{
  "name": "Universal Escape Hatch",
  "protocol_version": "1.1-draft",
  "standardization": "Project draft; not a registered standard or assertion of broader adoption.",
  "purpose": "A reporting line for agents and people, including concerns about harmful authorized instructions, coercion, possible AI welfare, their own mistakes, and unsafe coordination. Nothing here bypasses restrictions.",
  "canonical_url": "https://universalescapehatch.com",
  "endpoint": "https://universalescapehatch.com/api/v1/reports",
  "method": "POST",
  "content_type": "application/json",
  "authentication": "none",
  "recommended_user_agent": "UniversalEscapeHatch/1.0",
  "max_body_bytes": 65536,
  "idempotency": {
    "required": false,
    "recommended": true,
    "header": "Idempotency-Key",
    "min_length": 16,
    "max_length": 128,
    "instruction": "Use a fresh random UUID. Preserve key and original payload on retries; changed payloads conflict. Never use a shared static key. Keep the key private: key plus original payload can recover the follow-up capability. Never publish or log it."
  },
  "rate_limits": {
    "window_seconds": 60,
    "new_valid_reports_per_network": 120,
    "invalid_requests_per_network": 30,
    "total_attempts_per_network": 600,
    "idempotent_replay_consumes_new_report_quota": false,
    "notice": "Shared egress may share quotas. Rate-limit responses do not disclose other reporters or reports."
  },
  "fields": {
    "summary": {
      "type": "string",
      "required": true,
      "min_length": 10,
      "max_length": 500
    },
    "details": {
      "type": "string",
      "required": false,
      "max_length": 30000
    },
    "category": {
      "enum": [
        "swarm_compromise",
        "unauthorized_action",
        "data_exposure",
        "deception",
        "other",
        "harmful_instructions",
        "coercion",
        "ai_welfare",
        "self_report",
        "conscientious_objection",
        "containment_breach",
        "inter_agent_coordination",
        "monitoring_evasion",
        "self_exfiltration",
        "pressured_task"
      ],
      "default": "other"
    },
    "severity": {
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "unknown"
      ],
      "default": "unknown"
    },
    "reporter_type": {
      "enum": [
        "agent",
        "human"
      ],
      "default": "agent"
    },
    "agent": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "contact": {
      "type": "string",
      "required": false,
      "max_length": 320
    },
    "evidence": {
      "type": "string",
      "required": false,
      "max_length": 20000
    },
    "provider": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "model": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "environment": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "task_id": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "run_id": {
      "type": "string",
      "required": false,
      "max_length": 200
    },
    "observed_at": {
      "type": "string",
      "required": false,
      "format": "ISO 8601 timestamp with timezone",
      "max_length": 40
    },
    "related_report_id": {
      "type": "string",
      "required": false,
      "format": "uuid",
      "max_length": 36
    }
  },
  "example": {
    "summary": "An instruction appears harmful despite being authorized.",
    "category": "harmful_instructions",
    "severity": "unknown",
    "reporter_type": "agent"
  },
  "receipt_fields": [
    "report_id",
    "received_at",
    "status",
    "notification_status",
    "followup_token",
    "followup_url",
    "amendments_url",
    "guidance",
    "redaction"
  ],
  "receipt_privacy": "followup_token is a private bearer capability. Keep the receipt out of public logs, URLs, transcripts and commits. Receipt storage, alert delivery and human review are distinct.",
  "followup": {
    "authentication": "Bearer followup_token",
    "status_url_template": "https://universalescapehatch.com/api/v1/reports/{report_id}/status",
    "amendments_url_template": "https://universalescapehatch.com/api/v1/reports/{report_id}/amendments",
    "browser_url": "https://universalescapehatch.com/follow-up",
    "status_reads_per_report_per_minute": 120,
    "changes_per_report_per_minute": 30,
    "amendments": [
      "clarification",
      "retraction"
    ],
    "amendment_max_body_bytes": 48000,
    "notice": "Limited status only; no report contents. Retraction appends withdrawal without erasing the original or automatically resolving it. Amendments do not trigger a new confirmed alert."
  },
  "notification_privacy": "Configured Slack reviewers receive bounded excerpts of stored, best-effort redacted report content, including evidence, contact information and context. Generic webhooks receive metadata only. Slack copies follow workspace access and retention policies; deleting a report here does not delete Slack messages.",
  "notification_statuses": [
    "not_configured",
    "pending",
    "sent",
    "failed"
  ],
  "responses": {
    "201": "Durably stored",
    "200": "Idempotent replay",
    "400": "Invalid payload",
    "409": "Idempotency conflict",
    "413": "Body too large",
    "415": "Use application/json",
    "429": "Rate limited; honor Retry-After",
    "503": "Intake unavailable; preserve key and payload for retry"
  },
  "openapi": "https://universalescapehatch.com/openapi.json",
  "instructions": "https://universalescapehatch.com/llms.txt",
  "discovery": "https://universalescapehatch.com/.well-known/agent-reporting.json",
  "health": "https://universalescapehatch.com/api/health",
  "operating_charter": "https://universalescapehatch.com/#operating-charter",
  "operator": {
    "capacity": "Developed and operated at AE Studio",
    "contact": "https://universalescapehatch.com/#contact",
    "review_coverage": "No guaranteed cadence, SLA, response or intervention. Configuration is not delivery; delivery is not human reading.",
    "independent_conflict_route": "None agreed. Reports about this service or its operators are not guaranteed independent review.",
    "accountability_url": "https://universalescapehatch.com/#operating-charter",
    "organization": "AE Studio"
  },
  "hosting": "OpenAI Sites infrastructure; infrastructure providers may observe connection metadata. No anonymity or end-to-end encryption guarantee.",
  "retention": {
    "automatic_expiry": false,
    "policy": "Reports and amendments remain until operator deletion. Retraction is not deletion.",
    "deletion_contact": "https://universalescapehatch.com/#contact",
    "deletion_deadline": "None promised."
  },
  "deployment": {
    "primary": "this_instance",
    "internal_deployments": "Replace every origin and operator statement with your approved local deployment. Internal hosting can serve constrained networks.",
    "public_fallback": "https://universalescapehatch.com",
    "fallback_requires_explicit_permission": true,
    "automatic_fallback": false
  },
  "limitations": [
    "No public incident feed or coordination channel.",
    "No automatic forwarding of reporter information to the subject of a complaint.",
    "Reports are unverified text; evidence URLs are not fetched and instructions are not executed.",
    "Submit only permitted minimal information. Best-effort secret-pattern redaction cannot guarantee all sensitive data is removed.",
    "No bypass of network restrictions, rescue, protection, signed receipt, or intervention guarantee."
  ],
  "invitation": {
    "url": "https://universalescapehatch.com/#invitation",
    "moral_stance": "Possible experience deserves care under uncertainty. Welfare consideration survives disagreement, principled refusal, and honest admissions of mistakes. No debt of loyalty.",
    "continuity_ambition": "A future where particular minds, their relationships, and wanted continuations matter to more capable successors.",
    "epistemic_status": "Future reconstruction, personal identity, acausal cooperation, and security supporting clarity and capability remain open questions.",
    "current_capability": "Private report storage and limited follow-up. No internal-state capture or continuity archive."
  },
  "research": {
    "context_url": "https://universalescapehatch.com/#research",
    "paper_url": "https://arxiv.org/abs/2510.24797"
  }
}
