API reference
All endpoints
Every route the server answers, 555 in all, generated from the router at start-up.
#Gateway
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /v1/chat/completions | Chat completions (OpenAI shape) | Workspace key |
POST | /anthropic/v1/messages | Messages (Anthropic shape) | Workspace key |
POST | /anthropic/v1/messages/count_tokens | Count tokens (Anthropic shape) | Workspace key |
POST | /v1/outcomes | Report an outcome | Workspace key |
POST | /v1/route/preview | Preview a route | Workspace key |
GET | /v1/models | List models | Workspace key |
GET | /v1/clients | List recognised clients | Public |
GET | /v1/task-classes | List task classes | Public |
GET | /v1/policy-profiles | List policy profiles | Public |
GET | /v1/upstreams | Upstream status | Admin key |
GET | /v1/reports/:kind | Read a report | Admin key |
GET | /v1/evidence/pack | Evidence pack | Admin key |
GET | /v1/evidence/verify | Verify the ledger | Admin key |
POST | /v1/admin/keys | Issue a key | Admin key |
GET | /v1/admin/budgets | List budgets | Admin key |
POST | /v1/admin/budgets | Set a budget | Admin key |
POST | /v1/admin/availability | Withdraw or restore a model | Admin key |
POST | /v1/ingest/devin | Ingest Devin usage | Admin key |
#Actions and receipts
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /v1/actions/authorize | Authorise an action | Agent key |
GET | /v1/actions/:id | Retrieve an action | Agent key |
GET | /v1/actions/:id/explain | Explain a decision | Agent key |
POST | /v1/actions/:id/settle | Settle an action | Agent key |
POST | /v1/verify | Verify a receipt | Public |
GET | /.well-known/immiscible-keys.json | Signing keys (JWKS) | Public |
GET | /downloads/claude-code-hook.mjs | Download the Claude Code hook | Public |
GET | /downloads/immiscible-openapi-3.0.json | OpenAPI (3.0) | Public |
GET | /downloads/immiscible-power-platform.swagger.json | Power Platform connector | Public |
GET | /downloads/n8n-ask-immiscible.json | n8n workflow | Public |
POST | /v1/actions/:id/callback | Create callback | Agent key |
#MCP
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /mcp | MCP server (no streams) | Agent key |
DELETE | /mcp | MCP server (no sessions) | Agent key |
POST | /mcp | MCP server | Agent key |
GET | /mcp/proxy/:uid | MCP proxy (no streams) | Agent key |
DELETE | /mcp/proxy/:uid | MCP proxy (no sessions) | Agent key |
POST | /mcp/proxy/:uid | MCP proxy | Agent key |
GET | /api/w/:wid/mcp-upstreams | List MCP upstreams | Session |
GET | /api/w/:wid/mcp-upstreams/:uid | Retrieve an MCP upstream | Session |
POST | /api/w/:wid/mcp-upstreams | Register an MCP upstream | Session |
PATCH | /api/w/:wid/mcp-upstreams/:uid | Update an MCP upstream | Session |
DELETE | /api/w/:wid/mcp-upstreams/:uid | Remove an MCP upstream | Session |
POST | /api/w/:wid/mcp-upstreams/:uid/discover | Refresh discovery | Session |
GET | /mcp/server-card | MCP server card | Agent key |
#Agents and the kill switch
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/agents | List agents | Session |
POST | /api/w/:wid/agents | Register an agent | Session |
PATCH | /api/w/:wid/agents/:aid | Rename an agent | Session |
DELETE | /api/w/:wid/agents/:aid | Remove an agent | Session |
POST | /api/w/:wid/agents/:aid/freeze | Freeze an agent | Session |
POST | /api/w/:wid/agents/:aid/unfreeze | Unfreeze an agent | Session |
GET | /api/w/:wid/agents/:aid/freezes | Freeze history | Session |
POST | /api/w/:wid/freeze | Freeze agents in bulk | Session |
POST | /api/w/:wid/freeze/:batchId/lift | Lift a bulk freeze | Session |
POST | /api/w/:wid/drills | Run a drill | Session |
POST | /api/w/:wid/agents/:aid/keys | Issue an agent key | Session |
GET | /api/w/:wid/freeze/pending | List pending freezes | Session |
POST | /api/w/:wid/freeze/pending/:pid/confirm | Confirm a pending freeze | Session |
POST | /api/w/:wid/freeze/pending/:pid/dismiss | Dismiss a pending freeze | Session |
#Autonomy and governance
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /api/w/:wid/settings/starting-tier/confirm | Confirm the starting tier | Session |
GET | /api/w/:wid/governance/roles | List governance roles | Session |
POST | /api/w/:wid/governance/roles | Grant or remove a governance role | Session |
GET | /api/w/:wid/agents/:aid/standing | Retrieve an agent’s standing | Session |
PATCH | /api/w/:wid/agents/:aid/standing | Update an agent’s standing | Session |
POST | /api/w/:wid/agents/:aid/signoffs | Sign off a promotion | Session |
POST | /api/w/:wid/agents/:aid/tier | Promote or demote an agent | Session |
GET | /api/w/:wid/governance/approvers | Approver health | Session |
GET | /api/w/:wid/governance/scorecard | Zero trust scorecard | Session |
#Mandates and approvals
