# Developer Documentation Delivery

Developer Center documentation is delivered through the authenticated, tenant-scoped `developer.documentation.show` route. The route accepts only fixed resource keys and `DeveloperResourceService` maps those keys to fixed repository paths. Request data is never interpreted as a filesystem path.

## Inventory

| Card | Authoritative source | Delivered format | Availability |
| --- | --- | --- | --- |
| Quick Start Guide | `docs/documentation/source/04_Quick_Start_Guide.md` and its existing generated PDF | PDF | Available |
| Developer Integration Guide | `docs/documentation/source/01_Developer_Integration_Guide.md` and its existing generated PDF | PDF | Available |
| API Reference | `docs/api/openapi.yaml`, `docs/documentation/source/02_API_Reference.md`, and its existing generated PDF | PDF | Available |
| Webhook Integration Guide | `docs/documentation/source/03_Webhook_Integration_Guide.md` and its existing generated PDF | PDF | Available |
| OpenAPI | `docs/api/openapi.yaml` | YAML | Available |
| Authentication | Developer Integration Guide and its generated Authentication Guide | PDF | Available |
| Error Codes | `docs/api/API_V1_CONTRACT.md`, OpenAPI error schema, and the generated Error Codes Reference | PDF | Available |
| Rate Limits | Developer Integration Guide, approved Usage & Limits source, and the generated Rate Limits Guide | PDF | Available |
| Postman | No repository collection exists | — | Not yet available |
| SDKs | No official repository SDK exists | — | Not yet available |

The former duplicate **Webhook Guide** card was removed. **Webhook Integration Guide** is the canonical card.

## Security model

- Existing `workspace.tenant` middleware authenticates the user and verifies active membership for the route tenant.
- Resource keys are constrained by the route and checked again against a private allowlist.
- Only developer-facing files listed in the allowlist can be served.
- `.env`, `review/`, logs, storage files, architecture material, and arbitrary paths are unreachable.
- Responses are read-only, use `nosniff`, and are cached privately for at most five minutes.
- Existing HTTPS documentation URL overrides remain supported after scheme and URL validation.

## Manual production verification

1. Log in as a tenant developer or administrator.
2. Open Developer Center.
3. Open each available resource card.
4. Verify Quick Start Guide.
5. Verify Developer Integration Guide.
6. Verify API Reference.
7. Open or download OpenAPI YAML.
8. Verify Authentication documentation.
9. Verify Error Codes documentation.
10. Verify Rate Limits and the distinction between request throttling and durable usage quotas.
11. Verify Webhook Integration Guide.
12. Confirm Postman and SDK cards say they are not yet available.
13. Confirm guessed names, traversal paths, `.env`, `review`, storage, and logs return 404.
14. Repeat through approved LAN and public subdirectory URLs and confirm every link retains the deployment base path.
