Enterprise Manager API reference
The Enterprise Manager API covers users, groups, connectors, managed secrets, virtual API keys, budgets, and signed Stacklok CLI configuration.
The running service also self-serves this reference at /api/doc, which is
generated from the same source and therefore always matches the version you have
deployed.
The generated specification omits the SCIM provisioning and budget webhook
routes. Use /api/doc on the running service for its complete API reference.
Base URL
The REST API uses the Service's HTTP port (service.port, default 80). The
same Service also exposes gRPC and webhook ports for other integrations. For an
externally exposed deployment, use the Enterprise Manager URL configured as
resourceURL, including any path prefix your ingress requires.
With the default Service name and port, the in-cluster base URL is:
http://<RELEASE_NAME>-enterprise-manager.<NAMESPACE>.svc:80
<RELEASE_NAME> is your platform Helm release name. Helm name overrides can
change the Service name, and values overrides can change the port. Check your
installed Services:
kubectl get svc -n <NAMESPACE>
For a local connection, forward the Service's HTTP port:
kubectl port-forward -n <NAMESPACE> svc/<SERVICE_NAME> 8080:80
Replace <SERVICE_NAME> with the installed Service name. Keep the command
running in a separate terminal. Your local base URL is http://localhost:8080.
Append each endpoint path to the base URL once; for example,
http://localhost:8080/v1/me/connections. API authentication still applies when
using a port-forward.
For external access, ask your platform administrator for the URL routed to the Service above. See Expose the platform endpoints for the routing setup.
The request examples below use http://localhost:8080, which matches the
port-forward above. For calls from inside the cluster or through an external
endpoint, replace that address with your deployment's base URL.
Endpoints
Enterprise Manager API (0.1.0)
Download OpenAPI specification:Download
Stacklok Enterprise Manager — unified admin API for configuration delivery, directory, and budget management.
Budget cells summary
Authorizations:
query Parameters
| scope | string Enum: "user" "group" Principal tier filter |
| subject | string Subject id prefix match |
| at | string Instant the period windows are computed against, RFC 3339 (default now) |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 200, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "cells": [
- {
- "limit_usd": "string",
- "on_default": true,
- "ordinal": 0,
- "period": "string",
- "period_end": "string",
- "period_start": "string",
- "remaining_usd": "string",
- "scope": "string",
- "subject_id": "string",
- "used_usd": "string"
}
], - "next_cursor": "string"
}Budget consumption breakdown
One budget's current-period spend broken down by user, model, and provider. The period window is computed server-side (current period only). Each dimension's entries sum to total_used_usd.
Authorizations:
query Parameters
| scope required | string Enum: "user" "group" Principal tier |
| subject_id required | string Budget subject id (directory platform user UUID for user budgets, directory group UUID for group budgets) |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "by_model": [
- {
- "used_usd": "string",
- "value": "string"
}
], - "by_provider": [
- {
- "used_usd": "string",
- "value": "string"
}
], - "by_user": [
- {
- "used_usd": "string",
- "value": "string"
}
], - "period": "string",
- "period_end": "string",
- "period_start": "string",
- "scope": "string",
- "subject_id": "string",
- "total_used_usd": "string"
}Daily spend series
Zero-filled daily USD totals over the served window, including the current (in-progress) UTC day. from/to echo the bounds actually served after clamping (to at the end of the current UTC day, from at the retention horizon).
Authorizations:
query Parameters
| granularity | string Value: "day" Bucket granularity |
| from | string Window start, ISO date (default 30 days back, including today) |
| to | string Window end (exclusive), ISO date |
| model | string Served model of the underlying event, exact match |
| scope | string Enum: "user" "group" Payer tier charged |
| subject_id | string Payer charged, exact match |
Responses
Response samples
- 200
- 400
- 500
{- "buckets": [
- {
- "date": "string",
- "usd": "string"
}
], - "from": "string",
- "granularity": "string",
- "to": "string"
}Delete pricing catalog entry
Withdraw one (provider, model) rate. The entry is kept as an unpriced tombstone rather than removed, so a later baseline refresh cannot resurrect the rate; the next request for that model is denied at admission as unpriceable. Use POST .../revert to hand the rate back to the shipped baseline. This republishes the ENTIRE merged catalog as a new operator-dated version, but every other rate keeps its ownership and a later release's baseline refresh still reaches the ones nobody pinned.
Authorizations:
path Parameters
| provider required | string Literal provider as stored |
| model required | string Model name (may contain '/') |
header Parameters
| If-Match required | string ETag from GET /v1/budgets/pricing or the per-entry GET |
Responses
Response samples
- 404
- 409
- 412
- 428
- 500
{- "error": "string"
}Delete staged pricing catalog version
Remove a pricing catalog version staged to take effect later, addressed by its exact effective_from. Clears the 409 a staged version causes on every pricing write. A version that has already taken effect cannot be removed and returns 409.
Authorizations:
path Parameters
| effectiveFrom required | string Staged version's effective_from, RFC 3339 |
Responses
Response samples
- 400
- 404
- 409
- 500
{- "error": "string"
}Response samples
- 200
- 404
- 500
{- "effective_from": "string",
- "provider_aliases": {
- "property1": "string",
- "property2": "string"
}, - "spec": {
- "entries": [
- {
- "anthropic": {
- "cacheCreation1hInputUsdPerMillion": "string",
- "cacheCreation5mInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}, - "google": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedAudioInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "thoughtsOutputUsdPerMillion": "string"
}, - "managedBy": "string",
- "model": "string",
- "openai": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "reasoningOutputUsdPerMillion": "string"
}, - "provider": "string",
- "unpriced": true
}
], - "snapshotDate": "string",
- "tools": {
- "anthropic": {
- "webSearchUsdPerThousand": "string"
}, - "google": {
- "groundingSearchUsdPerThousand": "string"
}, - "openai": {
- "fileSearchUsdPerThousand": "string",
- "webSearchUsdPerThousand": "string"
}
}
}
}Get one pricing catalog version
Return the pricing catalog version occupying exactly the given effective_from — active, historical, or staged. Same body shape as GET /v1/budgets/pricing so two versions can be diffed through one decoder.
