Settings & governance
Workspace configuration, roles, plan & licence, portability, privacy and gateway export.
APIMaster Integration Workbench stores workspace state locally so the workbench is offline and desktop-portable. Retention policies apply automatically via the schedule tick and on demand below.
The audit ledger has a second limit these day counts do not show: it keeps the most recent 500 entries, and older ones fall off before their retention window ends. Pinned entries are never dropped by either limit — pin what you need to keep.
"Load public test APIs" adds four free no-auth APIs (JSONPlaceholder, PokeAPI, Open-Meteo, REST Countries) with endpoints, environments, scenarios, mappings, an AI config and an hourly smoke schedule — enough to exercise every workbench surface end-to-end.
Download the entire workspace — APIs, endpoints, scenarios, mappings, runs, audit trail and API Explorer state — as one portable bundle. The workspace export is created in this browser; static hosting and explicit/configured network operations remain separate Trust boundaries.
A privacy-safe SHA-256 recovery receipt is created and a browser download is requested alongside the bundle. It proves creation, not download or successful restore. Follow the recovery and restore guide.
Restore a .awpb.json bundle. Encrypted bundles are detected automatically and ask for their passphrase. A successful import creates a digest/count receipt and requests its browser download; verify representative content separately.
Trial — all features unlocked. Explore everything; premium features carry a small plan chip so you know what each tier covers. Nothing is blocked.
Signed AWP2 keys are verified offline (Ed25519, WebCrypto) — activation performs no network request. Explicit evaluation builds may also enable the unsigned AWP1-DEMO-* keys; production builds reject them.
There is no checkout or account flow. Commercial contact is UNVERIFIED/HOLD and disabled until mailbox delivery is proved; production issuance is an offline operator action.
| Free | The full workbench — catalog, explorer, designer, scenarios, mocks, mappings, schedules, audit |
| Pro | Free + CORS relay · Encrypted workspace bundles · CI pipeline exports · TM Forum conformance pack |
| Team | Pro + Evidence exports · Reviews & production locks at scale · Scheduled-run webhooks · API Change Intelligence |
| Enterprise | Team + EU-hosted encrypted sync · SSO (OIDC) (roadmap) |
| Name | Role | Description | |
|---|---|---|---|
| Alex Owner | alex@northwind.co | Full control · roles · exports | |
| Jordan Editor | jordan@northwind.co | Edit scenarios, mappings, OpenAI, endpoints | |
| Sam Ops | sam@northwind.co | Run scenarios · view all | |
| Riley Viewer | riley@northwind.co | Read-only access |
The multi-user model — 4 members across owner / editor / operator / viewer roles, mapping reviews and an audited actor — already ships and is enforced today. EU-hosted encrypted workspace sync and SSO (OIDC, then SAML) are on the roadmap, presented honestly with phases.
Today, share a workspace with the encrypted bundle in Workspace portability above — the same format team sync will move over the wire.
- · 3 services from your APIs
- · 8 routes
- · 4 active prevalidation plugins
- · 2 approved field mappings → response transformers
Preparing browser-local preview…
Reading the last export time from this browser.
- carriedapibox.state.v5The workspace itself — 52 persisted collections and settings.
- carriedapibox.explorer.favoritesCopied into the bundle's explorer slice.
- carriedapibox.explorer.userSpecsCopied into the bundle's explorer slice.
- carriedapibox.explorer.watchesCopied into the bundle's explorer slice.
| Key | Purpose | Size |
|---|---|---|
| Scanning local storage… | ||
Everything listed above lives in this browser profile. The canonical Trust manifest discloses 11 same-origin, explicit, configured, browser and host-conditional boundaries. Erasing here does not remove copies or request metadata held by those destinations, and it does not resolve the host callback conflict.
Removes every application key listed in the inventory and downloads a PDF deletion receipt (timestamp, key list, SHA-256 of the removed payload). The app reloads with seed data afterwards.
Different from "Reset workspace to seed", which only re-seeds the core state and keeps explorer data, plan and backups.
- Version
- 0.10.1-rc.3
- Commit
- 605660ba1d61
- Build date
- 2026-09-09T06:58:02.000Z
Generates a redacted JSON file for a support conversation: product version and commit, enabled flags, capability statuses, storage key names and sizes (never values), the current route, the declared network-boundary counts, the app/runner compatibility ranges and this session's error codes and route names (no messages, stacks or payloads — kept in memory only, never stored). Nothing is sent anywhere — you download it, review it and decide whether to share it.
| When | Kind | Label | By | Size |
|---|---|---|---|---|
| No snapshots yet — export a factsheet or gateway bundle. | ||||