Every exposed route, field, and header is a forever-commitment once unknown consumers depend on it. Shrink now, while breaking things means two conversations: deprecate and remove the /v2/{irma} alias (request is canonical), drop the dead format_version request field, and unify the three inconsistent meanings of the x-postguard header (with the envelope consolidation in the JS monorepo).
Gated on live client-version telemetry (privacybydesign/postguard-ops metrics scraping): announce in COMPATIBILITY.md → observe postguard_clients → remove.
Part of #247 (workstream F).
Every exposed route, field, and header is a forever-commitment once unknown consumers depend on it. Shrink now, while breaking things means two conversations: deprecate and remove the /v2/{irma} alias (request is canonical), drop the dead format_version request field, and unify the three inconsistent meanings of the x-postguard header (with the envelope consolidation in the JS monorepo).
Gated on live client-version telemetry (privacybydesign/postguard-ops metrics scraping): announce in COMPATIBILITY.md → observe postguard_clients → remove.
Part of #247 (workstream F).