Authorizations:
path Parameters
| effectiveFrom required | string Version's effective_from, RFC 3339 |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "effective_from": "string",
- "provider_aliases": {
- "property1": "string",
- "property2": "string"
}, - "spec": {
- "entries": [
- {
- "anthropic": {
- "cacheCreation1hInputUsdPerMillion": "string",
- "cacheCreation5mInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}, - "google": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedAudioInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "thoughtsOutputUsdPerMillion": "string"
}, - "managedBy": "string",
- "model": "string",
- "openai": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "reasoningOutputUsdPerMillion": "string"
}, - "provider": "string",
- "unpriced": true
}
], - "snapshotDate": "string",
- "tools": {
- "anthropic": {
- "webSearchUsdPerThousand": "string"
}, - "google": {
- "groundingSearchUsdPerThousand": "string"
}, - "openai": {
- "fileSearchUsdPerThousand": "string",
- "webSearchUsdPerThousand": "string"
}
}
}
}Get pricing catalog entry
Authorizations:
path Parameters
| provider required | string Literal provider as stored |
| model required | string Model name (may contain '/') |
Responses
Response samples
- 200
- 404
- 500
{- "anthropic": {
- "cacheCreation1hInputUsdPerMillion": "string",
- "cacheCreation5mInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}, - "google": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedAudioInputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "thoughtsOutputUsdPerMillion": "string"
}, - "managedBy": "string",
- "model": "string",
- "openai": {
- "audioInputUsdPerMillion": "string",
- "audioOutputUsdPerMillion": "string",
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string",
- "promptSizeTiers": [
- {
- "aboveTokens": 0,
- "cachedInputUsdPerMillion": "string",
- "inputUsdPerMillion": "string",
- "outputUsdPerMillion": "string"
}
], - "reasoningOutputUsdPerMillion": "string"
}, - "provider": "string",
- "unpriced": true
}Group budget breakdown slice
A group budget's current-period spend sliced by one dimension. dimension selects the slice axis; entries sum to total_used_usd.
Authorizations:
path Parameters
| id required | string Group subject_id |
query Parameters
| dimension required | string Enum: "user" "model" Slice axis |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "dimension": "string",
- "entries": [
- {
- "used_usd": "string",
- "value": "string"
}
], - "period": "string",
- "period_end": "string",
- "period_start": "string",
- "scope": "string",
- "subject_id": "string",
- "total_used_usd": "string"
}List charges
Authorizations:
query Parameters
| from | string Inclusive event_time lower bound, RFC 3339 |
| to | string Exclusive event_time upper bound, RFC 3339 |
| model | string Served model of the underlying event, exact match |
| scope | string Enum: "user" "group" Payer tier charged |
| subject_id | string Payer charged, exact match |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 10000, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "charges": [
- {
- "auth_subject": "string",
- "charged_usd": "string",
- "event_id": "string",
- "event_time": "string",
- "id": "string",
- "interaction_id": "string",
- "model": "string",
- "period_end": "string",
- "period_start": "string",
- "pricing_catalog_id": "string",
- "provider": "string",
- "scope": "string",
- "subject_id": "string"
}
], - "next_cursor": "string"
}List own charges
Lists the charge records derived from the caller's own usage events, scoped to the verified token subject. A page may contain fewer than limit records even when more data exists; keep following next_cursor until it is absent.
Authorizations:
query Parameters
| from | string Inclusive event_time lower bound, RFC 3339 |
| to | string Exclusive event_time upper bound, RFC 3339 |
| model | string Served model of the underlying event, exact match |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 200, clamped) |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "charges": [
- {
- "auth_subject": "string",
- "charged_usd": "string",
- "event_id": "string",
- "event_time": "string",
- "id": "string",
- "interaction_id": "string",
- "model": "string",
- "period_end": "string",
- "period_start": "string",
- "pricing_catalog_id": "string",
- "provider": "string",
- "scope": "string",
- "subject_id": "string"
}
], - "next_cursor": "string"
}List own usage events
Lists the caller's own usage events, scoped to the verified token subject. A page may contain fewer than limit records even when more data exists; keep following next_cursor until it is absent.
Authorizations:
query Parameters
| from | string Inclusive event_time lower bound, RFC 3339 |
| to | string Exclusive event_time upper bound, RFC 3339 |
| model | string Served model, exact match |
| outcome | string Enum: "delivered" "blocked_downstream" "client_disconnect" "upstream_error" Interaction outcome |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 200, clamped) |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "events": [
- {
- "auth_issuer": "string",
- "auth_subject": "string",
- "duration_ms": 0,
- "event_time": "string",
- "id": "string",
- "ingest_time": "string",
- "interaction_id": "string",
- "model": "string",
- "outcome": "string",
- "platform_groups": [
- "string"
], - "platform_user_id": "string",
- "provider": "string",
- "raw_usage": { },
- "requested_model": "string",
- "route": "string",
- "upstream_status": 0,
- "virtual_key_id": "string"
}
], - "next_cursor": "string"
}List pricing catalog versions
List the published pricing catalog versions, newest first, with provenance only (no rate tables). Address one of them by its effective_from on GET /v1/budgets/pricing/versions/{effectiveFrom}.
Authorizations:
Responses
Response samples
- 200
- 500
{- "versions": [
- {
- "created_at": "string",
- "effective_from": "string",
- "snapshotDate": "string"
}
]
}List usage events
Authorizations:
query Parameters
| from | string Inclusive event_time lower bound, RFC 3339 |
| to | string Exclusive event_time upper bound, RFC 3339 |
| model | string Served model, exact match |
| auth_subject | string Verified OIDC subject, exact match |
| outcome | string Enum: "delivered" "blocked_downstream" "client_disconnect" "upstream_error" Interaction outcome |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 10000, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "events": [
- {
- "auth_issuer": "string",
- "auth_subject": "string",
- "duration_ms": 0,
- "event_time": "string",
- "id": "string",
- "ingest_time": "string",
- "interaction_id": "string",
- "model": "string",
- "outcome": "string",
- "platform_groups": [
- "string"
], - "platform_user_id": "string",
- "provider": "string",
- "raw_usage": { },
- "requested_model": "string",
- "route": "string",
- "upstream_status": 0,
- "virtual_key_id": "string"
}
], - "next_cursor": "string"
}Own budgets summary
The caller's personal day/month cards (absent when no personal budget exists at that period) and every budget cell applicable to them. Group rows expose team aggregates, never teammate records; my_contribution_usd is the caller's own period-to-date share of that cell, exact for the whole of the cell's period.
