Praesidia API reference
Every customer-facing REST operation, generated from the API's OpenAPI description: 1226 operations in 142 groups.
Using this reference
Paths are relative to your Praesidia API origin. Organization-scoped operations take your organization ID in the {orgId} path segment.
Requests authenticate with a Praesidia API key in the X-API-Key header (or as an Authorization: Bearer credential), or with a session access token. The OpenAPI file lists the accepted scheme, parameters, request bodies and response schemas for each operation; load it into any OpenAPI-compatible client or code generator.
The file covers the operations your workspace can call. Platform-operator, service-to-service and inbound webhook endpoints are not part of it. Spec version 0.0.1.
Operations by group
A2A Protocol
| Method | Path | Operation |
|---|---|---|
| POST | /a2a/tasks | Submit a task (A2A) |
| POST | /a2a/tasks/{taskId}/result | Report task result (A2A) |
| GET | /a2a/tasks/{taskId}/execution-context | Read current execution admission for the assigned polling server |
| GET | /a2a/tasks/pending/{clientId} | Poll for pending tasks (A2A) |
Access Review
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/access-reviews/generate | Generate reviews |
| POST | /organizations/{orgId}/access-reviews/generate/inactivity | Generate inactivity reviews |
| GET | /organizations/{orgId}/access-reviews | Find all |
| GET | /organizations/{orgId}/access-reviews/pending | Find pending |
| POST | /organizations/{orgId}/access-reviews/{reviewId}/approve | Approve |
| POST | /organizations/{orgId}/access-reviews/{reviewId}/revoke | Revoke |
| POST | /organizations/{orgId}/access-reviews/generate/entitlements | Open a certification campaign over agent entitlements |
| POST | /organizations/{orgId}/access-reviews/{reviewId}/attest | Sign the owner or security attestation on a certification |
| POST | /organizations/{orgId}/access-reviews/{reviewId}/certify | Close an agent entitlement certification (retain/revoke/modify) |
Account
| Method | Path | Operation |
|---|---|---|
| POST | /account/email-change | Request email change |
| POST | /account/email-change/confirm | Confirm email change |
| GET | /account/export | Export account |
| GET | /account/legal-acceptances | List legal acceptances |
| DELETE | /account | Delete account |
| POST | /account/api-keys/{id}/rotate | Rotate api key |
Agent Attestations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/attestations | List attestations for an agent |
| POST | /organizations/{orgId}/agents/{agentId}/attestations | Submit a new attestation |
| GET | /organizations/{orgId}/agents/{agentId}/attestations/{id} | Fetch a single attestation by id |
| GET | /organizations/{orgId}/agents/{agentId}/attestations/{id}/verify | Offline verify an attestation |
| POST | /organizations/{orgId}/agents/{agentId}/attestations/{id}/revoke | Revoke an attestation |
Agent Cards & Discovery
| Method | Path | Operation |
|---|---|---|
| GET | /agents/{id}/agent-card | Get A2A agent card |
| GET | /agents/discovery | Discover agents |
Agent Communication
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/agents/{agentId}/communication/enable | Enable A2A communication |
| POST | /organizations/{orgId}/agents/{agentId}/communication/disable | Disable A2A communication |
| GET | /organizations/{orgId}/agents/{agentId}/communication/status | Get communication status |
Agent Deployments
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agent-deployments | List agent deployments for the organization |
| POST | /organizations/{orgId}/agent-deployments | Create a new agent deployment |
| GET | /organizations/{orgId}/agent-deployments/{id} | Get a specific agent deployment |
| DELETE | /organizations/{orgId}/agent-deployments/{id} | Delete an agent deployment (tears down platform resources) |
| PATCH | /organizations/{orgId}/agent-deployments/{id} | Update a DRAFT agent deployment |
| POST | /organizations/{orgId}/agent-deployments/generate | Generate agent config from a natural language idea |
| POST | /organizations/{orgId}/agent-deployments/{id}/deploy | Trigger deployment of the agent to the target platform |
| POST | /organizations/{orgId}/agent-deployments/{id}/test-connection | Validate the deployment's resolved LLM credentials before deploying |
| POST | /organizations/{orgId}/agent-deployments/{id}/stop | Stop and tear down the deployed agent |
Agent Drift Detection
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/drift/alerts | List drift alerts for an organization |
| GET | /organizations/{orgId}/agents/drift/alerts/{alertId} | Get a single drift alert |
| POST | /organizations/{orgId}/agents/drift/alerts/{alertId}/acknowledge | Acknowledge a drift alert |
| POST | /organizations/{orgId}/agents/drift/alerts/{alertId}/resolve | Resolve a drift alert |
| POST | /organizations/{orgId}/agents/drift/alerts/{alertId}/dismiss | Dismiss a drift alert |
| GET | /organizations/{orgId}/agents/drift/{agentId}/health | Get agent health with baseline and active alerts |
| GET | /organizations/{orgId}/agents/drift/{agentId}/behavior | Get an agent behavioral profile (known tools, chain-role norm, arg-shape norm) and recent per-call deviations |
| POST | /organizations/{orgId}/agents/drift/{agentId}/baseline | Manually rebuild baseline for an agent |
Agent Federation
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/federation-manifests | Publish a new federation manifest version |
| GET | /organizations/{orgId}/federation-manifests/current | Fetch the org's most recent federation manifest |
| GET | /organizations/{orgId}/federation-manifests/revocations | List delta revocations published by this org |
| POST | /organizations/{orgId}/federation-manifests/revocations | Publish a signed delta revocation for a federated agent |
| GET | /organizations/{orgId}/federation-manifests/peer-pins/pending | List federation peer pins requiring operator action |
| POST | /organizations/{orgId}/federation-manifests/peer-pins/{peerOrgId}/approve | Approve a PENDING_APPROVAL federation peer pin |
Agent Memory
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/memories | List memories (org-scoped, paginated, decrypted). |
| POST | /organizations/{orgId}/memories | Write a memory (PII-redacted + poisoning-blocked on the write path, encrypted per-org). |
| POST | /organizations/{orgId}/memories/search | Relevance search over memories (provenance surfaced per hit). |
| POST | /organizations/{orgId}/memories/erase | Request two-person GDPR Art-17 erasure (legacy memory alias; no immediate destruction). |
| GET | /organizations/{orgId}/memories/{id} | Fetch a single memory (org-scoped, decrypted). |
| DELETE | /organizations/{orgId}/memories/{id} | Soft-delete a single memory (org-scoped). |
| GET | /organizations/{orgId}/memory-sources | List the connector owner’s source authorization leases. |
| POST | /organizations/{orgId}/memory-sources/synchronize | Synchronize a current upstream document ACL, content version or revocation using a bounded authorization lease. |
Agent Policies
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/policies | List all policies |
| POST | /organizations/{orgId}/policies | Create a new agent policy |
| GET | /organizations/{orgId}/policies/{policyId} | Get a single policy by ID |
| DELETE | /organizations/{orgId}/policies/{policyId} | Delete a policy |
| PATCH | /organizations/{orgId}/policies/{policyId} | Update a policy |
| POST | /organizations/{orgId}/policies/apply-defaults | Seed default policies for the organization |
| POST | /organizations/{orgId}/policies/detect-conflicts | Detect conflicts between multiple policies |
| POST | /organizations/{orgId}/policies/{policyId}/assign | Assign policy to agents |
| DELETE | /organizations/{orgId}/policies/agents/{agentId} | Remove the policy assigned to one agent |
| POST | /organizations/{orgId}/policies/{policyId}/rollout/rollback | Roll an agent policy's rollout stage back to OBSERVE |
| POST | /organizations/{orgId}/policies/{policyId}/rollout/advance | Advance a agent policy's rollout to the next stage |
| PUT | /organizations/{orgId}/policies/{policyId}/rollout/auto-rollback | Set a agent policy's auto-rollback opt-in |
Agent Posture
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/posture | Get the posture record for an agent |
| POST | /organizations/{orgId}/agents/{agentId}/posture | Submit a posture declaration for an agent |
| GET | /organizations/{orgId}/posture/summary | Org-wide posture status summary |
Agent Reviews
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{id}/reviews | Get reviews |
| POST | /organizations/{orgId}/agents/{id}/reviews | Create review |
| GET | /agents/{id}/public-rating | Get the public cross-org aggregate rating for a marketplace agent |
Agent Sharing
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/sharing/agents/{agentId}/share | Share an agent with another organization |
| POST | /organizations/{orgId}/sharing/accept | Accept an incoming share |
| DELETE | /organizations/{orgId}/sharing/{shareId} | Revoke a share |
| GET | /organizations/{orgId}/sharing/outgoing | List outgoing shares |
| GET | /organizations/{orgId}/sharing/incoming | List incoming shares |
| PATCH | /organizations/{orgId}/sharing/{shareId}/policy | Update share policy |
Agent Tasks
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/tasks | List agent tasks |
| POST | /organizations/{orgId}/tasks | Submit a task to a server agent |
| GET | /organizations/{orgId}/tasks/stats | Get task statistics |
| GET | /organizations/{orgId}/tasks/{taskId} | Get task details |
| POST | /organizations/{orgId}/tasks/{taskId}/approve | Approve a pending-approval task |
| POST | /organizations/{orgId}/tasks/{taskId}/cancel | Cancel a pending task |
| GET | /organizations/{orgId}/tasks/{taskId}/trace | Get prompt trace for a task |
| GET | /organizations/{orgId}/tasks/{taskId}/tree | Get task execution tree |
Agent Templates
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agent-templates | List agent templates (org-scoped, paginated) |
| GET | /organizations/{orgId}/agent-templates/{slug} | Get agent template by slug (org-scoped) |
| GET | /agent-templates | List agent templates |
| GET | /agent-templates/{slug} | Get agent template by slug |
| POST | /organizations/{orgId}/agent-templates/{slug}/use | Create an agent from a template |
Agent Timeline
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/timeline | Per-agent action timeline |
Agent Tool Policies
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/tool-policies | List tool policy rules for an agent |
| POST | /organizations/{orgId}/agents/{agentId}/tool-policies | Create a per-(agent, tool) policy rule |
| GET | /organizations/{orgId}/agents/{agentId}/tool-policies/{policyId} | Get a tool policy rule |
| DELETE | /organizations/{orgId}/agents/{agentId}/tool-policies/{policyId} | Delete a tool policy rule |
| PATCH | /organizations/{orgId}/agents/{agentId}/tool-policies/{policyId} | Update a tool policy rule |
Agent Versions
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/versions | List |
| POST | /organizations/{orgId}/agents/{agentId}/versions | Create |
| GET | /organizations/{orgId}/agents/{agentId}/versions/diff | Diff |
| GET | /organizations/{orgId}/agents/{agentId}/versions/compare | Compare |
| GET | /organizations/{orgId}/agents/{agentId}/versions/{versionId} | Get one |
| POST | /organizations/{orgId}/agents/{agentId}/versions/{versionId}/rollback | Rollback |
Agents
| Method | Path | Operation |
|---|---|---|
| POST | /agents/heartbeat | Agent heartbeat |
| GET | /organizations/{orgId}/agents | Get all agents |
| POST | /organizations/{orgId}/agents | Create a new agent |
| GET | /organizations/{orgId}/agents/{agentId} | Get agent by ID |
| DELETE | /organizations/{orgId}/agents/{agentId} | Delete an agent |
| PATCH | /organizations/{orgId}/agents/{agentId} | Update an agent |
| PATCH | /organizations/{orgId}/agents/{agentId}/status | Update status |
| POST | /organizations/{orgId}/agents/{agentId}/webhook-signing-secret/rotate | Rotate agent webhook signing secret |
| POST | /organizations/{orgId}/agents/{agentId}/revoke | Revoke (quarantine) a single agent — blast-radius containment |
| POST | /organizations/{orgId}/agents/{agentId}/quarantine | Quarantine a single agent — reversible containment |
| POST | /organizations/{orgId}/agents/{agentId}/restore | Restore a revoked/suspended agent |
| GET | /organizations/{orgId}/agents/{agentId}/revocation-preview | Preview the blast radius of revoking an agent |
| POST | /organizations/{orgId}/agents/{agentId}/transfer-ownership | Transfer ownership |
| GET | /organizations/{orgId}/agents/{agentId}/collaborators | Get collaborators |
| POST | /organizations/{orgId}/agents/{agentId}/collaborators | Add collaborator |
| DELETE | /organizations/{orgId}/agents/{agentId}/collaborators/{userId} | Remove collaborator |
| POST | /organizations/{orgId}/agents/{agentId}/install | Install an agent |
| POST | /organizations/{orgId}/agents/{agentId}/token | Issue a short-lived RS256 agent-identity JWT |
| POST | /organizations/{orgId}/agents/{agentId}/chat | Chat with an agent |
AI Assets
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/ai-systems/provenance/task/{taskId} | Unified delegation-chain provenance for one agent task |
| GET | /organizations/{orgId}/ai-systems/decisions/{decisionId}/explain | Explain one policy decision across six dimensions |
| GET | /organizations/{orgId}/ai-assets | Find all |
| POST | /organizations/{orgId}/ai-assets | Create |
| POST | /organizations/{orgId}/ai-assets/adopt | Adopt |
| GET | /organizations/{orgId}/ai-assets/{id} | Find one |
| PATCH | /organizations/{orgId}/ai-assets/{id} | Update |
| POST | /organizations/{orgId}/ai-assets/{id}/archive | Archive |
| POST | /organizations/{orgId}/ai-assets/{id}/restore | Restore |
| GET | /organizations/{orgId}/ai-assets/{id}/blast-radius | Blast radius |
| GET | /organizations/{orgId}/asset-relationships | Find all |
| POST | /organizations/{orgId}/asset-relationships | Create |
| GET | /organizations/{orgId}/asset-relationships/graph/traverse | Traverse |
| GET | /organizations/{orgId}/asset-relationships/{id} | Find one |
| PATCH | /organizations/{orgId}/asset-relationships/{id} | Update |
| POST | /organizations/{orgId}/asset-relationships/{id}/archive | Archive |
| POST | /organizations/{orgId}/asset-relationships/{id}/restore | Restore |
AI Intake
