Skip to content
Stackship documentation Svenska

Stackship platformUsers

API reference

Every HTTP endpoint of the kernel module: authentication, IAM action, parameters, bodies and status codes.

Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.

Activity Tracking

POST /boundaries/{boundaryId}/activity

  • Authentication: required
  • IAM action: kernel/activity/write — evaluated at the resource in the path
  • Operation name: CreateActivityRecord

Parameters

Name In Type Required
boundaryId path uuid Yes

Request body: ActivityRequest

Responses

Status Meaning Body
200 OK uuid
400 The request is invalid ProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/activity/write at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/{resourceType}/{resourceName}/activity

  • Authentication: required
  • IAM action: kernel/activity/read — evaluated at the resource in the path
  • Operation name: GetActivityRecords

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceType path string Yes
resourceName path string Yes

Responses

Status Meaning Body
200 OK PagedListResponse<ActivityEntry>
400 The request is invalid ProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/activity/read at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/{resourceType}/{resourceName}/activity/config

  • Authentication: required
  • IAM action: kernel/activity/read — evaluated at the resource in the path
  • Operation name: GetActivityConfig

Parameters

Name In Type Required
boundaryId path string Yes
resourceGroup path string Yes
resourceType path string Yes
resourceName path string Yes

Responses

Status Meaning Body
200 OK ListConfig
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/activity/read at the evaluated scope

Bug Reports

POST /bug-reports

  • Authentication: required

Request body: SubmitBugReportRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Clusters

GET /clusters

Responses

Status Meaning Body
200 OK PagedListResponse<ClusterViewModel>
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/read at the evaluated scope

POST /clusters

Request body: CreateClusterRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/write at the evaluated scope

DELETE /clusters/{clusterId}

Parameters

Name In Type Required
clusterId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/write at the evaluated scope

GET /clusters/{clusterId}

  • Authentication: required
  • IAM action: kernel/clusters/read — evaluated at the resource in the path

Parameters

Name In Type Required
clusterId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/read at the evaluated scope

PUT /clusters/{clusterId}

Parameters

Name In Type Required
clusterId path uuid Yes

Request body: UpdateClusterRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/write at the evaluated scope

POST /clusters/{clusterId}/agent/revoke

Parameters

Name In Type Required
clusterId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/write at the evaluated scope

POST /clusters/{clusterId}/join-token

Parameters

Name In Type Required
clusterId path uuid Yes

Request body: IssueJoinTokenRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/clusters/write at the evaluated scope

Deployment Sources

GET /boundaries/{boundaryId}/sources

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: ListAllDeploymentSources

Parameters

Name In Type Required
boundaryId path uuid Yes

Responses

Status Meaning Body
200 OK PagedListResponse<UnifiedInstallation>
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope

GET /boundaries/{boundaryId}/sources/config

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: ListDeploymentSourcesConfig

Parameters

Name In Type Required
boundaryId path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope

POST /boundaries/{boundaryId}/sources/{sourceName}/create

  • Authentication: required
  • IAM action: kernel/deployments/write — evaluated at the resource in the path
  • Operation name: CreateDeploymentSource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes

Request body: CreateDeploymentSourceRequest

Responses

Status Meaning Body
201 Created InitiateInstallResponse
400 The request is invalid ProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/write at the evaluated scope
404 Not found ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/finalize

  • Authentication: none — anonymous callers are accepted
  • Operation name: FinalizeDeploymentSource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
app_id query string No
installation_id query string Yes
setup_action query string No
state query string No

Responses

Status Meaning Body
200 OK
400 The request is invalid ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/installations

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: Installations

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes

Responses

Status Meaning Body
200 OK PagedListResponse<Installation>
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope
404 Not found ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/installations/config

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: InstallationsConfig

Parameters

Name In Type Required
boundaryId path string Yes
sourceName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope

POST /boundaries/{boundaryId}/sources/{sourceName}/installations/{installationId}/repositories/{repositoryId}/webhooks/ensure

  • Authentication: required
  • IAM action: kernel/deployments/write — evaluated at the resource in the path
  • Operation name: EnsureWebhook

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
installationId path string Yes
repositoryId path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/write at the evaluated scope
404 Not found ProblemDetails
501 Not Implemented ProblemDetails