Authorizations:
Responses
Response samples
- 200
- 401
- 500
{- "budgets": [
- {
- "limit_usd": "string",
- "my_contribution_usd": "string",
- "on_default": true,
- "ordinal": 0,
- "period": "string",
- "period_end": "string",
- "period_start": "string",
- "remaining_usd": "string",
- "scope": "string",
- "subject_id": "string",
- "used_usd": "string"
}
], - "day": {
- "budgets": 0,
- "limit_usd": "string",
- "period_end": "string",
- "period_start": "string",
- "remaining_usd": "string",
- "used_usd": "string"
}, - "month": {
- "budgets": 0,
- "limit_usd": "string",
- "period_end": "string",
- "period_start": "string",
- "remaining_usd": "string",
- "used_usd": "string"
}, - "subject": "string"
}Own daily spend series
Authorizations:
query Parameters
| granularity | string Value: "day" Bucket granularity |
| from | string Window start, ISO date (default 30 days back, including today) |
| to | string Window end (exclusive), ISO date |
| model | string Served model of the underlying event, exact match |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "buckets": [
- {
- "date": "string",
- "usd": "string"
}
], - "from": "string",
- "granularity": "string",
- "to": "string"
}Put group budget
Authorizations:
path Parameters
| id required | string Group subject_id |
header Parameters
| If-Match | string ETag from GET /v1/budgets |
Request Body schema: application/jsonrequired
Group budget specification
Responses
Request samples
- Payload
{ }Response samples
- 400
- 412
- 500
{- "error": "string"
}Put pricing catalog entry
Upsert one (provider, model) rate row. The body must carry exactly one of anthropic / openai / google. This republishes the ENTIRE merged catalog as a new operator-dated version, but only the entry it writes becomes operator-managed: every other rate keeps its ownership and a later release's baseline refresh still reaches the ones nobody pinned. Use POST .../revert to hand this rate back.
Authorizations:
path Parameters
| provider required | string Literal provider to store under |
| model required | string Model name (may contain '/') |
header Parameters
| If-Match required | string ETag from GET /v1/budgets/pricing or the per-entry GET |
Request Body schema: application/jsonrequired
Rate block for this entry
Responses
Request samples
- Payload
{ }Response samples
- 400
- 404
- 409
- 412
- 428
- 500
{- "error": "string"
}Put user budget
Authorizations:
path Parameters
| id required | string User subject_id |
header Parameters
| If-Match | string ETag from GET /v1/budgets |
Request Body schema: application/jsonrequired
User budget specification
Responses
Request samples
- Payload
{ }Response samples
- 400
- 412
- 500
{- "error": "string"
}Revert pricing catalog entry to the shipped baseline
Hand one (provider, model) rate back to the built-in pricing baseline: the baseline's current rates are written into the entry, ownership is recorded as the baseline's, and any tombstone is cleared. This is the remedy for a rate pinned by mistake — a pinned rate is otherwise immune to baseline refreshes. Refused 409 when the shipped baseline does not price the pair, since there is no rate to restore.
Authorizations:
path Parameters
| provider required | string Literal provider as stored |
| model required | string Model name (may contain '/') |
header Parameters
| If-Match required | string ETag from GET /v1/budgets/pricing or the per-entry GET |
Responses
Response samples
- 404
- 409
- 412
- 428
- 500
{- "error": "string"
}Set budgets
Authorizations:
header Parameters
| If-Match | string ETag from GET /v1/budgets |
Request Body schema: application/jsonrequired
Complete budget collection
Responses
Request samples
- Payload
{ }Response samples
- 400
- 412
- 500
{- "error": "string"
}Spend export (CSV)
A grouped, bucketed rollup of charge records as CSV, sorted bucket ascending then charged_usd descending then group key(s) ascending. A single group_by dimension renders a fixed "group_key" column; two or more render one named column per dimension, in the order given. The served window (after default/retention clamping) is echoed in the X-Spend-Export-From/To response headers. Experiment-gated; 404s when the operator has not enabled it.
Authorizations:
query Parameters
| group_by | string Comma-separated grouping dimensions, e.g. user,model. Each must be one of user, model, provider, with no repeats. Defaults to user. |
| granularity | string Enum: "day" "week" "month" Bucket width |
| from | string Window start, RFC 3339 or YYYY-MM-DD (default 30 days back, including today) |
| to | string Window end (exclusive), RFC 3339 or YYYY-MM-DD |
| model | string Filter: served model of the underlying event, exact match. Narrows which charges are included; does not change the grouping — use group_by for that |
| scope | string Enum: "user" "group" Filter: payer tier charged |
| subject_id | string Filter: payer charged, exact match |
Responses
Spend export by conversation label (CSV)
The spend export broken down by conversation label, as CSV, sorted bucket ascending then charged_usd descending then group key(s) ascending. Columns are bucket, one per group_by dimension in the order given, then facet and label, then charge_count and charged_usd. Rows do NOT partition total spend: a session carries one label per facet, so summing either measure across more than one facet multiplies it by the facet count, charge_count exactly as much as charged_usd — pass facet to narrow the export to one. Under a facet filter every row carries that facet, coverage rows included, so pivoting on it is safe. Charges with no label are still counted, under a label naming why: (no-session), (uncaptured), (unclassified) or (unset). The served window (after default/retention clamping) is echoed in the X-Spend-Export-From/To response headers. Experiment-gated; 404s when the operator has not enabled it.
Authorizations:
query Parameters
| group_by | string Comma-separated grouping dimensions, e.g. user,model. Each must be one of user, model, provider, with no repeats. Defaults to user. The facet and label columns are always present in addition to these |
| granularity | string Enum: "day" "week" "month" Bucket width |
| from | string Window start, RFC 3339 or YYYY-MM-DD (default 30 days back, including today) |
| to | string Window end (exclusive), RFC 3339 or YYYY-MM-DD |
| facet | string Filter: restrict the label column to this facet's labels, exact match. The facet vocabulary is operator configuration, so an unknown value yields an empty result rather than an error. Sessions classified without a label for this facet are still counted, under (unset) |
| model | string Filter: served model of the underlying event, exact match |
| scope | string Enum: "user" "group" Filter: payer tier charged |
| subject_id | string Filter: payer charged, exact match |
Responses
User budget breakdown slice
A user's spend sliced by one dimension. dimension=model is the current-period spend on the user's own budget; dimension=group is every group budget the user belongs to or has contributed to (no single period window). Entries sum to total_used_usd.
