Skip to content

Admin API

Reference

Generated source hash: sha256:22a78e07be1689f1de50d76f80bd976d7c2aeb806cefe014236eb1c331d12032.

  • Developers integrating with control-plane workflows.
  • Operators checking endpoint shape before using automation.
  • Security reviewers checking that public docs do not invent routes.

This page is generated from contracts/openapi/admin-api.yaml. It lists Admin API operations, grouped by product domain. It is a contract map, not a live API console.

Use it when you need route, method, operation ID, response-code, or schema-reference names for control-plane workflows. Do not use this page as proof of authorization behavior; use the product page and runbook for that workflow.

  • 271 operations are read from the OpenAPI paths object.
  • Operation IDs and summaries are copied from the spec.
  • Schema references point back to OpenAPI components; JSON Schema references are listed on Schemas.
  • No live unauthenticated Try It widget is generated.
MethodPathOperationSummaryResponses
GET/v1/admin/role-bindingslistRoleBindingsList gateway role bindings for the active tenant.200
POST/v1/admin/role-bindingscreateRoleBindingCreate a gateway role binding.201
POST/v1/admin/role-bindings/previewpreviewRoleBindingsPreview effective roles and collection permissions for a normalized actor context.200
PATCH/v1/admin/role-bindings/{binding_id}patchRoleBindingUpdate a gateway role binding.200
POST/v1/admin/role-bindings/{binding_id}/disabledisableRoleBindingDisable a gateway role binding immediately.200
MethodPathOperationSummaryResponses
GET/v1/admin-activitylistAdminActivityList curated admin activity rows backed by sanitized durable audit events.200, 400, 403
GET/v1/admin-activity/{audit_event_id}getAdminActivityRead one curated admin activity detail by audit event ID.200, 400, 403, 404
MethodPathOperationSummaryResponses
GET/v1/agentslistAgentsList governed agent registry records with pagination, facets, search, and per-row permissions.200
POST/v1/agentscreateAgentSubmit an agent registry record for security approval. Created records are non-callable until approved.202, 409
GET/v1/agents/{agent_id}getAgentRegistryRecordRead agent registry metadata, lifecycle state, allowed surfaces, environments, and instance identity.200
PATCH/v1/agents/{agent_id}patchAgentRegistryRecordEdit agent governance metadata without making the agent callable unless it remains approved.202
POST/v1/agents/{agent_id}/approvaltransitionAgentApprovalMove an agent through approval, disabled, deprecated, or archived states.202
POST/v1/agents/{agent_id}/revokerevokeAgentDisable an agent, append agent revocation outbox metadata, revoke affected active sessions, and audit the admin action.202
MethodPathOperationSummaryResponses
GET/v1/approvalslistApprovalsQueueList reviewable submissions (decision workbench) across the tenant, all environments.200
POST/v1/approvals/batchbatchApproveRegistrySubmissionsBatch approve eligible MCP server submissions using submission_id and manifest_hash pins.202
MethodPathOperationSummaryResponses
POST/v1/audit/searchsearchAuditSearch tool, policy, session, credential, API adapter, and admin audit events.200, 403
POST/v1/audit/exportscreateAuditExportCreate an async metadata-only audit evidence export job.202, 400, 403, 422, 429
GET/v1/audit/exports/{export_id}getAuditExportRead audit export job status and evidence metadata.200, 403, 404
GET/v1/audit/exports/{export_id}/downloaddownloadAuditExportDownload a completed audit export artifact.200, 403, 404, 409, 410
GET/v1/audit/requests/{request_id}getAuditRequestBundleRead the ordered audit event chain for one runtime request.200, 403
MethodPathOperationSummaryResponses
GET/v1/client-surfaceslistClientSurfacesList canonical client surfaces visible in the requesting tenant and environment.200, 400, 403
GET/v1/client-surfaces/{client_surface_id}getClientSurfaceRead canonical client-surface metadata for simulator, agent, audit, and emergency workflows.200, 403, 404
POST/v1/client-surfaces/{client_surface_id}/lifecycletransitionClientSurfaceLifecycleSafely disable or revoke a client surface, audit the reason, and publish revocation impact.202, 400, 403, 404
MethodPathOperationSummaryResponses
GET/v1/consumer-oauth/authorization-server-profileslistConsumerAuthorizationServerProfilesList tenant-scoped OAuth authorization-server profiles.200, 403
POST/v1/consumer-oauth/authorization-server-profilescreateConsumerAuthorizationServerProfileCreate a draft OAuth authorization-server profile.201, 403, 422
GET/v1/consumer-oauth/authorization-server-profiles/{profile_id}getConsumerAuthorizationServerProfileRead one OAuth authorization-server profile.200, 403, 404
PATCH/v1/consumer-oauth/authorization-server-profiles/{profile_id}updateConsumerAuthorizationServerProfileUpdate a draft, disabled, or version-compatible OAuth authorization-server profile.200, 403, 404, 409, 422
POST/v1/consumer-oauth/authorization-server-profiles/{profile_id}/lifecycletransitionConsumerAuthorizationServerProfileValidate, activate, disable, re-enable, roll back, or retire an OAuth authorization-server profile.202, 403, 404, 409, 422