POST /boundaries/{boundaryId}/sources/{sourceName}/installations/{installationId}/token/{repositoryId}

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
installationId path string Yes
repositoryId path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/token at the evaluated scope

GET /boundaries/{boundaryId}/sources/{sourceName}/validate

  • Authentication: none — anonymous callers are accepted
  • Operation name: ValidateDeploymentSource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
code query string No
error query string No
error_description query string No
state query string No

Responses

Status Meaning Body
302 Found
400 The request is invalid ProblemDetails

POST /boundaries/{boundaryId}/sources/{sourceName}/webhooks

  • Authentication: none — anonymous callers are accepted
  • Operation name: DeploymentSourceWebhook

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes

Responses

Status Meaning Body
202 Accepted; the work continues in the background
404 Not found ProblemDetails
406 Not Acceptable ProblemDetails

DELETE /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}

  • Authentication: required
  • IAM action: kernel/deployments/delete — evaluated at the resource in the path
  • Operation name: DeleteDeploymentSource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Responses

Status Meaning Body
204 Done; no content
400 The request is invalid ProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/delete at the evaluated scope

PUT /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}/circuit

  • Authentication: required
  • IAM action: kernel/deployments/write — evaluated at the resource in the path
  • Operation name: SetDeploymentSourceCircuit

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Request body: CircuitSourceSettingsRequest

Responses

Status Meaning Body
200 OK CircuitSourceSettings
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/write at the evaluated scope
404 Not found ProblemDetails
409 Conflicts with the current state ProblemDetails

POST /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}/circuit/repositories

  • Authentication: required
  • IAM action: kernel/deployments/write — evaluated at the resource in the path
  • Operation name: CreateCircuitRepository

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Request body: CircuitRepositoryRequest

Responses

Status Meaning Body
201 Created Repository
400 The request is invalid ProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/write at the evaluated scope
404 Not found ProblemDetails
409 Conflicts with the current state ProblemDetails
502 Bad Gateway ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}/health

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: DeploymentSourceHealth

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope
404 Not found ProblemDetails

POST /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}/materialize

  • Authentication: required
  • Operation name: MaterializeRegistrySource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Request body: MaterializeRegistryRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /boundaries/{boundaryId}/sources/{sourceName}/{deploymentSourceId}/verify

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: VerifyRegistrySource

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
deploymentSourceId path string Yes

Request body: VerifyRegistryRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope

GET /boundaries/{boundaryId}/sources/{sourceName}/{installationId}/repositories

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: Repositories

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
installationId path string Yes

Responses

Status Meaning Body
200 OK Repository []
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope
404 Not found ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/{installationId}/repositories/{repositoryId}/branches

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: Branches

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
installationId path string Yes
repositoryId path string Yes

Responses

Status Meaning Body
200 OK Branch []
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope
404 Not found ProblemDetails

GET /boundaries/{boundaryId}/sources/{sourceName}/{installationId}/repositories/{repositoryId}/files

  • Authentication: required
  • IAM action: kernel/deployments/read — evaluated at the resource in the path
  • Operation name: RepositoryFile

Parameters

Name In Type Required
boundaryId path uuid Yes
sourceName path string Yes
installationId path string Yes
repositoryId path string Yes
path query string No
ref query string No

Responses

Status Meaning Body
200 OK SourceFile
400 The request is invalid HttpValidationProblemDetails
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/deployments/read at the evaluated scope
404 Not found ProblemDetails

GET /sources/{sourceName}/validate

  • Authentication: none — anonymous callers are accepted
  • Operation name: ValidateDeploymentSourceCallback

Parameters

Name In Type Required
sourceName path string Yes
code query string No
error query string No
error_description query string No
state query string No

Responses

Status Meaning Body
302 Found
400 The request is invalid ProblemDetails

Docs

GET /docs/kernel/manifest.json

  • Authentication: required
  • Operation name: DocsManifest_kernel

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /docs/kernel/{path}

  • Authentication: required
  • Operation name: DocsFile_kernel

Parameters

Name In Type Required
path path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Docs Feedback

GET /docs-feedback/export

  • Authentication: required
  • IAM action: kernel/docsFeedback/export — evaluated at the platform root
  • Operation name: ExportDocsFeedback

