Enterprise & Teams
APIMaster Integration Workbench is a browser-local workbench today. Current local controls, explicit outbound boundaries and future collaboration architecture are shown separately; plan packaging never promotes a roadmap capability.
Pilot scope is owner-approved, but the APIMaster sales mailbox is UNVERIFIED/HOLD and the public mail action remains disabled until delivery is proved.
Local product, scoped assurance, explicit release holds
Availability describes proven delivery only. Pricing copy never enables a capability, creates an account, starts checkout, or grants a production licence.
- Available browser-local
Community
Individual API designers
Free local workspace
- • Import and inspect API contracts
- • Local validation and workspace evidence
Browser-owned workspace; no hosted account or background service is implied.
- Available browser-local
Developer
Engineers comparing release candidates
Free beta evaluation
- • ContractRadar comparison
- • Local impact, policy, and evidence workflow
Browser-owned workspace; no hosted account or background service is implied.
- Evaluation; annual licence proposal
ContractRadar Team Local
Teams running a supported local release gate
Annual local licence — quote required
- • Shared release-decision semantics
- • Local runner and CI evidence formats
Package and container registry publication, provenance, and production licence custody remain externally held.
UNVERIFIED/HOLD: sales@apimaster.dev is the intended APIMaster-domain sales address, but inbound/outbound delivery, ownership and staffing have not been proved. The application does not expose a mailto action or response-time promise.
- Requestable scoped pilot
Contract Release Assurance Pilot
Teams validating 10–50 contracts
14 days or 2–4 weeks — custom proposal
- • Scoped inventory, baseline, diff, and impact evidence
- • Policy/CI gate, release decision bundle, and remediation review
Scope, timing, price, and owner availability are confirmed separately.
- Source-complete; legal release HOLD
TMF Release Assurance
Telecom teams reviewing TMF-based contract cascades
Scoped proposal after legal approval
- • Verified bundled-asset workflows
- • TMF622 → TMF641 cascade evidence
Redistribution, licence, trademark, and German professional-language approval remain external gates.
UNVERIFIED/HOLD: sales@apimaster.dev is the intended APIMaster-domain sales address, but inbound/outbound delivery, ownership and staffing have not been proved. The application does not expose a mailto action or response-time promise.
- Architecture preview; fulfilment HOLD
Enterprise Self-Hosted
Organizations requiring customer-controlled runtime boundaries
Custom annual agreement after verification
- • Only capabilities proven by the active capability manifest
Fulfilment HOLD: hosted collaboration, SSO, managed monitoring, registry delivery, and operational SLA are not currently available.
UNVERIFIED/HOLD: sales@apimaster.dev is the intended APIMaster-domain sales address, but inbound/outbound delivery, ownership and staffing have not been proved. The application does not expose a mailto action or response-time promise.
The current local product provides encrypted bundle export, audit evidence export and explicit offline Ed25519 licence issuance. Workspace storage is browser-local by default and is not application-level encrypted at rest; explicit API, import, realtime, Companion and configured webhook operations can reach destinations recorded in the Trust manifest.
Team sync, authenticated members, SSO and self-hosted execution are not available. They remain roadmap or release-HOLD records below.
- Encrypted workspace bundleRuns locally in this browser.
Bundle encryption does not encrypt browser storage at rest.
- Audit evidence exportRuns locally in this browser.
Exported evidence is not a compliance certification or legal attestation.
- Production licence issuanceRuns locally in this browser.
Offline production issuance uses an owner-approved Ed25519 public key; private signing remains an explicit offline operator action.
Owner, editor, operator and viewer exercise the existing local permission matrix. These evaluation roles are not authenticated identities.
Local member records carry name, e-mail and role. Invitation delivery, authentication, shared state and identity recovery are not implemented.
A local pending → approved / rejected workflow exercises reviewer roles and production locks without claiming a shared review service.
Local governance actions record an actor and role. Service-backed identity, integrity and retention require future authentication and sync decisions.
Counts are read from this local workspace. The owner/editor/operator/viewer permission model protects existing local actions, while member impersonation remains an evaluation aid rather than an identity or invitation service.
- CurrentRuns locally in this browser.Encrypted workspace bundle
A user can explicitly export a versioned, optionally encrypted workspace bundle and transfer that file through a channel they choose.
