Fit is computed from mount interfaces, never from names. A firearm declares what it exposes at each position (muzzle thread, rails, optic cut, stock and grip interfaces, magazine well); an attachment declares what it requires; the engine matches the two, through a named adapter where one bridges them. A caliber, bore or minimum-barrel mismatch is never bridged and never inferred.
Every fit carries `source` and `confidence`, and they are the first two fields to read. source is the weakest evidence in the chain that produced the fit; confidence is capped by the weakest interface it went through. The values, strongest first:
curated: a person recorded this interface or this fit against the maker's page.universal: the attachment requires nothing (a sling), so every firearm fits it.inherited:parent: the interface came from the firearm's parent record.inherited:platform: the interface came from a platform the firearm belongs to (an AK-100 default, a mil-spec AR-15 default).inferred: the interface was derived by a script from the record's own fields, at 0.6 or below. Convention rows are the weakest inferred evidence and are labelled as such: where a firearm is tagged threaded or optics-ready but names no standard, the backfill applies industry convention (a thread by cartridge and country, an optic plate by the maker's system) at 0.5 to 0.6, with a convention: note on the interface row.
A retailer or an engineering consumer should treat `inferred`, and anything below a confidence they choose, as unverified. Pass min_confidence to hide fits computed through interfaces below that figure; nothing in a response presents an inferred or convention row as verified, and neither should a product page built on it. via[] names each interface the fit went through with its own source, so a fit can be audited hop by hop; GET /v1/firearms/{id}/interfaces lists every row with its source, confidence and inheritedFrom.
Browsing the catalog (/v1/attachments, /v1/attachments/{id}, /v1/interfaces) is open to any key. Everything that answers "does this go on that" is Studio, and a lower plan receives 403 SUBSCRIPTION_REQUIRED rather than an empty list, so never read an error as "nothing fits". fits= on the attachment list is the same computation wearing a query parameter and is gated the same way.