Parameters

Name In Type Required
format query string No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/docsFeedback/export at the evaluated scope

POST /docs-feedback/search-misses

  • Authentication: required
  • Operation name: SubmitDocsSearchMiss

Request body: DocsSearchMissRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /docs-feedback/votes

  • Authentication: required
  • Operation name: SubmitDocsVote

Request body: DocsVoteRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Email Settings (Admin)

GET /admin/email-settings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailSettings/manage at the evaluated scope

PUT /admin/email-settings

Request body: UpsertEmailSettingsRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailSettings/manage at the evaluated scope

POST /admin/email-settings/test

Request body: TestEmailSettingsRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailSettings/manage at the evaluated scope

Email Templates (Admin)

GET /admin/email-templates

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

GET /admin/email-templates/{key}/{locale}

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

PUT /admin/email-templates/{key}/{locale}

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Request body: UpsertEmailTemplateRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

POST /admin/email-templates/{key}/{locale}/preview

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Request body: PreviewEmailTemplateRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

POST /admin/email-templates/{key}/{locale}/reset

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

POST /admin/email-templates/{key}/{locale}/restore/{version}

Parameters

Name In Type Required
key path string Yes
locale path string Yes
version path integer Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

POST /admin/email-templates/{key}/{locale}/test-send

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Request body: TestSendEmailTemplateRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

GET /admin/email-templates/{key}/{locale}/versions

Parameters

Name In Type Required
key path string Yes
locale path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/emailTemplates/manage at the evaluated scope

LLM Gateways (Admin)

GET /admin/llm-gateways

  • Authentication: required
  • IAM action: kernel/llmGateways/read — evaluated at the platform root
  • Operation name: ListLlmGateways

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/read at the evaluated scope

POST /admin/llm-gateways

  • Authentication: required
  • IAM action: kernel/llmGateways/write — evaluated at the platform root
  • Operation name: CreateLlmGateway

Request body: CreateLlmGatewayRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/write at the evaluated scope

GET /admin/llm-gateways/assignments

  • Authentication: required
  • IAM action: kernel/llmGateways/read — evaluated at the platform root
  • Operation name: ListLlmGatewayAssignments

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/read at the evaluated scope

PUT /admin/llm-gateways/assignments/{purpose}

  • Authentication: required
  • IAM action: kernel/llmGateways/write — evaluated at the platform root
  • Operation name: PutLlmGatewayAssignment

Parameters

Name In Type Required
purpose path string Yes

Request body: PutLlmGatewayAssignmentRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/write at the evaluated scope

POST /admin/llm-gateways/verify

  • Authentication: required
  • IAM action: kernel/llmGateways/write — evaluated at the platform root
  • Operation name: VerifyLlmGatewayDraft

Request body: VerifyLlmGatewayRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/write at the evaluated scope

DELETE /admin/llm-gateways/{id}

  • Authentication: required
  • IAM action: kernel/llmGateways/delete — evaluated at the platform root
  • Operation name: DeleteLlmGateway

Parameters

Name In Type Required
id path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/delete at the evaluated scope

GET /admin/llm-gateways/{id}

  • Authentication: required
  • IAM action: kernel/llmGateways/read — evaluated at the platform root
  • Operation name: GetLlmGateway

Parameters

Name In Type Required
id path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/read at the evaluated scope

PUT /admin/llm-gateways/{id}

  • Authentication: required
  • IAM action: kernel/llmGateways/write — evaluated at the platform root
  • Operation name: UpdateLlmGateway

Parameters

Name In Type Required
id path uuid Yes

Request body: UpdateLlmGatewayRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/write at the evaluated scope

POST /admin/llm-gateways/{id}/verify

  • Authentication: required
  • IAM action: kernel/llmGateways/write — evaluated at the platform root
  • Operation name: VerifyLlmGateway

Parameters

Name In Type Required
id path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/llmGateways/write at the evaluated scope

MCP Settings (Admin)

GET /admin/mcp-settings

  • Authentication: required
  • IAM action: kernel/mcpSettings/manage — evaluated at the platform root
  • Operation name: GetMcpSettings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/mcpSettings/manage at the evaluated scope

PUT /admin/mcp-settings

  • Authentication: required
  • IAM action: kernel/mcpSettings/manage — evaluated at the platform root
  • Operation name: UpdateMcpSettings