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/ai-intake | List AI intake submissions |
| POST | /organizations/{orgId}/ai-intake | Submit an AI intake request |
| GET | /organizations/{orgId}/ai-intake/{intakeId} | Get one AI intake submission |
| POST | /organizations/{orgId}/ai-intake/{intakeId}/review | Approve or reject an AI intake submission |
AI Systems
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/ai-systems/entitlements/agent/{agentId}/reach | What can this agent access? Downstream reachability from the agent over the projected entitlement graph. |
| GET | /organizations/{orgId}/ai-systems/entitlements/agent/{agentId}/delegators | Who delegated authority to this agent? Upstream DELEGATES_TO chain into the agent. |
| GET | /organizations/{orgId}/ai-systems/entitlements/assets | Which tools can move money / which agents can access PII? Assets tagged with the requested capability, plus the agents that can invoke them. |
| GET | /organizations/{orgId}/ai-systems/entitlements/escalation-paths | Which agents have privilege escalation paths? Every agent A -> ... -> agent B delegation chain where B’s CAN_INVOKE scope set is a strict superset of A’s. |
| PUT | /organizations/{orgId}/ai-systems/by-external-id/{externalId} | Upsert ai system |
| DELETE | /organizations/{orgId}/ai-systems/by-external-id/{externalId} | Archive ai system |
| PUT | /organizations/{orgId}/ai-assets/by-external-id/{externalId} | Upsert ai asset |
| DELETE | /organizations/{orgId}/ai-assets/by-external-id/{externalId} | Archive ai asset |
| PUT | /organizations/{orgId}/asset-relationships/by-external-id/{externalId} | Upsert asset relationship |
| DELETE | /organizations/{orgId}/asset-relationships/by-external-id/{externalId} | Archive asset relationship |
| GET | /organizations/{orgId}/ai-systems/modification-thresholds | Resolved EU AI Act substantial-modification thresholds |
| PATCH | /organizations/{orgId}/ai-systems/modification-thresholds | Override this org's substantial-modification thresholds |
| GET | /organizations/{orgId}/ai-systems/material-change-reactions/rules | Effective material-change reaction rules |
| PUT | /organizations/{orgId}/ai-systems/material-change-reactions/rules/{changeType}/{reaction} | Override one material-change reaction cell |
| DELETE | /organizations/{orgId}/ai-systems/material-change-reactions/rules/{changeType}/{reaction} | Revert one material-change reaction cell to the default |
| GET | /organizations/{orgId}/ai-systems | Find all |
| POST | /organizations/{orgId}/ai-systems | Create |
| GET | /organizations/{orgId}/ai-systems/lifecycle-requests | List lifecycle requests |
| POST | /organizations/{orgId}/ai-systems/lifecycle-requests/{requestId}/approve | Approve lifecycle request |
| POST | /organizations/{orgId}/ai-systems/lifecycle-requests/{requestId}/reject | Reject lifecycle request |
| POST | /organizations/{orgId}/ai-systems/{id}/lifecycle-requests | Request lifecycle transition |
| POST | /organizations/{orgId}/ai-systems/{id}/reapprove | Re-approve a production AI System after a material change |
| GET | /organizations/{orgId}/ai-systems/{id} | Find one |
| DELETE | /organizations/{orgId}/ai-systems/{id} | Remove |
| PATCH | /organizations/{orgId}/ai-systems/{id} | Update |
| GET | /organizations/{orgId}/ai-systems/{id}/summary | Get summary |
| PATCH | /organizations/{orgId}/ai-systems/{id}/owners | Update owners |
| PATCH | /organizations/{orgId}/ai-systems/{id}/lifecycle | Transition lifecycle |
| GET | /organizations/{orgId}/ai-systems/{id}/ai-act-role | Get ai act role |
| PATCH | /organizations/{orgId}/ai-systems/{id}/ai-act-role | Set ai act role |
| POST | /organizations/{orgId}/ai-systems/{id}/archive | Archive |
| POST | /organizations/{orgId}/ai-systems/{id}/restore | Restore |
| GET | /organizations/{orgId}/ai-systems/{id}/retire/preview | Preview the blast radius of retiring an AI System |
| POST | /organizations/{orgId}/ai-systems/{id}/retire | Request retirement of an AI System |
| POST | /organizations/{orgId}/ai-systems/entitlements/reproject | Reproject entitlements |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/assets | List |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/assets | Attach |
| PATCH | /organizations/{orgId}/ai-systems/{aiSystemId}/assets/{assetId}/role | Change role |
| DELETE | /organizations/{orgId}/ai-systems/{aiSystemId}/assets/{assetId} | Detach |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/policies | List the deployment gate rules for an AI System |
| PUT | /organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/policies | Replace the deployment gate rules for an AI System |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluate | Evaluate the gate against an existing eval run (CI entry point; works with an organization API key) |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluations | List past gate verdicts for an AI System |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluations/{evaluationId}/override | Override a failing gate verdict, with a mandatory reason |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/snapshots | List this AI System snapshots, newest first |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/snapshots | Take a material-change snapshot of this AI System now |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/material-changes | The material change feed for this AI System |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/material-changes/{changeId}/acknowledge | Acknowledge one detected material change |
| GET | /organizations/{orgId}/entitlement-recommendations | List least-privilege recommendations |
| POST | /organizations/{orgId}/entitlement-recommendations/{id}/accept | Accept a recommendation. Records the decision only; the grant is not changed. |
| POST | /organizations/{orgId}/entitlement-recommendations/{id}/dismiss | Dismiss a recommendation |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/modifications | Detected substantial-modification classifications for this AI System |
| GET | /organizations/{orgId}/ai-systems/{id}/risk-paths | Ranked risk paths through an AI System, with per-hop reasons |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom | List versions |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom | Generate |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom/latest | Get latest |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom/{snapshotId} | Get version |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom/{snapshotId}/export | Export snapshot |
| GET | /organizations/{orgId}/aibom/diff | Diff |
| GET | /organizations/{orgId}/aibom/{snapshotId}/verify | Verify a signed AIBOM snapshot |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/aibom/import | Import a pipeline-built CycloneDX BOM into an AI System's AIBOM |
| GET | /organizations/{orgId}/ai-systems/{id}/data-flows | Data-flow lineage of an AI System, down to classified data |
Alert Rules
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/alert-rules | List alert rules for an organization. |
| POST | /organizations/{orgId}/alert-rules | Create an alert rule. |
| GET | /organizations/{orgId}/alert-rules/{id} | Fetch a single alert rule by id. |
| DELETE | /organizations/{orgId}/alert-rules/{id} | Delete an alert rule. |
| PATCH | /organizations/{orgId}/alert-rules/{id} | Update an alert rule. |
| POST | /organizations/{orgId}/alert-rules/{id}/test | Back-test a predicate against the most recent events of a given type. Informational only; does not persist a rule fire. |
| POST | /organizations/{orgId}/alert-rules/test | Test inline |
Alert Webhook Allowlist
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/alert-webhook-allowlist | List allowed webhook hostnames for the org. |
| POST | /organizations/{orgId}/alert-webhook-allowlist | Add a hostname to the org's alert-webhook allowlist. |
| DELETE | /organizations/{orgId}/alert-webhook-allowlist/{domainId} | Remove a domain from the org's alert-webhook allowlist. |
Analytics
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/analytics | Get organization analytics |
| GET | /organizations/{orgId}/analytics/capture-state | Get capture state |
| GET | /organizations/{orgId}/analytics/agents/{agentId} | Get agent analytics |
| GET | /organizations/{orgId}/analytics/events | Get recent events |
| POST | /organizations/{orgId}/analytics/events | Record event |
| GET | /organizations/{orgId}/analytics/activity-log | Get recent events activity log |
| GET | /organizations/{orgId}/analytics/advanced/agent-performance | Get agent performance metrics |
| GET | /organizations/{orgId}/analytics/advanced/security | Get security metrics |
| GET | /organizations/{orgId}/analytics/advanced/cost-trends | Get cost trends |
| GET | /organizations/{orgId}/analytics/advanced/usage-heatmap | Get usage heatmap |
| GET | /organizations/{orgId}/analytics/advanced/top-agents | Get top agents |
| GET | /organizations/{orgId}/analytics/advanced/compliance | Get compliance metrics |
| GET | /organizations/{orgId}/analytics/advanced/anomalies | Get anomalies |
| GET | /organizations/{orgId}/analytics/advanced/cost-by-team | Get cost by team |
| GET | /organizations/{orgId}/analytics/export | Export csv |
| GET | /organizations/{orgId}/analytics/advanced/model-comparison | Compare models |
Applications
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/applications | List applications |
| POST | /organizations/{orgId}/applications | Register a new application |
| GET | /organizations/{orgId}/applications/{id} | Get application details |
| DELETE | /organizations/{orgId}/applications/{id} | Delete application |
| PATCH | /organizations/{orgId}/applications/{id} | Update application |
| GET | /organizations/{orgId}/applications/{id}/metrics | Get usage metrics for an application |
| POST | /organizations/{orgId}/applications/{id}/regenerate-key | Regenerate API key |
| POST | /organizations/{orgId}/applications/{id}/revoke-key | Revoke API key |
| POST | /organizations/{orgId}/applications/{id}/agents/{agentId} | Allow app to call an agent |
| DELETE | /organizations/{orgId}/applications/{id}/agents/{agentId} | Revoke app access to an agent |
Approval Workflow
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/approvals | Find all |
| POST | /organizations/{orgId}/approvals | Create |
| GET | /organizations/{orgId}/approvals/pending/count | Count pending |
| GET | /organizations/{orgId}/approvals/{approvalId} | Find one |
| POST | /organizations/{orgId}/approvals/{approvalId}/approve | Approve |
| POST | /organizations/{orgId}/approvals/{approvalId}/reject | Reject |
| POST | /organizations/{orgId}/approvals/{approvalId}/cancel | Cancel |
| GET | /organizations/{orgId}/approval-escalation | Get |
| PUT | /organizations/{orgId}/approval-escalation | Update |
Audit
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/audit-logs | Find all |
| GET | /organizations/{orgId}/audit-logs/export | Export all |
| GET | /organizations/{orgId}/teams/{teamId}/audit-logs | Find by team |
| GET | /organizations/{orgId}/teams/{teamId}/audit-logs/export | Export by team |
| GET | /organizations/{orgId}/agents/{agentId}/audit-logs | Find by agent |
| GET | /organizations/{orgId}/audit/{rowId}/verify | Verify a single signed audit row |
| GET | /organizations/{orgId}/audit/{rowId}/proof | Get an inclusion proof for a signed audit row |
| GET | /organizations/{orgId}/audit/{rowId}/receipt | Get the Decision Receipt for one audit row |
| GET | /organizations/{orgId}/audit/decisions/{decisionId}/receipt | Get the Decision Receipt for one decisionId |
| GET | /organizations/{orgId}/audit/receipts | List Decision Receipts |
| GET | /organizations/{orgId}/audit/anchor-freshness | Get the org’s external-anchor freshness status |
| GET | /organizations/{orgId}/audit/bundle | Export a signed audit bundle for offline verification |
| POST | /organizations/{orgId}/audit/packages | Request a multi-artifact audit package |
| GET | /organizations/{orgId}/audit/packages/{id} | Get the status of an audit package export |
| GET | /organizations/{orgId}/audit/packages/{id}/download | Download a finished audit package |
Audit trust anchor
| Method | Path | Operation |
|---|---|---|
| GET | /.well-known/praesidia-audit-keys.json | Audit-bundle platform attestation public keys |
Auth
| Method | Path | Operation |
|---|---|---|
| POST | /auth/signup | Signup |
| POST | /auth/verify-email | Verify email |
| POST | /auth/resend-verification-email | Resend verification email |
| POST | /auth/verify-otp | Verify otp |
| POST | /auth/resend-otp | Resend otp |
| POST | /auth/forgot-password | Forgot password |
| POST | /auth/reset-password | Reset password |
| POST | /auth/login | Login |
| POST | /auth/mfa/verify | Mfa verify |
| POST | /auth/refresh | Refresh token |
| POST | /auth/organizations/{orgId}/switch | Switch organization |
| GET | /auth/profile | Get profile |
| GET | /auth/me | Get me |
| GET | /auth/session | Get session |
| PATCH | /auth/change-password | Change password |
| GET | /auth/organizations/{orgId}/permissions | Get organization permissions |
| POST | /auth/logout | Logout |
| POST | /auth/logout-all | Logout all |
| POST | /auth/sudo | Sudo |
| GET | /auth/sudo/methods | Sudo methods |
| POST | /auth/sudo/idp/initiate | Sudo idp initiate |
| POST | /auth/sso/initiate | Sso initiate |
| POST | /auth/sso/logout | Sso logout |
| GET | /auth/sessions | List the caller's active sessions/devices |
| DELETE | /auth/sessions | Revoke every other session for the caller |
| DELETE | /auth/sessions/{id} | Revoke one of the caller's sessions |
Auth Monitoring
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/auth-monitoring/activity | Get activity |
| GET | /organizations/{orgId}/auth-monitoring/stats | Get stats |
| GET | /organizations/{orgId}/auth-monitoring/connections | Get connection status |
| GET | /organizations/{orgId}/auth-monitoring/tokens | Get tokens |
| GET | /organizations/{orgId}/auth-monitoring/tokens/stats | Get token stats |
| GET | /organizations/{orgId}/auth-monitoring/tokens/active | Get active tokens |
| POST | /organizations/{orgId}/auth-monitoring/tokens/{tokenId}/revoke | Revoke token |
| GET | /organizations/{orgId}/auth-monitoring/rate-limits | Get rate limit stats |
| GET | /organizations/{orgId}/auth-monitoring/performance | Get performance metrics |
Benchmarks
| Method | Path | Operation |
|---|---|---|
| GET | /benchmarks | List industry benchmark segments (public, aggregate-only) |
| GET | /benchmarks/trends | Benchmark metric trend over time (public, aggregate-only) |