Authorizations:
path Parameters
| id required | string User subject_id |
query Parameters
| dimension required | string Enum: "model" "group" Slice axis |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "dimension": "string",
- "entries": [
- {
- "used_usd": "string",
- "value": "string"
}
], - "period": "string",
- "period_end": "string",
- "period_start": "string",
- "scope": "string",
- "subject_id": "string",
- "total_used_usd": "string"
}Get enterprise configuration
Returns the signed enterprise configuration envelope for the calling client.
Authorizations:
header Parameters
| X-Client-Type required | string Enum: "toolhive-desktop" "toolhive-cli" "toolhive-cloud-ui" Client type |
| X-Client-Version required | string Client version (semver, e.g. 1.2.3) |
| If-None-Match | string ETag for conditional GET (RFC 7232) |
Responses
Response samples
- 200
- 400
- 503
{- "config": {
- "assistant": {
- "enforcement": "enforced",
- "value": true
}, - "build_env": { },
- "ca_certificate": {
- "enforcement": "enforced",
- "value": {
- "pem": "string",
- "url": "string"
}
}, - "degraded_mode": {
- "grace_period": "string",
- "message": "string",
- "policy": "warn"
}, - "gateway": {
- "enforcement": "enforced",
- "value": {
- "api_url": "string",
- "proxy_url": "string"
}
}, - "help_menu": {
- "enforcement": "enforced",
- "value": true
}, - "non_registry_servers": {
- "enforcement": "enforced",
- "value": true
}, - "playground": {
- "enforcement": "enforced",
- "value": true
}, - "registry": {
- "enforcement": "enforced",
- "value": {
- "allow_private_ip": true,
- "api_url": "string",
- "server_api_url": "string"
}
}, - "telemetry": {
- "enforcement": "enforced",
- "value": {
- "headers": {
- "property1": "string",
- "property2": "string"
}, - "insecure": true,
- "metrics_enabled": true,
- "otel_endpoint": "string",
- "sampling_rate": 0,
- "tracing_enabled": true
}
}
}, - "degraded_mode": {
- "grace_period": "string",
- "message": "string",
- "policy": "warn"
}, - "etag": "sha256:abc123",
- "issued_at": "string",
- "not_after": "string",
- "refresh_interval": "5m0s",
- "schema_version": "1",
- "signature": "string"
}Add subgroup
Authorizations:
path Parameters
| group_id required | string Group UUID |
| child_id required | string Child group UUID |
Responses
Response samples
- 200
- 400
- 404
- 409
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Add user member
Authorizations:
path Parameters
| group_id required | string Group UUID |
| user_id required | string User UUID |
Responses
Response samples
- 200
- 400
- 404
- 409
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Clear a group's tool restriction on a connector
Authorizations:
path Parameters
| connector_id required | string Connector UUID |
| group_id required | string UserGroup UUID |
header Parameters
| If-Match required | string ETag from GET .../tool-restriction |
Responses
Response samples
- 200
- 400
- 404
- 412
- 428
- 500
{- "connector_id": "string",
- "group_id": "string",
- "restriction_mode": "string",
- "tool_ids": [
- "string"
], - "version": 0
}Create a Model Set
Authorizations:
Request Body schema: application/jsonrequired
Model Set
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 409
- 413
- 422
- 500
{- "description": "string",
- "id": "string",
- "kind": "authored",
- "member_count": 0,
- "model_ids": [
- "string"
], - "name": "string",
- "unrestricted": true,
- "version": 0
}Create connector
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
Request Body schema: application/jsonrequired
Connector to create
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 409
- 500
{- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}Create connector identity provider
Authorizations:
Request Body schema: application/jsonrequired
Identity provider to create
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 409
- 500
{- "created_at": "string",
- "id": "string",
- "name": "string",
- "oauth2_config": {
- "allow_private_ips": true,
- "authorization_endpoint": "string",
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "redirect_uri": "string",
- "scopes": [
- "string"
], - "token_endpoint": "string",
- "token_endpoint_auth_method": "string"
}, - "oidc_config": {
- "additional_authorization_params": {
- "property1": "string",
- "property2": "string"
}, - "allow_private_ips": true,
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "issuer_url": "string",
- "redirect_uri": "string",
- "scopes": [
- "string"
], - "subject_claim": "string",
- "token_endpoint_auth_method": "string"
}, - "provider_type": "string",
- "registration_mode": "string",
- "source": "string",
- "updated_at": "string"
}Create group
Authorizations:
Request Body schema: application/jsonrequired
Group to create
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Create managed secret
Authorizations:
Request Body schema: application/jsonrequired
Managed secret to create
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 409
- 500
- 503
{- "created_at": "string",
- "id": "string",
- "name": "string",
- "updated_at": "string"
}Discover connector identity provider OAuth metadata
Probes an MCP server and returns its RFC 9728 protected-resource and RFC 8414 authorization-server metadata.