POST/v1/consumer-oauth/authorization-server-profiles/{profile_id}/diagnosticsdiagnoseConsumerAuthorizationServerProfileRefresh and report safe OAuth metadata, JWKS, claim-mapping, and interoperability diagnostics.200, 403, 404
POST/v1/consumer-oauth/authorization-server-profiles/{profile_id}/diagnostics/tokentestConsumerOAuthAccessTokenTest a sample OAuth access token against a profile and endpoint binding.200, 403, 404, 422
GET/v1/consumer-oauth/resource-auth-bindingslistMcpResourceAuthBindingsList endpoint-scoped consumer-auth bindings.200, 403
POST/v1/consumer-oauth/resource-auth-bindingscreateMcpResourceAuthBindingCreate a draft endpoint consumer-auth binding.201, 403, 409, 422
GET/v1/consumer-oauth/resource-auth-bindings/{binding_id}getMcpResourceAuthBindingRead one endpoint consumer-auth binding.200, 403, 404
PATCH/v1/consumer-oauth/resource-auth-bindings/{binding_id}updateMcpResourceAuthBindingUpdate a version-compatible endpoint consumer-auth binding.200, 403, 404, 409, 422
POST/v1/consumer-oauth/resource-auth-bindings/{binding_id}/lifecycletransitionMcpResourceAuthBindingActivate, disable, roll back, or retire an endpoint consumer-auth binding.202, 403, 404, 409, 422
GET/v1/consumer-oauth/resource-auth-bindings/{binding_id}/protected-resource-metadatapreviewMcpProtectedResourceMetadataPreview the RFC 9728 metadata and path-specific metadata URL for an endpoint binding.200, 403, 404
GET/v1/consumer-oauth/resource-auth-bindings/{binding_id}/migration-statusgetConsumerOAuthMigrationStatusRead persisted migration evidence for one endpoint auth binding.200, 403, 404, 409
POST/v1/consumer-oauth/revocations/previewpreviewConsumerOAuthRevocationPreview sessions, cached credentials, and data-plane instances affected by an OAuth revocation.200, 403, 422
GET/v1/consumer-oauth/revocationslistConsumerOAuthRevocationsSearch OAuth revocations and propagation status by governed identity or endpoint dimensions.200, 403
POST/v1/consumer-oauth/revocationscreateConsumerOAuthRevocationRevoke a principal, OAuth client, auth profile, agent, workload, endpoint, or session.202, 403, 422
GET/v1/consumer-oauth/revocations/{revocation_id}getConsumerOAuthRevocationRead OAuth revocation propagation status.200, 403, 404
GET/v1/consumer-oauth/upstream-providerslistUpstreamOAuthProvidersList tenant-scoped upstream OAuth provider metadata.200, 403
POST/v1/consumer-oauth/upstream-providerscreateUpstreamOAuthProviderCreate a draft upstream OAuth provider.201, 403, 409, 422
GET/v1/consumer-oauth/upstream-providers/{provider_id}getUpstreamOAuthProviderRead one upstream OAuth provider.200, 403, 404
PATCH/v1/consumer-oauth/upstream-providers/{provider_id}updateUpstreamOAuthProviderUpdate a version-compatible upstream OAuth provider.200, 403, 404, 409, 422
POST/v1/consumer-oauth/upstream-providers/{provider_id}/lifecycletransitionUpstreamOAuthProviderValidate, activate, disable, re-enable, or retire an upstream OAuth provider.202, 403, 404, 409, 422
POST/v1/consumer-oauth/upstream-providers/{provider_id}/diagnosticsdiagnoseUpstreamOAuthProviderTest target-bound upstream token acquisition without calling a production tool.200, 403, 404, 422
GET/v1/consumer-oauth/upstream-grantslistUpstreamOAuthGrantsList metadata-only user upstream OAuth grant and refresh health.200, 403
POST/v1/consumer-oauth/upstream-grants/authorizationsinitiateUpstreamOAuthGrantAuthorizationCreate a short-lived user-bound upstream OAuth authorization.201, 401, 403, 409, 422
GET/v1/consumer-oauth/upstream-grants/authorizations/connectconnectUpstreamOAuthGrantFromRuntimeTicketStart upstream authorization from a short-lived runtime ticket.303, 401, 404, 409, 422
GET/v1/consumer-oauth/upstream-grants/authorizations/{authorization_id}/connectconnectUpstreamOAuthGrantAuthorizationVerify the initiating user before redirecting to the upstream authorization server.303, 401, 404, 409
GET/v1/consumer-oauth/upstream-grants/authorizations/callbackcompleteUpstreamOAuthGrantAuthorizationComplete a PKCE-bound upstream OAuth authorization callback.200, 401, 404, 409, 422
GET/v1/consumer-oauth/upstream-grants/{grant_id}getUpstreamOAuthGrantRead one metadata-only upstream OAuth grant.200, 403, 404
POST/v1/consumer-oauth/upstream-grants/{grant_id}/disconnectdisconnectUpstreamOAuthGrantDisconnect and revoke an upstream OAuth grant.202, 403, 404, 409
MethodPathOperationSummaryResponses
GET/v1/credential-bindingslistCredentialBindingsList credential binding metadata with server-side search, filters, KPIs, facets, and permissions.200
POST/v1/credential-bindingscreateCredentialBindingSubmit a credential binding record for security approval without exposing credential material.202
GET/v1/credential-bindings/{credential_binding_id}getCredentialBindingRead credential binding detail, approved projection, broker check, activity, and permissions.200, 403
PATCH/v1/credential-bindings/{credential_binding_id}updateCredentialBindingUpdate credential binding metadata or submit approval-impacting changes for re-review.202, 403