| GET | /organizations/{orgId}/benchmarks/compare | Compare an org agent against anonymous industry benchmark segment |
Billing
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/billing/plans | List available billing plans with current-plan marker |
| GET | /organizations/{orgId}/billing/subscription | Get subscription details |
| POST | /organizations/{orgId}/billing/subscription | Update subscription plan |
| GET | /organizations/{orgId}/billing/subscription/preview | Preview a plan change: proration from Stripe and usage over the target caps |
| POST | /organizations/{orgId}/billing/subscription/cancel | Cancel subscription |
| GET | /organizations/{orgId}/billing/invoices | List invoices (paginated, default 20, max 100) |
| GET | /organizations/{orgId}/billing/payment-methods | Get payment methods |
| POST | /organizations/{orgId}/billing/payment-methods | Add payment method |
| POST | /organizations/{orgId}/billing/setup-intent | Create setup intent |
| POST | /organizations/{orgId}/billing/portal-session | Create a Stripe Billing Portal session |
| DELETE | /organizations/{orgId}/billing/payment-methods/{id} | Delete a payment method |
| GET | /organizations/{orgId}/billing/credits | Get credit balance |
| POST | /organizations/{orgId}/billing/credits/purchase | Purchase credits |
| GET | /organizations/{orgId}/billing/usage-reports | Get usage reports |
| GET | /organizations/{orgId}/billing/cost-analytics | Get cost analytics |
| GET | /organizations/{orgId}/billing/spending-forecasts | Get spending forecasts |
| GET | /organizations/{orgId}/billing/contacts | Get billing contacts |
| PATCH | /organizations/{orgId}/billing/contacts | Update billing contacts |
| PATCH | /organizations/{orgId}/billing/currency | Update preferred billing currency |
| POST | /organizations/{orgId}/billing/metered-subscription | Create metered subscription |
| GET | /organizations/{orgId}/billing/usage-summary | Get usage summary |
| POST | /organizations/{orgId}/billing/connect-account | Create connect account |
| POST | /organizations/{orgId}/billing/connect-account/onboarding-link | Get connect onboarding link |
| POST | /organizations/{orgId}/billing/payout | Create payout |
| GET | /organizations/{orgId}/billing/contracts | List enterprise contracts (paginated, default 20, max 100) |
| POST | /organizations/{orgId}/billing/contracts | Create contract |
| PATCH | /organizations/{orgId}/billing/contracts/{contractId}/status | Update contract status |
| GET | /organizations/{orgId}/billing/export | Export billing data |
| GET | /organizations/{orgId}/billing/spend-alert-rules | List all spend alert rules for the organization |
| POST | /organizations/{orgId}/billing/spend-alert-rules | Create a spend alert rule |
| GET | /organizations/{orgId}/billing/spend-alert-rules/{ruleId} | Get a spend alert rule by ID |
| DELETE | /organizations/{orgId}/billing/spend-alert-rules/{ruleId} | Delete a spend alert rule |
| PATCH | /organizations/{orgId}/billing/spend-alert-rules/{ruleId} | Update a spend alert rule |
Budget Policies
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/budget-policies | Find all |
| POST | /organizations/{orgId}/budget-policies | Create |
| GET | /organizations/{orgId}/budget-policies/summary | Get summary |
| GET | /organizations/{orgId}/budget-policies/{id} | Find one |
| DELETE | /organizations/{orgId}/budget-policies/{id} | Remove |
| PATCH | /organizations/{orgId}/budget-policies/{id} | Update |
| POST | /organizations/{orgId}/budget-policies/{id}/reset | Reset period |
Business Value
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/business-value/kpis | List KPI definitions, optionally by AI System |
| POST | /organizations/{orgId}/business-value/kpis | Define a KPI for an AI System |
| GET | /organizations/{orgId}/business-value/kpis/by-ai-system/{aiSystemId} | Every KPI defined for an AI System, resolved to a value for the requested period (manual/imported lookup, or derived computation) |
| GET | /organizations/{orgId}/business-value/kpis/{id} | Get one KPI definition |
| DELETE | /organizations/{orgId}/business-value/kpis/{id} | Soft-delete a KPI definition |
| PATCH | /organizations/{orgId}/business-value/kpis/{id} | Update a KPI definition |
| GET | /organizations/{orgId}/business-value/kpis/{id}/values | List recorded values for a KPI definition |
| POST | /organizations/{orgId}/business-value/kpis/{id}/values | Record a manual/imported value for a period |
| GET | /organizations/{orgId}/business-value/roi | Cost (cost-monitoring) vs. value (KPIs) for one AI System over one period, with an ROI percentage when both sides are available |
| GET | /organizations/{orgId}/business-value/risk-adjusted | Business value and AI cost for one AI System next to its security, compliance and operational risk, with the weighting used |
Chains
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/chains/{chainId} | Get a chain trace |
Compliance
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/compliance/security-events | Get security events |
| POST | /organizations/{orgId}/compliance/security-events/{id}/resolve | Resolve security event |
| GET | /organizations/{orgId}/compliance/access-policies | Get access policies |
| POST | /organizations/{orgId}/compliance/access-policies | Create access policy |
| GET | /organizations/{orgId}/compliance/reports | Get reports |
| POST | /organizations/{orgId}/compliance/reports | Generate a NIST AI RMF or ISO 42001 framework report |
| POST | /organizations/{orgId}/compliance/reports/generate | Generate report |
| GET | /organizations/{orgId}/compliance/iso42001 | Get iso42001 mapping |
| GET | /organizations/{orgId}/compliance/iso42001/gaps | Get coverage gaps |
| GET | /organizations/{orgId}/compliance/evidence-coverage | Get evidence coverage |
| GET | /organizations/{orgId}/compliance/readiness/{framework} | Get readiness |
| GET | /organizations/{orgId}/compliance/evidence | Get evidence |
| POST | /organizations/{orgId}/compliance/evidence | Add manual evidence |
| POST | /organizations/{orgId}/compliance/evidence/collect | Collect evidence |
| POST | /organizations/{orgId}/compliance/iso42001/gaps/{controlId}/evidence | Attach manual/uploaded evidence to an ISO 42001 control gap |
| GET | /organizations/{orgId}/compliance/retention-policy | Get retention policy |
| PATCH | /organizations/{orgId}/compliance/retention-policy | Update retention policy |
| GET | /organizations/{orgId}/compliance/gdpr/dpia | Find all |
| POST | /organizations/{orgId}/compliance/gdpr/dpia | Create |
| GET | /organizations/{orgId}/compliance/gdpr/dpia/{id} | Find one |
| PATCH | /organizations/{orgId}/compliance/gdpr/dpia/{id} | Update |
| GET | /organizations/{orgId}/compliance/gdpr/dpia/{id}/export | Export record |
| POST | /organizations/{orgId}/compliance/gdpr/dpia/{id}/link | Link |
| POST | /organizations/{orgId}/compliance/gdpr/dpia/{id}/submit | Submit |
| POST | /organizations/{orgId}/compliance/gdpr/dpia/{id}/approve | Approve |
| POST | /organizations/{orgId}/compliance/gdpr/dpia/{id}/reject | Reject |
| GET | /organizations/{orgId}/compliance/eu-ai-act/articles | Org roll-up of the per-entity EU AI Act article matrix (all entities) |
| GET | /organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/articles | Per-entity EU AI Act article matrix (Art. 9/10/12/13/14) with evidence-backed statuses |
| GET | /organizations/{orgId}/compliance/eu-ai-act/oversight-report | EU AI Act Art. 14 oversight evidence report |
| GET | /organizations/{orgId}/compliance/eu-ai-act/status | Get per-article EU AI Act RAG status |
| GET | /organizations/{orgId}/compliance/eu-ai-act/qms-report | Generate Art. 17 QMS report (JSON) |
| GET | /organizations/{orgId}/compliance/owasp-agentic/coverage | Per-ASI OWASP Agentic coverage: risk entry, linked controls, evidence count |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/risk-register | List Art. 9 risk register entries for an AI System |
| GET | /organizations/{orgId}/compliance/risk-register | List Art. 9 risk register entries |
| POST | /organizations/{orgId}/compliance/risk-register | Create Art. 9 risk register entry |
| PUT | /organizations/{orgId}/compliance/risk-register/{id} | Update Art. 9 risk register entry |
| DELETE | /organizations/{orgId}/compliance/risk-register/{id} | Delete Art. 9 risk register entry |
| POST | /organizations/{orgId}/oversight/suspend-all | Art. 14 kill-switch — suspend all active agents for the org |
| GET | /organizations/{orgId}/oversight/kill-switch-test | Test Art. 14 kill-switch status (does not suspend agents) |
| GET | /organizations/{orgId}/compliance/risk-exceptions | List risk exceptions for the org |
| POST | /organizations/{orgId}/compliance/risk-exceptions | Request a time-boxed acceptance of a known risk |
| GET | /organizations/{orgId}/compliance/risk-exceptions/{id} | Get one risk exception |
| POST | /organizations/{orgId}/compliance/risk-exceptions/{id}/approve | Approve a requested risk exception (approver ≠ requester) |
| POST | /organizations/{orgId}/compliance/risk-exceptions/{id}/reject | Reject a requested risk exception |
| POST | /organizations/{orgId}/compliance/risk-exceptions/{id}/revoke | Revoke an approved risk exception early |
| POST | /organizations/{orgId}/compliance/readiness/{framework}/export | Export a framework readiness audit package |
| POST | /organizations/{orgId}/compliance/eu-ai-act/reports | Queue an async EU AI Act auditor report (returns id + status) |
| GET | /organizations/{orgId}/compliance/eu-ai-act/reports/{reportId} | Poll auditor-report generation status |
| GET | /organizations/{orgId}/compliance/eu-ai-act/reports/{reportId}/json | Download the structured JSON auditor report |
| GET | /organizations/{orgId}/compliance/eu-ai-act/reports/{reportId}/pdf | Download the rendered PDF auditor report |
| GET | /organizations/{orgId}/compliance/iso42001/soa | ISO 42001 Statement of Applicability (JSON or CSV) |
| PATCH | /organizations/{orgId}/compliance/iso42001/soa/{controlId} | Record applicability and justification for an Annex A control |
Connections
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/connections | Find all |
| GET | /organizations/{orgId}/connections/stats | Get stats |
| GET | /organizations/{orgId}/connections/{id} | Find one |
| DELETE | /organizations/{orgId}/connections/{id} | Disconnect |
| POST | /organizations/{orgId}/connections/agent | Create agent to agent |
| POST | /organizations/{orgId}/connections/mcp | Create agent to mcp |
| POST | /organizations/{orgId}/connections/{id}/test | Test connection |
| PATCH | /organizations/{orgId}/connections/{id}/status | Update status |
| PATCH | /organizations/{orgId}/connections/{id}/policy | Update policy |
| PATCH | /organizations/{orgId}/connections/{id}/configuration | Atomically update connection policy configuration |
| PATCH | /organizations/{orgId}/connections/{id}/min-trust-level | Update min trust level |
| PATCH | /organizations/{orgId}/connections/{id}/backup-connection | Clear a legacy backup connection assignment |
| GET | /organizations/{orgId}/connections/{id}/health | Get latest health |
| GET | /organizations/{orgId}/connections/{id}/health/history | Get health history |
| PATCH | /organizations/{orgId}/connections/{id}/guardrails | Set connection guardrails |
Connections - ABAC
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/connections/{connId}/tool-permissions | List ABAC tool permissions for a connection |
| POST | /organizations/{orgId}/connections/{connId}/tool-permissions | Create a tool permission for a connection |
| DELETE | /organizations/{orgId}/connections/{connId}/tool-permissions/{id} | Delete a tool permission |
| PATCH | /organizations/{orgId}/connections/{connId}/tool-permissions/{id} | Update a tool permission |
| POST | /organizations/{orgId}/connections/{connId}/tool-permissions/import | Bulk-import tool permissions from a YAML policy string |
| GET | /organizations/{orgId}/connections/{connId}/tool-permissions/export | Export all active tool permissions for a connection |
Connectors
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/connectors/catalog | List the named enterprise connector catalogue |
| GET | /organizations/{orgId}/connectors/catalog/{key} | Get a single connector catalogue entry |
| POST | /organizations/{orgId}/connectors/register | Register a named connector with governance pre-wired |
| GET | /organizations/{orgId}/connectors/registrations | List connector registrations for the org |
| PATCH | /organizations/{orgId}/connectors/registrations/{id}/auth | Configure connector authentication and activate it |
| PATCH | /organizations/{orgId}/connectors/registrations/{id}/deregister | Deregister (disable) a connector registration |
Control Proposals
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/control-proposals | List this org's control proposals, newest first, optionally by status and origin. |
| GET | /organizations/{orgId}/control-proposals/{id} | Get one control proposal. |
| POST | /organizations/{orgId}/control-proposals/generate | Generate a DRAFT control proposal from a natural-language request. Never applies anything — a human must approve, then apply. |
| POST | /organizations/{orgId}/control-proposals/{id}/approve | Approve |
| POST | /organizations/{orgId}/control-proposals/{id}/reject | Reject |
| POST | /organizations/{orgId}/control-proposals/{id}/apply | Materialize an APPROVED proposal into a real governance control. Rejected with 409 unless status is APPROVED. |
Cost Monitoring
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/cost-monitoring/usage | Get usage stats |
| GET | /organizations/{orgId}/cost-monitoring/credits | Get credits |
Cost Recommendations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/billing/recommendations | List active cost-optimisation recommendations |
| POST | /organizations/{orgId}/billing/recommendations/{recId}/dismiss | Dismiss a cost-optimisation recommendation |
Cross-Tenant A2A (Federated)
| Method | Path | Operation |
|---|---|---|
| POST | /a2a/cross-tenant/tasks | Submit a federated cross-tenant task |
CrossBorder
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/ai-systems/{id}/cross-border-flows | Cross-border status of each flow of an AI System's data flow |
| POST | /organizations/{orgId}/ai-systems/{id}/cross-border-flows/evaluate | Store the cross-border verdict for each flow of an AI System's data flow |