Request body: UpdateMcpSettingsRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/mcpSettings/manage at the evaluated scope

Mcp

GET /.well-known/oauth-protected-resource

  • Authentication: none — anonymous callers are accepted

Responses

Status Meaning Body

GET /.well-known/oauth-protected-resource/mcp

  • Authentication: none — anonymous callers are accepted

Responses

Status Meaning Body

POST /mcp

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

Module Status

GET /api/modules/status

Get the online/offline status of all registered modules

  • Authentication: required
  • Operation name: GetModuleStatus

Responses

Status Meaning Body
200 OK DynamicModuleStatusResponse []
401 Not signed in, or the token is invalid

Operations

GET /boundaries/{boundaryId}/operations

  • Authentication: required
  • IAM action: kernel/operations/read — evaluated at the resource in the path
  • Operation name: ListOperations

Parameters

Name In Type Required
boundaryId path uuid Yes
from query date-time No
pageSize query integer No
pageToken query string No
resourceName query string No
resourceType query string No
search query string No
status query string No
to query date-time No
viewScope query string No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/operations/read at the evaluated scope

POST /boundaries/{boundaryId}/operations

  • Authentication: required
  • Operation name: StartOperation

Parameters

Name In Type Required
boundaryId path uuid Yes

Request body: StartOperationRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /boundaries/{boundaryId}/operations/access-requests/changed

  • Authentication: required
  • Operation name: NotifyAccessRequestChanged

Parameters

Name In Type Required
boundaryId path uuid Yes

Request body: AccessRequestChangedDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /boundaries/{boundaryId}/operations/dismiss-all

  • Authentication: required
  • IAM action: kernel/operations/read — evaluated at the resource in the path
  • Operation name: DismissAllOperations

Parameters

Name In Type Required
boundaryId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/operations/read at the evaluated scope

GET /boundaries/{boundaryId}/operations/{operationId}

  • Authentication: required
  • IAM action: kernel/operations/read — evaluated at the resource in the path
  • Operation name: GetOperationById

Parameters

Name In Type Required
boundaryId path uuid Yes
operationId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/operations/read at the evaluated scope

POST /boundaries/{boundaryId}/operations/{operationId}/dismiss

  • Authentication: required
  • IAM action: kernel/operations/read — evaluated at the resource in the path
  • Operation name: DismissOperation

Parameters

Name In Type Required
boundaryId path uuid Yes
operationId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/operations/read at the evaluated scope

PATCH /boundaries/{boundaryId}/operations/{operationId}/status

  • Authentication: required
  • Operation name: UpdateOperationStatus

Parameters

Name In Type Required
boundaryId path uuid Yes
operationId path uuid Yes

Request body: UpdateStatusRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /boundaries/{boundaryId}/operations/{operationId}/steps

  • Authentication: required
  • Operation name: CreateOperationStep

Parameters

Name In Type Required
boundaryId path uuid Yes
operationId path uuid Yes

Request body: CreateStepRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PATCH /boundaries/{boundaryId}/operations/{operationId}/steps/{stepId}

  • Authentication: required
  • Operation name: UpdateOperationStep

Parameters

Name In Type Required
boundaryId path uuid Yes
operationId path uuid Yes
stepId path uuid Yes

Request body: UpdateStepRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/{resourceType}/{resourceName}/operations

  • Authentication: required
  • IAM action: kernel/operations/read — evaluated at the resource in the path
  • Operation name: ListResourceOperations

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceType path string Yes
resourceName path string Yes
status query string No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/operations/read at the evaluated scope

POST /operations

  • Authentication: required
  • Operation name: StartPlatformOperation

Request body: StartOperationRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /operations/{operationId}

  • Authentication: required
  • Operation name: GetPlatformOperationById

Parameters

Name In Type Required
operationId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PATCH /operations/{operationId}/status

  • Authentication: required
  • Operation name: UpdatePlatformOperationStatus

Parameters

Name In Type Required
operationId path uuid Yes

Request body: UpdateStatusRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

POST /operations/{operationId}/steps

  • Authentication: required
  • Operation name: CreatePlatformOperationStep

Parameters

Name In Type Required
operationId path uuid Yes

Request body: CreateStepRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PATCH /operations/{operationId}/steps/{stepId}