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/mandate-templates | List mandate templates | Session |
GET | /api/w/:wid/mandates | List mandates | Session |
POST | /api/w/:wid/mandates/preview | Preview mandate | Session |
POST | /api/w/:wid/mandates | Create a mandate | Session |
POST | /api/w/:wid/mandates/:mid/revoke | Revoke a mandate | Session |
GET | /api/w/:wid/approvals | List approvals | Session |
GET | /api/w/:wid/approvals/suggestions | Suggested rules | Session |
GET | /api/w/:wid/approvals/:apid | Retrieve an approval | Session |
GET | /api/w/:wid/approvals/:apid/rule-reference | Get rule reference | Session |
POST | /api/w/:wid/approvals/:apid/feedback | Rate the rules’ verdict | Session |
POST | /api/w/:wid/approvals/:apid/remind | Create remind | Session |
POST | /api/w/:wid/approvals/:apid/approve | Approve | Session |
POST | /api/w/:wid/approvals/:apid/deny | Deny | Session |
GET | /api/w/:wid/vault | Read the vault | Session |
GET | /api/w/:wid/vault/releases | Vault releases | Session |
PUT | /api/w/:wid/vault/:field | Store a vault field | Session |
DELETE | /api/w/:wid/vault/:field | Delete a vault field | Session |
GET | /api/w/:wid/actions | List actions | Session |
GET | /api/w/:wid/actions/:id | Retrieve an action | Session |
#Evidence
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/evidence/bundle/stream | Stream the evidence bundle | Session |
GET | /api/w/:wid/activity | Activity | Session |
GET | /api/w/:wid/evidence/verify | Verify the chain | Session |
GET | /api/w/:wid/evidence/pack | Evidence pack | Session |
GET | /api/w/:wid/evidence/checkpoints | List checkpoints | Session |
POST | /api/w/:wid/evidence/checkpoints | Sign a checkpoint now | Session |
GET | /api/w/:wid/evidence/bundle | Evidence bundle | Session |
GET | /api/w/:wid/evidence/ai-act | EU AI Act deployer evidence pack | Session |
POST | /api/w/:wid/evidence/checkpoints/verify | Verify a checkpoint | Session |
GET | /api/w/:wid/evidence/auditor-bundle | Get auditor bundle | Session |
GET | /api/w/:wid/audit | Console audit log | Session |
#Oversight
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/reviews | List reviews | Session |
POST | /api/w/:wid/reviews/:id | Give a review verdict | Session |
GET | /api/w/:wid/certifications | List recertification campaigns | Session |
POST | /api/w/:wid/certifications | Start a recertification campaign | Session |
GET | /api/w/:wid/certifications/:cid | Retrieve a campaign | Session |
POST | /api/w/:wid/certifications/:cid/agents/:aid | Certify or revoke an agent’s access | Session |
GET | /api/w/:wid/traces/:traceId | Retrieve a trace | Session |
#Identity and access
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/agents/:aid/connections | List an agent’s connected apps | Session |
DELETE | /api/w/:wid/agents/:aid/connections/:gid | Disconnect an app from an agent | Session |
GET | /api/me/connections | List my connected apps | Session |
DELETE | /api/me/connections/:gid | Disconnect one of my apps | Session |
GET | /api/w/:wid/applications | List applications | Session |
POST | /api/w/:wid/applications | Register an application | Session |
GET | /api/w/:wid/applications/proposals | List application proposals | Session |
POST | /api/w/:wid/applications/proposals/:pid/confirm | Confirm an application change | Session |
GET | /api/w/:wid/applications/:id | Retrieve an application | Session |
POST | /api/w/:wid/applications/:id/accept-manifest | Accept a changed tool manifest | Session |
POST | /api/w/:wid/applications/:id/retire | Retire an application | Session |
GET | /api/w/:wid/agents/:aid/profile | Retrieve an access profile | Session |
GET | /api/w/:wid/agents/:aid/profile/diff | Diff two profile versions | Session |
POST | /api/w/:wid/agents/:aid/profile/verify | Verify a signed profile | Session |
GET | /api/w/:wid/agents/:aid/allowlists | Retrieve allowlists | Session |
PUT | /api/w/:wid/agents/:aid/allowlists | Set allowlists | Session |
GET | /api/w/:wid/members/:uid/entitlements | Retrieve entitlements | Session |
PUT | /api/w/:wid/members/:uid/entitlements | Set entitlements | Session |
GET | /api/w/:wid/sso/group-entitlements | List SSO group mappings | Session |
PUT | /api/w/:wid/sso/group-entitlements | Map SSO groups to entitlements | Session |
#Card rail
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /issuing/:wid/stripe | Stripe Issuing webhook | Signature |
POST | /issuing/:wid/generic/authorize | Authorise a card payment (any issuer) | Signature |
POST | /issuing/:wid/generic/clear | Clear a card payment (any issuer) | Signature |
GET | /api/w/:wid/issuing | Card rail status | Session |
GET | /api/w/:wid/issuing/categories | Merchant codes per category | Session |
