
Needs a machine key. Mint one:
curl -sS -X POST https://zeq.me/api/demo-key/mint, then spin up your machine.
Generated from the live OpenAPI description (https://zeq.me/openapi.json, spec version 1.287.0) by scripts/generate-reference.mjs. Do not edit — this file is rewritten on every run.