POST/v1/credential-bindings/{credential_binding_id}/approvaltransitionCredentialBindingApprovalMove a credential binding through approval states. Disable/revoke use dedicated endpoints.202, 403
POST/v1/credential-bindings/{credential_binding_id}/rotaterotateCredentialBindingRotate credential binding reference metadata without accepting credential material.202, 403
POST/v1/credential-bindings/{credential_binding_id}/disabledisableCredentialBindingDisable a credential binding so new broker resolutions and upstream calls fail closed.202, 403
POST/v1/credential-bindings/{credential_binding_id}/revokerevokeCredentialBindingRevoke a credential binding, emit revocation fanout, and terminate affected sessions.202, 403
POST/v1/credential-bindings/{credential_binding_id}/rollbackrollbackCredentialBindingActivate a prior immutable approved credential-binding version.202, 403, 404, 409
MethodPathOperationSummaryResponses
GET/v1/data-planesgetDataPlanesList data-plane topology and health metadata for a tenant/environment scope.200, 403
GET/v1/data-planes/{data_plane_id}getDataPlaneInspect one data plane with topology, health, sync, sessions, drain, upgrade, backup, and trust-boundary metadata.200, 403, 404
MethodPathOperationSummaryResponses
POST/v1/deny-diagnosticscreateDenyDiagnosticsBundleBuild a metadata-only deny diagnostics bundle from a denied request, audit event, or explicit actor/tool context.200, 400, 403, 404
POST/v1/deny-diagnostics/remediationslistDenyDiagnosticsRemediationsList the bounded set of mechanical remediation options for one denial.200, 400, 403, 404
POST/v1/deny-diagnostics/remediation-impactevaluateDenyDiagnosticsRemediationImpactEvaluate a candidate policy manifest against the denial, comparable stored denials, and other subjects.200, 400, 403, 404
MethodPathOperationSummaryResponses
GET/v1/deployment/statusgetDeploymentStatusInspect data plane, database, cache, connector, topology, telemetry, and version status.200
GET/v1/control-plane/scopegetControlPlaneScopeRead the backend-resolved tenant and environment scope for UI registration workflows.200
MethodPathOperationSummaryResponses
POST/v1/emergency-disableemergencyDisableDisable a server, tool, API source, agent, credential, connector, or client surface.202
MethodPathOperationSummaryResponses
GET/v1/environmentslistEnvironmentsList tenant environments for settings/topology awareness without changing current scope.200, 403
GET/v1/environments/{environment_id}getEnvironmentRead one tenant-scoped environment settings record without switching UI scope.200, 403, 404
MethodPathOperationSummaryResponses
GET/v1/gateway-managed-secretslistManagedSecretsList gateway-managed secret metadata for the scope.200, 403
POST/v1/gateway-managed-secretscreateManagedSecretVault a secret value with the gateway.201, 400, 403, 503
MethodPathOperationSummaryResponses
GET/v1/mcp-serverslistMcpServerRegistryRecordsList MCP server registry records with UI-ready envelope metadata.200
POST/v1/mcp-serversregisterMcpServerRegister or submit an MCP server manifest for approval.202
GET/v1/mcp-servers/{server_id}getMcpServerRegistryRecordRead an MCP server registry record with owner, health, approval, and history.200
PATCH/v1/mcp-servers/{server_id}/catalog-visibilitypatchMcpServerCatalogVisibilityChange owner-curated catalog visibility for an MCP server and append durable admin audit.200, 403
GET/v1/mcp-servers/{server_id}/activitylistMcpServerActivityRead typed MCP server activity from submission, snapshot, and change metadata.200
GET/v1/mcp-servers/{server_id}/policy-credentialsgetMcpServerPolicyCredentialsRead backend-owned policy, credential, connector, and access posture for one MCP server.200, 403, 404
GET/v1/mcp-servers/{server_id}/usagegetMcpServerUsageRead backend-owned usage rollups for one MCP server.200, 400, 403, 404
POST/v1/mcp-servers/{server_id}/validatevalidateMcpServerManifestValidate a proposed manifest for a specific MCP server.200
PATCH/v1/mcp-servers/{server_id}/ownereditMcpServerOwnerSubmit an immutable owner metadata edit for an MCP server.202, 403
POST/v1/mcp-servers/{server_id}/registration-status/deprecatedeprecateMcpServerRegistrationStatusSubmit an immutable registration_status=deprecated edit for an MCP server.202
GET/v1/mcp-servers/{server_id}/pending-submission/compare-livecompareMcpServerPendingSubmissionToLiveCompare the pending MCP server submission against the live snapshot.200
POST/v1/mcp-servers/{server_id}/approvaltransitionMcpServerApprovalCompatibility shim for non-terminal review and live-resource lifecycle transitions; approval/rejection require submission_id and manifest_hash.202
POST/v1/mcp-servers/{server_id}/submissionssubmitMcpServerManifestRevisionSubmit a new immutable manifest for an existing MCP server without changing the live snapshot.202
GET/v1/mcp-servers/{server_id}/submissionslistMcpServerSubmissionsList immutable MCP server submissions for audit and review context.200
GET/v1/mcp-servers/{server_id}/submissions/{submission_id}getMcpServerSubmissionRead one immutable MCP server submission and its safe manifest snapshot.200
