Result 2026-06-27: Aligned catalog/docs/OpenAPI behavior with the active ops-hub gate. Static catalogs and docs are public; hub registry/bootstrap data is protected. `/api/v2/openapi.json` now includes the unprefixed path aliases expected by ops-hub gate checks. Local gate probe passed against Core Hub.
Result 2026-06-27: Replaced placeholders with persistence-backed protected routes for hubs, manifests, API consumers, API keys, widgets, interaction events, and hub registry. Runtime API keys are generated display-once and stored hashed. The real `ops-hub/scripts/ops-hub-bootstrap-api.py` passed against local Core Hub, creating ops-hub, an active manifest, API consumer, runtime key, 14 widgets, and one readiness event.
2026-06-27: Local smoke passed with a throwaway operator token and SQLite smoke DB. Remaining closure requires deployed Core Hub runtime plus approved credential routing. No secrets in logs, workplans, or chat.
2026-06-27 continuation: `CORE-WP-0008-T02` owns the deployed API smoke harness that should close this task once it passes against a deployed Core Hub runtime.