{
  "entries" : [
    {
      "host" : "api.anthropic.com",
      "purpose" : "Claude usage API (Bearer)",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "platform.claude.com",
      "purpose" : "Claude OAuth token refresh",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "chatgpt.com",
      "purpose" : "Codex/ChatGPT usage API (Bearer)",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "auth.openai.com",
      "purpose" : "Codex OAuth token refresh",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "cloudcode-pa.googleapis.com",
      "purpose" : "Gemini Code Assist quota (Bearer)",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "oauth2.googleapis.com",
      "purpose" : "Gemini OAuth token refresh",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "cursor.com",
      "purpose" : "Cursor usage summary (Cookie)",
      "tier" : "credentialReachable",
      "trafficSchema" : {
        "negativeDeclaration" : "",
        "sentFieldCategories" : [

        ]
      }
    },
    {
      "host" : "license.silent-spell.com",
      "purpose" : "License activate/refresh/reset/trial-sync",
      "tier" : "noCredential",
      "trafficSchema" : {
        "negativeDeclaration" : "Never contains provider credentials, user prompts, or usage body content.",
        "sentFieldCategories" : [
          {
            "description" : "Gumroad license key supplied by the user",
            "key" : "license"
          },
          {
            "description" : "Per-device identifier used for license binding",
            "key" : "device_id"
          },
          {
            "description" : "Public key for this device's license proof",
            "key" : "device_public_key"
          },
          {
            "description" : "Mana app version",
            "key" : "app_version"
          },
          {
            "description" : "Coarse Mac model identifier when readable",
            "key" : "device_model"
          },
          {
            "description" : "Apple DeviceCheck token for trial sync",
            "key" : "device_check_token"
          },
          {
            "description" : "Coarse trial progress bucket",
            "key" : "progress"
          },
          {
            "description" : "Device-proof nonce",
            "key" : "nonce"
          },
          {
            "description" : "Device-proof signature",
            "key" : "device_proof"
          },
          {
            "description" : "Signed Mana license token",
            "key" : "token"
          }
        ]
      }
    },
    {
      "host" : "downloads.silent-spell.com",
      "purpose" : "App auto-updates: the Sparkle updater fetches the appcast and DMG here. Sparkle uses its own networking, not Mana's guarded HTTP client, so this host is listed for firewall completeness but is not enforced by the egress guard.",
      "tier" : "noCredential",
      "trafficSchema" : {
        "negativeDeclaration" : "Never contains provider credentials, user prompts, or usage body content.",
        "sentFieldCategories" : [
          {
            "description" : "Sparkle HTTPS GET request metadata only; no Mana request body",
            "key" : "sparkle_update_request"
          }
        ]
      }
    }
  ],
  "generatedBy" : "ManaCore.EgressAllowlist",
  "officialEndpointSummary" : "Official vendor endpoints use your own token to call the official API. Mana does not send provider credentials to Silent Spell or Mana infrastructure."
}