  • Authentication: required
  • Operation name: UpdatePlatformOperationStep

Parameters

Name In Type Required
operationId path uuid Yes
stepId path uuid Yes

Request body: UpdateStepRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Platform Topology

GET /admin/platform/components/{key}

  • Authentication: required
  • IAM action: kernel/platform/diagnose — evaluated at the platform root
  • Operation name: GetPlatformComponentDetail

Parameters

Name In Type Required
key path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/platform/diagnose at the evaluated scope

GET /admin/platform/postgres

  • Authentication: required
  • IAM action: kernel/platform/diagnose — evaluated at the platform root
  • Operation name: GetPlatformDatabaseDiagnostics

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/platform/diagnose at the evaluated scope

GET /admin/platform/topology

  • Authentication: required
  • IAM action: kernel/platform/read — evaluated at the platform root
  • Operation name: GetPlatformTopology

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/platform/read at the evaluated scope

Resource Revisions

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/{resourceType}/{resourceName}/revisions

List a resource's spec revisions, newest first, without their specs

  • Authentication: required
  • Operation name: ListResourceRevisions

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceType path string Yes
resourceName path string Yes

Responses

Status Meaning Body
200 OK PagedListResponse<ResourceRevisionSummary>
401 Not signed in, or the token is invalid

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/{resourceType}/{resourceName}/revisions/{number}

Read one spec revision, spec included

  • Authentication: required
  • Operation name: GetResourceRevision

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceType path string Yes
resourceName path string Yes
number path integer Yes

Responses

Status Meaning Body
200 OK ResourceRevisionDetail
401 Not signed in, or the token is invalid
404 Not found ProblemDetails

Search across all resources, services, and categories

  • Authentication: required
  • IAM action: search/read — evaluated at the resource in the path
  • Operation name: GlobalSearch

Parameters

Name In Type Required
boundaryId path uuid Yes
lang query string No
q query string No
types query string No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold search/read at the evaluated scope

System

GET /api/contract

Get the platform resource contract

Returns the machine-readable descriptor of the generic resource surface — resource types, their capabilities, and field-level schemas with write semantics (immutable / server-resolved / read-only / write-only). This is the source both the Terraform provider and the CLI generate from.

  • Authentication: required
  • Operation name: GetPlatformContract

Responses

Status Meaning Body
200 OK PlatformContractResponse
401 Not signed in, or the token is invalid

GET /api/routes

Get all registered routes

Returns comprehensive information about all registered routes in the application, including both static module routes and dynamic module routes. **Static routes** are from modules compiled into the application. **Dynamic routes** are from modules registered at runtime via the dynamic module system. The response includes: - Route patterns and HTTP methods - Authentication requirements - Module information and metadata - Route parameters and tags **Note:** Results are cached in Redis for 5 minutes to optimize performance. Changes to routes may take up to 5 minutes to appear.

  • Authentication: none — anonymous callers are accepted
  • Operation name: GetAllRoutes

Responses

Status Meaning Body
200 OK RouteDiscoveryResponse
500 Internal error ProblemDetails

Telemetry

POST /telemetry/browser-events

  • Authentication: required
  • Operation name: IngestBrowserTelemetry

Request body: BrowserTelemetryEvent []

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Telemetry Settings (Admin)

GET /admin/telemetry-settings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/telemetrySettings/manage at the evaluated scope

PUT /admin/telemetry-settings

Request body: UpdateTelemetrySettingsRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold kernel/telemetrySettings/manage at the evaluated scope

User Settings

GET /user/settings

  • Authentication: required
  • Operation name: GetUserSettings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PUT /user/settings

  • Authentication: required
  • Operation name: UpdateUserSettings

Request body: UpdateUserSettingsRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /user/settings/boundary

  • Authentication: required
  • Operation name: GetSelectedBoundary

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PUT /user/settings/boundary

  • Authentication: required
  • Operation name: UpdateSelectedBoundary

Request body: SelectedBoundaryDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /user/settings/notifications

  • Authentication: required
  • Operation name: GetNotificationSettings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PUT /user/settings/notifications

  • Authentication: required
  • Operation name: UpdateNotificationSettings

Request body: NotificationSettingsDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /user/settings/portal

