Revoke a registered extension
Takes the registration away with everything on it, including the models a picker was offering. Requires extensions:manage. It takes effect on the next transformation rather than at the next restart, so an owner can stop a misbehaving extension while a turn is waiting on it. The audit rows stay: a registry that cannot say who installed what is a registry nobody can be accountable for.
A row Lerian installed cannot be revoked here. The owner’s power over it is the standing veto — enabled: false through the update operation.
Autorizaciones
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parámetros de ruta
The publisher half of the extension's namespaced name.
The name is publisher/extension and travels as TWO path segments rather than one. The single-segment spelling is not broken — a generated client percent-encodes a path parameter's slash and the router decodes it back — so this is a deployment choice rather than a repair: an encoded slash is normalised or rejected by most reverse proxies a hosted home sits behind, and two segments read the way the name reads, /v1/extensions/lerian/redactor.
^[a-z0-9][a-z0-9-]*$"lerian"
The extension half of the namespaced name.
^[a-z0-9][a-z0-9-]*$"redactor"
Respuesta
The registration is gone.

