src/app/api/. Exact request schemas are enforced in each route.ts; this page groups the surface by trust boundary.
Internal routes cover stage claims and finalization, outbox delivery, job context, analysis, strategy, editorial plans, actions, receipts, verification, usage, budgets, assets, notifications, retention, and proactive cycles. An
internal URL is not a security boundary by itself; deployment identity and server-side authentication are required.