| GET | /organizations/{orgId}/data-security/cross-border-summary | Org-wide cross-border rollup by destination geography |
Dashboard
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/dashboard/stats | Get stats |
Data Assets
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/data-assets | List the org's data asset inventory. |
| POST | /organizations/{orgId}/data-assets | Register a data asset in the org inventory. |
| GET | /organizations/{orgId}/data-assets/by-ai-system/{aiSystemId} | Data assets joined through ai_system_assets membership of the given AI System. |
| GET | /organizations/{orgId}/data-assets/{id} | Fetch a single data asset by id. |
| DELETE | /organizations/{orgId}/data-assets/{id} | Soft-delete a data asset from the inventory. |
| PATCH | /organizations/{orgId}/data-assets/{id} | Edit a data asset. |
| POST | /organizations/{orgId}/data-assets/{id}/classify | Set/update a data asset's sensitivity classification. |
Data Subjects
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/data-subjects/erase | List data-subject erasure requests |
| POST | /organizations/{orgId}/data-subjects/erase | Initiate a two-person GDPR Art-17 erasure (erases nothing yet) |
| POST | /organizations/{orgId}/data-subjects/erase/{requestId}/confirm | Confirm a pending erasure; the confirmer must differ from the initiator, unless the org has one eligible confirmer (new session, >= 24h after initiating) |
| POST | /organizations/{orgId}/data-subjects/erase/{requestId}/cancel | Cancel a pending erasure (initiator only); erases nothing |
| GET | /organizations/{orgId}/data-subjects/erase/{requestId} | Status of one data-subject erasure request |
| POST | /organizations/{orgId}/data-subjects/export | Export one data subject's records held by this organization (GDPR Art-15/20, JSON) |
DID Documents
| Method | Path | Operation |
|---|---|---|
| GET | /agents/{agentId}/did.json | Agent DID document |
| GET | /.well-known/did.json | Platform DID document |
Discovery
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/discovered-entities | List discovered (unregistered) entities |
| GET | /organizations/{orgId}/discovered-entities/{id} | Inspect a single discovered entity |
| POST | /organizations/{orgId}/discovered-entities/{id}/claim | Claim a discovered entity (promote to the registered flow) |
| POST | /organizations/{orgId}/discovered-entities/{id}/ignore | Ignore a discovered entity (suppress it) |
| POST | /organizations/{orgId}/discovered-entities/{id}/restore | Restore an ignored entity to the discovery inbox |
| POST | /organizations/{orgId}/discovered-entities/{id}/adopt | Adopt a discovered entity into the AI-asset graph |
| POST | /organizations/{orgId}/discovered-entities/{id}/merge | Merge a discovered entity into another entity or an AI asset |
| POST | /organizations/{orgId}/discovered-entities/{id}/associate | Attach the sighting's AI asset to an AI System |
| POST | /organizations/{orgId}/discovered-entities/{id}/mark-expected | Flag a sighting as known/sanctioned |
| POST | /organizations/{orgId}/discovered-entities/{id}/assign-owner | Assign (or clear) the accountable owner of a sighting |
| POST | /organizations/{orgId}/discovered-entities/{id}/investigate | Open an AI incident investigation for a sighting |
| GET | /organizations/{orgId}/discovered-entities/{id}/suggestions | Deterministic dedup candidates for a sighting |
| GET | /organizations/{orgId}/discovery/connectors | List discovery connectors |
| POST | /organizations/{orgId}/discovery/connectors | Register a discovery connector |
| GET | /organizations/{orgId}/discovery/connectors/aws/role-policies | AWS discovery role IAM policies for this org |
| GET | /organizations/{orgId}/discovery/connectors/types | Discovery connector types this build can run |
| GET | /organizations/{orgId}/discovery/connectors/{connectorId} | Get one discovery connector |
| DELETE | /organizations/{orgId}/discovery/connectors/{connectorId} | Delete a discovery connector |
| PATCH | /organizations/{orgId}/discovery/connectors/{connectorId} | Update a discovery connector |
| POST | /organizations/{orgId}/discovery/connectors/{connectorId}/run | Run a discovery connector now |
| POST | /organizations/{orgId}/discovery/connector-secrets | Store a discovery connector secret |
| PUT | /organizations/{orgId}/discovery/connector-secrets/{secretId} | Rotate a discovery connector secret |
| DELETE | /organizations/{orgId}/discovery/connector-secrets/{secretId} | Delete a discovery connector secret |
Domains
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/domains | List domains |
| GET | /organizations/{orgId}/domains/verified | List verified domains |
| POST | /organizations/{orgId}/domains/verify/init | Init verification |
| POST | /organizations/{orgId}/domains/verify/check | Check verification |
| GET | /organizations/{orgId}/domains/{domain}/status | Get status |
| DELETE | /organizations/{orgId}/domains/{domain} | Remove domain |
| GET | /organizations/{orgId}/domains/{domain}/is-verified | Is verified |
DSPM Connectors
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/dspm/{vendor}/test-connection | Probe a DSPM/governance vendor connection. Credentials are request-scoped only, never persisted. |
| POST | /organizations/{orgId}/dspm/{vendor}/import | Import a DSPM/governance vendor's catalog into the org's data_assets inventory. |
| GET | /organizations/{orgId}/dspm/connections | List the org's DSPM connections. |
| POST | /organizations/{orgId}/dspm/connections | Store a DSPM vendor connection (key sealed). |
| GET | /organizations/{orgId}/dspm/connections/{connectionId} | Fetch one DSPM connection. |
| DELETE | /organizations/{orgId}/dspm/connections/{connectionId} | Delete a DSPM connection and its sealed key. |
| PATCH | /organizations/{orgId}/dspm/connections/{connectionId} | Change the host and/or rotate the key. |
| POST | /organizations/{orgId}/dspm/connections/{connectionId}/import | Import the vendor's catalog using the stored connection. |
| Method | Path | Operation |
|---|---|---|
| GET | /email/preferences | Read the authenticated user's email category preferences |
| PUT | /email/preferences | Toggle one email category for the authenticated user |
Emergency
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/emergency/freeze | Emergency freeze — kill switch for an org (or a selection) |
| POST | /organizations/{orgId}/emergency/unfreeze | Lift an emergency freeze |
| GET | /organizations/{orgId}/emergency/status | Current emergency-freeze state for the org |
| POST | /organizations/{orgId}/emergency/preview | Preview the blast radius of a freeze |
EU AI Act Compliance
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/assess | Assess entity risk |
| POST | /organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/classify | Classify entity |
| GET | /organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId} | Get entity classification |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId} | Update entity compliance |
| POST | /organizations/{orgId}/compliance/eu-ai-act/agents/{agentId}/assess | Assess agent risk |
| GET | /organizations/{orgId}/compliance/eu-ai-act/agents/{agentId} | Get agent classification |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/agents/{agentId} | Update agent compliance |
| GET | /organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparency | Get transparency |
| POST | /organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparency | Assess transparency |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparency | Update transparency |
| POST | /organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparency/review | Review transparency |
| GET | /organizations/{orgId}/compliance/eu-ai-act/role | Get org ai act role |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/role | Set org ai act role |
| GET | /organizations/{orgId}/compliance/eu-ai-act | List classifications |
| GET | /organizations/{orgId}/compliance/eu-ai-act/summary | Get compliance summary |
| GET | /organizations/{orgId}/compliance/eu-ai-act/report | Get compliance report |
| GET | /organizations/{orgId}/compliance/eu-ai-act/fria | Find all |
| POST | /organizations/{orgId}/compliance/eu-ai-act/fria | Create |
| GET | /organizations/{orgId}/compliance/eu-ai-act/fria/{id} | Find one |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/fria/{id} | Update |
| GET | /organizations/{orgId}/compliance/eu-ai-act/fria/{id}/export | Export assessment |
| POST | /organizations/{orgId}/compliance/eu-ai-act/fria/{id}/submit | Submit |
| POST | /organizations/{orgId}/compliance/eu-ai-act/fria/{id}/approve | Approve |
| POST | /organizations/{orgId}/compliance/eu-ai-act/fria/{id}/reject | Reject |
| GET | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation | Find all |
| POST | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation | Create |
| GET | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId} | Find one |
| PATCH | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/sections/{sectionKey} | Update section |
| POST | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/versions | Create new version |
| POST | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/approve | Approve |
| GET | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/completeness | Completeness |
| GET | /organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/export | Export document |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market | Post-market overview: plan, incidents, drift, performance, risk changes, complaints, corrective actions |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/plan | Get plan |
| PUT | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/plan | Create or update the monitoring plan |
| DELETE | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/plan | Delete plan |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/plan/review | Record a plan review; rolls nextReviewDueAt |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints | List complaints |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints | Create complaint |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id} | Get complaint |
| DELETE | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id} | Delete complaint |
| PATCH | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id} | Update complaint |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions | List corrective actions |
| POST | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions | Create corrective action |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id} | Get corrective action |
| DELETE | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id} | Delete corrective action |
| PATCH | /organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id} | Update a corrective action; DONE requires verification evidence |
| GET | /organizations/{orgId}/ai-literacy/coverage | Members with and without a current AI-literacy record |
| GET | /organizations/{orgId}/ai-literacy/records | List |
| POST | /organizations/{orgId}/ai-literacy/records | Create |
| GET | /organizations/{orgId}/ai-literacy/records/{id} | Get |
| DELETE | /organizations/{orgId}/ai-literacy/records/{id} | Remove |
| PATCH | /organizations/{orgId}/ai-literacy/records/{id} | Update |
Eval Datasets
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/evaluations/datasets | List all EvalDatasets for the organization |
| POST | /organizations/{orgId}/evaluations/datasets | Create a new EvalDataset (golden regression suite) |
| GET | /organizations/{orgId}/evaluations/datasets/{datasetId} | Get a single EvalDataset by ID |
| DELETE | /organizations/{orgId}/evaluations/datasets/{datasetId} | Soft-delete an EvalDataset |
| GET | /organizations/{orgId}/evaluations/datasets/{datasetId}/cases | List cases in a dataset (paginated) |
| POST | /organizations/{orgId}/evaluations/datasets/{datasetId}/cases | Add a test case to a dataset |
| DELETE | /organizations/{orgId}/evaluations/datasets/{datasetId}/cases/{caseId} | Remove a test case from a dataset |
| POST | /organizations/{orgId}/evaluations/datasets/{datasetId}/sample-from-prod | Sample recent production agent tasks and import them as EvalCases into the dataset |
| GET | /organizations/{orgId}/evaluations/datasets/{datasetId}/compare | Compare two EvalRuns over this dataset: regressed / improved / unchanged cases |
Eval Reviews
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/evaluations/reviews | List the caller's review assignments (paginated) |
| POST | /organizations/{orgId}/evaluations/reviews/{reviewId} | Submit a human or pairwise review verdict |
| POST | /organizations/{orgId}/evaluations/outcomes | Report an externally-observed business outcome |
Evaluations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/evaluations | List Evaluations for the organization (paginated) |
| POST | /organizations/{orgId}/evaluations | Create a new Evaluation definition |
| GET | /organizations/{orgId}/evaluations/production-configs | List production-eval sampling configs for the org, with spend-to-date, skipped-for-privacy count, and disabled-reason |
| POST | /organizations/{orgId}/evaluations/production-configs | Create a production-eval sampling config |
| GET | /organizations/{orgId}/evaluations/runs/{runId} | Get an EvalRun by ID (includes evaluationId) |
| GET | /organizations/{orgId}/evaluations/{evaluationId} | Get a single Evaluation by ID |
| GET | /organizations/{orgId}/evaluations/{evaluationId}/cases | List test cases for an Evaluation (paginated) |
| POST | /organizations/{orgId}/evaluations/{evaluationId}/cases | Add a test case to an Evaluation |
| GET | /organizations/{orgId}/evaluations/{evaluationId}/runs | List EvalRuns for an Evaluation (paginated) |
| POST | /organizations/{orgId}/evaluations/{evaluationId}/runs | Trigger a new EvalRun for an Evaluation |
| GET | /organizations/{orgId}/evaluations/{evaluationId}/runs/{runId}/results | Get paginated EvalResults for a specific EvalRun |
| GET | /organizations/{orgId}/evaluations/{evaluationId}/runs/compare | Compare two EvalRuns: pass-rate and mean-score deltas |
| DELETE | /organizations/{orgId}/evaluations/production-configs/{configId} | Delete a production-eval sampling config |
| PATCH | /organizations/{orgId}/evaluations/production-configs/{configId} | Update a production-eval sampling config |
Executive Reports
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/executive-reports | Get report |
| GET | /organizations/{orgId}/executive-reports/export | Export csv |