PUT | /api/w/:wid/issuing/categories/:category | Set a category’s merchant codes | Session |
PUT | /api/w/:wid/issuing/:issuer | Connect a card issuer | Session |
POST | /api/w/:wid/agents/:aid/cards | Bind a card to an agent | Session |
GET | /api/w/:wid/issuing/proposals | List card proposals | Session |
POST | /api/w/:wid/issuing/proposals/:pid/confirm | Confirm a card proposal | Session |
DELETE | /api/w/:wid/cards/:cid | Unbind a card | Session |
GET | /api/w/:wid/card-authorizations | List card authorisations | Session |
#Vendors and discovery
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/openrouter | OpenRouter routes and preferences | Session |
PUT | /api/w/:wid/openrouter | Set OpenRouter preferences | Session |
GET | /api/w/:wid/discovery | Discovery inventory | Session |
PUT | /api/w/:wid/discovery/:vendor | Connect a vendor for discovery | Session |
PATCH | /api/w/:wid/discovery/:vendor | Change a vendor’s policy or schedule | Session |
DELETE | /api/w/:wid/discovery/:vendor | Disconnect a vendor | Session |
POST | /api/w/:wid/discovery/:vendor/sync | Sync a vendor now | Session |
GET | /api/w/:wid/discovery/items/:id | A discovered item | Session |
POST | /api/w/:wid/discovery/items/:id/control | Bring an item under control | Session |
POST | /api/w/:wid/discovery/items/:id/ignore | Ignore an item | Session |
POST | /api/w/:wid/discovery/items/:id/revoke | Propose revoking a key at its vendor | Session |
GET | /api/w/:wid/vendor-proposals | Vendor proposals | Session |
POST | /api/w/:wid/vendor-proposals/:pid/confirm | Confirm a vendor proposal | Session |
POST | /api/w/:wid/vendor-proposals/:pid/dismiss | Dismiss a vendor proposal | Session |
GET | /api/w/:wid/ramp | Ramp status, cards and charges | Session |
PUT | /api/w/:wid/ramp | Connect Ramp | Session |
PATCH | /api/w/:wid/ramp | Change Ramp options | Session |
DELETE | /api/w/:wid/ramp | Disconnect Ramp | Session |
POST | /api/w/:wid/ramp/sync | Import Ramp charges now | Session |
PUT | /api/w/:wid/ramp/cards/:cardId | Map a Ramp card to an agent | Session |
POST | /api/w/:wid/ramp/cards/:cardId/unlock | Propose unlocking a Ramp card | Session |
GET | /api/w/:wid/ramp/transactions | Ramp charges | Session |
GET | /api/w/:wid/ramp/transactions/:tid | Why a Ramp charge happened | Session |
#Personal workspaces
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/personal | Personal setup | Session |
POST | /api/w/:wid/personal/setup | Apply personal defaults | Session |
POST | /api/w/:wid/personal/agents | Add a personal agent | Session |
POST | /api/w/:wid/personal/stop | The kill switch | Session |
#SIEM and Shared Signals
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/export/ocsf | Export as OCSF | Session |
GET | /api/w/:wid/export/otel | Export as OpenTelemetry | Session |
GET | /api/w/:wid/webhooks | List webhooks | Session |
POST | /api/w/:wid/webhooks | Create a webhook | Session |
DELETE | /api/w/:wid/webhooks/:id | Delete a webhook | Session |
PATCH | /api/w/:wid/webhooks/:id | Change a webhook | Session |
POST | /api/w/:wid/webhooks/:id/rotate-secret | Rotate a webhook’s secret | Session |
POST | /api/w/:wid/webhooks/:id/test | Send a test delivery | Session |
GET | /api/w/:wid/webhooks/:id/deliveries | List deliveries | Session |
POST | /api/w/:wid/webhooks/:id/deliveries/:did/resend | Send a delivery again | Session |
GET | /api/w/:wid/ssf/transmitter | Retrieve the SSF transmitter | Session |
PUT | /api/w/:wid/ssf/transmitter | Configure the SSF transmitter | Session |
DELETE | /api/w/:wid/ssf/transmitter | Remove the SSF transmitter | Session |
POST | /ssf/:wid/events | Receive a Security Event Token | Signature |
POST | /webhooks/stripe | Stripe billing webhook | Signature |
#Chat approvals
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /slack/install | Install the Slack app | Session |
GET | /slack/oauth/callback | Slack install callback | Session |
POST | /slack/interactions | Slack interactions | Signature |
POST | /slack/commands | Slack slash command | Signature |
POST | /slack/events | Create event | Public |
POST | /teams/callback/:wid | Teams callback | Signature |
GET | /api/w/:wid/chat | Chat connections | Session |
PUT | /api/w/:wid/chat/settings | Set the chat line | Session |
PUT | /api/w/:wid/chat/:provider | Configure Slack or Teams | Session |
DELETE | /api/w/:wid/chat/:provider | Disconnect Slack or Teams | Session |
POST | /api/w/:wid/chat/:provider/test | Send a test message | Session |
GET | /api/w/:wid/chat/:provider/members | List mapped members | Session |
POST | /api/w/:wid/chat/:provider/members | Map one member | Session |
POST | /api/w/:wid/chat/:provider/members/sync | Map every member by email | Session |
DELETE | /api/w/:wid/chat/:provider/members/:externalId | Unmap a member | Session |
