API reference
Every REST operation, generated from the control plane's own OpenAPI document — methods, paths, authentication, permissions, query parameters and request bodies.
This reference is generated from GET /api/v1/openapi.json of a control plane built from the documented release. Your
own installation serves the same document for its exact version, which tools such as Postman or OpenAPI code generators
can import directly.
112 operations · core v0.1.1 · exported Sep 29, 2026. Paths are relative to /api/v1. The worker protocol is internal and not listed.
admin
get/admin/featuresFeature flags with their platform and organization settings
auth: bearer
put/admin/features/{key}Turn a feature flag on or off for everyone (null: back to its default)
auth: bearer
Body
enabled* boolean
put/admin/features/{key}/orgs/{organizationId}Turn a feature flag on or off for one organization (null: remove the override)
auth: bearer
Body
enabled* boolean
get/admin/organizationsAll organizations on this server (for feature flag overrides)
auth: bearer
Query
qstring
get/admin/serverEffective server configuration and status (secrets never included)
auth: bearer
patch/admin/server/settingsChange server settings that can be managed in the web app (null clears a value)
auth: bearer
Body
values* object
get/admin/usersPeople on this server (search by email or name)
auth: bearer
Query
qstring
post/admin/users/{userId}/reset-mfaTurn off someone's two-factor authentication (they are signed out and emailed)
auth: bearer
Body
reason* string
get/admin/worker-releasesWorker releases hosted by this server
auth: bearer
put/admin/worker-releases/{channel}/manifestPublish a signed manifest for an uploaded worker package
auth: bearer
audit
get/orgs/{orgId}/auditAudit log
auth: bearerpermission: audit.read
Query
cursorstringlimitintegeractionstring
auth
get/auth/device/{code}What a device sign-in code is for (to approve it)
auth: bearer
post/auth/device/{code}/decisionApprove or deny a device sign-in
auth: bearer
Body
approve* boolean
post/auth/device/pollPoll a device sign-in: pending, or the session once approved
auth: none
Body
pollSecret* string
post/auth/device/startStart a device sign-in: returns a code to approve in the web app
auth: none
Body
clientName* string
post/auth/loginSign in
auth: none
Body
email* stringpassword* stringmfaCodestring
post/auth/logoutRevoke session
auth: none
Body
refreshTokenstring
get/auth/oauth/{provider}/callbackProvider redirect target (redirects to the web app)
auth: none
Query
codestringstatestringerrorstring
get/auth/oauth/{provider}/startStart signing in with a provider (redirects to it)
auth: none
Query
nextstringinvitationstring
post/auth/oauth/completeExchange the sign-in ticket for a session
auth: none
Body
ticket* stringmfaCodestring
get/auth/oauth/providersConfigured sign-in providers
auth: none
post/auth/password-resetRequest a password reset email
auth: none
Body
email* string
post/auth/password-reset/confirmSet a new password
auth: none
Body
token* stringpassword* string
post/auth/refreshRotate refresh token
auth: none
Body
refreshTokenstring
post/auth/registerCreate an account and organization
auth: none
Body
email* stringpassword* stringname* stringorganizationNamestringinvitationTokenstring
post/auth/verify-emailVerify email address
auth: none
Body
token* string
post/invitations/acceptAccept an invitation as the signed-in user
auth: bearer
Body
token* string
post/invitations/previewShow an invitation before accepting it
auth: none
Body
token* string
get/meCurrent user and memberships
auth: bearer
delete/me/identities/{provider}Disconnect a provider from your account
auth: bearer
post/me/mfa/disableTurn off two-factor authentication
auth: bearer
Body
password* stringcode* string
post/me/mfa/enableConfirm a code and turn on two-factor authentication
auth: bearer
Body
code* string
post/me/mfa/setupStart two-factor setup (returns a new TOTP secret)
auth: bearer
post/me/oauth/{provider}/linkStart connecting a provider to your account (returns its URL)
auth: bearer
get/me/tokensYour API tokens (never the token values)
auth: bearer
post/me/tokensCreate an API token for one organization; the value is returned once
auth: bearer
Body
name* stringorganizationId* stringrole"OWNER" | "ADMIN" | "MANAGER" | "DEVELOPER" | "VIEWER"expiresInDaysinteger
delete/me/tokens/{id}Revoke an API token
auth: bearer
capabilities
get/orgs/{orgId}/capabilitiesRegistry (org + platform)
auth: bearer
post/orgs/{orgId}/capabilitiesRegister a capability manifest
auth: bearerpermission: capability.manage
