HTTP API reference¶
This endpoint inventory is generated from the Python route declarations on every documentation build. Follow a handler link to inspect its request and response models. The running gateway exposes the complete JSON schemas at /openapi.json and an interactive explorer at /docs.
All /api/ and /v1/ requests require a provisioned bearer identity. /api/admin/ requires a management identity. /health is public. The MCP mount at /mcp/ uses the same trusted bearer identities and is listed separately in the integration reference.
| Method | Path | Source handler |
|---|---|---|
GET |
/api/admin/audit.jsonl |
audit_export |
POST |
/api/admin/policies/activate |
activate_policy |
POST |
/api/admin/policies/draft |
draft_policy |
POST |
/api/admin/policies/preview |
preview_policy |
PUT |
/api/admin/policy |
save_policy |
POST |
/api/admin/reload |
reload_policy |
POST |
/api/admin/rules/preview |
preview_rule |
GET |
/api/admin/rules/schema |
rule_schema |
POST |
/api/admin/semantic/preview |
preview |
GET |
/api/admin/status |
status |
POST |
/api/documents/markdown |
document_markdown |
POST |
/api/invoke |
invoke |
GET |
/api/me |
me |
POST |
/api/models/complete |
complete |
GET |
/health |
health |
POST |
/v1/chat/completions |
complete |
GET |
/v1/models |
models |
Response semantics¶
An HTTP 200 response from a protected invocation can still contain a blocked security verdict. Check decision, reason and upstream_executed; do not use HTTP status alone as an authorization result. A blocked output can follow an already executed upstream operation.
OpenAI-compatible calls return their endpoint-specific schema. Streaming, arbitrary upstream providers and arbitrary MCP proxying are not implied by this inventory. See the protocol contract.