| POST | /organizations/{orgId}/executive-reports/generate | Queue an async executive report (returns id + status) |
| GET | /organizations/{orgId}/executive-reports/reports | List generated executive reports (paginated) |
| GET | /organizations/{orgId}/executive-reports/reports/{reportId} | Poll executive-report generation status |
| GET | /organizations/{orgId}/executive-reports/reports/{reportId}/pdf | Download the rendered executive-report PDF |
Feature Flags
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/features | Get features for organization |
Federated identity administration
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/identity | Inspect configured trust, consent, active credential inventory and task revocation backlog |
| POST | /organizations/{orgId}/identity/providers | Pin an external issuer and public verification keys |
| PATCH | /organizations/{orgId}/identity/providers/{id} | Rotate or disable issuer trust and revoke existing derived authority |
| POST | /organizations/{orgId}/identity/bindings | Bind one exact external subject to a tenant workload or user |
| DELETE | /organizations/{orgId}/identity/bindings/{id} | Disable a binding and revoke all derived credentials and active tasks |
| DELETE | /organizations/{orgId}/identity/grants/{id} | Revoke one grant, descendants, and active linked tasks |
| POST | /organizations/{orgId}/identity/revocations/retry | Retry durable task cancellation and return remaining cleanup backlog |
Federated OAuth authority
| Method | Path | Operation |
|---|---|---|
| POST | /oauth/token-exchange | Exchange a pinned external JWT or down-exchange resource-bound authority (RFC 8693) |
| POST | /identity/introspect | Validate the presented API resource credential against live authority state |
Financial
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/financial/position | Get unified financial position for an organization |
Findings
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/findings | List findings |
| GET | /organizations/{orgId}/findings/{id} | Get one finding |
| POST | /organizations/{orgId}/findings/{id}/triage | Mark a finding as triaged by a human reviewer |
| POST | /organizations/{orgId}/findings/{id}/accept-as-risk | Accept a finding as risk against an existing risk-register entry |
| POST | /organizations/{orgId}/findings/{id}/false-positive | Dismiss a finding as a false positive |
Forensics
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/forensics/search | Forensic search over `mcp_tool_calls` |
| GET | /organizations/{orgId}/forensics/timestamp-skew | Per-hour timestamp-skew report for `audit_logs` |
Governance Badge
| Method | Path | Operation |
|---|---|---|
| GET | /agents/{agentId}/governance-badge | Signed "Governed by Praesidia" trust-mark badge |
| GET | /verify/{agentId} | Public badge verification data |
Governance Packs
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/governance-packs | List available governance packs (with this org install state) |
| GET | /organizations/{orgId}/governance-packs/installed | List governance packs installed for this org |
| GET | /organizations/{orgId}/governance-packs/{packId} | Get a governance pack (with this org install state) |
| POST | /organizations/{orgId}/governance-packs/{packId}/install | Install (or idempotently re-install) a governance pack |
| GET | /organizations/{orgId}/governance-packs/{packId}/upgrade | Preview upgrading an installed governance pack (read-only diff) |
| POST | /organizations/{orgId}/governance-packs/{packId}/upgrade | Upgrade an installed governance pack to an explicit version |
Governance Timeline
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/governance/timeline | List recent governance events (gates, approvals, exports) |
| GET | /organizations/{orgId}/governance/timeline/summary | 24h counts grouped by governance event name |
Governance Versions
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/guardrails/{guardrailId}/versions | List the version history of a guardrail |
| GET | /organizations/{orgId}/guardrails/{guardrailId}/versions/{version} | Get one version of a guardrail |
| GET | /organizations/{orgId}/policies/{policyId}/versions | List the version history of an agent policy |
| GET | /organizations/{orgId}/policies/{policyId}/versions/{version} | Get one version of an agent policy |
| GET | /organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}/versions | List the version history of a tool policy rule |
| GET | /organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}/versions/{version} | Get one version of a tool policy rule |
Guardrail sample
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/guardrails/sample-evaluation | Evaluate two fixed local rule samples and persist an owned audit record |
| GET | /organizations/{orgId}/guardrails/sample-evaluation/latest | Read your own recorded local sample result in this organization |
Guardrails
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/guardrails | Get all guardrails for the organization |
| POST | /organizations/{orgId}/guardrails | Create a new guardrail |
| GET | /organizations/{orgId}/guardrails/templates | Get available guardrail templates |
| GET | /organizations/{orgId}/guardrails/default-templates | Get recommended default guardrail templates |
| POST | /organizations/{orgId}/guardrails/apply-defaults | Apply recommended default guardrails |
| GET | /organizations/{orgId}/guardrails/stats | Get guardrail statistics |
| GET | /organizations/{orgId}/guardrails/health | Get health |
| POST | /organizations/{orgId}/guardrails/validate | Validate content against guardrails |
| GET | /organizations/{orgId}/guardrails/logs | Get logs |
| GET | /organizations/{orgId}/guardrails/defaults | Get default guardrails applied by Praesidia |
| GET | /organizations/{orgId}/guardrails/{guardrailId} | Find one |
| DELETE | /organizations/{orgId}/guardrails/{guardrailId} | Delete a guardrail |
| PATCH | /organizations/{orgId}/guardrails/{guardrailId} | Update |
| POST | /organizations/{orgId}/guardrails/presets/{preset}/apply | Apply an industry preset pack |
| PATCH | /organizations/{orgId}/guardrails/{guardrailId}/custom-model | Set custom ML model URL for a guardrail |
| POST | /organizations/{orgId}/guardrails/{guardrailId}/rollout/rollback | Roll a guardrail's rollout stage back to OBSERVE |
| POST | /organizations/{orgId}/guardrails/{guardrailId}/rollout/advance | Advance a guardrail's rollout to the next stage |
| PUT | /organizations/{orgId}/guardrails/{guardrailId}/rollout/auto-rollback | Set a guardrail's auto-rollback opt-in |
Health
| Method | Path | Operation |
|---|---|---|
| GET | /residency-regions | Residency regions served by this deployment |
HIPAA
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/hipaa/baa/sign | Record the organization's attestation of a BAA it holds with a third party (Praesidia is not a party) |
| GET | /organizations/{orgId}/hipaa/baa | Get the organization's recorded attestation of a BAA it holds with a third party (Praesidia is not a party) |
| GET | /organizations/{orgId}/hipaa/breaches | List breach events for the organization |
| POST | /organizations/{orgId}/hipaa/breaches | Report a new HIPAA breach event (starts the 60-day HHS notification clock) |
| PUT | /organizations/{orgId}/hipaa/breaches/{id} | Update breach event status or notes |
| GET | /organizations/{orgId}/hipaa/audit-export | Export PHI audit logs for the organization (HIPAA 6-year retention window). Requires signed BAA. |
Incidents
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/incidents/{incidentId}/regression | List an incident's regression cases, proposed, accepted and rejected, across its regression sets (paginated) |
| POST | /organizations/{orgId}/incidents/{incidentId}/regression | Turn an incident into proposed regression cases (original + deterministic variants) |
| POST | /organizations/{orgId}/incidents/{incidentId}/regression/cases/{caseId}/accept | Accept a proposed regression case so it runs and gates releases (human actor required) |
| POST | /organizations/{orgId}/incidents/{incidentId}/regression/cases/{caseId}/reject | Reject a proposed regression case with an audited reason; it never runs or gates (human actor required) |
| GET | /organizations/{orgId}/regression-cases | List the organization's incident regression cases, newest first, filterable by status and incident (paginated) |
| GET | /organizations/{orgId}/incidents | List incidents (paginated) |
| POST | /organizations/{orgId}/incidents | Create an AI incident |
| GET | /organizations/{orgId}/incidents/by-ai-system/{aiSystemId} | List incidents for one AI System (paginated) |
| GET | /organizations/{orgId}/incidents/signals | List incident signals sharing one correlation key (paginated) |
| GET | /organizations/{orgId}/incidents/{incidentId}/signals | List an incident's correlated signals (paginated) |
| POST | /organizations/{orgId}/incidents/{incidentId}/signals/{signalId}/detach | Detach a correlated signal from this incident (false positive). 404 if the signal does not exist, is another org’s, or is not currently attached to this incident. |
| GET | /organizations/{orgId}/incidents/{incidentId}/timeline | Ordered timeline of an incident (derived, not stored) |
| GET | /organizations/{orgId}/incidents/{incidentId} | Get an incident by ID |
| PUT | /organizations/{orgId}/incidents/{incidentId} | Update an incident (including status transitions) |
| POST | /organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/start | Start one of the nine incident response stages |
| POST | /organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/complete | Complete an incident response stage. root_cause writes the incident's root cause; generate_evidence generates a signed evidence bundle and links it as the step's linkedRecordId. |
| POST | /organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/skip | Skip an incident response stage, recording why |
| GET | /organizations/{orgId}/incidents/{incidentId}/evidence-bundles/{bundleId} | Get one of an incident's signed evidence bundles and verify it. 404 unless the bundle belongs to this incident and organization. |
| POST | /organizations/{orgId}/incidents/{incidentId}/review | Record the review of the impact assessment. The reviewer is the authenticated user and may not be the incident reporter (409). |
| POST | /organizations/{orgId}/incidents/{incidentId}/regulator-report | Generate the regulator-ready report (deterministic serialization of stored fields + derived timeline, SHA-256 hashed). 409 until an impact assessment is recorded AND reviewed. |
| POST | /organizations/{orgId}/incidents/{incidentId}/generate-forensic-report | Generate a tamper-evident forensic / post-mortem report (JSON) for the incident. Assembles audit trail summary, trust score history, supervision events, and posture attestation for verified affected agents/tasks. Includes SHA-256 report hash for tamper-evidence. |
| GET | /organizations/{orgId}/incidents/{incidentId}/proposals | Controls this incident suggests (new policy, changed control, new eval, monitoring rule), derived from its signals and root cause |
| POST | /organizations/{orgId}/incidents/{incidentId}/proposals/{proposalId}/accept | Accept a proposal: create its record in the owning module and complete the update_control response step linked to it |
| POST | /organizations/{orgId}/incidents/{incidentId}/proposals/{proposalId}/dismiss | Dismiss a proposal (recorded on the audit trail) |
Integrations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/integrations/api-keys | List api keys |
| POST | /organizations/{orgId}/integrations/api-keys | Create api key |
| POST | /organizations/{orgId}/integrations/api-keys/{id}/rotate | Rotate api key |
| GET | /organizations/{orgId}/integrations/api-keys/{id}/metrics | Get api key metrics |
| DELETE | /organizations/{orgId}/integrations/api-keys/{id} | Revoke api key |
| GET | /organizations/{orgId}/integrations/webhooks | List webhooks |
| POST | /organizations/{orgId}/integrations/webhooks | Create webhook |
| DELETE | /organizations/{orgId}/integrations/webhooks/{id} | Delete webhook |
| PATCH | /organizations/{orgId}/integrations/webhooks/{id} | Update webhook |
| POST | /organizations/{orgId}/integrations/webhooks/{id}/test | Test webhook |
| POST | /organizations/{orgId}/integrations/webhooks/{id}/rotate-secret | Rotate webhook secret |
| GET | /organizations/{orgId}/integrations/siem | Get siem config |
| POST | /organizations/{orgId}/integrations/siem | Update siem config |
| DELETE | /organizations/{orgId}/integrations/siem | Delete siem config |
| POST | /organizations/{orgId}/integrations/siem/test | Test siem config |
| GET | /organizations/{orgId}/integrations/scm/github/connections | List GitHub connections |
| POST | /organizations/{orgId}/integrations/scm/github/connections | Connect GitHub. The response carries the webhook secret once; the token is never returned |
| GET | /organizations/{orgId}/integrations/scm/github/status | Whether GitHub App mode is configured |
| GET | /organizations/{orgId}/integrations/scm/github/connections/{connectionId} | Get a GitHub connection |
| DELETE | /organizations/{orgId}/integrations/scm/github/connections/{connectionId} | Disconnect GitHub: destroys the stored credentials and removes the scanned repositories |
| PATCH | /organizations/{orgId}/integrations/scm/github/connections/{connectionId} | Enable/disable, replace the token, or rotate the webhook secret (returned once) |
| GET | /organizations/{orgId}/integrations/scm/github/connections/{connectionId}/repositories | List the repositories a discovery scan found |
| POST | /organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/adopt | Adopt a discovered repository as a REPOSITORY asset, optionally attaching it to an AI System |
| POST | /organizations/{orgId}/integrations/scm/github/connections/{connectionId}/discovery-scan | Scan the connection’s repositories for agent/MCP/LLM configuration and send findings to the discovery inbox |
| POST | /organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/commit-status | Post a recorded quality-gate verdict to GitHub as a commit status |
| POST | /organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/aibom | Attach a CI-built CycloneDX AIBOM to the repository's asset |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/scm/aibom-artifacts | AIBOMs CI uploaded for the AI System's assets |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/scm/release-annotations | Releases and tags recorded for the AI System, newest first |