Authorizations:
Request Body schema: application/jsonrequired
MCP server to inspect
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 422
- 502
{- "authorization_endpoint": "string",
- "authorization_server": "string",
- "discovery_url": "string",
- "mcp_url": "string",
- "registration_endpoint": "string",
- "resource": "string",
- "resource_metadata_url": "string",
- "scopes_supported": [
- "string"
], - "token_endpoint": "string",
- "token_endpoint_auth_methods_supported": [
- "string"
]
}Explain a User's effective model access
Authorizations:
path Parameters
| id required | string User UUID |
Responses
Response samples
- 200
- 400
- 500
{- "sets": [
- {
- "kind": "string",
- "member_count": 0,
- "name": "string",
- "set_id": "string",
- "sources": [
- {
- "group_id": "string",
- "group_name": "string",
- "kind": "default"
}
]
}
], - "unrestricted": true
}Get a group's tool restriction on a connector
Authorizations:
path Parameters
| connector_id required | string Connector UUID |
| group_id required | string UserGroup UUID |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "connector_id": "string",
- "group_id": "string",
- "restriction_mode": "string",
- "tool_ids": [
- "string"
], - "version": 0
}Response samples
- 200
- 400
- 404
- 500
{- "description": "string",
- "id": "string",
- "kind": "authored",
- "member_count": 0,
- "model_ids": [
- "string"
], - "name": "string",
- "unrestricted": true,
- "version": 0
}Response samples
- 200
- 400
- 404
- 500
{- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}Get connector
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}Get connector identity provider
Authorizations:
path Parameters
| id required | string IdentityProvider UUID |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "created_at": "string",
- "id": "string",
- "name": "string",
- "oauth2_config": {
- "allow_private_ips": true,
- "authorization_endpoint": "string",
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "redirect_uri": "string",
- "scopes": [
- "string"
], - "token_endpoint": "string",
- "token_endpoint_auth_method": "string"
}, - "oidc_config": {
- "additional_authorization_params": {
- "property1": "string",
- "property2": "string"
}, - "allow_private_ips": true,
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "issuer_url": "string",
- "redirect_uri": "string",
- "scopes": [
- "string"
], - "subject_claim": "string",
- "token_endpoint_auth_method": "string"
}, - "provider_type": "string",
- "registration_mode": "string",
- "source": "string",
- "updated_at": "string"
}Get connector policy
Authorizations:
path Parameters
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Response samples
- 200
- 400
- 404
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Get group members
Authorizations:
path Parameters
| id required | string Group UUID |
query Parameters
| limit | integer Maximum items per collection (default 50, max 200) |
| users_cursor | string Opaque cursor — pages the transitive-users collection forward (mutually exclusive with users_before) |
| users_before | string Opaque cursor — pages the transitive-users collection backward (mutually exclusive with users_cursor) |
| groups_cursor | string Opaque cursor — pages the direct-child-groups collection forward (mutually exclusive with groups_before) |
| groups_before | string Opaque cursor — pages the direct-child-groups collection backward (mutually exclusive with groups_cursor) |
| active | boolean Filter the transitive-users collection by active status (direct_child_groups is unaffected) |
| search | string Case-insensitive substring search: display_name/user_name/email on the transitive-users collection, display_name/name on the direct-child-groups collection |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "direct_child_groups": [
- {
- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}
], - "next_groups_cursor": "string",
- "next_users_cursor": "string",
- "prev_groups_cursor": "string",
- "prev_users_cursor": "string",
- "transitive_users": [
- {
- "active": true,
- "created_at": "string",
- "display_name": "string",
- "email": "string",
- "id": "string",
- "photo_url": "string",
- "source": "string",
- "updated_at": "string",
- "user_name": "string"
}
]
}Response samples
- 200
- 400
- 404
- 500
{- "active": true,
- "created_at": "string",
- "display_name": "string",
- "email": "string",
- "id": "string",
- "photo_url": "string",
- "source": "string",
- "updated_at": "string",
- "user_name": "string"
}Response samples
- 200
- 400
- 404
- 500
{- "items": [
- {
- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List connector connections
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "items": [
- {
- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}Response samples
- 200
- 500
{- "items": [
- {
- "created_at": "string",
- "id": "string",
- "name": "string",
- "oauth2_config": {
- "allow_private_ips": true,
- "authorization_endpoint": "string",
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "redirect_uri": "string",
- "scopes": [
- "string"
], - "token_endpoint": "string",
- "token_endpoint_auth_method": "string"
}, - "oidc_config": {
- "additional_authorization_params": {
- "property1": "string",
- "property2": "string"
}, - "allow_private_ips": true,
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "issuer_url": "string",
- "redirect_uri": "string",
- "scopes": [
- "string"
], - "subject_claim": "string",
- "token_endpoint_auth_method": "string"
}, - "provider_type": "string",
- "registration_mode": "string",
- "source": "string",
- "updated_at": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List connectors
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
Responses
Response samples
- 200
- 500
{- "items": [
- {
- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List discovered MCP servers
Lists the MCP servers the cluster is running as candidates a connector could be admitted from, each carrying the connectors on this gateway that already hold its endpoint.
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
Responses
Response samples
- 200
- 404
- 500
- 503
{- "servers": [
- {
- "allow_private_ips": true,
- "endpoint": "string",
- "existing_connectors": [
- {
- "id": "string",
- "name": "string"
}
], - "group": "string",
- "health": "string",
- "name": "string",
- "namespace": "string",
- "transport": "string"
}
]
}List groups
Authorizations:
query Parameters
| name | string Filter by group name |
| display_name | string Filter by display name |
| source | string Filter by provisioning source (e.g. scim) |
| search | string Case-insensitive substring search across display_name and name |
| cursor | string Opaque pagination cursor — pages forward from here (mutually exclusive with before) |
| before | string Opaque pagination cursor — pages backward from here (mutually exclusive with cursor) |
| limit | integer Maximum items to return (default 50, max 200) |
Responses
Response samples
- 200
- 400
- 500
{- "items": [
- {
- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List Model Sets
Authorizations:
query Parameters
| search | string Case-insensitive substring match on name |
| cursor | string Opaque pagination cursor |
| limit | integer Maximum items to return (default 50, max 200) |
Responses
Response samples
- 200
- 400
- 500
{- "items": [
- {
- "description": "string",
- "id": "string",
- "kind": "authored",
- "member_count": 0,
- "name": "string",
- "unrestricted": true,
- "version": 0
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List users
Authorizations:
query Parameters
string Filter by email address | |
| user_name | string Filter by username |
| source | string Filter by provisioning source (e.g. scim) |
| active | boolean Filter by active status |
| search | string Case-insensitive substring search across display_name, user_name, and email |
| cursor | string Opaque pagination cursor — pages forward from here (mutually exclusive with before) |
| before | string Opaque pagination cursor — pages backward from here (mutually exclusive with cursor) |
| limit | integer Maximum items to return (default 50, max 200) |
Responses
Response samples
- 200
- 400
- 500
{- "items": [
- {
- "active": true,
- "created_at": "string",
- "display_name": "string",
- "email": "string",
- "id": "string",
