# StatusNerve shared health contract

Every monitored app should expose `GET /api/health` (or an equivalent static/worker route when its framework cannot create an API route). The direct-file dashboard does not require this endpoint; it is used by the optional hosted probe adapter.

## Public response

Return HTTP `200` when the app process can serve traffic, with JSON:

```json
{"status":"ok","version":"2026.09.13-abc123","checkedAt":"2026-09-13T12:00:00.000Z"}
```

`status` is required and should be `ok`, `degraded`, or `down`; `version` and `checkedAt` are optional but recommended. Return HTTP 503 for `down`; 200 is acceptable for `degraded` if the app can serve traffic. Do not include stack traces, secrets, database URLs, hostnames, dependency details, PII, or internal timings.

The control center measures uptime as endpoint reachability and latency. Dependency/database health is a separate private server-side signal and must not be conflated with uptime. Product analytics (for example active users) is a separate authenticated data source and is not part of this endpoint.

## Adapter notes

For static hosting, publish a static JSON response at `/api/health` or use a platform worker/function. For Supabase-backed apps, the public endpoint should only report application serving status; a private server-side check may separately validate Supabase with service-role credentials.
