# Wirtwerk (a Datum app) > ## For agents Generated from this app's declarations; filtered to your identity: anonymous. Available actions: Wirtwerk is a Datum application. 6 screens and 72 HTTP API endpoints. Everything below is generated from the app's own declarations and is filtered to what the requesting identity may see; this is the anonymous view. Bot keys: Authorization: Bearer ; re-read this file with the key to see exactly the granted actions. Surfaces: MCP https://wirtwerk.diginery.com/mcp (streamable HTTP); OpenAPI /openapi.json; domain model /.well-known/datum-app-spec.json; guide /docs. Enforced: current owner rights intersect bot grants; no security scopes or bot creation by bots; per-bot rate limits; audit attribution; immediate revocation. ## Machine contracts - [OpenAPI 3.1](/openapi.json): every endpoint below, with its parameters, its schemas and its auth. Fetch this to CALL the app. - [Surface model](/.well-known/datum-app-spec.json): the same surface as domain facts — relations, deletion policy, enum labels — rather than as transport. Fetch this to UNDERSTAND the app. ## API endpoints - [GET /bot/widget.wasm](/openapi.json#/paths/~1bot~1widget.wasm): ChatbotEmbedService.widgetWasm — public - [GET /bot/{id}/embed.js](/openapi.json#/paths/~1bot~1%7Bid%7D~1embed.js): ChatbotEmbedService.embedJs — public - [GET /bot/{id}/preview](/openapi.json#/paths/~1bot~1%7Bid%7D~1preview): ChatbotPreviewService.preview — public - [GET /api/chatbot/whatsapp/{connectionId}](/openapi.json#/paths/~1api~1chatbot~1whatsapp~1%7BconnectionId%7D): ChatbotWhatsappWebhookService.verify — public, 120/hour - [POST /api/chatbot/whatsapp/{connectionId}](/openapi.json#/paths/~1api~1chatbot~1whatsapp~1%7BconnectionId%7D): ChatbotWhatsappWebhookService.receive — public, 30000/hour - [POST /api/bot/{id}/message](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1message): ChatbotAnswerService.message — public, 600/hour - [POST /api/bot/{id}/run](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1run): ChatbotAnswerService.result — public, 1200/hour - [POST /api/bot/{id}/rate](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1rate): ChatbotAnswerService.rate — public, 600/hour - [POST /api/bot/{id}/thread](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1thread): ChatbotAnswerService.threads — public, 1200/hour - [POST /api/bot/{id}/attachment](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1attachment): ChatbotAttachmentService.upload — public, 60/hour - [POST /api/bot/{id}/attachment/{attachmentId}](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1attachment~1%7BattachmentId%7D): ChatbotAttachmentService.download — public, 120/hour - [POST /api/bot/{id}/privacy](/openapi.json#/paths/~1api~1bot~1%7Bid%7D~1privacy): ChatbotPrivacyService.privacy — public, 60/hour - [GET /api/chatbot/export/{token}/attachment/{attachmentId}](/openapi.json#/paths/~1api~1chatbot~1export~1%7Btoken%7D~1attachment~1%7BattachmentId%7D): ChatbotExportService.attachment — public, 120/hour - [GET /api/chatbot/export/{token}](/openapi.json#/paths/~1api~1chatbot~1export~1%7Btoken%7D): ChatbotExportService.export — public, 60/hour - [POST /notifications/telegram/webhook](/openapi.json#/paths/~1notifications~1telegram~1webhook): NotificationTelegramService.webhook — public - [GET /notifications/ack](/openapi.json#/paths/~1notifications~1ack): EscalationService.acknowledge — public - [GET /push/vapid](/openapi.json#/paths/~1push~1vapid): PushService.vapid — public - [POST /api/sms/status](/openapi.json#/paths/~1api~1sms~1status): SmsStatusWebhookService.receive — public, 6000/hour - [GET /_datum/app.wasm](/openapi.json#/paths/~1_datum~1app.wasm): AppClientAssets.wasm — public - [GET /_datum/app.js](/openapi.json#/paths/~1_datum~1app.js): AppClientAssets.js — public - [GET /_datum/app.mjs](/openapi.json#/paths/~1_datum~1app.mjs): AppClientAssets.module — public - [GET /_health](/openapi.json#/paths/~1_health): ProbeRoutes.health — public - [GET /readyz](/openapi.json#/paths/~1readyz): ProbeRoutes.readyz — public - [POST /_error](/openapi.json#/paths/~1_error): ShellRoutes.clientError — public - [GET /healthz](/openapi.json#/paths/~1healthz): ShellRoutes.healthz — public - [GET /datum/idiomorph.js](/openapi.json#/paths/~1datum~1idiomorph.js): ShellRoutes.idiomorph — public - [GET /manifest.json](/openapi.json#/paths/~1manifest.json): ShellRoutes.manifest — public - [GET /sw.js](/openapi.json#/paths/~1sw.js): ShellRoutes.serviceWorker — public - [GET /favicon.ico](/openapi.json#/paths/~1favicon.ico): ShellRoutes.favicon — public - [POST /csp-report](/openapi.json#/paths/~1csp-report): ShellRoutes.cspReport — public - [GET /_datum/i18n.js](/openapi.json#/paths/~1_datum~1i18n.js): ShellRoutes.i18nJs — public - [GET /_datum/client.js](/openapi.json#/paths/~1_datum~1client.js): ShellRoutes.clientJs — public - [GET /pwa-icon.png](/openapi.json#/paths/~1pwa-icon.png): ShellRoutes.pwaIcon — public - [GET /_datum/icon-192.png](/openapi.json#/paths/~1_datum~1icon-192.png): ShellRoutes.icon192 — public - [GET /_datum/icon-512.png](/openapi.json#/paths/~1_datum~1icon-512.png): ShellRoutes.icon512 — public - [GET /_datum/icon-maskable-192.png](/openapi.json#/paths/~1_datum~1icon-maskable-192.png): ShellRoutes.iconMaskable192 — public - [GET /_datum/icon-maskable-512.png](/openapi.json#/paths/~1_datum~1icon-maskable-512.png): ShellRoutes.iconMaskable512 — public - [GET /apple-touch-icon.png](/openapi.json#/paths/~1apple-touch-icon.png): ShellRoutes.appleTouchIcon — public - [GET /_datum/favicon-32.png](/openapi.json#/paths/~1_datum~1favicon-32.png): ShellRoutes.favicon32 — public - [GET /assets/favicon.svg](/openapi.json#/paths/~1assets~1favicon.svg): ShellRoutes.faviconPlaceholder — public - [GET /session-clear](/openapi.json#/paths/~1session-clear): ShellRoutes.sessionClear — public - [POST /session](/openapi.json#/paths/~1session): ShellRoutes.session — public - [GET /_config/export](/openapi.json#/paths/~1_config~1export): ConfigApiService.configExport — public - [POST /_config/import](/openapi.json#/paths/~1_config~1import): ConfigApiService.configImport — public - [GET /demo](/openapi.json#/paths/~1demo): DemoService.enter — public - [POST /demo/claim](/openapi.json#/paths/~1demo~1claim): DemoService.claim — public, 60/hour - [GET /auth/invites](/openapi.json#/paths/~1auth~1invites): InviteService.roles — public - [POST /auth/invites](/openapi.json#/paths/~1auth~1invites): InviteService.invite — public - [POST /auth/magic/request](/openapi.json#/paths/~1auth~1magic~1request): MagicLinkService.request — public - [GET /auth/magic](/openapi.json#/paths/~1auth~1magic): MagicLinkService.consume — public - [POST /_sync/logout](/openapi.json#/paths/~1_sync~1logout): OfflineMountService.offlineSignOut — public - [GET /_datum/offline-lifecycle.js](/openapi.json#/paths/~1_datum~1offline-lifecycle.js): OfflineMountService.offlineLifecycle — public - [GET /_datum/offline.js](/openapi.json#/paths/~1_datum~1offline.js): OfflineMountService.offlineModule — public - [GET /_datum/offline.wasm](/openapi.json#/paths/~1_datum~1offline.wasm): OfflineMountService.offlineWasm — public - [GET /_offline](/openapi.json#/paths/~1_offline): OfflineMountService.offlineShell — public - [POST /auth/otp/request](/openapi.json#/paths/~1auth~1otp~1request): OtpService.request — public - [POST /auth/otp/verify](/openapi.json#/paths/~1auth~1otp~1verify): OtpService.verify — public - [POST /auth/passkey/login/options](/openapi.json#/paths/~1auth~1passkey~1login~1options): PasskeyService.loginOptions — public - [POST /auth/passkey/login](/openapi.json#/paths/~1auth~1passkey~1login): PasskeyService.login — public - [POST /_sync/register](/openapi.json#/paths/~1_sync~1register): SyncService.syncRegister — public - [GET /_sync/pull](/openapi.json#/paths/~1_sync~1pull): SyncService.syncPull — public - [POST /_sync/upload](/openapi.json#/paths/~1_sync~1upload): SyncService.syncUpload — public - [POST /_sync/push](/openapi.json#/paths/~1_sync~1push): SyncService.syncPush — public - [POST /_rum](/openapi.json#/paths/~1_rum): RumRoutes.beacon — public, 600/hour - [GET /.well-known/mcp.json](/openapi.json#/paths/~1.well-known~1mcp.json): McpService.descriptor — public - [POST /mcp](/openapi.json#/paths/~1mcp): McpService.rpc — public - [GET /mcp](/openapi.json#/paths/~1mcp): McpService.rpcMethodNotAllowed — public - [GET /openapi.json](/openapi.json#/paths/~1openapi.json): SpecService.openapiRoot — public - [GET /.well-known/openapi.json](/openapi.json#/paths/~1.well-known~1openapi.json): SpecService.openapi — public - [GET /.well-known/datum-app-spec.json](/openapi.json#/paths/~1.well-known~1datum-app-spec.json): SpecService.appSpec — public - [GET /llms.txt](/openapi.json#/paths/~1llms.txt): SpecService.llmsTxt — public - [GET /](/openapi.json#/paths/~1): HomeRedirectService.landing — public ## Screens - [GET /demo/busy](/openapi.json#/paths/~1demo~1busy): The demo is busy — public - [GET /demo/claim-sent](/openapi.json#/paths/~1demo~1claim-sent): Check your inbox — public - [GET /demo/confirm](/openapi.json#/paths/~1demo~1confirm): Create your account — public - [GET /login](/openapi.json#/paths/~1login): Login — public - [GET /reset](/openapi.json#/paths/~1reset): Reset password — public - [GET /demo/preparing](/openapi.json#/paths/~1demo~1preparing): Preparing your demo… — public ## Errors - [Problem](/openapi.json#/components/schemas/Problem): the body of every 4xx and 5xx a framework route returns: {"error": ""}