- "photo_url": "string",
- "source": "string",
- "updated_at": "string",
- "user_name": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}Patch group
Authorizations:
path Parameters
| id required | string Group UUID |
Request Body schema: application/jsonrequired
Fields to update
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 409
- 412
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Preview what deleting a Model Set would remove
Authorizations:
path Parameters
| id required | string Model Set UUID |
query Parameters
| kind | string Enum: "user" "group" Restrict subjects to one kind |
| search | string Case-insensitive substring match: a user on display name, user name or email; a group on display name or name. Counts stay totals. |
| cursor | string Opaque cursor from next_cursor; returns the page after it |
| before | string Opaque cursor from prev_cursor; returns the page before it (exclusive with cursor) |
| limit | integer Maximum subjects to return (default 50, max 200) |
Responses
Response samples
- 200
- 400
- 404
- 500
{- "group_grants": 0,
- "next_cursor": "string",
- "prev_cursor": "string",
- "subjects": [
- {
- "display_name": "string",
- "email": "string",
- "granted_at": "string",
- "id": "string",
- "kind": "user",
- "source": "scim"
}
], - "user_grants": 0
}Remove subgroup
Authorizations:
path Parameters
| group_id required | string Group UUID |
| child_id required | string Child group UUID |
Responses
Response samples
- 200
- 400
- 404
- 409
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Remove user member
Authorizations:
path Parameters
| group_id required | string Group UUID |
| user_id required | string User UUID |
Responses
Response samples
- 200
- 400
- 404
- 409
- 500
{- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}Rename a Model Set
Authorizations:
path Parameters
| id required | string Model Set UUID |
header Parameters
| If-Match required | string ETag from GET /v1/model-sets/{id} |
Request Body schema: application/jsonrequired
New name
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 409
- 412
- 422
- 428
- 500
{- "description": "string",
- "id": "string",
- "kind": "authored",
- "member_count": 0,
- "model_ids": [
- "string"
], - "name": "string",
- "unrestricted": true,
- "version": 0
}Replace a connector policy's granted user groups
Authorizations:
path Parameters
| id required | string Connector UUID |
header Parameters
| If-Match required | string ETag from GET /v1/connectors/{id}/policy |
Request Body schema: application/jsonrequired
User group ids
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 409
- 412
- 413
- 422
- 428
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Replace a Model Set's membership
Authorizations:
path Parameters
| id required | string Model Set UUID |
header Parameters
| If-Match required | string ETag from GET /v1/model-sets/{id} |
Request Body schema: application/jsonrequired
Model ids, or unrestricted
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 412
- 413
- 422
- 428
- 500
{- "description": "string",
- "id": "string",
- "kind": "authored",
- "member_count": 0,
- "model_ids": [
- "string"
], - "name": "string",
- "unrestricted": true,
- "version": 0
}Replace the Model Sets granted directly to a User
Authorizations:
path Parameters
| id required | string User UUID |
header Parameters
| If-Match required | string ETag from GET /v1/users/{id}/model-sets |
Request Body schema: application/jsonrequired
Model Set ids
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 412
- 422
- 428
- 500
{- "items": [
- {
- "id": "string",
- "kind": "authored",
- "name": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}Replace the Model Sets granted to a UserGroup
Authorizations:
path Parameters
| id required | string UserGroup UUID |
header Parameters
| If-Match required | string ETag from GET /v1/groups/{id}/model-sets |
Request Body schema: application/jsonrequired
Model Set ids
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 412
- 422
- 428
- 500
{- "items": [
- {
- "id": "string",
- "kind": "authored",
- "name": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}Revoke a user group's access to a connector
Authorizations:
path Parameters
| id required | string Connector UUID |
| group_id required | string User group UUID |
Responses
Response samples
- 200
- 400
- 404
- 409
- 412
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Set a connector policy's Cedar document
Authorizations:
path Parameters
| id required | string Connector UUID |
Request Body schema: application/jsonrequired
Cedar document
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 409
- 412
- 413
- 422
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Set a group's tool restriction on a connector
Authorizations:
path Parameters
| connector_id required | string Connector UUID |
| group_id required | string UserGroup UUID |
header Parameters
| If-Match required | string ETag from GET .../tool-restriction |
Request Body schema: application/jsonrequired
Restriction mode and tool ids
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 412
- 422
- 428
- 500
{- "connector_id": "string",
- "group_id": "string",
- "restriction_mode": "string",
- "tool_ids": [
- "string"
], - "version": 0
}Switch a connector policy back to structured authoring mode
Authorizations:
path Parameters
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 404
- 412
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Switch a connector policy to Cedar authoring mode
Authorizations:
path Parameters
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 404
- 412
- 500
{- "connector_id": "string",
- "document": "string",
- "granted_user_groups": [
- {
- "display_name": "string",
- "id": "string",
- "name": "string"
}
], - "mode": "string"
}Update connector
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
| id required | string Connector UUID |
Request Body schema: application/jsonrequired
Connector's new state
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 409
- 500
{- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}Update connector identity provider
Authorizations:
path Parameters
| id required | string IdentityProvider UUID |
Request Body schema: application/jsonrequired
Identity provider's new state
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 404
- 409
- 500
{- "created_at": "string",
- "id": "string",
- "name": "string",
- "oauth2_config": {
- "allow_private_ips": true,
- "authorization_endpoint": "string",
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "redirect_uri": "string",
- "scopes": [
- "string"
], - "token_endpoint": "string",
- "token_endpoint_auth_method": "string"
}, - "oidc_config": {
- "additional_authorization_params": {
- "property1": "string",
- "property2": "string"
}, - "allow_private_ips": true,
- "client_id": "string",
- "client_secret": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "dcr": {
- "discovery_url": "string",
- "initial_access_token": {
- "kubernetes_secret": {
- "key": "string",
- "name": "string",
- "namespace": "string"
}, - "managed_secret_id": "string"
}, - "registration_endpoint": "string",
- "software_id": "string",
- "software_statement": "string"
}, - "issuer_url": "string",
- "redirect_uri": "string",
- "scopes": [
- "string"
], - "subject_claim": "string",
- "token_endpoint_auth_method": "string"
}, - "provider_type": "string",
- "registration_mode": "string",
- "source": "string",
- "updated_at": "string"
}OAuth protected resource metadata
Returns RFC 9728 metadata describing this protected resource.
Responses
Response samples
- 200
{- "authorization_servers": [
- "string"
], - "bearer_methods_supported": [
- "string"
], - "jwks_uri": "string",
- "resource": "string",
- "scopes_supported": [
- "string"
]
}ToolHive configuration discovery
Returns a discovery document for ToolHive client bootstrap.
Responses
Response samples
- 200
{- "client_id": "string",
- "config_endpoint": "string",
- "issuer": "string",
- "jwks_uri": "string",
- "oauth_protected_resource": "string",
- "scopes_supported": [
- "string"
]
}Create a virtual API key
Mints a key tied to the authenticated caller's OIDC identity. The full plaintext secret is returned ONLY in this response — it is never retrievable afterwards. Ownership is derived from the caller's token, not the request body.