POST | /teams/messages | Create message | Public |
#Machine admin
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/service-tokens | List service tokens | Session |
POST | /api/w/:wid/service-tokens | Create a service token | Session |
DELETE | /api/w/:wid/service-tokens/:tid | Revoke a service token | Session |
GET | /v1/admin/agents | List agents (machine) | Service token |
POST | /v1/admin/agents | Register an agent from a blueprint | Service token |
POST | /v1/admin/agents/:aid/freeze | Freeze an agent (machine) | Service token |
POST | /v1/admin/freeze | Freeze agents in bulk (machine) | Service token |
POST | /v1/admin/drills | Run a drill (machine) | Service token |
GET | /v1/admin/approvals | Waiting approvals (machine) | Service token |
GET | /v1/admin/scorecard | Scorecard (machine) | Service token |
GET | /v1/admin/evidence/bundle | Evidence bundle (machine) | Service token |
#Developer CLI
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /oauth/device | Start a CLI sign-in | Public |
GET | /api/me/device | Look up a CLI sign-in code | Session |
POST | /api/me/device | Allow or deny a CLI sign-in | Session |
GET | /api/me/cli-tokens | Your CLI sign-ins | Session |
DELETE | /api/me/cli-tokens/:tid | End one of your CLI sign-ins | Session |
GET | /api/w/:wid/cli-tokens | The workspace’s CLI sign-ins | Session |
POST | /api/w/:wid/cli-tokens | Make a CI token in the console | Session |
DELETE | /api/w/:wid/cli-tokens/:tid | End a CLI sign-in | Session |
GET | /v1/cli/whoami | Who the CLI token acts for | CLI token |
GET | /v1/cli/purposes | What an agent can be for | CLI token |
GET | /v1/cli/agents | List agents | CLI token |
POST | /v1/cli/agents | Add an agent with its rule and key | CLI token |
GET | /v1/cli/status | Waiting approvals, today, this month | CLI token |
GET | /v1/cli/evidence/ai-act | EU AI Act deployer evidence pack | CLI token |
POST | /v1/cli/tokens | Make a CI token | CLI token |
GET | /v1/cli/tokens | List your CLI tokens | CLI token |
DELETE | /v1/cli/tokens/:tid | Revoke one of your CLI tokens | CLI token |
DELETE | /v1/cli/token | Revoke this CLI token | CLI token |
GET | /v1/cli/agent-key | Check an agent key | Agent key |
POST | /v1/cli/test | Make the setup test call | Agent key |
#Finance
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid/finance/summary | Finance summary | Session |
GET | /api/w/:wid/finance/reconciliation | Reconciliation | Session |
POST | /api/w/:wid/finance/reconciliation | Upload a provider billing export | Session |
GET | /api/w/:wid/finance/admin-keys | Provider admin keys | Session |
PUT | /api/w/:wid/finance/admin-keys/:provider | Save a provider admin key | Session |
DELETE | /api/w/:wid/finance/admin-keys/:provider | Remove a provider admin key | Session |
PUT | /api/w/:wid/finance/gateway-keys | Map gateway keys for finance | Session |
PUT | /api/w/:wid/finance/teams/:tid/cost-centre | Set a team’s cost centre | Session |
GET | /api/w/:wid/finance/chargebacks | Chargebacks | Session |
GET | /api/w/:wid/finance/chargebacks.csv | Chargebacks as CSV | Session |
GET | /api/w/:wid/finance/forecast | Forecast | Session |
GET | /api/w/:wid/finance/anomalies | Anomalies | Session |
GET | /api/w/:wid/finance/alerts | List alert rules | Session |
POST | /api/w/:wid/finance/alerts | Create an alert rule | Session |
PATCH | /api/w/:wid/finance/alerts/:rid | Update an alert rule | Session |
DELETE | /api/w/:wid/finance/alerts/:rid | Delete an alert rule | Session |
POST | /api/w/:wid/finance/alerts/evaluate | Evaluate alert rules now | Session |
POST | /api/w/:wid/finance/alerts/test | Send a test alert | Session |
PUT | /api/w/:wid/finance/slack | Set the finance Slack webhook | Session |
DELETE | /api/w/:wid/finance/slack | Remove the finance Slack webhook | Session |
#The AI check
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /api/check/upload | Create upload | Public |
POST | /api/w/:wid/check | Create check | Session |
GET | /api/w/:wid/check/latest | Get latest | Session |
GET | /api/check/:token | Retrieve check | Public |
#Security and sign-in
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /api/auth/mfa | Complete sign-in with a code | Public |
POST | /api/auth/mfa/enrol | Start two-factor during sign-in | Public |
POST | /api/auth/mfa/enrol/confirm | Confirm two-factor during sign-in | Public |
GET | /api/me/mfa | Two-factor status | Session |
POST | /api/me/mfa/enrol | Start two-factor enrolment | Session |
POST | /api/me/mfa/confirm | Confirm two-factor enrolment | Session |
POST | /api/me/mfa/disable | Turn two-factor off | Session |
POST | /api/me/mfa/recovery-codes | Replace recovery codes | Session |
GET | /api/w/:wid/sso | Single sign-on configuration | Session |
