Governed API Access

H33-API-G

APIs With Authority, Not Secrets

Authority-based API execution.

Part of the H33 Authority Center family.

Why it exists
APIs today grant access with copyable bearer tokens; possession isn't proof of permission, and there's no independent record of why a call was allowed.
Primary value
Makes every API request individually authorized and independently verifiable.
What it does
Runs an operation only when the exact request is cryptographically proven allowed, leaving a tamper-proof receipt for every call.
Why it's different
A call executes because authority is proven for that specific request, not because a reusable token was presented — and the receipt lets anyone verify the decision later.
Get Governed API Access →
H33-API-G governed access pilot. Not a production-admitted authority.

Go deeper

Proof Lab
Valid but Unauthorized
Everything passed. The action still did not execute — and the refusal names the missing condition.
White Paper · Draft
A Valid Request Is Not an Authorized Action
The category definition: identity, authentication, authorization, authority, evidence — and why the last two are decided nowhere.

Frequently asked

Answers projected from the H33-API-G authority record.

What is H33-API-G?

H33-API-G is a governed post-quantum API authorization layer that controls whether API actions are permitted based on cryptographic authority, policy, and evidence rather than transport or token possession alone.

How is this different from an API gateway?

A gateway decides whether a caller may reach an endpoint. H33-API-G decides whether a specific request is authorized to execute, and leaves a receipt showing why. A call executes because authority is proven for that exact request, not because a reusable token was presented.

Why are bearer tokens not sufficient?

APIs today grant access with copyable bearer tokens. Possession is not proof of permission, and there is no independent record of why a call was allowed.

What evidence does a call produce?

Every call leaves a tamper-proof receipt, so the authorization decision can be verified later by someone who was not present when it was made.

Is H33-API-G available in production?

No. H33-API-G is currently a governed access pilot and is not a production-admitted authority.

What does H33-API-G compose with?

H33-Key, H33-BIND and HATS. Authority Center describes H33-API-G, but does not own it — H33-API-G is an admitted core product in its own right.