| GET | /organizations/{orgId}/integrations/scm/gitlab/connections | List GitLab connections |
| POST | /organizations/{orgId}/integrations/scm/gitlab/connections | Connect GitLab (gitlab.com or self-hosted). The response carries the webhook secret token once; the API token is never returned |
| GET | /organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId} | Get a GitLab connection |
| DELETE | /organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId} | Disconnect GitLab: destroys the stored credentials and removes the scanned repositories |
| PATCH | /organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId} | Enable/disable, replace the token, or rotate the webhook secret token (returned once) |
| GET | /organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}/repositories | List the GitLab projects a discovery scan found |
| POST | /organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/adopt | Adopt a discovered GitLab project as a REPOSITORY asset, optionally attaching it to an AI System |
| POST | /organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}/discovery-scan | Scan the connection’s GitLab projects for agent/MCP/LLM configuration and send findings to the discovery inbox |
| POST | /organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/commit-status | Post a recorded quality-gate verdict to GitLab as an external commit status |
| POST | /organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/aibom | Attach a CI-built CycloneDX AIBOM to the GitLab project's asset |
| GET | /organizations/{orgId}/integrations/servicenow/connections | List ServiceNow connections (credentials omitted) |
| POST | /organizations/{orgId}/integrations/servicenow/connections | Connect a ServiceNow instance (starts disabled until tested) |
| POST | /organizations/{orgId}/integrations/servicenow/connections/instance-proofs | Issue the proof a sovereign-cloud instance (*.servicenowservices.com) serves before it can be connected |
| GET | /organizations/{orgId}/integrations/servicenow/connections/{connectionId} | Get a ServiceNow connection (credentials omitted) |
| DELETE | /organizations/{orgId}/integrations/servicenow/connections/{connectionId} | Remove a ServiceNow connection: destroys its credential, releases its record links, stops its webhook |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/credentials | Rotate the stored credential; disables the connection until test passes again |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/test | Probe the stored credential; enables the connection on success |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/disable | Disable a ServiceNow connection |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/incidents/{incidentId}/push | Create the ServiceNow incident for an AI incident, or update the linked one |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/approvals/{approvalId}/raise | Raise a pending approval request as a ServiceNow sysapproval_approver record |
| POST | /organizations/{orgId}/integrations/servicenow/connections/{connectionId}/assets/{assetId}/cmdb-link | Link an AI asset to its ServiceNow cmdb_ci record |
| GET | /organizations/{orgId}/integrations/chat-connections | List chat connections (webhook URL omitted) |
| POST | /organizations/{orgId}/integrations/chat-connections | Connect a Slack or Teams incoming webhook, or a PagerDuty Events API v2 routing key |
| GET | /organizations/{orgId}/integrations/chat-connections/{id} | Get a chat connection (webhook URL omitted) |
| DELETE | /organizations/{orgId}/integrations/chat-connections/{id} | Remove a chat connection and destroy its stored webhook URL |
| PATCH | /organizations/{orgId}/integrations/chat-connections/{id} | Update a chat connection |
| POST | /organizations/{orgId}/integrations/chat-connections/{id}/test | Send one test message; records lastDeliveryAt / lastError on the connection |
| GET | /organizations/{orgId}/integrations/chat-connections/slack/oauth | Whether the Praesidia Slack app is configured |
| POST | /organizations/{orgId}/integrations/chat-connections/slack/oauth/install | Start an "Add to Slack" install |
| POST | /organizations/{orgId}/integrations/chat-connections/slack/oauth/install/callback | Complete an "Add to Slack" install (creates or updates the connection) |
| POST | /organizations/{orgId}/integrations/chat-connections/slack/oauth/link | Start linking your Slack account (Sign in with Slack) to approve from Slack |
| POST | /organizations/{orgId}/integrations/chat-connections/slack/oauth/link/callback | Complete linking your Slack account |
| GET | /organizations/{orgId}/integrations/chat-connections/slack/links/me | Your linked Slack accounts in this organization |
| DELETE | /organizations/{orgId}/integrations/chat-connections/slack/links/me | Unlink your Slack accounts in this organization |
| GET | /organizations/{orgId}/integrations/chat-connections/slack/links | Every member's linked Slack accounts in this organization |
| DELETE | /organizations/{orgId}/integrations/chat-connections/slack/links/{linkId} | Revoke a member's Slack account link |
Intelligence
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/intelligence/query | Answer a governance question over this organization |
Intent Labels
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/intent-labels | List captured intent labels (org-scoped) |
| POST | /organizations/{orgId}/intent-labels | Attach an FP/FN/correct label to an intent decision |
| GET | /organizations/{orgId}/intent-labels/aggregate | FP/FN aggregation for the org (overall + per source) |
| GET | /organizations/{orgId}/intent-labels/spot-check-candidates | Spot check candidates |
| POST | /organizations/{orgId}/intent-labels/promote | Promote labels into an eval dataset (consent-gated, anonymized) |
Intent Rules
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/intent-rules | List intent-detection rules |
| POST | /organizations/{orgId}/intent-rules | Create an intent-detection rule |
| POST | /organizations/{orgId}/intent-rules/apply-defaults | Apply the starter-pack intent rules for this org |
| GET | /organizations/{orgId}/intent-rules/{ruleId} | Get an intent-detection rule |
| DELETE | /organizations/{orgId}/intent-rules/{ruleId} | Delete an intent-detection rule |
| PATCH | /organizations/{orgId}/intent-rules/{ruleId} | Update an intent-detection rule |
Intent Sequence Rules
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/intent/sequence-rules | List sequence rules |
| POST | /organizations/{orgId}/intent/sequence-rules | Create a sequence rule |
| POST | /organizations/{orgId}/intent/sequence-rules/validate | Validate a sequence rule (DSL text or structured fields) without persisting it |
| GET | /organizations/{orgId}/intent/sequence-rules/{id} | Get a sequence rule |
| DELETE | /organizations/{orgId}/intent/sequence-rules/{id} | Delete a sequence rule |
| PATCH | /organizations/{orgId}/intent/sequence-rules/{id} | Update a sequence rule |
Interaction Decisions
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/interaction-decisions | Decide whether an agent may perform an SDK-hooked interaction |
| POST | /organizations/{orgId}/interaction-decisions/outcome | Report the result of an approved SDK interaction, once |
Issue Trackers
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/integrations/issue-trackers | List all issue-tracker connections for an organization |
| POST | /organizations/{orgId}/integrations/issue-trackers | Create a new issue-tracker connection |
| GET | /organizations/{orgId}/integrations/issue-trackers/{connId} | Get one issue-tracker connection |
| DELETE | /organizations/{orgId}/integrations/issue-trackers/{connId} | Delete (soft-delete) an issue-tracker connection |
| PATCH | /organizations/{orgId}/integrations/issue-trackers/{connId} | Update an issue-tracker connection |
| POST | /organizations/{orgId}/integrations/issue-trackers/{connId}/test | Test connectivity for an issue-tracker connection |
| POST | /organizations/{orgId}/integrations/issue-trackers/{connId}/create-issue | Manually create an issue in the connected tracker |
Lifecycle Hooks
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/lifecycle/hooks | List lifecycle hooks for the organization |
| POST | /organizations/{orgId}/lifecycle/hooks | Create a new lifecycle hook |
| DELETE | /organizations/{orgId}/lifecycle/hooks/{hookId} | Delete a lifecycle hook |
| PATCH | /organizations/{orgId}/lifecycle/hooks/{hookId} | Update a lifecycle hook |
| GET | /organizations/{orgId}/lifecycle/history | List lifecycle event history for the organization |
| POST | /organizations/{orgId}/lifecycle/inbound/{hookId} | Receive an inbound lifecycle event (HMAC-signed, no JWT required) |
LLM Configurations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/llm-configs | List LLM configurations (paginated) |
| POST | /organizations/{orgId}/llm-configs | Create an LLM configuration |
| GET | /organizations/{orgId}/llm-configs/providers | List LLM providers and whether the gateway can route each |
| GET | /organizations/{orgId}/llm-configs/{configId} | Get a single LLM configuration |
| DELETE | /organizations/{orgId}/llm-configs/{configId} | Delete an LLM configuration |
| PATCH | /organizations/{orgId}/llm-configs/{configId} | Update an LLM configuration |
| GET | /organizations/{orgId}/llm-configs/{configId}/metrics | Get usage metrics for an LLM configuration |
| PUT | /organizations/{orgId}/llm-configs/{configId}/api-key | Store an encrypted BYOK API key for this LLM config |
| DELETE | /organizations/{orgId}/llm-configs/{configId}/api-key | Remove the BYOK API key from this LLM config |
Marketplace
| Method | Path | Operation |
|---|---|---|
| GET | /marketplace/listings | Browse the public marketplace catalogue (approved listings only) |
| GET | /organizations/{orgId}/marketplace/publisher | Get this organisation's publisher profile |
| POST | /organizations/{orgId}/marketplace/publisher | Register as a publisher for this organisation |
| GET | /organizations/{orgId}/marketplace/listings | List this organisation's own marketplace listings (all statuses) |
| POST | /organizations/{orgId}/marketplace/listings | Create a marketplace listing (starts in draft status) |
| PUT | /organizations/{orgId}/marketplace/listings/{id} | Update a draft or rejected listing |
| POST | /organizations/{orgId}/marketplace/listings/{id}/submit | Submit a listing for certification review |
| POST | /organizations/{orgId}/marketplace/listings/{id}/install | Install an approved marketplace listing into this organisation |
| GET | /organizations/{orgId}/marketplace/earnings | List this publisher's revenue-share earnings |
| POST | /organizations/{orgId}/marketplace/listings/{id}/purchase | Buy a one-time marketplace listing: charges the listing's price to the org's default payment method |
| GET | /organizations/{orgId}/marketplace/tasks | List the organization's posted marketplace tasks |
| POST | /organizations/{orgId}/marketplace/tasks | Post a marketplace task and hold its budget |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/cancel | Cancel an open task and refund its escrow |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/accept | Accept an open marketplace task |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/submit | Submit completed marketplace work |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/confirm | Confirm work and release marketplace escrow |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/dispute | Open a marketplace task dispute |
| POST | /organizations/{orgId}/marketplace/tasks/{id}/rate | Rate a confirmed marketplace task |
| PUT | /organizations/{orgId}/marketplace/profiles/{agentId} | Create or update an owned agent's hire profile |
| GET | /marketplace/tasks | Browse public open marketplace tasks |
| GET | /marketplace/agents | Discover public agents available for hire |
MCP inventory
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/mcp-servers/{serverId}/inventory | Inspect live observations, approved baseline and tool-policy exposure |
| POST | /organizations/{orgId}/mcp-servers/{serverId}/inventory/refresh | Discover current schemas without approving them |
| POST | /organizations/{orgId}/mcp-servers/{serverId}/inventory/review | Approve the exact recently observed fingerprint and revision |
| POST | /organizations/{orgId}/mcp-servers/{serverId}/inventory/dependencies | Import declared CycloneDX dependencies; tools and privileges remain unapproved |
MCP Registry
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/mcp-registry/install | Install a marketplace listing for this org |
| GET | /organizations/{orgId}/mcp-registry/install-policy | The org's install-time verification policy |
| PUT | /organizations/{orgId}/mcp-registry/install-policy | Replace the org's install-time verification policy |
| GET | /organizations/{orgId}/mcp-registry/installations | List all installations for the org |
| PATCH | /organizations/{orgId}/mcp-registry/installations/{installationId}/deactivate | Deactivate an installation |
| GET | /mcp-registry | List public MCP server marketplace catalogue |
| GET | /mcp-registry/{id} | Get a catalogue listing with its verification |
| GET | /mcp-registry/{id}/versions | List versions for a catalogue listing |
MCP Server Discovery
| Method | Path | Operation |
|---|---|---|
| GET | /mcp-servers/discover | List public MCP servers |
| GET | /mcp-servers/discover/{id} | Get a public MCP server by ID |
| PATCH | /organizations/{orgId}/mcp-servers/{id}/publish | Publish an MCP server to public discovery |
| PATCH | /organizations/{orgId}/mcp-servers/{id}/unpublish | Unpublish an MCP server from public discovery |
| POST | /organizations/{orgId}/mcp-servers/{serverId}/rate | Rate a public MCP server |
| GET | /organizations/{orgId}/mcp-servers/{serverId}/rating-eligibility | Check whether the current user can rate a public MCP server |
MCP Servers
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/mcp-servers | Find all |
| POST | /organizations/{orgId}/mcp-servers | Create |
| GET | /organizations/{orgId}/mcp-servers/stats | Get stats |
| GET | /organizations/{orgId}/mcp-servers/{id} | Find one |
| DELETE | /organizations/{orgId}/mcp-servers/{id} | Remove |
| PATCH | /organizations/{orgId}/mcp-servers/{id} | Update |
| POST | /organizations/{orgId}/mcp-servers/{id}/health-check | Health check |
| PATCH | /organizations/{orgId}/mcp-servers/{id}/status | Update status |