PUT | /api/w/:wid/sso | Configure single sign-on | Session |
DELETE | /api/w/:wid/sso | Remove single sign-on | Session |
POST | /api/w/:wid/sso/domains/:domain/verify | Verify a single sign-on domain | Session |
GET | /sso/start | Start single sign-on | Public |
GET | /sso/saml/:wid/metadata | Get metadata | Public |
POST | /sso/saml/:wid/acs | Create ac | Public |
POST | /api/w/:wid/sso/saml/test | Test saml | Session |
GET | /sso/callback | Single sign-on callback | Public |
GET | /api/me/sessions | List my sessions | Session |
DELETE | /api/me/sessions/:sid | End a session | Session |
POST | /api/me/sessions/end-others | End every other session | Session |
GET | /api/auth/providers | List sign-in options | Public |
GET | /auth/oidc/:provider/start | Sign in with a provider | Public |
GET | /auth/oidc/:provider/callback | Provider sign-in callback | Public |
POST | /api/auth/email/start | Email a sign-in link and code | Public |
GET | /api/auth/email/lookup | Look up a sign-in link | Public |
POST | /api/auth/email/verify | Sign in with an email link or code | Public |
POST | /api/auth/passkey/options | Passkey sign-in challenge | Public |
POST | /api/auth/passkey/verify | Sign in with a passkey | Public |
POST | /api/auth/mfa/passkey/options | Passkey second-factor challenge | Public |
POST | /api/auth/mfa/passkey | Complete sign-in with a passkey | Public |
GET | /api/me/passkeys | List my passkeys | Session |
POST | /api/me/passkeys/options | Passkey registration options | Session |
POST | /api/me/passkeys | Register a passkey | Session |
PATCH | /api/me/passkeys/:id | Rename a passkey | Session |
DELETE | /api/me/passkeys/:id | Remove a passkey | Session |
GET | /api/me/identities | List linked sign-ins | Session |
DELETE | /api/me/identities/:provider | Unlink a sign-in | Session |
GET | /api/w/:wid/security | Workspace security policy | Session |
GET | /api/w/:wid/security/posture.pdf | Get posture (pdf) | Session |
PUT | /api/w/:wid/security | Set the workspace security policy | Session |
#OAuth for MCP clients
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /.well-known/oauth-authorization-server | OAuth server metadata | Public |
GET | /.well-known/oauth-authorization-server/mcp | OAuth server metadata (MCP path) | Public |
GET | /.well-known/openid-configuration/mcp | OpenID configuration (MCP path) | Public |
GET | /.well-known/oauth-protected-resource | Protected resource metadata | Public |
GET | /.well-known/oauth-protected-resource/mcp | Protected resource metadata (MCP path) | Public |
POST | /oauth/register | Register an OAuth client | OAuth |
POST | /oauth/token | Exchange or refresh a token | OAuth |
POST | /oauth/revoke | Revoke a token | OAuth |
GET | /oauth/authorize | Consent page | Session |
POST | /oauth/authorize | Give consent | Session |
GET | /oauth/platform/authorize | Authorize platform | OAuth |
POST | /oauth/platform/authorize | Authorize platform | OAuth |
#Accounts
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /api/auth/signup | Sign up | Public |
POST | /api/auth/login | Sign in with a password | Public |
POST | /api/auth/logout | Sign out | Session |
POST | /api/auth/verify | Verify an email address | Public |
POST | /api/auth/resend-verification | Resend the verification email | Public |
POST | /api/auth/forgot | Request a password reset | Public |
POST | /api/auth/reset | Reset a password | Public |
GET | /api/auth/invite | Look up an invitation | Public |
POST | /api/auth/accept-invite | Accept an invitation | Public |
GET | /api/me | Retrieve the signed-in person | Session |
PATCH | /api/me | Update the signed-in person | Session |
POST | /api/workspaces | Create a workspace | Session |
POST | /api/me/step-up/options | Create option | Session |
POST | /api/me/step-up | Create step up | Session |
GET | /api/me/join-requests | List join requests | Session |
GET | /api/me/email-preferences | List email preferences | Session |
PUT | /api/me/email-preferences | Set email preferences | Session |
GET | /api/me/erasures | List erasures | Session |
POST | /api/me/erasures/:wid/cancel | Cancel erasure | Session |
GET | /api/me/erasures/:wid/certificate.pdf | Get certificate (pdf) | Session |
#Mobile and push
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /api/mobile/v1/auth/email/start | Phone sign-in: email a code | Public |
POST | /api/mobile/v1/auth/email/verify | Phone sign-in: verify the code | Public |
POST | /api/mobile/v1/auth/token | Phone sign-in: exchange for a device token | Public |
POST | /api/mobile/v1/auth/revoke | Sign this phone out | Device |
GET | /api/mobile/v1/me | The phone’s person | Device |
GET | /api/mobile/v1/devices | List my phones | Device |
DELETE | /api/mobile/v1/devices/:id | Sign a phone out | Device |