Body
manifest* objectprivatebooleanplatformboolean
get/orgs/{orgId}/capability-installationsInstalled capabilities
auth: bearer
Query
projectIdstring
post/orgs/{orgId}/capability-installationsInstall capability at a scope
auth: bearerpermission: capability.install
Body
capabilityId* stringversionstringscope* "ORGANIZATION" | "PROJECT" | "TASK"projectIdstringenabledbooleanconfigobject
delete/orgs/{orgId}/capability-installations/{id}Uninstall
auth: bearer
patch/orgs/{orgId}/capability-installations/{id}Enable/disable installation
auth: bearer
Body
enabled* boolean
post/orgs/{orgId}/capability-installations/{id}/approveApprove pending installation
auth: bearerpermission: capability.manage
dashboard
get/orgs/{orgId}/overviewOperational overview
auth: bearer
github
get/orgs/{orgId}/githubGitHub App status, installations and your GitHub connection
auth: bearer
delete/orgs/{orgId}/github/appRemove the GitHub App configuration (projects stay)
auth: bearerpermission: settings.manage
post/orgs/{orgId}/github/app/manifestStart creating the GitHub App (the browser posts the manifest to GitHub)
auth: bearerpermission: settings.manage
Body
organizationstringpublicboolean
post/orgs/{orgId}/github/installationsLink to install the app on a GitHub account
auth: bearerpermission: settings.manage
delete/orgs/{orgId}/github/installations/{installationId}Forget an installation (projects stay)
auth: bearerpermission: settings.manage
get/orgs/{orgId}/github/ownersGitHub accounts new repositories can be created in
auth: bearer
post/orgs/{orgId}/github/repositoriesCreate a GitHub repository and add it to a (new) project
auth: bearerpermission: project.create
Body
owner* stringname* stringprivatebooleandescriptionstringprojectIdstringcloneToWorkerIdsstring[]
post/orgs/{orgId}/github/syncSync repositories from every installation now
auth: bearerpermission: settings.manage
delete/orgs/{orgId}/github/userForget your GitHub authorization
auth: bearer
post/orgs/{orgId}/github/userLink to authorize the app with your GitHub account
auth: bearer
integrations
get/orgs/{orgId}/integrationsIntegrations (inbound webhooks that create tasks)
auth: bearerpermission: settings.manage
post/orgs/{orgId}/integrationsCreate an integration; the webhook secret is returned once
auth: bearerpermission: settings.manage
Body
name* stringkind* "github" | "gitlab" | "generic"projectId* stringenabledbooleansettingsobject
delete/orgs/{orgId}/integrations/{id}Delete an integration
auth: bearerpermission: settings.manage
patch/orgs/{orgId}/integrations/{id}Change an integration
auth: bearerpermission: settings.manage
Body
namestringprojectIdstringenabledbooleansettingsobject
post/orgs/{orgId}/integrations/{id}/rotate-secretReplace the webhook secret; the new one is returned once
auth: bearerpermission: settings.manage
notifications
post/me/push-tokensRegister a mobile push token
auth: bearer
Body
token* stringplatformstring
get/orgs/{orgId}/notificationsMy notifications
auth: bearer
Query
cursorstringlimitintegerunreadOnlyboolean
post/orgs/{orgId}/notifications/readMark notifications read
auth: bearer
Body
ids* string[] | "all"
organizations
post/orgsCreate organization
auth: bearer
Body
name* string
get/orgs/{orgId}Get organization
auth: bearerpermission: org.read
patch/orgs/{orgId}Update organization, policy, settings
auth: bearerpermission: org.update
Body
namestringpolicyobjectknowledgestringsettingsobject
get/orgs/{orgId}/featuresFeature flags in effect for this organization
auth: bearerpermission: org.read
get/orgs/{orgId}/invitationsList pending invitations
auth: bearerpermission: member.read
delete/orgs/{orgId}/invitations/{invitationId}Revoke an invitation
auth: bearerpermission: member.invite
get/orgs/{orgId}/membersList members
auth: bearerpermission: member.read
post/orgs/{orgId}/membersAdd a member, or invite someone without an account
auth: bearerpermission: member.invite
Body
email* stringrole* "OWNER" | "ADMIN" | "MANAGER" | "DEVELOPER" | "VIEWER"
delete/orgs/{orgId}/members/{userId}Remove member
auth: bearerpermission: member.remove
patch/orgs/{orgId}/members/{userId}Change member role
auth: bearerpermission: member.update_role
Body
role* "OWNER" | "ADMIN" | "MANAGER" | "DEVELOPER" | "VIEWER"
post/orgs/{orgId}/members/{userId}/reset-mfaTurn off a member's two-factor authentication (only members of this organization alone)
auth: bearerpermission: member.remove
Body
reason* string
get/orgs/{orgId}/teamsList teams
auth: bearer
post/orgs/{orgId}/teamsCreate team
auth: bearerpermission: team.manage
Body
name* stringmemberIdsstring[]