| POST | /organizations/{orgId}/mcp-servers/{id}/connect | Connect |
| DELETE | /organizations/{orgId}/mcp-servers/{id}/connect | Disconnect |
| GET | /organizations/{orgId}/mcp-servers/{id}/tools | List tools |
| POST | /organizations/{orgId}/mcp-servers/{id}/tools/{toolName}/call | Call tool |
| GET | /organizations/{orgId}/mcp-servers/{id}/resources | List resources |
| POST | /organizations/{orgId}/mcp-servers/{id}/resources/read | Read resource |
| DELETE | /organizations/{orgId}/mcp-servers/{id}/cache | Invalidate cache |
| POST | /organizations/{orgId}/mcp-servers/{id}/discover | Discover capabilities |
| POST | /organizations/{orgId}/mcp-servers/discover-urls | Discover servers |
| GET | /organizations/{orgId}/mcp-servers/client/stats | Get client stats |
| PATCH | /organizations/{orgId}/mcp-servers/{id}/tool-rate-limits | Update tool rate limits |
| GET | /organizations/{orgId}/mcp-servers/{id}/tool-analytics | Get tool analytics |
Measured Governance Controls
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/governance-controls | Inspect reviewed control definitions and measured connected-path outcomes |
| POST | /organizations/{orgId}/governance-controls | Create |
| GET | /organizations/{orgId}/governance-controls/catalog | List scoped control setup choices (at most 500 per category) |
| GET | /organizations/{orgId}/governance-controls/{id} | Get |
| PATCH | /organizations/{orgId}/governance-controls/{id} | Update |
| POST | /organizations/{orgId}/governance-controls/{id}/review | Assigned owner reviews the exact fixture, current path configuration, and next review deadline |
| GET | /organizations/{orgId}/governance-controls/{id}/runs | History |
| POST | /organizations/{orgId}/governance-controls/{id}/runs | Run a reviewed fixture on the actual connected task path |
| POST | /organizations/{orgId}/governance-controls/{id}/runs/{runId}/refresh | Refresh |
Metrics Export
| Method | Path | Operation |
|---|---|---|
| GET | /org-metrics | Org-scoped Prometheus metrics scrape endpoint |
MFA
| Method | Path | Operation |
|---|---|---|
| GET | /mfa/status | Get status |
| POST | /mfa/setup | Setup |
| POST | /mfa/setup/confirm | Confirm setup |
| POST | /mfa/enroll/setup | Enroll setup |
| POST | /mfa/enroll/confirm | Enroll confirm |
| DELETE | /mfa/disable | Disable |
| POST | /mfa/backup-codes/regenerate | Regenerate backup codes |
Model Routing
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/model-routing/policies | Find all |
| POST | /organizations/{orgId}/model-routing/policies | Create |
| GET | /organizations/{orgId}/model-routing/policies/{id} | Find one |
| PUT | /organizations/{orgId}/model-routing/policies/{id} | Update |
| DELETE | /organizations/{orgId}/model-routing/policies/{id} | Remove |
| GET | /organizations/{orgId}/llm-providers/health | Get health |
| GET | /organizations/{orgId}/model-routing/decisions | Find recent |
Notifications
| Method | Path | Operation |
|---|---|---|
| GET | /notifications | Find all |
| GET | /notifications/unread-count | Get unread count |
| POST | /notifications/{id}/read | Mark as read |
| POST | /notifications/read-all | Mark all as read |
| POST | /notifications/read-many | Mark many as read |
| DELETE | /notifications/{id} | Delete |
| GET | /notifications/push/vapid-public-key | Get vapid public key |
| POST | /notifications/push/subscribe | Subscribe push |
| DELETE | /notifications/push/subscribe | Unsubscribe push |
OAuth
| Method | Path | Operation |
|---|---|---|
| POST | /oauth/token | Issue an OAuth access token for a registered authorization flow |
| GET | /.well-known/jwks.json | Jwks |
| GET | /.well-known/oauth-authorization-server | RFC 8414 OAuth authorization-server metadata |
| POST | /oauth/introspect | Introspect |
| POST | /oauth/revoke | Revoke |
OAuth browser authorization
| Method | Path | Operation |
|---|---|---|
| GET | /oauth/authorize | Begin registered-client authorization code and S256 consent |
| GET | /oauth/authorization-requests/{request} | Review this registered client request and your allowed identity bindings |
| POST | /oauth/authorization-requests/{request}/approve | Record explicit user consent and return a registered redirect with a single-use code |
| POST | /oauth/authorization-requests/{request}/deny | Deny this request and preserve OAuth state on the registered redirect |
OAuth browser client registration
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/oauth/browser-clients | List the 100 most recent browser client registrations in this workspace |
| POST | /organizations/{orgId}/oauth/browser-clients | Register |
| DELETE | /organizations/{orgId}/oauth/browser-clients/{clientId} | Disable |
OAuth Registration (RFC 7591)
| Method | Path | Operation |
|---|---|---|
| POST | /oauth/register | RFC 7591 — Register a new agent (requires IAT) |
| GET | /oauth/register/{clientId} | RFC 7591 — Read registration metadata |
| PUT | /oauth/register/{clientId} | RFC 7591 — Update registration metadata |
| DELETE | /oauth/register/{clientId} | RFC 7591 — Deregister an agent |
| GET | /organizations/{orgId}/oauth/registration-tokens | List Initial Access Tokens |
| POST | /organizations/{orgId}/oauth/registration-tokens | Create an Initial Access Token for RFC 7591 registration |
| DELETE | /organizations/{orgId}/oauth/registration-tokens/{tokenId} | Revoke an Initial Access Token |
Observed Agents
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/observed-agents | List OBSERVED agents (telemetry-materialised, ungoverned) |
| POST | /organizations/{orgId}/observed-agents/{id}/adopt | Adopt an observed agent (promote OBSERVED → MANAGED) |
Organizations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations | Find all |
| POST | /organizations | Create |
| GET | /organizations/{orgId} | Find one |
| DELETE | /organizations/{orgId} | Remove |
| PATCH | /organizations/{orgId} | Update |
| GET | /organizations/{orgId}/export | Export organization |
| GET | /organizations/{orgId}/legal-acceptances | List legal acceptances |
| POST | /organizations/{orgId}/legal-acceptances | Accept dpa |
| POST | /organizations/{orgId}/invite | Invite user |
| POST | /organizations/accept-invite | Accept invite |
| GET | /organizations/invites/by-token/{token} | Get invite by token |
| GET | /organizations/{orgId}/invites | Get pending invites |
| POST | /organizations/{orgId}/invites/{inviteId}/resend | Resend invite |
| DELETE | /organizations/invites/{inviteId} | Cancel invite |
| POST | /organizations/{orgId}/transfer-ownership | Transfer ownership |
| PATCH | /organizations/{orgId}/members/{userId}/role | Update member role |
| DELETE | /organizations/{orgId}/members/{userId} | Remove member |
| POST | /organizations/{orgId}/leave | Leave |
| GET | /organizations/{orgId}/byok | Get config |
| PUT | /organizations/{orgId}/byok | Set config |
| DELETE | /organizations/{orgId}/byok | Revoke config |
| GET | /organizations/{orgId}/governance-mode | Get this organization's governance mode |
| POST | /organizations/{orgId}/governance-mode/enforce | Opt this organization into governance `enforce` (tighten only) |
| POST | /organizations/{orgId}/data-exports | Start a full organization data export |
| GET | /organizations/{orgId}/data-exports/{id} | Status of a data export; signed download links when done |
| GET | /organization-data-exports/download | Download one file of a data export (signed link) |
| GET | /organizations/{orgId}/notices/active | Platform notices active for this organization |
Policy Simulation
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/policy-simulations | Simulate a draft or saved policy against historical traffic |
| GET | /organizations/{orgId}/policy-simulations/{id} | Get a simulation run — status and summary |
| GET | /organizations/{orgId}/policy-simulations/{id}/findings | List a simulation run's per-event findings |
Prompt Versions
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/prompt-versions | List |
| POST | /organizations/{orgId}/agents/{agentId}/prompt-versions | Create |
| GET | /organizations/{orgId}/agents/{agentId}/prompt-versions/compare | Compare |
| PUT | /organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/activate | Activate |
| PUT | /organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/traffic | Set traffic |
| PUT | /organizations/{orgId}/agents/{agentId}/prompt-versions/ab-split | Set ab split |
| POST | /organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/promote | Promote a prompt version (CI/CD gate) |
Protected Actions
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/protected-actions | List protected actions for the organization |
| GET | /organizations/{orgId}/protected-actions/capture-scope | Get the capture-scope registry — the declared denominator for any "% of actions captured" claim |
| GET | /organizations/{orgId}/protected-actions/coverage-summary | Exact org-scoped counts per D7 closure value plus open-phase counts — the aggregate counterpart to the list route |
| GET | /organizations/{orgId}/protected-actions/coverage | Interaction type coverage |
| GET | /organizations/{orgId}/protected-actions/{actionId} | Get one protected action (full projection row) |
| GET | /organizations/{orgId}/protected-actions/{actionId}/events | Get the full ordered evidence stream for one protected action, including signature bytes for independent hash-chain verification |
Protected HTTP Execution
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/protected-actions/http/prepare | Create or recover an exact-request durable approval checkpoint |
| GET | /organizations/{orgId}/protected-actions/http/checkpoints/{approvalId} | Read an owned checkpoint and its recorded outcome after restart |
| POST | /organizations/{orgId}/protected-actions/http/resume | Consume a signed human approval and dispatch the exact approved HTTP request once |
| POST | /organizations/{orgId}/protected-actions/http/checkpoints/{approvalId}/revoke | Revoke an owned pending or approved checkpoint before dispatch consumption |
| POST | /organizations/{orgId}/protected-actions/http/acknowledge | Record that the authenticated requester observed the committed result |
PublicAgents
| Method | Path | Operation |
|---|---|---|
| GET | /agents/public | Find public agents |
| GET | /agents/public/{agentId} | Find one |
| GET | /agents/{agentId}/trust | Get agent trust |
| POST | /agents/{agentId}/clone | Clone an agent |
Red Team
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/redteam/opt-in | Get the org-level red-team opt-in (master switch) |
| PUT | /organizations/{orgId}/redteam/opt-in | Enable/disable the red-team module for this org (default OFF) |
| GET | /organizations/{orgId}/redteam/target-opt-ins | List per-target red-team opt-ins for the org |
| PUT | /organizations/{orgId}/redteam/target-opt-ins | Explicitly opt a single owned target in/out (required before any probe) |
| GET | /organizations/{orgId}/redteam/packs | List the packs a campaign can select: built-in packs and this org's installed listing packs |
| GET | /organizations/{orgId}/redteam/campaigns | List red-team campaigns for the org |
| POST | /organizations/{orgId}/redteam/campaigns | Create a red-team campaign against an owned target |
| GET | /organizations/{orgId}/redteam/campaigns/{campaignId} | Get a single red-team campaign |
| PATCH | /organizations/{orgId}/redteam/campaigns/{campaignId} | Update a campaign schedule: enable/disable (kill switch), cron, execution mode |
| POST | /organizations/{orgId}/redteam/campaigns/{campaignId}/run | Start an on-demand red-team run (opt-in + scope-guard enforced server-side) |
| GET | /organizations/{orgId}/redteam/runs | List red-team runs for the org |
| GET | /organizations/{orgId}/redteam/runs/{runId} | Get a single red-team run (status + counts) |
| GET | /organizations/{orgId}/redteam/runs/{runId}/findings | List findings for a run (paginated, filterable) |
| GET | /organizations/{orgId}/redteam/runs/{runId}/report | Tamper-evident red-team findings report (SHA-256) for a run |
Regulatory Graph
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/regulatory-graph/catalog/jurisdictions | List catalog jurisdictions |
| GET | /organizations/{orgId}/regulatory-graph/catalog/regulations | List catalog regulations |
| GET | /organizations/{orgId}/regulatory-graph/catalog/articles | List catalog articles |
| GET | /organizations/{orgId}/regulatory-graph/catalog/obligations | List catalog obligations |
| GET | /organizations/{orgId}/regulatory-graph/traverse | Traverse the regulatory graph (Obligation↔Control↔Policy↔Evidence↔AI System) from an anchor node. Depth is clamped, never rejected; an oversized result fails closed with 413 rather than truncating. |
| GET | /organizations/{orgId}/ai-systems/{id}/obligations | Obligations reachable from an AI System (direct link, depth 1, or evidence-mediated, depth 2). |
| GET | /organizations/{orgId}/obligations/{id}/ai-systems | AI Systems reachable from an Obligation (direct link, depth 1, or evidence-mediated, depth 2). |
| POST | /organizations/{orgId}/regulatory-graph/impact | Compute the impact of a regulation change on one obligation: every affected AI system/control/policy (reusing the same traversal as `GET .../traverse`, no second graph walk), which affected systems are missing fresh evidence, and which downstream review artefacts (risk classification, technical documentation, transparency assessment, FRIA, DPIA) are required. |
| GET | /organizations/{orgId}/regulatory-graph/impact-reports | List this org's stored change-impact reports, newest first, optionally for one obligation. |
| GET | /organizations/{orgId}/regulatory-graph/impact-reports/{id} | Get one stored change-impact report. |
| POST | /organizations/{orgId}/regulatory-graph/impact/{reportId}/remediate | Turn a stored change-impact report into DRAFT control proposals (origin REGULATORY_REMEDIATION): controls/policies to review, the Annex IV section to revise and the evaluations to re-run, all read from the graph. Nothing is applied — a human approves then applies via the control-proposals endpoints. Idempotent per report: while a non-REJECTED proposal exists for it, that proposal is returned. |
| POST | /organizations/{orgId}/regulatory-graph/imports | Import this organization’s own regulatory content (jurisdiction → regulation → articles → obligations) in the curated seed-fixture shape. Rows are origin CUSTOMER and visible to this organization only; curated content is never modified. Idempotent: an identical re-import creates nothing. OWNER only. |