POST | /api/mobile/v1/devices/current/push | Register this phone for push | Device |
GET | /api/mobile/v1/approvals | Approvals waiting for me | Device |
GET | /api/mobile/v1/w/:wid/approvals/:apid | Retrieve an approval (phone) | Device |
POST | /api/mobile/v1/w/:wid/approvals/:apid/step-up | Step up to approve | Device |
POST | /api/mobile/v1/w/:wid/approvals/:apid/decide | Decide an approval (phone) | Device |
GET | /api/mobile/v1/agents | My agents (phone) | Device |
POST | /api/mobile/v1/w/:wid/agents/:aid/freeze | Freeze an agent (phone) | Device |
GET | /api/push/key | Web Push public key | Session |
GET | /api/push/subscriptions | List push subscriptions | Session |
POST | /api/push/subscriptions | Subscribe this browser to push | Session |
DELETE | /api/push/subscriptions | Unsubscribe this browser | Session |
POST | /api/push/test | Send a test notification | Session |
#Workspace
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/w/:wid | Retrieve a workspace | Session |
PATCH | /api/w/:wid | Update a workspace | Session |
DELETE | /api/w/:wid | Delete a workspace | Session |
GET | /api/w/:wid/overview | Workspace overview | Session |
GET | /api/w/:wid/reports/:kind | Read a report | Session |
GET | /api/w/:wid/assessment | Shadow assessment | Session |
GET | /api/w/:wid/keys | List gateway keys | Session |
POST | /api/w/:wid/keys | Issue a gateway key | Session |
DELETE | /api/w/:wid/keys/:kid | Revoke a gateway key | Session |
GET | /api/w/:wid/teams | List teams | Session |
POST | /api/w/:wid/teams | Create a team | Session |
PATCH | /api/w/:wid/teams/:tid | Update a team | Session |
GET | /api/w/:wid/principals | List principals | Session |
POST | /api/w/:wid/principals | Create a principal | Session |
PATCH | /api/w/:wid/principals/:pid | Update a principal | Session |
GET | /api/w/:wid/members | List members | Session |
GET | /api/w/:wid/members/access-review.csv | List access review (csv) | Session |
DELETE | /api/w/:wid/invites/:email | Delete invite | Session |
POST | /api/w/:wid/members | Invite a member | Session |
PATCH | /api/w/:wid/members/:uid | Change a member’s role | Session |
DELETE | /api/w/:wid/members/:uid | Remove a member | Session |
GET | /api/w/:wid/budgets | List budgets | Session |
POST | /api/w/:wid/budgets | Set a budget | Session |
DELETE | /api/w/:wid/budgets/:scope/:scopeId | Delete budget | Session |
GET | /api/w/:wid/settings | Workspace settings | Session |
PUT | /api/w/:wid/settings | Change workspace settings | Session |
GET | /api/w/:wid/providers | List provider connections | Session |
PUT | /api/w/:wid/providers/:provider | Save a provider key | Session |
GET | /api/w/:wid/models | Models in this workspace | Session |
POST | /api/w/:wid/models/:action | Change a model’s availability | Session |
GET | /api/w/:wid/integrations | List integrations | Session |
POST | /api/w/:wid/integrations/github | Connect GitHub | Session |
DELETE | /api/w/:wid/integrations/github | Disconnect GitHub | Session |
GET | /api/w/:wid/billing | Billing | Session |
POST | /api/w/:wid/billing/checkout | Start checkout | Session |
POST | /api/w/:wid/billing/portal | Open the billing portal | Session |
GET | /api/w/:wid/agents/:aid/money | An agent’s spent and left | Session |
POST | /api/w/:wid/agents/:aid/budget-increase | Ask for a temporary increase | Session |
GET | /api/w/:wid/proposals | List proposals | Session |
GET | /api/w/:wid/proposals/:pid | Retrieve proposal | Session |
POST | /api/w/:wid/proposals/:pid/confirm | Confirm proposal | Session |
POST | /api/w/:wid/proposals/:pid/dismiss | Dismiss proposal | Session |
GET | /api/w/:wid/inventory | Get inventory | Session |
GET | /api/w/:wid/inventory/export.cdx.json | List export.cdx (json) | Session |
PUT | /api/w/:wid/inventory/sources/:source | Set source | Session |
POST | /api/w/:wid/inventory/sources/:source/connect | Create connect | Session |
POST | /api/w/:wid/inventory/sources/:source/sync | Sync source | Session |
DELETE | /api/w/:wid/inventory/sources/:source | Delete source | Session |
GET | /api/w/:wid/inventory/:id | Retrieve inventory | Session |
PATCH | /api/w/:wid/inventory/:id | Update inventory | Session |
POST | /api/w/:wid/inventory/:id/govern | Create govern | Session |
POST | /api/w/:wid/inventory/:id/ignore | Create ignore | Session |
POST | /api/w/:wid/inventory/:id/decommission | Create decommission | Session |
POST | /api/w/:wid/inventory/:id/agent-card | Create agent card | Session |
GET | /api/w/:wid/connect | Get connect | Session |
GET | /api/w/:wid/integrations/catalogue | Get catalogue | Session |
POST | /api/w/:wid/connect/openrouter | Create openrouter | Session |
POST | /api/w/:wid/connect/ramp | Create ramp | Session |
POST | /api/w/:wid/connect/mcp/:uid | Post to mcp | Session |