delete/orgs/{orgId}/teams/{teamId}Delete team
auth: bearerpermission: team.manage
projects
get/orgs/{orgId}/discoveredRepositories found on workers that are in no project yet
auth: bearer
post/orgs/{orgId}/discovered/acceptCreate a project for a found repository (or add it to one) and map it where it was found
auth: bearer
Body
ids* string[]projectIdstringnamestring
post/orgs/{orgId}/discovered/dismissStop suggesting found repositories
auth: bearer
Body
ids* string[]
get/orgs/{orgId}/projectsList projects
auth: bearer
post/orgs/{orgId}/projectsCreate project
auth: bearerpermission: project.create
Body
name* stringdescriptionstringrepositoryUrlstringdefaultBranchstringpolicyobjectenvironmentsobject[]knowledgestring
delete/orgs/{orgId}/projects/{projectId}Archive project
auth: bearerpermission: project.delete
get/orgs/{orgId}/projects/{projectId}Get project
auth: bearer
patch/orgs/{orgId}/projects/{projectId}Update project
auth: bearerpermission: project.update
Body
namestringdescriptionstringrepositoryUrlstringdefaultBranchstringpolicyobjectenvironmentsobject[]knowledgestring
post/orgs/{orgId}/projects/{projectId}/readinessRun the AI readiness analysis on a worker that has the project
auth: bearer
post/orgs/{orgId}/projects/{projectId}/repositoriesAdd a repository (by URL, or moved from another project)
auth: bearerpermission: project.update
patch/orgs/{orgId}/projects/{projectId}/repositories/{repositoryId}Rename a repository, change its branch, or make it primary
auth: bearerpermission: project.update
Body
namestringdefaultBranchstringprimarytrue
post/orgs/{orgId}/projects/{projectId}/repositories/{repositoryId}/cloneClone a repository into workers' projects folders
auth: bearerpermission: project.update
Body
workerIds* string[]
post/orgs/{orgId}/projects/{projectId}/repositories/{repositoryId}/splitMove a repository into a new project of its own
auth: bearerpermission: project.update
providers
get/orgs/{orgId}/providersOrganization provider configs
auth: bearer
delete/orgs/{orgId}/providers/{providerId}Delete provider config
auth: bearerpermission: provider.manage
put/orgs/{orgId}/providers/{providerId}Create/update provider config
auth: bearerpermission: provider.manage
Body
kind* stringname* stringbaseUrlstringenabledbooleanmodelsobject[]
settings
get/orgs/{orgId}/secretsList secrets (masked)
auth: bearerpermission: settings.manage
delete/orgs/{orgId}/secrets/{name}Delete secret
auth: bearerpermission: settings.manage
put/orgs/{orgId}/secrets/{name}Set secret
auth: bearerpermission: settings.manage
Body
value* string
tasks
get/orgs/{orgId}/tasksList tasks (cursor)
auth: bearer
Query
cursorstringlimitintegerprojectIdstringstatusobjectworkerIdstringqstring
post/orgs/{orgId}/tasksCreate task
auth: bearerpermission: task.create
Body
projectId* stringkind"code" | "review" | "plan"reviewobjecttitle* stringprompt* stringknowledgestringpriority"CRITICAL" | "HIGH" | "NORMAL" | "LOW"dependenciesstring[]requirementsobjectpolicyobjectenvironmentstringcapabilityIdsstring[]requirePlanApprovalbooleanidempotencyKeystring
post/orgs/{orgId}/tasks/{id}/apply-planCreate the tasks a completed plan proposes (idempotent)
auth: bearerpermission: task.create
get/orgs/{orgId}/tasks/{taskId}Get task
auth: bearer
post/orgs/{orgId}/tasks/{taskId}/actionsPause/resume/cancel/retry/restart/input/approve/deny
auth: bearerpermission: task.control
Body
action* "pause" | "resume" | "cancel" | "retry" | "restart" | "input" | "approve" | "deny"inputstringreasonstring
get/orgs/{orgId}/tasks/{taskId}/artifacts/{name}Download a task artifact
auth: bearer
get/orgs/{orgId}/tasks/{taskId}/eventsTask timeline (ascending, cursor)
auth: bearer
Query
afterstringlimitintegerincludeOutputboolean
usage
get/orgs/{orgId}/usageAI usage aggregates
auth: bearer
Query
daysinteger
workers
get/orgs/{orgId}/workersList workers
auth: bearer
delete/orgs/{orgId}/workers/{workerId}Revoke worker credential
auth: bearerpermission: worker.manage
get/orgs/{orgId}/workers/{workerId}Get worker
auth: bearer
patch/orgs/{orgId}/workers/{workerId}Update worker
auth: bearerpermission: worker.manage
Body
namestringlabelsstring[]maxConcurrentTasksintegerstatus"DISABLED" | "OFFLINE"
post/orgs/{orgId}/workers/{workerId}/approveApprove worker
auth: bearerpermission: worker.approve
get/pairing/{userCode}Describe a pending pairing
auth: bearer
post/pairing/approveApprove a worker pairing code
auth: bearer
Body
userCode* stringorganizationId* stringnamestring
post/pairing/denyDeny a worker pairing code
auth: bearer
Body
userCode* stringorganizationId* string