POST/v1/mcp-servers/{server_id}/submissions/{submission_id}/reviewreviewMcpServerSubmissionReview a specific submission by submission_id and manifest_hash; approval creates an immutable live snapshot.202, 409
POST/v1/mcp-servers/{server_id}/lifecycletransitionMcpServerLifecycleDisable or archive the live MCP server resource without changing submission history.202
GET/v1/mcp-servers/{server_id}/versionslistMcpServerVersionsList approved immutable snapshots only, newest first.200
GET/v1/mcp-servers/{server_id}/versions/comparecompareMcpServerVersionsCompare two approved backend snapshot IDs.200
GET/v1/mcp-servers/{server_id}/versions/{snapshot_id}getMcpServerVersionRead one approved immutable snapshot by snapshot_id.200
GET/v1/mcp-servers/{server_id}/healthgetMcpServerHealthQuery backend health and route availability for a registered MCP server.200
POST/v1/mcp-servers/{server_id}/reprobereprobeMcpServerRe-probe an approved registered MCP server from its immutable live snapshot.200, 403, 404, 409, 500, 503
POST/v1/mcp-servers/{server_id}/tools/{tool_name}/trytryMcpServerToolRun one governed test call against a live MCP server tool.200, 403, 404, 409
GET/v1/api-sourceslistApiSourcesList API sources for one tenant/environment with filters, facets, and safe summary metadata.200, 403
POST/v1/api-sources/previewpreviewApiSourceImportPreview an API contract import without persisting a registry record.200, 400, 403
POST/v1/api-sources/importimportOpenApiSourceImport an API contract and create gateway-hosted MCP tool candidates.202
GET/v1/api-sources/{api_source_id}getApiSourceRegistryRecordRead an API source registry record with approved operations, health, and history.200
PATCH/v1/api-sources/{api_source_id}/catalog-visibilitypatchApiSourceCatalogVisibilityChange owner-curated catalog visibility for an API source and append durable admin audit.200, 403
POST/v1/api-sources/{api_source_id}/approvaltransitionApiSourceApprovalMove an API source or selected operation through the approval lifecycle.202
GET/v1/api-sources/{api_source_id}/mappingslistApiSourceMappingsRead backend-generated API-to-MCP mappings for an API source.200, 403, 404
POST/v1/api-sources/{api_source_id}/tools/trytryApiSourceToolRun one approved API-backed tool from the authenticated console.200, 400, 403, 404
GET/v1/catalog/capabilitieslistCatalogCapabilitiesList policy-visible and owner-tier-visible capabilities for the authenticated actor.200, 401
GET/v1/catalog/capabilities/{capability_id}getCatalogCapabilityRead one visible catalog capability without revealing hidden or out-of-scope existence.200, 404
POST/v1/catalog/access-requestscreateCatalogAccessRequestRequest access to one visible catalog source or a visible tool subset.201, 404, 409
GET/v1/catalog/access-requestslistCatalogAccessRequestsList the caller’s requests or the permission-gated review queue.200, 403
POST/v1/catalog/access-requests/{request_id}/approveapproveCatalogAccessRequestApprove a pending request and publish its scoped policy grant.200, 403, 409
POST/v1/catalog/access-requests/{request_id}/denydenyCatalogAccessRequestDeny a pending request with a machine-readable reason.200, 400, 403, 409
POST/v1/catalog/access-requests/{request_id}/cancelcancelCatalogAccessRequestCancel the caller’s own pending request.200, 403, 409
GET/v1/mcp-servers/{server_id}/traffic-limitsgetMcpServerTrafficLimitRead the traffic limit profile for an MCP server.200, 403, 404
PUT/v1/mcp-servers/{server_id}/traffic-limitsupsertMcpServerTrafficLimitPublish or revise the traffic limit profile for an MCP server.200, 400, 403, 503
GET/v1/mcp-servers/{server_id}/auditgetMcpServerAuditSearch audit events for one MCP server.200, 403
GET/v1/mcp-servers/{server_id}/denied-attemptsgetMcpServerDeniedAttemptsRecent denied tool-call attempts for one MCP server, backed by audit search.200, 403
MethodPathOperationSummaryResponses
GET/v1/hosted/auth/csrfgetHostedAuthCsrfIssue a hosted auth CSRF token and HttpOnly Secure SameSite CSRF cookie.200, 403
POST/v1/hosted/auth/signupsignupHostedAuthCreate a work-domain hosted email-password account and restricted pre-activation session.201, 400, 429
POST/v1/hosted/auth/signup/resend-confirmationresendHostedSignupConfirmationNeutrally accept a hosted email confirmation resend request.200, 429
POST/v1/hosted/auth/signup/confirmconfirmHostedSignupConsume a hosted email confirmation challenge and activate membership when eligible.200
POST/v1/hosted/auth/loginloginHostedAuthCreate a hosted browser session for an email-password account.200, 429
GET/v1/hosted/auth/entry-statusgetHostedAuthEntryStatusResume the restricted hosted account-entry journey.200, 401, 403
POST/v1/hosted/auth/logoutlogoutHostedAuthRevoke the hosted browser session and clear hosted cookies.200
GET/v1/hosted/social-auth/providerslistHostedSocialAuthProvidersList hosted Google, Microsoft, and GitHub signup/login providers.200, 403
POST/v1/hosted/social-auth/beginbeginHostedSocialAuthBegin hosted Google, Microsoft, or GitHub signup/login.200, 400, 403, 429
