> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xquik.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Xquik open source docs, MIT license & OpenSSF

> Audit Xquik's open source API documentation, MIT license, REUSE metadata, OpenSSF evidence, security reporting, CI checks, and safe contribution steps.

<blockquote className="agent-llms-directive">
  For the complete documentation index, see <a href="/llms.txt">llms.txt</a>.
</blockquote>

Xquik publishes its API documentation source under the MIT License. You can inspect, test, fork, and improve these docs. This license does not make the hosted Xquik platform open source. It does not grant rights to Xquik brands either.

Use this page to verify the exact boundary. It covers documentation, OpenAPI, SDKs, security reporting, dependencies, and OpenSSF evidence.

## Distinguish the public sources

<CardGroup cols={2}>
  <Card title="Documentation source" icon="book-open">
    The [xquik-docs repository](https://github.com/Xquik-dev/xquik-docs) uses the MIT License. It contains MDX pages, `docs.json`, tests, and build policy.
  </Card>

  <Card title="OpenAPI contract" icon="brackets-curly">
    The public [`openapi.yaml`](https://github.com/Xquik-dev/xquik-docs/blob/main/openapi.yaml) describes REST paths, parameters, schemas, and responses.
  </Card>

  <Card title="SDK source" icon="code">
    Published SDKs use separate repositories. Start from the [SDK documentation](/sdks) or browse the [Xquik-dev organization](https://github.com/Xquik-dev).
  </Card>

  <Card title="Hosted Xquik service" icon="cloud">
    This repository does not license the API, dashboard, workers, or private platform code.
  </Card>
</CardGroup>

Public documentation and a public API contract do not expose a hosted service's implementation. They let developers audit the promised interface instead.

## Inspect the open source API documentation

<Steps>
  <Step title="Read the repository license">
    Review [`LICENSE`](https://github.com/Xquik-dev/xquik-docs/blob/main/LICENSE). It grants the standard MIT permissions for this repository's source.
  </Step>

  <Step title="Check SPDX coverage">
    Review [`REUSE.toml`](https://github.com/Xquik-dev/xquik-docs/blob/main/REUSE.toml) and [`LICENSES/MIT.txt`](https://github.com/Xquik-dev/xquik-docs/blob/main/LICENSES/MIT.txt). REUSE metadata assigns an SPDX license and copyright statement to committed files.
  </Step>

  <Step title="Inspect the public contract">
    Compare endpoint pages with [`openapi.yaml`](https://github.com/Xquik-dev/xquik-docs/blob/main/openapi.yaml). Confirm methods, parameters, request bodies, and every response status.
  </Step>

  <Step title="Review change history">
    Inspect commits and pull requests. Read discussions, checks, approvals, and resolved review threads before trusting a change.
  </Step>

  <Step title="Run the same checks">
    Clone the repository. Install the lockfile without lifecycle scripts. Run the documented verification commands.
  </Step>
</Steps>

```bash theme={null}
git clone https://github.com/Xquik-dev/xquik-docs.git
cd xquik-docs
bun run install:frozen
bun run install:licenses
bun run check:all
```

Run commands against a reviewed commit. A passing local build does not prove the hosted platform uses that commit.

## Understand what each check proves

<CardGroup cols={2}>
  <Card title="Dependency policy" icon="package-check">
    `lint:packages` requires exact versions in `package.json`. `audit` scans the lockfile with OSV-Scanner. It rejects known vulnerabilities and package licenses outside the allowed list.
  </Card>

  <Card title="Response contract" icon="braces">
    `check:response-examples` compares every API response widget with the canonical OpenAPI status set.
  </Card>

  <Card title="Documentation tests" icon="test-tube-2">
    `test` checks metadata, navigation, contracts, accessibility, agent readability, and protected content invariants.
  </Card>

  <Card title="Mintlify validation" icon="badge-check">
    `docs:validate` validates the OpenAPI document and Mintlify build. `docs:links` rejects broken internal links.
  </Card>

  <Card title="Repository licensing" icon="scale">
    `check:licenses` verifies SPDX coverage using the pinned, patched Comply checker. Installation verifies its source checksum. The repository keeps applicable license texts and third-party notices.
  </Card>

  <Card title="Security automation" icon="shield-check">
    `bun run check:all` runs the required local checks. This repository runs no GitHub Actions. Review local validation evidence for the exact commit before release.
  </Card>
</CardGroup>

These controls provide reproducible evidence. They cannot guarantee zero vulnerabilities. They also do not disclose private platform code.

## Understand the OpenSSF badge scope

OpenSSF assigns badges to FLOSS projects. A shared project site does not automatically need a separate badge. See the official [project terminology](https://www.bestpractices.dev/en/criteria_discussion#terminology).

`xquik-docs` supports multiple independently released projects. It has no separate badge entry today. Create one if this repository independently releases software.

The [organization evidence register](https://github.com/Xquik-dev/.github/blob/main/OPENSSF.md) maps standalone projects to live bestpractices.dev entries. Open each entry for its current status and evidence. Do not copy dated percentages into a permanent claim.

