ONYXStromstudios
ESENPTRU
Sign inCreate account
Reference

Documentation

How a connector integratesINT-1238
StepWhat you do
1Create a key
In your panel, Connectors tab. Shown once, starts with onx_live_.
2Tell it what you see
Send sightings in batches. No need to wait for an answer: fire and forget.
3Ask before you act
Query a domain or an account and get a SIGNED verdict you can keep and check later without trusting us.
4Check the signature
Fetch the public key once and verify locally. If ONYX got it wrong you have the receipt; and if you blocked somebody, so do they.
APIAPI-1239
routepurposeaccess
POST /v1/query (/v1/consulta)Ask about a domain or an account. Returns the signed verdict.with credential
PUT /v1/ingestSend what you have seen. In batches, no answer needed.with credential
GET /v1/blocks (/v1/bloqueos)The list of identities YOUR space has blocked, so you can keep a local copy instead of asking on every visit. It returns who, and whether it still stands; no action — what to do with the list is your call. With `?desde=` you only get what changed.with credential
POST /v1/ethosDoes this identity hold up? You send numbers already computed —writing profile, hour histogram, how they moved in the portal, what the browser says— plus the known accounts from YOUR space to compare against. It returns a category, how much could be examined and every reason in writing; no action. Raw text is rejected. Nothing is stored.with credential
GET /v1/keys (/v1/claves)The public key to check any signature of ours.public
GET /v1/listThe PROBE list, signed: what came in and went out since `since`. Sync it page by page and compare AT HOME; ONYX never learns which link you checked.with credential
GET /v1/p/{prefix}Every entry whose hash starts with those 4 bytes, signed (even when empty). For connectors that do not keep the whole list.with credential
GET /v1/dossier/{h}The dossier of an entry: which source, when, which rule fired and with which code version. Public, so whoever had a message removed can see why.public
POST /v1/probeSend suspicious URLs your connector did not know, without saying who posted them or where. Verified connectors only.with credential
curl -X POST https://onyxos.duckdns.org/v1/query \
  -H "authorization: Bearer onx_live_..." \
  -d '{"tipo":"dominio","valor":"ejemplo.com"}'

All these routes exist and answer. What PROBE (ONX-13) signs is checked with the same public key as the verdicts.

The five verdictsDIC-1240
verdictwhat it means
bloqueadoThe tenant itself has blocked it from their panel. Not an inference: a named person decided it, it was logged, and it can be appealed.
maliciousIt is on the PROBE list (ONX-13) as malicious: a public feed, the curated list or a hard rule. It carries its category and the hash of its dossier.
campanaThe same link spreading across several communities at once. Act.
sospechaStarting to look like a campaign, not certain yet. Watch, do not delete.
cadenaThat account performed a sequence already seen in an attack.
reincidenteSeveral different communities have already sanctioned it. Not attacking right now, but not a first offence.
limpioSeen, and nothing odd about it. There is data behind this.
desconocidoWe have NEVER seen it. This is NOT clean: there is nothing to say yet.

Mistaking unknown for clean is the bug that makes a connector approve exactly what nobody has looked at.

Why the verdict is signedFIR-1241

A verdict you must believe because we said so is worth little. A signed one can be kept and checked years later with the public key, without asking us and without us being able to take it back. It cuts both ways, and that is why it counts.

GET https://onyxos.duckdns.org/v1/keys
{ "kid": "…", "alg": "Ed25519", "pub": "…" }
What it does not solveLIM-1242
  • A single issuer. Credentials are signed by ONYX. Splitting that role across independent issuers is still an open problem.
  • Walking the groups. Given time, someone can query groups one by one and rebuild part of the list. A per-client limit is missing.
  • Size and timing. The channel encrypts content. How many queries you make, and when, is still visible from the network.
  • Pages that disguise themselves. A malicious site can detect our address range and serve a clean page.
These four are here and not in the small print. What ONYX offers is not that something is impossible, but that it cannot be done without leaving a trace.