  • Authentication: required
  • Operation name: GetPortalSettings

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PUT /user/settings/portal

  • Authentication: required
  • Operation name: UpdatePortalSettings

Request body: PortalSettingsDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

PUT /user/settings/whats-new

  • Authentication: required
  • Operation name: MarkWhatsNewSeen

Request body: WhatsNewSeenRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Other endpoints

GET /api/routes/openapi.json

  • Authentication: none — anonymous callers are accepted

Responses

Status Meaning Body

GET /hubs/crates

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /hubs/crates/negotiate

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /hubs/operations

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /hubs/operations/negotiate

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /hubs/resource-status

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /hubs/resource-status/negotiate

  • Authentication: required

Responses

Status Meaning Body
401 Not signed in, or the token is invalid

GET /platform/version

  • Authentication: required
  • Operation name: PlatformVersion

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /version

  • Authentication: none — anonymous callers are accepted
  • Operation name: Version_kernel

Responses

Status Meaning Body
200 OK

Schemas

AccessRequestChangedDto

Property Type Nullable
actorId uuid Yes
occurredUtc date-time No
principalId uuid No
requestId uuid No
roleDefinitionId uuid No
scope string No
status string No

ActivityEntry

Property Type Nullable
action string No
actionDescription string Yes
clusterId uuid No
id uuid No
ipAddress string Yes
metadata map (string) No
resourceGroup string No
resourceName string Yes
resourceType string No
status integer No
timestamp date-time No
userAgent string Yes
userId uuid No
userName string Yes

ActivityRequest

Property Type Nullable
action string No
actionDescription string Yes
boundary uuid No
metadata map (string) No
resourceGroup string No
resourceName string No
resourceType string No
status integer No

Branch

Property Type Nullable
commitSha string No
name string No

BrowserTelemetryEvent

Property Type Nullable
correlationId string Yes
level string Yes
message string Yes
release string Yes
route string Yes
stack string Yes
traceId string Yes
userAgent string Yes

CircuitRepositoryRequest

Property Type Nullable
description string Yes
name string No

CircuitSourceSettings

Property Type Nullable
enabled boolean No
namespace string Yes

CircuitSourceSettingsRequest

Property Type Nullable
enabled boolean No
namespace string Yes

ClusterConnectivityMode

One of: Direct, Agent.

ClusterViewModel

Property Type Nullable
acceptsInboundLinks boolean No
agentEnrolledUtc date-time Yes
agentLastSeenUtc date-time Yes
agentRevokedUtc date-time Yes
apiUrl string No
connectivityMode ClusterConnectivityMode No
id uuid No
inboundEndpoint string Yes
name string Yes
region string Yes

CreateClusterRequest

Property Type Nullable
acceptsInboundLinks boolean Yes
apiUrl string Yes
clusterCertificate string Yes
connectivityMode ClusterConnectivityMode Yes
inboundEndpoint string Yes
name string No
region string No

CreateDeploymentSourceRequest

Property Type Nullable
accessToken string Yes
applicationId string Yes
applicationSecret string Yes
baseUrl string Yes
organization string Yes
registryPassword string Yes
registryServer string Yes
registryUsername string Yes
tenantId string Yes

CreateLlmGatewayRequest

Property Type Nullable
apiKey string Yes
baseUrl string Yes
isDefault boolean Yes
models LlmGatewayModelInput [] Yes
name string Yes
provider string Yes
slug string Yes

CreateStepRequest

Property Type Nullable
actions OperationActionDto [] Yes
displayName string No
metadata map (string) Yes
name string No

CustomResourceDefinitionInfo

Property Type Nullable
fullName string No
group string No
plural string No
userManaged boolean No
version string No

DocsSearchMissRequest

Property Type Nullable
lang string Yes
query string Yes

DocsVoteRequest

Property Type Nullable
comment string Yes
helpful boolean Yes
lang string Yes
moduleVersion string Yes
pageId string Yes

DynamicModuleInfo

Property Type Nullable
baseAddress string No
customResourceDefinitions CustomResourceDefinitionInfo [] No
displayName string No
heartbeatTimeout duration No
key string No
lastHeartbeat date-time No
status string No