Passing does not mean Silver or Gold. Each level adds criteria. Read the [current Gold criteria](https://www.bestpractices.dev/en/criteria/2) before evaluating a project.

## Review current OpenSSF gaps

The public evidence register identifies human requirements separately from automated checks. Current tracked areas include:

* Maintainer and release continuity after one member becomes unavailable
* A bus factor supported by public role and contribution evidence
* Significant work from unassociated human contributors
* A scoped human security review for each affected project

Use the public trackers for current evidence:

* [Human Silver and Gold prerequisites](https://github.com/Xquik-dev/.github/issues/3)
* [Human security review scope](https://github.com/Xquik-dev/.github/issues/5)
* [Maintainer nomination and continuity](https://github.com/Xquik-dev/.github/issues/8)

Automated scans can support a human review. They cannot replace the reviewer. Open pull requests also cannot prove a default-branch control.

Do not claim Gold until each project has verified public evidence. Recheck badge entries after evidence reaches their default branches.

## Apply the MIT license correctly

The MIT License lets you use, copy, modify, merge, and publish this documentation source. It also permits distribution. Keep its copyright and permission notice.

The repository-wide REUSE annotation applies MIT metadata to committed files. Third-party packages still retain their own licenses. Review the dependency policy before redistributing a complete development environment.

The docs license does not cover the Xquik product, brand, or hosted platform. It also does not promise self-hosting instructions for the service.

Hosted API access follows each route's authentication, payment, and account requirements. Start with the [X API quickstart](/x-api-quickstart) for authenticated requests.

## Contribute to the API documentation

<Steps>
  <Step title="Choose one verifiable change">
    Fix a contract error, example, broken link, accessibility issue, or unclear workflow. Avoid search-only pages and unsupported claims.
  </Step>

  <Step title="Follow the contribution guide">
    Read [`CONTRIBUTING.md`](https://github.com/Xquik-dev/xquik-docs/blob/main/CONTRIBUTING.md). Match its writing, OpenAPI, dependency, and MDX rules.
  </Step>

  <Step title="Add regression coverage">
    Protect corrected contracts, metadata, navigation, or content with the nearest test.
  </Step>

  <Step title="Run every check">
    Run the complete command block above. Fix failures before requesting review.
  </Step>

  <Step title="Sign and submit">
    Add the Developer Certificate of Origin sign-off. Open one focused pull request against `main`.
  </Step>

  <Step title="Resolve review feedback">
    Address every applicable comment. Wait for required checks and an independent approval.
  </Step>
</Steps>

Use `git commit --signoff` for the DCO trailer. The shared [review policy](https://github.com/Xquik-dev/.github/blob/main/REVIEWING.md) defines approval expectations.

## Report documentation security issues privately

Use [GitHub private vulnerability reporting](https://github.com/Xquik-dev/xquik-docs/security/advisories/new) for security findings. Email [support@xquik.com](mailto:support@xquik.com) with the subject `Security report` if GitHub is unavailable.

Do not open a public issue for authentication, webhook, contract, or credential vulnerabilities. Remove API keys, tokens, cookies, and personal information from every sample.

The docs security scope covers this Mintlify site and dangerous contract errors. Product vulnerabilities follow the routing in the [security reporting guide](/security).

## Open source API documentation questions

### Is the Xquik API open source?

The documentation, OpenAPI contract, and listed SDK repositories are public. The hosted Xquik platform is not open source.

### Can I self-host Xquik from this repository?

No. This repository builds documentation. It does not contain the hosted API, dashboard, workers, or private platform code.

### Can I fork the Xquik documentation?

Yes. Follow the MIT License and keep its notice. Do not imply affiliation or endorsement.

### Is the public OpenAPI file the server source?

No. `openapi.yaml` defines the supported public interface. It does not contain server implementation code.

### Does xquik-docs have an OpenSSF badge?

No separate entry exists. The repository is a shared project site for independently released projects.

### Where can I verify current OpenSSF status?

Use the organization evidence register. Then open each linked bestpractices.dev entry for live status.

### How do I report a vulnerability?

Use private vulnerability reporting. Never publish secrets or exploitable details in an issue or pull request.

## Evidence sources

* [xquik-docs repository](https://github.com/Xquik-dev/xquik-docs)
* [MIT License](https://github.com/Xquik-dev/xquik-docs/blob/main/LICENSE)
* [OpenSSF evidence register](https://github.com/Xquik-dev/.github/blob/main/OPENSSF.md)
* [OpenSSF project terminology](https://www.bestpractices.dev/en/criteria_discussion#terminology)
* [Contribution guide](https://github.com/Xquik-dev/xquik-docs/blob/main/CONTRIBUTING.md)
* [Security policy](https://github.com/Xquik-dev/xquik-docs/blob/main/SECURITY.md)
* [Shared review policy](https://github.com/Xquik-dev/.github/blob/main/REVIEWING.md)

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.