> ## Documentation Index
> Fetch the complete documentation index at: https://docs.infrawatch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the closed set of fields authorable for a rule input kind.

> The immutable schema is derived from the protobuf descriptors linked into the same binary as the YARA-X runtime. The response is cacheable privately for five minutes and supports If-None-Match.



## OpenAPI

````yaml https://api.infrawatch.com/openapi.json?contract=d15375c get /rules/authoring/schema
openapi: 3.1.0
info:
  description: >-
    Customer-facing Infrawatch APIs. Authenticate with an API key unless an
    operation documents another supported credential.


    ### Infrawatch Public API


    Public API authenticated exclusively with Infrawatch API keys.


    ### Infrawatch Customer Alerting API


    Project alert rules, destinations, silences, inbox state, and delivery
    history.


    ### Infrawatch Remote Browser API


    Project-scoped interactive browser sessions owned by Platform Core.


    Session admission, lifecycle, RBAC, audit, usage, screenshot history, and

    stream tickets are Platform Core resources. The browser master is private

    infrastructure and its identifiers, proxy routes, process options, and

    credentials are never exposed by this API.


    A session and all of its evidence are private to the credential that created

    it. Project managers may list project session metadata, inspect one
    session's

    metadata, and terminate it, but cannot access its live stream, screenshots,

    or network events.


    Terminal session metadata and screenshots are retained indefinitely. A

    creator can replay a terminal session as a new queued resource while

    preserving a durable link to the source session.


    ### Infrawatch ESI API


    Customer-facing External Surface Intelligence API for project-scoped

    product data authenticated by an Infrawatch API key. API keys

    are constrained to their immutable owner's project ceiling and assigned

    ESI scopes; human project-manager fallback never expands an API key.

    Authorised API-key requests are rate-limited and consume monthly quota.


    ### Infrawatch Reports API


    Threat report discovery API authenticated by an Infrawatch API key.


    ### Infrawatch Public Rules API


    Account-aware rule authoring, taxonomy, catalogue, and runtime observations
    for API clients.


    ### Infrawatch Search API


    Search hosts, services, DNS records, and certificates. Complete
    percent-encoded query strings are limited to 65536 bytes.
  title: Infrawatch Customer API
  version: 1.0.0
servers:
  - description: Infrawatch customer API
    url: https://api.infrawatch.com/api/v1
security: []
tags:
  - name: API Usage
  - name: Projects
  - name: Alert destinations
  - name: Alert rules
  - name: Alert silences
  - name: Alerts
  - name: Browser sessions
  - name: Browser evidence
  - name: Browser streaming
  - name: Access
  - name: Inventory
  - name: Dangling DNS
  - name: Findings
  - name: Secrets
  - name: Typosquatting
  - name: Services
  - name: AI Surface
  - description: Search hosts, services, DNS records, certificates, and open directories.
    name: Search
  - name: Dashboard
  - name: Reports
  - name: Rules
  - name: Rule tags
  - name: Rule observations
paths:
  /rules/authoring/schema:
    servers:
      - url: https://api.infrawatch.com/api/v1
    get:
      tags:
        - Rules
      summary: Get the closed set of fields authorable for a rule input kind.
      description: >-
        The immutable schema is derived from the protobuf descriptors linked
        into the same binary as the YARA-X runtime. The response is cacheable
        privately for five minutes and supports If-None-Match.
      operationId: getRuleAuthoringSchema
      parameters:
        - in: query
          name: input_kind
          schema:
            $ref: '#/components/schemas/rules_v1_RuleInputKind'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rules_v1_RuleAuthoringSchema'
          description: Closed authoring schema.
          headers:
            Cache-Control:
              description: Private five-minute cache policy.
              schema:
                const: private, max-age=300
                type: string
            ETag:
              description: Strong entity tag for this immutable schema representation.
              schema:
                type: string
            X-Infrawatch-Protobuf-Commit:
              $ref: '#/components/headers/rules_v1_RuleProtobufCommit'
            X-Infrawatch-YARA-Runtime-Commit:
              $ref: '#/components/headers/rules_v1_RuleYARARuntimeCommit'
        '304':
          description: The supplied entity tag still identifies the current schema.
        '400':
          $ref: '#/components/responses/rules_v1_BadRequest'
        '403':
          $ref: '#/components/responses/rules_v1_Forbidden'
      security:
        - apiKeyAuth: []
components:
  schemas:
    rules_v1_RuleInputKind:
      enum:
        - scan_result
        - certificate_event
      type: string
    rules_v1_RuleAuthoringSchema:
      additionalProperties: false
      properties:
        fields:
          items:
            $ref: '#/components/schemas/rules_v1_RuleAuthoringField'
          maxItems: 4096
          minItems: 1
          type: array
        input_kind:
          $ref: '#/components/schemas/rules_v1_RuleInputKind'
        language:
          const: infrawatch-rule
          type: string
      required:
        - language
        - input_kind
        - fields
      type: object
    rules_v1_RuleAuthoringField:
      additionalProperties: false
      properties:
        description:
          maxLength: 2048
          minLength: 1
          type: string
        friendly_name:
          maxLength: 256
          minLength: 1
          type: string
        in_overview:
          type: boolean
        kind:
          maxLength: 32
          minLength: 1
          type: string
        path:
          maxLength: 512
          minLength: 1
          type: string
        suggestion_terms:
          items:
            type: string
          type: array
        type:
          maxLength: 128
          minLength: 1
          type: string
      required:
        - path
        - type
        - kind
        - description
      type: object
  headers:
    rules_v1_RuleProtobufCommit:
      description: Protobuf commit used by the linked rule modules.
      schema:
        pattern: ^[0-9a-f]{12,64}$
        type: string
    rules_v1_RuleYARARuntimeCommit:
      description: >-
        Collection YARA runtime commit or deterministic development build
        identity.
      schema:
        pattern: ^[0-9a-f]{40,64}$
        type: string
  responses:
    rules_v1_BadRequest:
      description: Invalid request.
    rules_v1_Forbidden:
      description: Permission denied.
  securitySchemes:
    apiKeyAuth:
      description: >-
        Infrawatch API key. Supply the complete key directly as the header
        value.
      in: header
      name: X-API-Key
      type: apiKey

````