Authorizations:
Request Body schema: application/jsonrequired
Key creation parameters
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 401
- 500
{- "key": {
- "created_at": "string",
- "created_by": "string",
- "expires_at": "string",
- "id": "string",
- "last_used_at": "string",
- "metadata": {
- "property1": "string",
- "property2": "string"
}, - "name": "string",
- "owner_ref": "string",
- "prefix": "string",
- "status": "string"
}, - "secret": "string"
}Get one of the caller's virtual API keys
Never includes key secrets or hashes. Returns 404 (not 403) when the id exists but is owned by another caller, so key existence is not leaked across owners.
Authorizations:
path Parameters
| id required | string Key short ID |
Responses
Response samples
- 200
- 401
- 404
- 500
{- "created_at": "string",
- "created_by": "string",
- "expires_at": "string",
- "id": "string",
- "last_used_at": "string",
- "metadata": {
- "property1": "string",
- "property2": "string"
}, - "name": "string",
- "owner_ref": "string",
- "prefix": "string",
- "status": "string"
}List the caller's virtual API keys
Returns every key owned by the authenticated caller. Never includes key secrets or hashes.
Authorizations:
Responses
Response samples
- 200
- 401
- 500
{- "keys": [
- {
- "created_at": "string",
- "created_by": "string",
- "expires_at": "string",
- "id": "string",
- "last_used_at": "string",
- "metadata": {
- "property1": "string",
- "property2": "string"
}, - "name": "string",
- "owner_ref": "string",
- "prefix": "string",
- "status": "string"
}
]
}Re-enable one of the caller's disabled virtual API keys
Moves a disabled key back to active. Re-enabling a revoked key is rejected with 409 — revocation is permanent.
Authorizations:
path Parameters
| id required | string Key short ID |
Responses
Response samples
- 401
- 404
- 409
- 500
{- "error": "string"
}Rotate one of the caller's virtual API keys
Generates a new secret for the same key ID. The old secret keeps validating for a 24h grace period so in-flight callers can pick up the new secret. The new plaintext secret is returned only once.
Authorizations:
path Parameters
| id required | string Key short ID |
Responses
Response samples
- 200
- 401
- 404
- 500
{- "key": {
- "created_at": "string",
- "created_by": "string",
- "expires_at": "string",
- "id": "string",
- "last_used_at": "string",
- "metadata": {
- "property1": "string",
- "property2": "string"
}, - "name": "string",
- "owner_ref": "string",
- "prefix": "string",
- "status": "string"
}, - "secret": "string"
}Create my connection
Authorizations:
Request Body schema: application/jsonrequired
Connection to create
Responses
Request samples
- Payload
{ }Response samples
- 201
- 400
- 401
- 403
- 404
- 409
- 500
{- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}Enable or disable my connection
Authorizations:
path Parameters
| id required | string Connection UUID |
Request Body schema: application/jsonrequired
New enablement
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}Get a Connector visible to me
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
| id required | string Connector UUID |
Responses
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}Get my connection
Authorizations:
path Parameters
| id required | string Connection UUID |
Responses
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}Get the caller's own directory profile
Returns the authenticated caller's directory profile and transitive group membership, resolved from their verified token rather than a path parameter. An authenticated caller with no directory binding (never provisioned, or deactivated) gets 200 with an empty group list, not a 404 — a miss is not a failure. subject and issuer are always present since they come from the verified token; echoing issuer lets a caller self-diagnose a cross-issuer provisioning gap.
Authorizations:
Responses
Response samples
- 200
- 401
- 500
{- "active": true,
- "display_name": "string",
- "email": "string",
- "groups": [
- {
- "created_at": "string",
- "description": "string",
- "display_name": "string",
- "drained": true,
- "id": "string",
- "members": [
- {
- "display": "string",
- "id": "string",
- "type": "string"
}
], - "name": "string",
- "projected_deletion_at": "string",
- "source": "string",
- "source_value": "string",
- "source_variable": "string",
- "transitive_member_count": 0,
- "updated_at": "string"
}
], - "id": "string",
- "issuer": "string",
- "source": "string",
- "subject": "string",
- "user_name": "string"
}List Connectors visible to me
Authorizations:
path Parameters
| gateway_id required | string Connector-gateway install id |
query Parameters
| cursor | string Opaque pagination cursor — pages forward from here (mutually exclusive with before) |
| before | string Opaque pagination cursor — pages backward from here (mutually exclusive with cursor) |
| limit | integer Maximum items to return (default 20, max 200) |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "items": [
- {
- "allow_private_ips": true,
- "auth": {
- "aws_sts": {
- "fallback_role_arn": "string",
- "provider_id": "string",
- "region": "string",
- "role_claim": "string",
- "role_mappings": [
- {
- "claim": "string",
- "matcher": "string",
- "priority": 0,
- "role_arn": "string"
}
], - "service": "string",
- "session_duration": 0,
- "session_name_claim": "string"
}, - "header_injection": {
- "header_name": "string"
}, - "obo": {
- "audience": "string",
- "authority": "string",
- "cache_skew": "string",
- "client_id": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "tenant_id": "string"
}, - "token_exchange": {
- "audience": "string",
- "client_id": "string",
- "client_secret_configured": true,
- "external_token_header_name": "string",
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "token_url": "string"
}, - "type": "none",
- "upstream_inject": {
- "provider_id": "string"
}, - "xaa": {
- "idp_client_id": "string",
- "idp_token_url": "string",
- "insecure_target_token_url": true,
- "provider_id": "string",
- "scopes": [
- "string"
], - "subject_token_type": "string",
- "target_audience": "string",
- "target_client_id": "string",
- "target_resource": "string",
- "target_token_url": "string"
}
}, - "created_at": "string",
- "deployment_mode": "string",
- "description": "string",
- "endpoint": "string",
- "gateway_id": "string",
- "icon_url": "string",
- "id": "string",
- "name": "string",
- "origin": "string",
- "repository_url": "string",
- "source_name": "string",
- "source_namespace": "string",
- "status": "string",
- "support_url": "string",
- "transport": "string",
- "updated_at": "string",
- "version": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}List my connections
Authorizations:
query Parameters
| gateway_id | string Narrow to Connections on one gateway install |
| cursor | string Opaque pagination cursor — pages forward from here (mutually exclusive with before) |
| before | string Opaque pagination cursor — pages backward from here (mutually exclusive with cursor) |