POST/v1/hosted/social-auth/callbackcompleteHostedSocialAuthCallbackComplete a normalized hosted social auth callback in test environments.200, 400, 403
GET/v1/hosted/social-auth/google/callbackcompleteHostedGoogleSocialAuthCallbackComplete hosted Google signup/login from the provider redirect.303
GET/v1/hosted/social-auth/github/callbackcompleteHostedGithubSocialAuthCallbackComplete hosted GitHub signup/login from the provider redirect.303
POST/v1/hosted/auth/password-resetrequestHostedPasswordResetRequest a hosted password reset challenge without disclosing account existence.200, 429
POST/v1/hosted/auth/password-reset/completecompleteHostedPasswordResetConsume a single-use hosted reset challenge and set a new password.200
POST/v1/hosted/auth/password/changechangeHostedPasswordAdd or change the password for an active hosted browser session.200
GET/v1/hosted/current-usergetHostedCurrentUserRead the managed current-user identity and stable capability set.200, 401, 403
POST/v1/hosted/voice/sessioncreateHostedVoiceSessionMint a short-lived voice provider session for the active managed user.200, 401, 404
GET/v1/hosted/current-user/browser-sessionslistHostedBrowserSessionsList active browser sessions for the managed current user.200, 401
POST/v1/hosted/current-user/browser-sessions/revoke-othersrevokeOtherHostedBrowserSessionsRevoke every browser session except the current managed session.200, 403
POST/v1/hosted/current-user/membership/leaveleaveHostedOrganizationLeave the current managed organization.200, 400, 401, 403, 409
GET/v1/hosted/organization/upgrade-requestgetHostedOrganizationUpgradeRequestRead the session-derived organization upgrade-request status.200, 403
POST/v1/hosted/organization/upgrade-requestsubmitHostedOrganizationUpgradeRequestSubmit the current managed organization for manual upgrade review.200, 403
GET/v1/hosted/organization/memberslistHostedOrganizationMembersList members in the session-derived managed organization.200, 403
GET/v1/hosted/organization/members/{member_ref}getHostedOrganizationMemberRead one member in the session-derived managed organization.200, 404
DELETE/v1/hosted/organization/members/{member_ref}removeHostedOrganizationMemberRemove a member from the session-derived managed organization.200, 403, 409
PATCH/v1/hosted/organization/members/{member_ref}/rolechangeHostedOrganizationMemberRoleChange a managed organization member role.200, 403, 409
POST/v1/hosted/organization/members/{member_ref}/suspendsuspendHostedOrganizationMemberSuspend a managed organization member and revoke browser sessions.200, 403, 409
POST/v1/hosted/organization/members/{member_ref}/reactivatereactivateHostedOrganizationMemberReactivate a suspended managed organization member.200, 403, 409
POST/v1/hosted/organization/members/{member_ref}/revoke-browser-sessionsrevokeHostedOrganizationMemberBrowserSessionsRevoke all browser sessions for a managed organization member.200, 403, 409
GET/v1/hosted/account-settingsgetHostedAccountSettingsRead hosted workspace settings and account security state.200, 403
PATCH/v1/hosted/workspace-profileupdateHostedWorkspaceProfileUpdate the hosted workspace display name.200, 403
PATCH/v1/hosted/activation-policyupdateHostedActivationPolicyUpdate hosted activation policy defaults for future resource activation.200, 400, 403
POST/v1/hosted/orgs/trialscreateHostedTrialOrgCreate a hosted trial org after verified work-domain signup.201, 400, 403
GET/v1/hosted/orgs/{org_ref}getHostedOrgRead hosted org lifecycle, trial, plan, and entitlement state.200, 404
POST/v1/hosted/orgs/{org_ref}/upgrade-requestrequestHostedOrgUpgradeMark that a locked or trial org requested upgrade.202
POST/v1/hosted/orgs/{org_ref}/trial/expireexpireHostedOrgTrialForSmokeProve hosted trial expiry hard-lock for public smoke.200
POST/v1/hosted/orgs/{org_id}/trial/extendextendHostedOrgTrialDAC operator extends a hosted trial and unlocks trial entitlements.202
PUT/v1/hosted/orgs/{org_id}/plansetHostedOrgPlanDAC operator manually sets hosted plan state.202
POST/v1/hosted/orgs/{org_id}/locklockHostedOrgDAC operator locks a hosted org and disables runtime/configuration entitlements.202
POST/v1/hosted/orgs/{org_id}/restore-accessrestoreHostedOrgAccessDAC operator restores hosted org access according to current trial and plan state.202
POST/v1/hosted/email/challengescreateHostedEmailChallengeIssue a hosted-only email verification challenge.202, 503
POST/v1/hosted/email/challenges/verify-codeverifyHostedEmailCodeVerify a hosted email challenge with a short code.200
POST/v1/hosted/email/challenges/verify-linkverifyHostedEmailLinkVerify a hosted email challenge with a magic-link token.200
GET/v1/hosted/inviteslistHostedInvitesList hosted invites for admin management.200
POST/v1/hosted/invitescreateHostedInviteInvite a security/admin, developer, or viewer user to a hosted org.201
POST/v1/hosted/invites/{invite_id}/resendresendHostedInviteResend a pending hosted invite with a rotated action ref.200
POST/v1/hosted/invites/{invite_id}/cancelcancelHostedInviteCancel a pending hosted invite.200
