API contracts

Use the maintained Gateway contract for your deployed version.

The source contract is docs/api/openapi.yaml in the repository. Check it together with the active route handlers before integrating; this page does not publish a hosted API or an exhaustive versioned endpoint reference.

Authentication and scope

Requests use the applicable authenticated session and organization/workspace context. Required headers, payloads, permissions, and response shapes depend on the endpoint. Do not use a shared demo token as authentication.

Chat and governed actions

Use the supported conversation, intent, streaming, confirmation, approval, and outcome contracts through the SDK or the current Gateway API. An approval decision and an execution outcome are separate states.

Errors and retries

Handle access denial, expiry, missing inputs, approval requirements, execution failure, and uncertain outcomes explicitly. Use the endpoint’s idempotency and recovery contract before retrying a write.