orders.openapi.yaml and orders.asyncapi.yaml describe the same small order
webhook family. metadata/order-delivered.json is a metadata-only delivery
observation.
learning/ contains clearly synthetic, credential-free inputs for the
compatibility report, migration assessment, and support evidence commands:
webhook-portal compatibility-report \
examples/learning/compatibility-previous.openapi.yaml \
examples/learning/compatibility-next-breaking.openapi.yaml \
--format markdown
webhook-portal migration-assess \
examples/learning/migration.inventory.json \
examples/learning/compatibility-previous.openapi.yaml \
--target-capabilities examples/learning/target-capabilities.json \
--target-policy examples/learning/target-policy.json
webhook-portal support-evidence \
examples/learning/support-timeline.json \
--case-id case_synthetic_001 \
--scope examples/learning/support-scope.json \
--from 2026-07-18T10:00:00.000Z \
--to 2026-07-18T10:03:00.000Z \
--out support-evidence.jsonThe compatibility example is intentionally breaking and exits 5. The migration
command is read-only, and the support timeline contains metadata only—no
payloads, headers, endpoint URLs, credentials, or personal data.
Run the authenticated HTTPS demo:
./examples/demo.shThe script generates credentials on first use, builds the production image,
waits for migration-aware readiness, then builds the host CLI together with its
workspace dependencies before publishing with an idempotency key. The Docker
image remains isolated from host build output. The demo creates an
endpoint/secret, sends one signed test, and ingests metadata. Publish uses the
checksum-derived stable key and verifies it through publish-status, so a
re-run recovers the original release. Type generation accepts the documented
partial exit intentionally. Metadata ingest explicitly uses the credential ID
generated into infra/.env; neither that ID nor its secret is printed.
The Compose app and preview remain running after the script exits:
curl --config infra/.curl-auth \
--cacert infra/certs/ca.crt \
https://127.0.0.1:3210/previewCleanup is deliberately separate:
./examples/demo-cleanup.sh
./examples/demo-cleanup.sh --volumes # also erase local dataEvery input here is handwritten and synthetic. The contracts, metadata
observations, and learning inputs describe a fictional order webhook family and
contain no real customer data, payloads, headers, endpoint URLs, credentials, or
personal data — the metadata samples are metadata-only by construction. Example
destinations use reserved documentation domains (example.com,
*.example.internal) and loopback addresses, never a real endpoint.
These files are source inputs, not generated output: the CLI reads them to
produce fixtures, types, reports, and evidence, and that output is not
committed. See
../docs/generated-artifacts.md for the
generated-versus-handwritten policy.