Skip to main content
The Skydive API is a REST API for managing agents and their credentials programmatically. It is the surface the Skydive CLI is built on: list and create agents, mint and revoke API keys, and manage the secrets an agent’s sandbox can see.
All endpoints are served from a single versioned base URL:
Requests and responses are JSON. The API is also self-describing: the current OpenAPI document and an interactive reference are served by the API itself.

Authentication

Every request requires an API key in the Authorization header:
Keys are created from an agent’s API access settings in the app, or through the API itself. The full key value is returned exactly once, at creation. Skydive stores only a hash, so a lost key cannot be recovered, only replaced. Requests without a valid key return 401.
An API key carries the authority to act on your agents. Keep it out of client-side code and version control. If a key is exposed, revoke it and mint a new one; revocation takes effect immediately.

Scopes and binding

Every key has a scope and a binding, set at creation. Together they determine exactly what a request may do: A request that exceeds the key’s scope or binding fails with 403 and an explanatory message. It never partially succeeds. Keys minted through POST /v1/agents/{agentId}/api-keys are always agent-bound with the use scope.

Errors

The API uses conventional HTTP status codes. Every error response has the same shape: an error field with a human-readable message, and on some errors a machine-readable code.

Pagination

List endpoints return results newest first and paginate with an opaque cursor. Pass limit (1 to 100, default 50) to size the page, and pass the previous response’s nextCursor to fetch the next page. A null nextCursor means you have reached the end.
Treat cursors as opaque strings: URL-encode them when passing them back, and do not parse or construct them.

Versioning

The path prefix is the API version. Within v1, response shapes are additive only: new fields may appear, but existing fields are never removed, renamed, or retyped. Breaking changes ship as a new version prefix. Write clients that ignore unknown fields.

Secrets are write-only

Secret values can be set and deleted but never read back. GET /v1/agents/{agentId}/secrets returns key names only. This matches how secrets work inside the agent’s sandbox and keeps the API from becoming a way to exfiltrate credentials. To rotate a secret, set the new value; to verify one exists, list the names.

Endpoints

Agents

List, fetch, and create agents.

API keys

Mint, list, and revoke an agent’s keys.

Secrets

Set and remove an agent’s secrets.