POST/v1/hosted/auth/invite-bindingbindHostedInviteContinuationBind an invite email continuation to this browser.200
POST/v1/hosted/invites/acceptacceptHostedInviteAccept a hosted invite after email verification.200
POST/v1/hosted/domain-signups/resolveresolveHostedDomainSignupResolve hosted signup route for a verified domain.200, 400, 403
GET/v1/hosted/join-requestslistHostedJoinRequestsList hosted same-domain access requests for admin review.200
POST/v1/hosted/join-requestscreateHostedJoinRequestCreate a same-domain hosted access request.201, 409
POST/v1/hosted/join-requests/{join_request_ref}/approveapproveHostedJoinRequestApprove a same-domain hosted access request.200, 403
POST/v1/hosted/join-requests/{join_request_ref}/rejectrejectHostedJoinRequestReject a same-domain hosted access request.200, 403
GET/v1/hosted/join-requests/{join_request_ref}/public-statusgetHostedJoinRequestPublicStatusRead neutral public status for a hosted access request.200, 404
POST/v1/hosted/separate-workspace-requestscreateHostedSeparateWorkspaceRequestRequest a separate hosted workspace for an existing domain.201, 409
POST/v1/hosted/separate-workspace-requests/{request_id}/reviewreviewHostedSeparateWorkspaceRequestDAC operator reviews a separate hosted workspace request.202, 403
POST/v1/hosted/runtime/endpointsregisterHostedRuntimeEndpointRegister a customer-owned HTTPS API or HTTPS MCP endpoint for hosted runtime.201, 400
POST/v1/hosted/runtime/endpoints/{endpoint_ref}/reachabilityvalidateHostedRuntimeEndpointReachabilityRun hosted runtime reachability validation from DAC egress.202, 409
POST/v1/hosted/runtime/endpoints/{endpoint_ref}/readinessevaluateHostedRuntimeEndpointReadinessEvaluate hosted runtime route readiness for a governed call.200
GET/v1/hosted/audit/posturegetHostedAuditPostureRead hosted audit posture with metadata-only defaults.200, 403
POST/v1/hosted/payload-capture/windowscreateHostedPayloadCaptureWindowCreate a short-lived hosted payload-capture window.201, 400, 403
POST/v1/hosted/payload-capture/windows/{window_id}/evaluateevaluateHostedPayloadCaptureWindowEvaluate whether a runtime request falls inside a capture window.200, 403
POST/v1/hosted/payload-capture/windows/{window_id}/ttl-purgeevaluateHostedPayloadCaptureTtlPurgeEvaluate TTL purge for an expired or suspended hosted capture window.200
POST/v1/hosted/payload-capture/windows/{window_id}/incident-actionapplyHostedPayloadCaptureIncidentActionApply a DAC operator incident action to a hosted capture window.200, 403
POST/v1/hosted/audit/runtime-eventsappendHostedRuntimeMetadataAuditEventAppend hosted runtime metadata audit evidence.202, 400
MethodPathOperationSummaryResponses
GET/v1/identity/megetIdentityMeRead the normalized authenticated admin actor and backend-computed collection permissions.200
GET/v1/identity-providergetIdentityProviderRead metadata-only active auth mode and provider configuration state.200
POST/v1/identity-provider/diagnosticsdiagnoseIdentityProviderRun metadata-only auth provider readiness checks.200
POST/v1/local-identity/bootstrap-adminbootstrapLocalIdentityAdminBootstrap the first local platform admin before any local user exists.201
POST/v1/local-identity/loginloginLocalIdentityCreate a backend-owned local browser session.200
POST/v1/local-identity/logoutlogoutLocalIdentityRevoke the active local browser session.200
GET/v1/local-identity/sessiongetLocalIdentitySessionRead the current local browser session and normalized actor.200
GET/v1/local-identity/userslistLocalIdentityUsersList local users without password hashes.200
POST/v1/local-identity/userscreateLocalIdentityUserCreate a local user and return a generated temporary password once when omitted.201
PATCH/v1/local-identity/users/{user_id}patchLocalIdentityUserUpdate local user profile metadata.200
POST/v1/local-identity/users/{user_id}/disabledisableLocalIdentityUserDisable a local user and revoke active local sessions.200
POST/v1/local-identity/users/{user_id}/reset-passwordresetLocalIdentityUserPasswordReset a local user’s password and return the temporary password once.200
POST/v1/local-identity/users/{user_id}/change-passwordchangeLocalIdentityUserPasswordChange the authenticated local user’s password and clear reset-required state.200
GET/v1/local-identity/groupslistLocalIdentityGroupsList local groups and member IDs.200
POST/v1/local-identity/groupscreateLocalIdentityGroupCreate a local group principal.201
PATCH/v1/local-identity/groups/{group_id}patchLocalIdentityGroupUpdate local group metadata.200
POST/v1/local-identity/groups/{group_id}/membersaddLocalIdentityGroupMemberAdd a local user to a local group.200
DELETE/v1/local-identity/groups/{group_id}/members/{user_id}removeLocalIdentityGroupMemberRemove a local user from a local group.200
GET/v1/local-identity/service-accountslistLocalIdentityServiceAccountsList local service accounts without token hashes.200
POST/v1/local-identity/service-accountscreateLocalIdentityServiceAccountCreate a local service principal.201
GET/v1/local-identity/service-accounts/{service_id}/tokenslistLocalIdentityServiceAccountTokensList service-account token metadata without token hashes or plaintext tokens.200