- Local export and import in Settings
- AES-GCM bundle encryption with a user-supplied passphrase
- Replace or merge import with a conflict preview
- Design target 1Planned; not available in the current product.Encrypted workspace sync
A future sync layer may reuse the bundle contract, but no hosted sync service, invited-member flow or service operator is evidenced today.
- Future control and data plane separation
- Minimal metadata crossing as a design requirement
- Deployment and retention model require owner and security decisions
- Design target 2Planned; not available in the current product.Merge and conflict handling
A future client merge engine would need deterministic conflict semantics and compatibility evidence before shared workspace state can be promoted.
- Entity-level conflict policy remains to be approved
- Audit and run-history merge semantics require preservation tests
- No real-time collaboration capability is available today
- Design target 3Planned; not available in the current product.Invited members and key management
Authenticated members, invitations and per-member key wrapping are future architecture, not an extension of the current local role-impersonation demo.
- Identity provider and invitation lifecycle are undecided
- Key ceremony and recovery require a security review
- Current local roles are not authenticated team identities
- Design target 4Planned; not available in the current product.Single sign-on and self-hosted execution
OIDC, SAML and self-hosted runner deployment remain roadmap records until implementation, compatibility and release evidence exist.
- No SSO integration is currently available
- No self-hosted runner package is currently released
- Commercial availability requires separate owner confirmation
The current product can create an encrypted workspace bundle after an explicit export action. A future sync design may reuse that format, but no hosted sync service, shared key lifecycle or zero-knowledge service guarantee is implemented today.
- 01Runs locally in this browser.Browser workspace
Application-managed workspace state is stored in the current browser profile.
- 02Runs locally in this browser.Explicit encrypted export
A passphrase is used locally when the user chooses to export an encrypted bundle.
- 03Planned; not available in the current product.Future sync contract
Reusing the versioned bundle for sync is a design target, not a current transport.
- 04Planned; not available in the current product.Future identity and hosting
Member key wrapping, service operation, retention and recovery all require future decisions.
Current collaboration is asynchronous: the user explicitly exports a bundle and chooses how to transfer it. That external transfer channel is not operated or audited by the workbench.
Current local controls
Available nowEvidence-backed capabilities available in the current local product and operator tooling.
- Encrypted workspace bundleRuns locally in this browser.
Bundle encryption does not encrypt browser storage at rest.
- Audit evidence exportRuns locally in this browser.
Exported evidence is not a compliance certification or legal attestation.
- Production licence issuanceRuns locally in this browser.
Offline production issuance uses an owner-approved Ed25519 public key; private signing remains an explicit offline operator action.
Future design targets
RoadmapThese records are not available and are never promoted by plan packaging.
- Team workspace syncPlanned; not available in the current product.
Current collaboration is limited to asynchronous bundle export and import.
- Single sign-onPlanned; not available in the current product.
OIDC and SAML are design targets, not available sign-in methods.
- Self-hosted runner or agentPlanned; not available in the current product.
No released self-hosted runner or agent is part of the current product.
Scope and deliverables
- Agree a bounded set of 10–50 API contracts.
- Create or review local baselines with the existing import workflow.
- Run manual or one-shot agent checks using the shared ContractRadar engines.
- Review classification, dependency impact, policy, CI gate, release decision, and evidence outputs.
- A scoped inventory, baseline, and evaluation-coverage summary.
- Breaking-change and dependency-impact evidence from the shared local engines.
- A CI configuration, release decision, checksummed evidence bundle, and executive/technical reports.
- A prioritized remediation backlog and review of limitations and next steps.
- A written limitations and next-step summary; no certification or legal attestation.
Prerequisites and limitations
- A named pilot owner and permission to process the selected contracts locally.
- Sample or production-safe API contracts with secrets removed.
- An active browser session for browser-scheduled demonstrations.
- A separately running Companion only if native fingerprint mode is in scope.
- The current browser scheduler is not a continuously hosted monitoring service.
- Generic URL checks can download the full specification.
- Team sync, SSO, hosted control plane, and supported registry distribution remain unavailable or externally held.
- The intended APIMaster-domain sales mailbox is UNVERIFIED/HOLD, so public mailto actions stay disabled until delivery proof exists.
Pilot scope is owner-approved, but the APIMaster sales mailbox is UNVERIFIED/HOLD and the public mail action remains disabled until delivery is proved.
Scope and price require an owner-approved proposal; this manifest does not quote or guarantee a pilot fee.