Skip to content

HTTP API reference

This endpoint inventory is generated from the Python route declarations on every documentation build. Follow a handler link to inspect its request and response models. The running gateway exposes the complete JSON schemas at /openapi.json and an interactive explorer at /docs.

All /api/ and /v1/ requests require a provisioned bearer identity. /api/admin/ requires a management identity. /health is public. The MCP mount at /mcp/ uses the same trusted bearer identities and is listed separately in the integration reference.

Method Path Source handler
GET /api/admin/audit.jsonl audit_export
POST /api/admin/policies/activate activate_policy
POST /api/admin/policies/draft draft_policy
POST /api/admin/policies/preview preview_policy
PUT /api/admin/policy save_policy
POST /api/admin/reload reload_policy
POST /api/admin/rules/preview preview_rule
GET /api/admin/rules/schema rule_schema
POST /api/admin/semantic/preview preview
GET /api/admin/status status
POST /api/documents/markdown document_markdown
POST /api/invoke invoke
GET /api/me me
POST /api/models/complete complete
GET /health health
POST /v1/chat/completions complete
GET /v1/models models

Response semantics

An HTTP 200 response from a protected invocation can still contain a blocked security verdict. Check decision, reason and upstream_executed; do not use HTTP status alone as an authorization result. A blocked output can follow an already executed upstream operation.

OpenAI-compatible calls return their endpoint-specific schema. Streaming, arbitrary upstream providers and arbitrary MCP proxying are not implied by this inventory. See the protocol contract.