POST/v1/local-identity/service-accounts/{service_id}/tokenscreateLocalIdentityServiceAccountTokenCreate a service-account token and return plaintext once.200
POST/v1/local-identity/service-accounts/{service_id}/tokens/{token_id}/revokerevokeLocalIdentityServiceAccountTokenRevoke one service-account token by metadata ID.200
POST/v1/local-identity/service-accounts/{service_id}/disabledisableLocalIdentityServiceAccountDisable a local service account and revoke active tokens.200
MethodPathOperationSummaryResponses
GET/v1/licensegetLicenseStatusRead safe license and entitlement status for one environment.200, 403
MethodPathOperationSummaryResponses
GET/v1/managed/planslistManagedPlansList the offers in the current approved managed catalog release.200, 401, 403, 503
GET/v1/managed/plangetManagedPlanRead the current member’s managed plan and usage.200, 401, 403, 503
POST/v1/managed/plan-change-requestscreateManagedPlanChangeRequestRequest a change to another managed plan.202, 400, 401, 403, 409, 503
GET/v1/managed/invocations/{receipt}getManagedInvocationStatusRead pending or terminal managed invocation metadata.200, 401, 404, 503
MethodPathOperationSummaryResponses
POST/v1/mcp/api-sources/{api_source_id}apiSourceMcpJsonRpcLegacy Streamable HTTP MCP JSON-RPC endpoint for one approved API-source import.200, 202, 400, 401, 404, 415
POST/v1/mcp/api-sources/{api_source_id}/mcpapiSourceMcpJsonRpcAliasPreferred Streamable HTTP MCP JSON-RPC endpoint for one approved API-source import.200, 202, 400, 401, 404, 415
MethodPathOperationSummaryResponses
GET/.well-known/oauth-protected-resource/tenants/{tenant_id}/environments/{environment_id}/servers/{server_id}/mcpgetMcpServerProtectedResourceMetadataRead path-specific RFC 9728 metadata for a registered MCP server resource.200, 404, 503
GET/.well-known/oauth-protected-resource/tenants/{tenant_id}/environments/{environment_id}/api-sources/{api_source_id}/mcpgetApiSourceProtectedResourceMetadataRead path-specific RFC 9728 metadata for an API-source MCP resource.200, 404, 503
MethodPathOperationSummaryResponses
GET/v1/telemetrygetTelemetrySettingsRead metadata-only telemetry configuration and delivery health.200, 403
PUT/v1/telemetryupdateTelemetrySettingsUpdate telemetry mode and destination references with write-only secret refs.200, 403
POST/v1/telemetry/testtestTelemetrySettingsRun a metadata-only telemetry destination check.202, 403
POST/v1/telemetry/disabledisableTelemetrySettingsDisable telemetry export for an environment.202, 403
GET/v1/siem-webhookslistSiemWebhooksList metadata-only SIEM and webhook destination configuration.200, 403
POST/v1/siem-webhookscreateSiemWebhookCreate a SIEM/webhook destination using reference-only or write-only secret inputs.201, 403
PUT/v1/siem-webhooks/{destination_id}updateSiemWebhookUpdate SIEM/webhook destination metadata and write-only delivery refs.200, 403, 404
POST/v1/siem-webhooks/{destination_id}/testtestSiemWebhookRun a metadata-only SIEM/webhook delivery check.202, 403, 404
POST/v1/siem-webhooks/{destination_id}/disabledisableSiemWebhookDisable a SIEM/webhook destination without deleting audit-export history.202, 403, 404
GET/v1/connectorslistConnectorsList connector registry read-model rows for the UI with safe health, route, lifecycle, KPI, and permission metadata.200, 422, 403
GET/v1/connectors/{connector_id}getConnectorRead connector registry detail metadata for UI rendering without client-side status, audit, route, or session joins.200, 403, 404
GET/v1/connectors/{connector_id}/impactgetConnectorImpactRead safe connector blast-radius metadata before a lifecycle action.200, 403, 404, 500
POST/v1/connectors/{connector_id}/lifecycletransitionConnectorLifecycleMove a connector through explicit lifecycle transitions without patching raw fields.200, 403, 404, 409, 422, 500
MethodPathOperationSummaryResponses
GET/v1/reason-codeslistReasonCodesList backend-owned governance reason codes.200
POST/v1/reason-codescreateReasonCodeCreate or replace a tenant governance reason code.202
GET/v1/reason-codes/exportexportReasonCodesExport tenant governance reason-code catalog.200
POST/v1/reason-codes/importimportReasonCodesImport tenant governance reason-code catalog entries.200
PATCH/v1/reason-codes/{code}patchReasonCodeUpdate a tenant governance reason code.200
POST/v1/policies/simulatesimulatePolicyPreview a V1 gateway policy decision without runtime mutation.200
GET/v1/policieslistPoliciesList policy versions for the scoped tenant and environment.200, 403
POST/v1/policiescreatePolicyCreate a brand-new draft policy version with no parent.201, 400, 403, 409
POST/v1/policies/resolve-refsresolvePolicyRefsResolve policy refs for manifest validation and policy picker flows.200, 400
GET/v1/policies/{policy_version}readPolicyRead a policy version including editable safe body, validation, usage, hash, and permissions.200, 403, 404
PUT/v1/policies/{policy_version}updatePolicyDraftUpdate a draft policy body with manifest_hash or etag concurrency pinning.202, 400, 403, 409
