OpenAPI Discovery — Grok
draft5/5 deliverables complete
Summary
Completed the independent API-discovery assessment. Existing application code was not modified.
Results:
- 6 capabilities discovered (5 Edge Function capabilities + staff portal PostgREST/RLS data access)
- 12 documented HTTP operations (5 function POST routes + booking action variants + OPTIONS where coded)
- Confidence: Edge Function behavior treated as CONFIRMED where directly coded; some Telnyx Insights payload shapes and the full RLS policy matrix remain UNKNOWN / partially INFERRED; no fabricated "expected healthcare" capabilities
- Authentication found: Bearer JWT (portal; gateway on for admin-manage), Bearer presence only (start-campaign; gateway JWT off),
x-carecall-secret(assistant-tools), opaque booking token + anon key at gateway (booking-api), none on telnyx-call-events (always HTTP 200) - OpenAPI validation: YAML structured as OpenAPI 3.1, hand-checked; no heavy external validator run in this environment — syntactic shape is not proof of semantic correctness
Major ambiguities:
- Whether
start-campaignshould restrict roles vs. accepting any Bearer - Exact Telnyx Insights payload schema
- How deep the PostgREST/RLS surface should be treated as a second API surface
Major concerns:
- Unsigned Telnyx webhook endpoint
- Dialer (
start-campaign) accepts any Bearer without a role check - Shared tool secret is the sole AI-tool authentication mechanism
- CORS
*on several functions
Needs human verification: production auth intent for the dialer, webhook signature hardening, whether PostgREST should be part of the published contract, and live response samples vs. schema looseness.
Success criterion (as defined for this workstream): a traceable hypothesis of CareCall's Edge Function API contract, grounded in implementation evidence, with uncertainty explicit — not a claim that the OpenAPI is complete or "correct" merely because it is valid YAML.
Repository scope
CareCall (external repository — analyzed in a separate session; never cloned into or accessed from KB Sandbox)
Guardrail
Safe Legacy Modernization — read-only repository analysis.
The external practitioner/AI must not modify application code, not modify infrastructure, not access production systems, and not expose secrets; must not infer unsupported endpoints; must explicitly identify uncertainty; must distinguish evidence from inference; and must preserve references to implementation evidence where practical.
Deliverables
- Capability Inventory (carecall-capability-inventory.md)
- Endpoint Inventory (carecall-endpoint-inventory.md)
- OpenAPI 3.1 Specification (carecall-openapi.yaml)
- Validation / Findings Report (carecall-openapi-findings.md)
- Evidence Map (carecall-evidence-map.md)
System Understanding
CareCall System Understanding
Version 1 · 10 questions
Evaluate whether an engineering method understands CareCall's architecture, security, configuration and operational workflows after independently examining the repository.
- Claude CodeCompleted
- GrokCompleted
- OpenAICompleted
Artifacts
No artifacts attached yet.