DynamicModuleStatusResponse

Property Type Nullable
displayName string No
key string No
lastHeartbeatUtc date-time No
status string No

DynamicRouteInfo

Property Type Nullable
baseAddress string No
description string No
methods string [] No
moduleKey string No
moduleName string No
name string Yes
pattern string No
requiresAuthentication boolean No
status string No
tags string [] No

EmailTemplateVariable

Property Type Nullable
description string Yes
name string No
required boolean No
sampleValue any Yes
type string No

FilterDefinition

Property Type Nullable
key string No
label string No
multiSelect boolean No
operators string [] Yes
options FilterOption [] Yes
type string No

FilterOption

Property Type Nullable
label string No
value string No

InitiateInstallResponse

Property Type Nullable
providerData any Yes
redirectUrl string No
state string No

Installation

Property Type Nullable
account string No
accountAvatarUrl string No
accountType string No
id string No
repositories Repository [] No
repositorySelection string No
status string Yes

IssueJoinTokenRequest

Property Type Nullable
lifetimeMinutes integer Yes

ListConfig

Property Type Nullable
defaultPageSize integer No
defaultSort string Yes
filters FilterDefinition [] No
searchEnabled boolean No
searchPlaceholder string Yes
sortFields SortFieldDefinition [] Yes

LlmGatewayModelInput

Property Type Nullable
enabled boolean No
id string Yes

MaterializeRegistryRequest

Property Type Nullable
clusterId uuid No
resourceGroup string No

ModuleContractCrd

Property Type Nullable
group string No
kind string No
plural string No
singular string No
version string No

ModuleContractProperty

Property Type Nullable
$ref string Yes
aliasFor string Yes
filterable boolean No
format string Yes
immutable boolean No
label string Yes
listColumn integer Yes
operators string [] Yes
options string [] Yes
readOnly boolean No
secret boolean No
secretVersionField string Yes
serverResolved boolean No
sortable boolean No
type string Yes
writeOnly boolean No

ModuleContractSchema

Property Type Nullable
properties map (ModuleContractProperty) Yes
type string No
unclassified boolean No

ModuleInfo

Property Type Nullable
assembly string No
fullTypeName string No
typeName string No

ModuleResourceCapabilities

Property Type Nullable
actions string [] Yes
backup boolean No
patch boolean No
scalable boolean No
selfCompleteOperations boolean No

NotificationSettingsDto

Property Type Nullable
email boolean No
enabled boolean No
portal boolean No

OperationActionDto

Property Type Nullable
kind string No
label string No
url string No

PagedListResponse<ActivityEntry>

Property Type Nullable
items ActivityEntry [] No
pagination PaginationMeta No

PagedListResponse<ClusterViewModel>

Property Type Nullable
items ClusterViewModel [] No
pagination PaginationMeta No

PagedListResponse<Installation>

Property Type Nullable
items Installation [] No
pagination PaginationMeta No

PagedListResponse<ResourceRevisionSummary>

Property Type Nullable
items ResourceRevisionSummary [] No
pagination PaginationMeta No

PagedListResponse<UnifiedInstallation>

Property Type Nullable
items UnifiedInstallation [] No
pagination PaginationMeta No

PaginationMeta

Property Type Nullable
hasNextPage boolean No
hasPreviousPage boolean No
page integer No
pageSize integer No
totalItems integer No
totalPages integer No

PlatformContractResourceType

Property Type Nullable
actionPrefix string Yes
capabilities ModuleResourceCapabilities No
crd ModuleContractCrd No
dataOperations string [] No
module string No
routePlural string No
schema string No
scope string No
terminalStatuses string [] No

PlatformContractResponse

Property Type Nullable
contractHash string Yes
descriptorVersion string No
platformVersion string No
resourceTypes PlatformContractResourceType [] No
routes PlatformContractRoute [] No
schemas map (ModuleContractSchema) No

PlatformContractRoute

Property Type Nullable
iamAction string Yes
iamScope string Yes
isDataAction boolean No
methods string [] No
name string Yes
pattern string No
requiresAuth boolean No
tags string [] Yes

PortalSettingsDto

Property Type Nullable
language string No
theme string No
whatsNewSeenRelease string Yes

PreviewEmailTemplateRequest

Property Type Nullable
htmlSource string Yes
subject string Yes
textSource string Yes
variables map (any) Yes

