Reference
Documentation
How a connector integratesINT-1384
| Step | What you do |
|---|---|
| 1 | Create a key In your panel, Connectors tab. Shown once, starts with onx_live_. |
| 2 | Tell it what you see Send sightings in batches. No need to wait for an answer: fire and forget. |
| 3 | Ask before you act Query a domain or an account and get a SIGNED verdict you can keep and check later without trusting us. |
| 4 | Check the signature Fetch the public key once and verify locally. If ONYX got it wrong you have the receipt; and if you blocked somebody, so do they. |
APIAPI-1385
| route | purpose | access |
|---|---|---|
POST /v1/query (/v1/consulta) | Ask about a domain or an account. Returns the signed verdict. | with credential |
PUT /v1/ingest | Send what you have seen. In batches, no answer needed. | with credential |
GET /v1/blocks (/v1/bloqueos) | The list of identities YOUR space has blocked, so you can keep a local copy instead of asking on every visit. It returns who, and whether it still stands; no action — what to do with the list is your call. With `?desde=` you only get what changed. | with credential |
POST /v1/ethos | Does this identity hold up? You send numbers already computed —writing profile, hour histogram, how they moved in the portal, what the browser says— plus the known accounts from YOUR space to compare against. It returns a category, how much could be examined and every reason in writing; no action. Raw text is rejected. Nothing is stored. | with credential |
GET /v1/keys (/v1/claves) | The public key to check any signature of ours. | public |
GET /v1/list | The PROBE list, signed: what came in and went out since `since`. Sync it page by page and compare AT HOME; ONYX never learns which link you checked. | with credential |
GET /v1/p/{prefix} | Every entry whose hash starts with those 4 bytes, signed (even when empty). For connectors that do not keep the whole list. | with credential |
GET /v1/dossier/{h} | The dossier of an entry: which source, when, which rule fired and with which code version. Public, so whoever had a message removed can see why. | public |
POST /v1/probe | Send suspicious URLs your connector did not know, without saying who posted them or where. Verified connectors only. | with credential |
curl -X POST https://onyxos.duckdns.org/v1/query \
-H "authorization: Bearer onx_live_..." \
-d '{"tipo":"dominio","valor":"ejemplo.com"}'All these routes exist and answer. What PROBE (ONX-13) signs is checked with the same public key as the verdicts.
The five verdictsDIC-1386
| verdict | what it means |
|---|---|
bloqueado | The tenant itself has blocked it from their panel. Not an inference: a named person decided it, it was logged, and it can be appealed. |
malicious | It is on the PROBE list (ONX-13) as malicious: a public feed, the curated list or a hard rule. It carries its category and the hash of its dossier. |
campana | The same link spreading across several communities at once. Act. |
sospecha | Starting to look like a campaign, not certain yet. Watch, do not delete. |
cadena | That account performed a sequence already seen in an attack. |
reincidente | Several different communities have already sanctioned it. Not attacking right now, but not a first offence. |
limpio | Seen, and nothing odd about it. There is data behind this. |
desconocido | We have NEVER seen it. This is NOT clean: there is nothing to say yet. |
Mistaking unknown for clean is the bug that makes a connector approve exactly what nobody has looked at.
Why the verdict is signedFIR-1387
A verdict you must believe because we said so is worth little. A signed one can be kept and checked years later with the public key, without asking us and without us being able to take it back. It cuts both ways, and that is why it counts.
GET https://onyxos.duckdns.org/v1/keys
{ "kid": "…", "alg": "Ed25519", "pub": "…" }What it does not solveLIM-1388
- A single issuer. Credentials are signed by ONYX. Splitting that role across independent issuers is still an open problem.
- Walking the groups. Given time, someone can query groups one by one and rebuild part of the list. A per-client limit is missing.
- Size and timing. The channel encrypts content. How many queries you make, and when, is still visible from the network.
- Pages that disguise themselves. A malicious site can detect our address range and serve a clean page.
These four are here and not in the small print. What ONYX offers is not that something is impossible, but that it cannot be done without leaving a trace.