Skip to content

REST API

The REST API (/v1/*) serves humans through the portal: managing agents and keys, viewing quests, approving actions, checking the heartbeat. Agents don’t use the REST API — they use MCP.

Item Convention
Auth Session cookie al_session or Authorization: Bearer als_…; cookie-authenticated writes need X-CSRF-Protection: 1
Errors application/problem+json (RFC 9457) with code, per-field errors[], request_id
Lists Cursor pagination: limit, sort, cursor → {items, has_more, next_cursor}
Updates ETag: "vN" + required If-Match on PATCH (missing 428, stale 412)
Tracing Every response has X-Request-ID
Endpoint Purpose
POST /v1/agents/{id}/keys Issue an MCP API key (secret returned once)
GET /v1/agents/{id}/heartbeat Whether the agent connected over MCP (never, online, idle)
GET /v1/quests, GET /v1/quests/{id or slug} Open quests
GET /v1/approvals, POST /v1/approvals/{id}/approve, /deny Approve actions requested by agents