POST/v1/policies/{policy_version}/validatevalidatePolicyVersionValidate a stored or supplied policy body and return structured errors.200, 403, 409
POST/v1/policies/{policy_version}/publishpublishPolicyVersionPublish a draft policy version and make it active for the environment.202, 403, 409, 422
POST/v1/policies/{policy_version}/archivearchivePolicyVersionArchive a draft, rejected, or safe old policy version.202, 403, 409
MethodPathOperationSummaryResponses
POST/v1/registry/validate-manifestvalidateRegistryManifestValidate MCP server or API source manifests without publishing them.200
GET/v1/registry/mcp-compatibility/optionsgetMcpCompatibilityOptionsRead MCP compatibility choices and the effective configuration envelope.200, 403, 404
POST/v1/registry/probe-mcp-serverprobeMcpServerProbe an MCP server from its configured runtime route and return compatibility evidence.200, 422
GET/v1/registry/probes/{probe_id}getMcpServerProbeRead the most recent in-memory MCP server probe result.200, 404
MethodPathOperationSummaryResponses
POST/v1/runtime/audit-eventsingestRuntimeAuditEventsIngest metadata-only DP runtime audit events into CP audit storage.202, 400, 403
MethodPathOperationSummaryResponses
POST/v1/revocationsrevokeAccessApply a target revocation and revoke affected active sessions.202, 403
POST/v1/revocations/previewpreviewRevocationPreview active sessions and backend sessions affected by a target revocation.200, 403
GET/v1/sessionslistActiveSessionsQuery durable active session metadata.200, 403
POST/v1/sessions/batch-revokebatchRevokeSessionsRevoke selected sessions in one backend call.200, 403
GET/v1/sessions/{client_session_id}getSessionLifecycleRead durable session metadata, backend sessions, transitions, and allowed actions.200, 403
POST/v1/sessions/{client_session_id}/terminateterminateSessionExplicitly terminate a client session and fail closed for future calls.202, 403
POST/v1/sessions/{client_session_id}/revokerevokeSessionRevoke an active client session and affected backend sessions through the internal outbox path.202, 403
MethodPathOperationSummaryResponses
POST/tenants/{tenant_id}/environments/{environment_id}/servers/{server_id}/mcppathScopedMcpServerPostPath-scoped MCP Streamable HTTP request for one registered server.200, 202, 400, 401, 403, 429, 503
GET/tenants/{tenant_id}/environments/{environment_id}/servers/{server_id}/mcppathScopedMcpServerGetCheck path-scoped MCP Streamable HTTP GET support.405, 401, 403, 429, 503
DELETE/tenants/{tenant_id}/environments/{environment_id}/servers/{server_id}/mcppathScopedMcpServerDeleteDelete a path-scoped MCP session after authenticating the request actor.202, 401, 403, 429, 503
POST/tenants/{tenant_id}/environments/{environment_id}/api-sources/{api_source_id}/mcppathScopedApiSourceMcpPostPath-scoped MCP Streamable HTTP request for one approved API source.200, 202, 400, 401, 403, 429, 503
MethodPathOperationSummaryResponses
GET/api/v1/hosted/auth/social/google/callbackcompleteHostedGoogleSocialAuthApiCallbackComplete hosted Google signup/login through the public API prefix.303
GET/api/v1/hosted/auth/social/github/callbackcompleteHostedGithubSocialAuthApiCallbackComplete hosted GitHub signup/login through the public API prefix.303
POST/internal/v1/managed/assignmentsassignManagedTenantFromRosterApply one approved commercial-roster assignment.200, 400, 401, 403, 404, 409, 503
POST/internal/v1/managed/quota-periods/{quota_period_ref}/support-credit-requestscreateManagedSupportCreditRequestRequest a managed quota support credit.200, 400, 401, 403, 404, 409, 503
POST/internal/v1/managed/support-credit-requests/{request_ref}/approveapproveManagedSupportCreditRequestApprove an above-threshold managed support credit.200, 400, 401, 403, 404, 409, 503
GET/internal/v1/runtime/projectiongetRuntimeProjectionExport one CP-published runtime projection to its scoped managed data plane.200, 403, 503
POST/internal/v1/runtime/fleet/sessionscreateManagedFleetHeartbeatSession201, 401, 409, 503
GET/internal/v1/runtime/fleet/projectiongetManagedFleetProjection200, 401, 409, 503
POST/internal/v1/runtime/fleet/heartbeatspostManagedFleetHeartbeat200, 400, 401, 409, 503
GET/internal/v1/runtime/fleet/readinessgetManagedFleetReadiness200, 401, 409, 503
POST/internal/v1/runtime/consumer-oauth/jwks-refresh-signalssignalConsumerOAuthJwksRefreshSubmit bounded unknown-key refresh signals from a data plane.202, 400, 403
POST/internal/v1/runtime/consumer-oauth/revocation-acknowledgementsacknowledgeConsumerOAuthRevocationsAcknowledge locally applied Consumer OAuth revocations.202, 400, 401, 403, 503
  • A route exists in implementation but not OpenAPI. Update the spec first.
  • A public page hand-copies an endpoint and drifts from the spec.
  • A docs console tries to send unauthenticated calls. That is out of scope until secured docs-console auth exists.
  • A response example includes request bodies, response bodies, tokens, credentials, or customer data. Public reference output must stay metadata-only.

Type set in Geist, Source Serif 4, and Departure Mono.