| limit | integer Maximum items to return (default 20, max 200) |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "items": [
- {
- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}
], - "next_cursor": "string",
- "prev_cursor": "string"
}Set my connection's tool narrowing
Authorizations:
path Parameters
| id required | string Connection UUID |
Request Body schema: application/jsonrequired
New tool policy
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 401
- 403
- 404
- 413
- 500
{- "connector_id": "string",
- "created_at": "string",
- "enabled": true,
- "gateway_id": "string",
- "id": "string",
- "tools_enabled_by_default": true,
- "tools_exception_list": [
- "string"
], - "updated_at": "string",
- "user_id": "string"
}Connector tool-call activity
Authorizations:
path Parameters
| id required | string Connector id |
query Parameters
| gateway_id required | string connector-gateway instance id |
| user_id | string Platform user id (UUID); narrows to one user's calls |
| outcome | string Enum: "ok" "error" Outcome filter |
| decision | string Enum: "allowed" "denied" Decision filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| cursor | string Opaque keyset cursor from a previous page, pages forward (older) |
| before | string Opaque keyset cursor from a previous page, pages backward (newer); mutually exclusive with cursor |
| limit | integer Page size (default 50, max 500, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "next_cursor": "string",
- "prev_cursor": "string",
- "records": [
- {
- "billable": true,
- "billable_reason": "string",
- "call_id": "string",
- "category": "string",
- "connector_id": "string",
- "connector_name": "string",
- "decision": "string",
- "definition_version": "string",
- "environment": "string",
- "gateway_id": "string",
- "groups": [
- {
- "id": "string",
- "name": "string"
}
], - "occurred_at": "string",
- "original_tool_name": "string",
- "outcome": "string",
- "tool_name": "string",
- "user_email": "string",
- "user_id": "string"
}
]
}Connector usage
Authorizations:
path Parameters
| id required | string Connector id |
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
Responses
Response samples
- 200
- 400
- 500
{- "connector_id": "string",
- "connector_name": "string",
- "group_series": [
- {
- "group": {
- "id": "string",
- "name": "string"
}, - "points": [
- {
- "bucket_start": "string",
- "tool_call_count": 0
}
]
}
], - "tool_call_count": 0
}My tool-call activity
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| connector_id required | string Connector id |
| outcome | string Enum: "ok" "error" Outcome filter |
| decision | string Enum: "allowed" "denied" Decision filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| cursor | string Opaque keyset cursor from a previous page, pages forward (older) |
| before | string Opaque keyset cursor from a previous page, pages backward (newer); mutually exclusive with cursor |
| limit | integer Page size (default 50, max 500, clamped) |
Responses
Response samples
- 200
- 400
- 401
- 500
{- "next_cursor": "string",
- "prev_cursor": "string",
- "records": [
- {
- "billable": true,
- "billable_reason": "string",
- "call_id": "string",
- "category": "string",
- "connector_id": "string",
- "connector_name": "string",
- "decision": "string",
- "definition_version": "string",
- "environment": "string",
- "gateway_id": "string",
- "groups": [
- {
- "id": "string",
- "name": "string"
}
], - "occurred_at": "string",
- "original_tool_name": "string",
- "outcome": "string",
- "tool_name": "string",
- "user_email": "string",
- "user_id": "string"
}
]
}Per-event usage export
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| cursor | string Opaque keyset cursor from a previous page |
| limit | integer Page size (default 50, max 500, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "checkpoints": [
- {
- "chain_hash": "string",
- "chain_id": "string",
- "hash_alg": "string",
- "key_id": "string",
- "sequence": 0,
- "sig_alg": "string",
- "signature": "string",
- "signed_at": "string"
}
], - "next_cursor": "string",
- "records": [
- {
- "chain_id": "string",
- "id": "string",
- "prev_hash": "string",
- "record_hash": "string",
- "sequence": 0,
- "usage": {
- "billable": true,
- "billable_reason": "string",
- "call_id": "string",
- "category": "string",
- "connector_id": "string",
- "connector_name": "string",
- "decision": "string",
- "definition_version": "string",
- "environment": "string",
- "gateway_id": "string",
- "groups": [
- {
- "id": "string",
- "name": "string"
}
], - "occurred_at": "string",
- "original_tool_name": "string",
- "outcome": "string",
- "tool_name": "string",
- "user_email": "string",
- "user_id": "string"
}
}
]
}Top connectors
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| limit | integer Max entries (default 10, max 100, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "connectors": [
- {
- "connector_id": "string",
- "connector_name": "string",
- "tool_call_count": 0
}
]
}Top tools
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| limit | integer Max entries (default 10, max 100, clamped) |
Responses
Response samples
- 200
- 400
- 500
{- "tools": [
- {
- "connector_id": "string",
- "connector_name": "string",
- "original_tool_name": "string",
- "tool_call_count": 0,
- "tool_name": "string"
}
]
}Usage summary
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
Responses
Response samples
- 200
- 400
- 500
{- "active_user_count": 0,
- "tool_call_count": 0
}Usage time series
Authorizations:
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start | string Window start, RFC 3339 (default: unbounded) |
| end | string Window end, RFC 3339, exclusive (default: unbounded) |
| dimension | string Enum: "environment" "tool" "decision" "connector" Breakdown dimension |
Responses
Response samples
- 200
- 400
- 500
{- "bucket_width_seconds": 0,
- "buckets": [
- {
- "breakdown": [
- {
- "key": "string",
- "tool_call_count": 0
}
], - "bucket_start": "string",
- "tool_call_count": 0
}
], - "dimension": "string"
}User usage
Authorizations:
path Parameters
| id required | string Platform user id (UUID) |
query Parameters
| gateway_id required | string connector-gateway instance id |
| environment | string Deployment environment filter |
| start required | string Window start, RFC 3339 |
| end required | string Window end, RFC 3339, exclusive |
Responses
Response samples
- 200
- 400
- 500
{- "connectors": [
- {
- "connector_id": "string",
- "connector_name": "string",
- "last_activity": "string",
- "tool_call_count": 0,
- "tools": [
- {
- "last_activity": "string",
- "tool_call_count": 0,
- "tool_name": "string"
}
]
}
], - "last_activity": "string",
- "series": [
- {
- "bucket_start": "string",
- "tool_call_count": 0
}
], - "tool_call_count": 0,
- "user_id": "string"
}Set gateway connectivity state
Authorizations:
path Parameters
| gateway required | string Enum: "ai-gateway" "connector-gateway" Gateway key |
Request Body schema: application/jsonrequired
Desired state
Responses
Request samples
- Payload
{ }Response samples
- 200
- 400
- 403
- 500
{- "state": "string"
}