Skip to content
bucker

API reference

evidence-pricing

6 operations. Shapes are sketches of the declared schemas, bounded in depth — the authoritative document is linked from the index.

GET/evidence-pricing/tiers

No declared credential scheme

Reachable without a Bucker session token. Static tier ladder; the same bytes for everyone.

Response 200

{
  pricingBasis: string
  disclosure: string
  tiers: {
    tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
    rank: integer
    priceCents: integer
    pricingBasis: string
    claim: string
    doesNotProve: string
    requirements: {
      id: string
      description: string
      measuredFrom: string
    }[]
  }[]
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/evidence-pricing/tiers

GET/orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade

Requires bearerAuth

Parameters

Parameters for GET /orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
proposalIdrequiredpathstringmin length 1

Response 200

{
  proposalId: string
  tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
  tierRank: integer
  priceCents: integer
  pricingBasis: string
  facts: {
    verificationTier: string
    reproQualified: boolean
    pinMeasured: boolean
    pinScore: number | null
    pinThreshold: number
    flakeVerdict: string
    noiseBandKnown: boolean
    transitionInsideNoiseBand: boolean
    searchSeeds: integer
    behavioralDiffReplayed: integer
    behavioralDiffCoverage: number | null
    behavioralDiffUnintended: integer
    divergenceLocalized: boolean
    durabilityWatchDays: integer
    proofLedgerCommitted: boolean
  }
  shortfalls: {
    tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
    requirementId: string
    description: string
    measuredFrom: string
  }[]
  claim: string
  doesNotProve: string
  disclosure: string
  gradedAt: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade \
  -H 'authorization: Bearer $BUCKER_TOKEN'

POST/orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade

Requires bearerAuth

Parameters

Parameters for POST /orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
proposalIdrequiredpathstringmin length 1

Response 200

{
  proposalId: string
  tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
  tierRank: integer
  priceCents: integer
  pricingBasis: string
  facts: {
    verificationTier: string
    reproQualified: boolean
    pinMeasured: boolean
    pinScore: number | null
    pinThreshold: number
    flakeVerdict: string
    noiseBandKnown: boolean
    transitionInsideNoiseBand: boolean
    searchSeeds: integer
    behavioralDiffReplayed: integer
    behavioralDiffCoverage: number | null
    behavioralDiffUnintended: integer
    divergenceLocalized: boolean
    durabilityWatchDays: integer
    proofLedgerCommitted: boolean
  }
  shortfalls: {
    tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
    requirementId: string
    description: string
    measuredFrom: string
  }[]
  claim: string
  doesNotProve: string
  disclosure: string
  gradedAt: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X POST https://api.bucker.io/orgs/{orgSlug}/evidence-pricing/proposals/{proposalId}/grade \
  -H 'authorization: Bearer $BUCKER_TOKEN'

GET/orgs/{orgSlug}/evidence-pricing/quotes

Requires bearerAuth

Parameters

Parameters for GET /orgs/{orgSlug}/evidence-pricing/quotes
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
limitqueryintegerdefault 100, min 1, max 200

Response 200

{
  quotes: {
    id: string
    orgId: string
    projectId: string | null
    issueId: string | null
    requestedTier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
    priceCents: integer
    pricingBasis: string
    breakdown: {
      tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
      rank: integer
      priceCents: integer
      pricingBasis: string
      claim: string
      doesNotProve: string
      requirements: object[]
    }[]
    requestedByPrincipalId: string
    createdAt: string
    disclosure: string
  }[]
  disclosure: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/orgs/{orgSlug}/evidence-pricing/quotes \
  -H 'authorization: Bearer $BUCKER_TOKEN'

POST/orgs/{orgSlug}/evidence-pricing/quotes

Requires bearerAuth

Parameters

Parameters for POST /orgs/{orgSlug}/evidence-pricing/quotes
NameInTypeNotes
orgSlugrequiredpathstringmin length 1

Request body (required) · application/json

{
  tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
  projectId?: string | null
  issueId?: string | null
}

Response 201

{
  id: string
  orgId: string
  projectId: string | null
  issueId: string | null
  requestedTier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
  priceCents: integer
  pricingBasis: string
  breakdown: {
    tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
    rank: integer
    priceCents: integer
    pricingBasis: string
    claim: string
    doesNotProve: string
    requirements: {
      id: string
      description: string
      measuredFrom: string
    }[]
  }[]
  requestedByPrincipalId: string
  createdAt: string
  disclosure: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X POST https://api.bucker.io/orgs/{orgSlug}/evidence-pricing/quotes \
  -H 'authorization: Bearer $BUCKER_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ … }'

GET/orgs/{orgSlug}/evidence-pricing/tier-mix

Requires bearerAuth

Parameters

Parameters for GET /orgs/{orgSlug}/evidence-pricing/tier-mix
NameInTypeNotes
orgSlugrequiredpathstringmin length 1

Response 200

{
  period: {
    start: string
    end: string
  }
  quoted: {
    total: integer
    byTier: {
      tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
      count: integer
      share: number | null
    }[]
  }
  graded: {
    total: integer
    byTier: {
      tier: "NONE" | "BASELINE" | "CORROBORATED" | "ADJUDICATED"
      count: integer
      share: number | null
    }[]
    revenueCents: integer
  }
  meanQuotedRank: number | null
  meanGradedRank: number | null
  note: string
  disclosure: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/orgs/{orgSlug}/evidence-pricing/tier-mix \
  -H 'authorization: Bearer $BUCKER_TOKEN'