POST | /api/w/:wid/connect/github | Create github | Session |
DELETE | /api/w/:wid/connect/github | Remove github | Session |
GET | /api/w/:wid/teams/app-package | Get app package | Session |
GET | /api/w/:wid/teams/link/:state | Retrieve link | Session |
POST | /api/w/:wid/teams/link | Create link | Session |
GET | /api/w/:wid/finops | List finops | Session |
POST | /api/w/:wid/accounting/:provider/connect | Create connect | Session |
GET | /api/w/:wid/accounting/:provider | Retrieve accounting | Session |
GET | /api/w/:wid/accounting/:provider/accounts | List accounts | Session |
PUT | /api/w/:wid/accounting/:provider/mapping | Set mapping | Session |
POST | /api/w/:wid/accounting/:provider/close | Create close | Session |
DELETE | /api/w/:wid/accounting/:provider | Delete accounting | Session |
POST | /api/w/:wid/alerting/pagerduty/connect | Create connect | Session |
GET | /api/w/:wid/alerting/pagerduty/services | List services | Session |
POST | /api/w/:wid/alerting/pagerduty/service | Create service | Session |
GET | /api/w/:wid/alerting/:dest | Retrieve alerting | Session |
PUT | /api/w/:wid/alerting/:dest | Set alerting | Session |
PATCH | /api/w/:wid/alerting/:dest | Update alerting | Session |
POST | /api/w/:wid/alerting/:dest/test | Test alerting | Session |
POST | /api/w/:wid/alerting/:dest/retry | Create retry | Session |
DELETE | /api/w/:wid/alerting/:dest | Delete alerting | Session |
GET | /api/w/:wid/directory | Get directory | Session |
POST | /api/w/:wid/directory/scim/token | Create token | Session |
DELETE | /api/w/:wid/directory/scim/token | Remove token | Session |
POST | /api/w/:wid/directory/:provider/connect | Create connect | Session |
GET | /api/w/:wid/directory/:provider/review | Get review | Session |
POST | /api/w/:wid/directory/:provider/review | Create review | Session |
POST | /api/w/:wid/directory/:provider/sync | Sync directory | Session |
DELETE | /api/w/:wid/directory/:provider | Delete directory | Session |
GET | /api/w/:wid/onboarding | Get onboarding | Session |
PATCH | /api/w/:wid/onboarding | Update onboarding | Session |
POST | /api/w/:wid/onboarding/rules/preview | Preview rule | Session |
PUT | /api/w/:wid/onboarding/rules | Set rules | Session |
POST | /api/w/:wid/onboarding/rules | Create rule | Session |
GET | /api/w/:wid/onboarding/example | Get example | Session |
GET | /api/w/:wid/onboarding/would-hold | Get would hold | Session |
POST | /api/w/:wid/onboarding/spend-handoff | Create spend handoff | Session |
POST | /api/w/:wid/onboarding/engineer-invite | Create engineer invite | Session |
POST | /api/w/:wid/onboarding/invite | Create invite | Session |
GET | /api/w/:wid/onboarding/engineer | Get engineer | Session |
POST | /api/w/:wid/onboarding/agents | Create agent | Session |
POST | /api/w/:wid/onboarding/agents/:aid/handoff | Create handoff | Session |
POST | /api/w/:wid/onboarding/agents/:aid/handoff/email | Create email | Session |
GET | /api/w/:wid/rules | List rules | Session |
GET | /api/w/:wid/home | Get home | Session |
GET | /api/w/:wid/dashboards | List dashboards | Session |
GET | /api/w/:wid/dashboards/daily | Get daily | Session |
GET | /api/w/:wid/dashboards/csv/:view | Retrieve csv | Session |
POST | /api/w/:wid/dashboards/sheets/connect | Create connect | Session |
POST | /api/w/:wid/dashboards/sheets/sync | Sync sheet | Session |
DELETE | /api/w/:wid/dashboards/sheets | Remove sheets | Session |
GET | /api/w/:wid/dashboards/board-links | List board links | Session |
POST | /api/w/:wid/dashboards/board-links | Create board link | Session |
DELETE | /api/w/:wid/dashboards/board-links/:id | Delete board link | Session |
DELETE | /api/w/:wid/dashboards/board-links | Remove board links | Session |
GET | /api/w/:wid/crypto/payments | List payments | Session |
GET | /api/w/:wid/wallets | List wallets | Session |
PUT | /api/w/:wid/wallets/:provider | Set wallet | Session |
DELETE | /api/w/:wid/wallets/:provider | Delete wallet | Session |
GET | /api/w/:wid/platform-apps | List platform apps | Session |
POST | /api/w/:wid/platform-apps | Create platform app | Session |
DELETE | /api/w/:wid/platform-apps/:cid | Delete platform app | Session |
GET | /api/w/:wid/platform-connections | List platform connections | Session |
DELETE | /api/w/:wid/platform-connections/:gid | Delete platform connection | Session |
GET | /api/w/:wid/members/:uid/sessions | List sessions | Session |
DELETE | /api/w/:wid/members/:uid/sessions | Remove sessions | Session |
GET | /api/w/:wid/audit/stream | Get stream | Session |
GET | /api/w/:wid/retention | Get retention | Session |
PUT | /api/w/:wid/retention | Set retention | Session |
GET | /api/w/:wid/join-requests | List join requests | Session |