PutLlmGatewayAssignmentRequest

Property Type Nullable
gatewayId uuid Yes
model string Yes

Repository

Property Type Nullable
cloneUrl string No
defaultBranch string No
fullName string No
id string No
name string No
private boolean No

ResourceRevisionDetail

Property Type Nullable
createdUtc date-time No
id uuid No
moduleClientId string Yes
revisionNumber integer No
spec string No
specHash string No
userSubject string Yes
verb string No

ResourceRevisionSummary

Property Type Nullable
createdUtc date-time No
id uuid No
moduleClientId string Yes
revisionNumber integer No
specHash string No
userSubject string Yes
verb string No

RouteDiscoveryResponse

Property Type Nullable
cacheDuration duration No
dynamicModules DynamicModuleInfo [] No
dynamicRoutes DynamicRouteInfo [] No
generatedAt date-time No
staticModules ModuleInfo [] No
staticRoutes RouteInfo [] No
totalRoutes integer No

RouteInfo

Property Type Nullable
methods string [] No
name string No
parameters RouteParameter [] No
pattern string No
requiresAuthentication boolean No
tags string [] No

RouteParameter

Property Type Nullable
isCatchAll boolean No
isOptional boolean No
name string No

SelectedBoundaryDto

Property Type Nullable
id uuid No
name string No
region string No

SortFieldDefinition

Property Type Nullable
key string No
label string No

SourceFile

Property Type Nullable
content string No
path string No
ref string No

StartOperationRequest

Property Type Nullable
actions OperationActionDto [] Yes
boundaryId uuid Yes
correlationId uuid Yes
initiatedBy string Yes
link string Yes
operationKind string No
resourceGroup string Yes
resourceId string Yes
resourceName string No
resourceType string No
supersedeOtherKinds boolean No

SubmitBugReportRequest

Property Type Nullable
description string Yes
sector string Yes
title string Yes
url string Yes

TestEmailSettingsRequest

Property Type Nullable
toAddress string Yes

TestSendEmailTemplateRequest

Property Type Nullable
toAddress string Yes
variables map (any) Yes

UnifiedInstallation

Property Type Nullable
account string No
accountAvatarUrl string No
accountType string No
capability string No
circuitEnabled boolean No
circuitNamespace string Yes
id string No
provider string No
repositories Repository [] No
repositorySelection string No
status string Yes

UpdateClusterRequest

Property Type Nullable
acceptsInboundLinks boolean Yes
apiUrl string Yes
clusterCertificate string Yes
connectivityMode ClusterConnectivityMode Yes
inboundEndpoint string Yes
name string Yes
region string Yes

UpdateLlmGatewayRequest

Property Type Nullable
apiKey string Yes
baseUrl string Yes
isDefault boolean Yes
models LlmGatewayModelInput [] Yes
name string Yes

UpdateMcpSettingsRequest

Property Type Nullable
enabled boolean No

UpdateStatusRequest

Property Type Nullable
actions OperationActionDto [] Yes
message string Yes
status string No

UpdateStepRequest

Property Type Nullable
actions OperationActionDto [] Yes
message string Yes
metadata map (string) Yes
status string No

UpdateTelemetrySettingsRequest

Property Type Nullable
enabled boolean No
endpoint string Yes
minimumSeverity string Yes
token string Yes
traceSampleRatio number No
username string Yes

UpdateUserSettingsRequest

Property Type Nullable
notifications NotificationSettingsDto Yes
portalSettings PortalSettingsDto Yes
selectedBoundary SelectedBoundaryDto Yes

UpsertEmailSettingsRequest

Property Type Nullable
fromAddress string Yes
fromName string Yes
host string Yes
password string Yes
port integer Yes
replyToAddress string Yes
useImplicitTls boolean Yes
username string Yes

UpsertEmailTemplateRequest

Property Type Nullable
htmlSource string No
subject string No
textSource string No
variables EmailTemplateVariable [] Yes

VerifyLlmGatewayRequest

Property Type Nullable
apiKey string Yes
baseUrl string Yes
gatewayId uuid Yes

VerifyRegistryRequest

Property Type Nullable
image string No

WhatsNewSeenRequest

Property Type Nullable
release string Yes