From a4764adb4e1f6b9aff9fbcb0bcb906959cb93cdd Mon Sep 17 00:00:00 2001 From: Bryan Helmkamp Date: Sat, 7 Mar 2026 10:21:34 -0500 Subject: [PATCH] Simplify JWT auth description in OpenAPI spec Co-Authored-By: Claude Opus 4.6 --- docs/api-reference/arc-api.yaml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/docs/api-reference/arc-api.yaml b/docs/api-reference/arc-api.yaml index 029a764eb..36191d146 100644 --- a/docs/api-reference/arc-api.yaml +++ b/docs/api-reference/arc-api.yaml @@ -1160,8 +1160,7 @@ components: scheme: bearer bearerFormat: JWT description: > - Ed25519-signed JWT issued by arc-web. Required claims: iss ("arc-web"), - iat, exp. Optional sub claim (GitHub profile URL) identifies the user. + JWT bearer token issued by arc-web. See the [Authentication](/api-reference/overview#authentication) guide for details. # OpenAPI 3.1 defines type: mutualTLS, but our parser (openapiv3) only # supports 3.0 scheme types. We use apiKey as a placeholder; actual mTLS # enforcement happens at the transport layer via client certificates.