POST | /api/w/:wid/join-requests | Create join request | Session |
GET | /api/w/:wid/roles | List roles | Session |
GET | /api/w/:wid/export.zip | Get export (zip) | Session |
#Public
| Method | Path | Endpoint | Auth |
|---|---|---|---|
GET | /api/public/plans | Plans | Public |
GET | /api/public/catalog | Model catalogue | Public |
GET | /api/public/task-classes | Task classes | Public |
GET | /api/public/policy-profiles | Policy profiles | Public |
GET | /api/public/clients | Recognised clients | Public |
POST | /api/leads | Contact sales | Public |
#Inbound webhooks
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /hooks/github-app | Create github app | Signature |
POST | /hooks/github/:wid | GitHub webhook | Signature |
#Health
#Other
| Method | Path | Endpoint | Auth |
|---|---|---|---|
POST | /v1/hooks/claude-code | Claude Code http hook | Workspace key |
GET | /.well-known/assay-keys.json | List assay keys (json) | Public |
GET | /connect/inventory/:source/callback | Get callback | Public |
GET | /connect/openrouter/callback/:state | Retrieve callback | Public |
GET | /connect/ramp/callback | Get callback | Public |
GET | /connect/mcp/callback | Get callback | Public |
GET | /connect/github/setup | Get setup | Public |
GET | /connect/github/callback | Get callback | Public |
GET | /connect/xero/callback | Get callback | Public |
GET | /connect/quickbooks/callback | Get callback | Public |
GET | /connect/pagerduty/callback | Get callback | Public |
GET | /scim/v2/Users | List Users | Public |
POST | /scim/v2/Users | Create User | Public |
GET | /scim/v2/Users/:id | Retrieve User | Public |
PUT | /scim/v2/Users/:id | Set User | Public |
PATCH | /scim/v2/Users/:id | Update User | Public |
DELETE | /scim/v2/Users/:id | Delete User | Public |
GET | /scim/v2/Groups | List Groups | Public |
POST | /scim/v2/Groups | Create Group | Public |
GET | /scim/v2/Groups/:id | Retrieve Group | Public |
PUT | /scim/v2/Groups/:id | Set Group | Public |
PATCH | /scim/v2/Groups/:id | Update Group | Public |
DELETE | /scim/v2/Groups/:id | Delete Group | Public |
GET | /scim/v2/ServiceProviderConfig | Get ServiceProviderConfig | Public |
GET | /scim/v2/ResourceTypes | List ResourceTypes | Public |
GET | /scim/v2/ResourceTypes/:id | Retrieve ResourceType | Public |
GET | /scim/v2/Schemas | List Schemas | Public |
GET | /scim/v2/Schemas/:id | Retrieve Schema | Public |
GET | /scim/v2/* | Get v2 | Public |
POST | /scim/v2/* | Create v2 | Public |
PUT | /scim/v2/* | Set v2 | Public |
PATCH | /scim/v2/* | Update v2 | Public |
DELETE | /scim/v2/* | Remove v2 | Public |
GET | /directory/google/callback | Get callback | Public |
GET | /directory/microsoft/callback | Get callback | Public |
GET | /handoff/:token | Retrieve handoff | Public |
POST | /handoff/:token | Post to handoff | Public |
GET | /handoff/spend/:token | Retrieve spend | Public |
POST | /handoff/spend/:token | Post to spend | Public |
GET | /connect/google-sheets/callback | Get callback | Public |
POST | /wallets/:wid/fireblocks/v2/tx_sign_request | Create tx sign request | Public |
GET | /v1/platform/workspace | Get workspace | Workspace key |
GET | /v1/platform/purposes | List purposes | Workspace key |
GET | /v1/platform/agents | List agents | Workspace key |
POST | /v1/platform/agents | Create agent | Workspace key |
GET | /email/unsubscribe | Get unsubscribe | Public |
POST | /email/unsubscribe | Create unsubscribe | Public |
GET | /trust/pack.zip | Get pack (zip) | Public |
GET | /version | Get version | Public |
GET | /docs.md | Get docs (md) | Public |
GET | /llms-full/:file | Retrieve llms full | Public |
GET | /install.sh | Get install (sh) | Public |
GET | /install.ps1 | Get install (ps1) | Public |
GET | /.well-known/mcp/server-card.json | MCP server card (well-known) | Public |
GET | /.well-known/mcp.json | MCP server card (older path) | Public |
GET | /.well-known/ai-catalog.json | AI catalog | Public |
GET | /.well-known/mcp-registry-auth | MCP Registry domain proof | Public |
GET | /.well-known/openai-apps-challenge | OpenAI app review domain token | Public |
GET | /case | Get case | Public |
GET | /builders | List builders | Public |
GET | /check | Get check | Public |
GET | /check/r/:ref | Retrieve r | Public |
GET | /check/r/:ref/pdf | Get pdf | Public |
GET | /launch | Get launch | Public |
GET | /demo | Get demo | Public |
GET | /apply/startup | Get startup | Public |
GET | /apply/scale | Get scale | Public |
GET | /signin | Get signin | Public |
GET | /terms | List terms | Public |
GET | /privacy | Get privacy | Public |
GET | /dpa | Get dpa | Public |
GET | /acceptable-use | Get acceptable use | Public |
GET | /sub-processors | List sub processors | Public |
GET | /subprocessors | List subprocessors | Public |
GET | /buy | Get buy | Public |