Authentication
Every request requires an API key in theAuthorization header:
401.
Scopes and binding
Every key has a scope and a binding, set at creation. Together they determine exactly what a request may do:
A request that exceeds the key’s scope or binding fails with
403 and an explanatory message. It never partially succeeds.
Keys minted through POST /v1/agents/{agentId}/api-keys are always agent-bound with the use scope.
Errors
The API uses conventional HTTP status codes. Every error response has the same shape: anerror field with a human-readable message, and on some errors a machine-readable code.
Pagination
List endpoints return results newest first and paginate with an opaque cursor. Passlimit (1 to 100, default 50) to size the page, and pass the previous response’s nextCursor to fetch the next page. A null nextCursor means you have reached the end.
Versioning
The path prefix is the API version. Withinv1, response shapes are additive only: new fields may appear, but existing fields are never removed, renamed, or retyped. Breaking changes ship as a new version prefix. Write clients that ignore unknown fields.
Secrets are write-only
Secret values can be set and deleted but never read back.GET /v1/agents/{agentId}/secrets returns key names only. This matches how secrets work inside the agent’s sandbox and keeps the API from becoming a way to exfiltrate credentials. To rotate a secret, set the new value; to verify one exists, list the names.
Endpoints
Agents
List, fetch, and create agents.
API keys
Mint, list, and revoke an agent’s keys.
Secrets
Set and remove an agent’s secrets.