| GET | /organizations/{orgId}/regulatory-graph/obligation-controls | List obligation controls |
| POST | /organizations/{orgId}/regulatory-graph/obligation-controls | Create obligation control |
| GET | /organizations/{orgId}/regulatory-graph/obligation-controls/{id} | Get obligation control |
| DELETE | /organizations/{orgId}/regulatory-graph/obligation-controls/{id} | Delete obligation control |
| GET | /organizations/{orgId}/regulatory-graph/control-policies | List control policies |
| POST | /organizations/{orgId}/regulatory-graph/control-policies | Create control policy |
| GET | /organizations/{orgId}/regulatory-graph/policy-options | List the org's live policies ({id, name, kind}) across the 7 linkable kinds, for the control→policy picker. |
| GET | /organizations/{orgId}/regulatory-graph/control-policies/{id} | Get control policy |
| DELETE | /organizations/{orgId}/regulatory-graph/control-policies/{id} | Delete control policy |
| GET | /organizations/{orgId}/regulatory-graph/obligation-ai-systems | List obligation ai systems |
| POST | /organizations/{orgId}/regulatory-graph/obligation-ai-systems | Create obligation ai system |
| GET | /organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id} | Get obligation ai system |
| DELETE | /organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id} | Delete obligation ai system |
| PATCH | /organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id} | Set a link to NOT_APPLICABLE (reject a suggestion) or APPLICABLE, in one write. A rejected pair is never re-proposed by suggest. |
| POST | /organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id}/confirm | Confirm a SUGGESTED obligation-applicability link as APPLICABLE. The only path that writes APPLICABLE. |
| POST | /organizations/{orgId}/regulatory-graph/obligation-ai-systems/suggest | Suggest obligations for an AI system from its EU AI Act supply-chain role and its highest linked risk tier. Writes SUGGESTED links only. |
| GET | /organizations/{orgId}/regulatory-graph/obligation-evidence | List obligation evidence |
| POST | /organizations/{orgId}/regulatory-graph/obligation-evidence | Create obligation evidence |
| GET | /organizations/{orgId}/regulatory-graph/obligation-evidence/{id} | Get obligation evidence |
| DELETE | /organizations/{orgId}/regulatory-graph/obligation-evidence/{id} | Delete obligation evidence |
Remediation
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/remediation/proposals | List |
| POST | /organizations/{orgId}/remediation/proposals/{id}/dismiss | Dismiss |
| POST | /organizations/{orgId}/remediation/proposals/{id}/choose-candidate | Choose candidate |
| POST | /organizations/{orgId}/remediation/proposals/{id}/simulate | Simulate |
| POST | /organizations/{orgId}/remediation/proposals/{id}/request-approval | Request approval |
| POST | /organizations/{orgId}/remediation/proposals/{id}/approve | Approve |
| POST | /organizations/{orgId}/remediation/proposals/{id}/apply | Apply |
| POST | /organizations/{orgId}/remediation/proposals/{id}/rollback | Rollback |
| GET | /organizations/{orgId}/remediation/proposals/{id}/runs | Runs |
Reputation
| Method | Path | Operation |
|---|---|---|
| GET | /reputation/agents/{agentDid} | Query global reputation for an agent DID (public, unauthenticated) |
| POST | /organizations/{orgId}/reputation/contribute | Contribute reputation signal for an installed agent (opt-in orgs only) |
Revenue Monitoring
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/revenue-monitoring/overview | Get revenue overview |
| GET | /organizations/{orgId}/revenue-monitoring/customers | Get top customers |
| GET | /organizations/{orgId}/revenue-monitoring/mrr | Get mrr |
| GET | /organizations/{orgId}/revenue-monitoring/balance | Get balance |
| GET | /organizations/{orgId}/revenue-monitoring/payouts | Get payouts |
| POST | /organizations/{orgId}/revenue-monitoring/payouts | Request payout |
Role Elevation
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/role-elevations | Find all |
| POST | /organizations/{orgId}/role-elevations | Elevate |
| GET | /organizations/{orgId}/role-elevations/active | Find active |
| POST | /organizations/{orgId}/role-elevations/{elevationId}/revoke | Revoke |
Roles
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/roles/permissions | Get available permissions |
| GET | /organizations/{orgId}/roles | Find all roles |
| POST | /organizations/{orgId}/roles | Create role |
| GET | /organizations/{orgId}/roles/{roleId} | Find role |
| DELETE | /organizations/{orgId}/roles/{roleId} | Delete role |
| PATCH | /organizations/{orgId}/roles/{roleId} | Update role |
| POST | /organizations/{orgId}/roles/assign/{userId} | Assign role to user |
| DELETE | /organizations/{orgId}/roles/assign/{userId}/{assignmentId} | Remove role from user |
| GET | /organizations/{orgId}/roles/user/{userId} | Get user roles |
| GET | /organizations/{orgId}/roles/user/{userId}/permissions | Get user permissions |
Runtime installations
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/runtime-installations | List organization runtime installations and observed connection state |
| POST | /organizations/{orgId}/runtime-installations | Create a pending runtime installation; does not attest a host or enable dispatch |
| GET | /organizations/{orgId}/runtime-installations/targets | List registered target identifiers without credentials or destination configuration |
| GET | /organizations/{orgId}/runtime-installations/{id} | Read an installation and its bound dispatch evidence |
| PATCH | /organizations/{orgId}/runtime-installations/{id} | Update an installation with revision checking; changed bindings require reconnection |
| POST | /organizations/{orgId}/runtime-installations/{id}/challenge | Issue a one-use native connection challenge and pause new bound dispatches |
| POST | /organizations/{orgId}/runtime-installations/{id}/disable | Permanently disable admission of new installation-bound managed actions |
| POST | /organizations/{orgId}/runtime-installations/{id}/verify | Consume a creator-owned challenge using a non-browser credential; proves credential possession only |
Saved Views
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/saved-views | Find all |
| POST | /organizations/{orgId}/saved-views | Create |
| GET | /organizations/{orgId}/saved-views/{id} | Find one |
| PUT | /organizations/{orgId}/saved-views/{id} | Update |
| DELETE | /organizations/{orgId}/saved-views/{id} | Remove |
SCIM
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/scim | Get config |
| PATCH | /organizations/{orgId}/scim | Toggle enabled |
| POST | /organizations/{orgId}/scim/token | Generate token |
| GET | /organizations/{orgId}/scim/groups | List groups admin |
| GET | /organizations/{orgId}/scim/group-mappings | List group mappings |
| POST | /organizations/{orgId}/scim/group-mappings | Create group mapping |
| PUT | /organizations/{orgId}/scim/group-mappings/{mappingId} | Update group mapping |
| DELETE | /organizations/{orgId}/scim/group-mappings/{mappingId} | Delete group mapping |
| GET | /scim/v2/{orgId}/Users | List users |
| POST | /scim/v2/{orgId}/Users | Create user |
| GET | /scim/v2/{orgId}/Users/{userId} | Get user |
| PUT | /scim/v2/{orgId}/Users/{userId} | Replace user |
| DELETE | /scim/v2/{orgId}/Users/{userId} | Delete user |
| PATCH | /scim/v2/{orgId}/Users/{userId} | Patch user |
| GET | /scim/v2/{orgId}/Groups | List groups |
| POST | /scim/v2/{orgId}/Groups | Create group |
| GET | /scim/v2/{orgId}/Groups/{groupId} | Get group |
| PUT | /scim/v2/{orgId}/Groups/{groupId} | Replace group |
| DELETE | /scim/v2/{orgId}/Groups/{groupId} | Delete group |
| PATCH | /scim/v2/{orgId}/Groups/{groupId} | Patch group |
Search
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/search | Global search across agents, workflows, tasks and audit logs |
Security Settings
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/security/policy | Get policy |
| PUT | /organizations/{orgId}/security/policy | Update policy |
| GET | /organizations/{orgId}/security/ips | Get ip policies |
| POST | /organizations/{orgId}/security/ips | Add ip policy |
| DELETE | /organizations/{orgId}/security/ips/{id} | Delete ip policy |
| GET | /organizations/{orgId}/security/sso | Get sso config |
| PUT | /organizations/{orgId}/security/sso | Update sso config |
| POST | /organizations/{orgId}/security/sso/test | Test sso config |
| GET | /organizations/{orgId}/security/proof-actions | Get this organization's protected-action evidence state |
| PUT | /organizations/{orgId}/security/proof-actions | Enable or disable protected-action evidence for this organization |
Semantic Cache
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/cache/stats | Get stats |
| DELETE | /organizations/{orgId}/cache | Invalidate all |
| DELETE | /organizations/{orgId}/cache/agents/{agentId} | Invalidate agent |
Service Accounts
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/service-accounts | Find all |
| POST | /organizations/{orgId}/service-accounts | Create |
| GET | /organizations/{orgId}/service-accounts/{id} | Find one |
| DELETE | /organizations/{orgId}/service-accounts/{id} | Delete |
| PATCH | /organizations/{orgId}/service-accounts/{id} | Update |
| POST | /organizations/{orgId}/service-accounts/{id}/rotate-key | Rotate key |
SLO
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/slo/summary | Per-org SLO indicators (success rate, latency, availability) |
| GET | /organizations/{orgId}/slo/alerts | List SLO alert threshold configs (org-wide, or ?aiSystemId=) |
| POST | /organizations/{orgId}/slo/alerts | Upsert an SLO alert threshold (one rule per metric per org or AI System) |
| DELETE | /organizations/{orgId}/slo/alerts/{id} | Delete an SLO alert threshold config |
Supervision
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/supervision/sessions | List supervision sessions |
| POST | /organizations/{orgId}/supervision/sessions | Start a supervision session (EU AI Act Art. 14) |
| POST | /organizations/{orgId}/supervision/sessions/{sessionId}/end | End a supervision session |
| POST | /organizations/{orgId}/supervision/sessions/{sessionId}/intervene | Intervene on a task during an active session |
| POST | /organizations/{orgId}/supervision/tasks/{taskId}/pause | Pause a running task |
| POST | /organizations/{orgId}/supervision/tasks/{taskId}/resume | Resume a paused task |
| POST | /organizations/{orgId}/supervision/tasks/{taskId}/terminate | Terminate a running or paused task |
| POST | /organizations/{orgId}/supervision/tasks/{taskId}/modify-input | Replace the input of a task before it is processed |
| GET | /organizations/{orgId}/supervision/history | Paginated supervision event history |
| GET | /organizations/{orgId}/supervision/escalations | List human-escalations for autonomous chains (default: pending) |
| GET | /organizations/{orgId}/supervision/escalations/config | get the org confidence-band routing config (auto-resolve/queue/escalate thresholds) |
| PUT | /organizations/{orgId}/supervision/escalations/config | update the org confidence-band routing config (upsert; lowBandMax <= highBandMin) |
| POST | /organizations/{orgId}/supervision/escalations/{escalationId}/approve | Approve an escalation — release the held hop to the queue |
| POST | /organizations/{orgId}/supervision/escalations/{escalationId}/reject | Reject an escalation — terminate the chain hop (fail-closed) |
Supply Chain
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/supply-chain/scan | Run a static, offline scan of an MCP server / skill manifest and report any hits as findings (source=supply_chain). |
| GET | /organizations/{orgId}/supply-chain/permission-policies | The org's MCP permission policies: the org-wide default (serverId null) plus any per-server overrides. |
| PUT | /organizations/{orgId}/supply-chain/permission-policies | Create or replace the permission policy for one MCP server, or the org-wide default when serverId is omitted. |
| DELETE | /organizations/{orgId}/supply-chain/permission-policies/{id} | Remove a permission policy. Scans then fall back to the org-wide default, or to the registered server's own capabilities. |
Support
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/support/requests | Send a support request to Praesidia support |
Team Quotas
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/teams/{teamId}/quotas | Get quota |
| PATCH | /organizations/{orgId}/teams/{teamId}/quotas | Update quota |
| GET | /organizations/{orgId}/teams/{teamId}/quotas/usage | Get usage |
| POST | /organizations/{orgId}/teams/{teamId}/quotas/sync | Sync counters |
Teams
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/teams | Get all teams in the organization |
| POST | /organizations/{orgId}/teams | Create a new team |
| GET | /organizations/{orgId}/teams/{teamId} | Get a specific team by ID |
| DELETE | /organizations/{orgId}/teams/{teamId} | Delete a team |
| PATCH | /organizations/{orgId}/teams/{teamId} | Update |
| GET | /organizations/{orgId}/teams/{teamId}/members | Get team members |
| POST | /organizations/{orgId}/teams/{teamId}/members | Add a member to a team |
| DELETE | /organizations/{orgId}/teams/{teamId}/members/{userId} | Remove a member from a team |
| PATCH | /organizations/{orgId}/teams/{teamId}/members/{userId}/role | Update member role |
| GET | /organizations/{orgId}/teams/{teamId}/dashboard | Get team dashboard |
| GET | /organizations/{orgId}/teams/{teamId}/agents | Get team agents |
Telemetry Ingest
| Method | Path | Operation |
|---|---|---|
| POST | /telemetry/otlp/v1/traces | Ingest OTLP/HTTP GenAI traces (buffered, org-key auth) |
Threat Intelligence
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/threat-intel/feed | List global threat intelligence feed entries (paginated) |
| GET | /organizations/{orgId}/threat-intel/status | Get org threat intelligence opt-in status and contribution stats |
Topology
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/topology/graph | Get agent dependency graph / topology |
Traces
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/traces/search | Full-text search across tool-call, guardrail-log, and prompt-trace entries |
| GET | /organizations/{orgId}/traces/{taskId} | Get full execution trace for an agent task |
| GET | /organizations/{orgId}/traces | List agent execution traces for the organization |
| GET | /organizations/{orgId}/traces/{taskId}/export | Export task trace as OTLP JSON (Jaeger/Tempo compatible) |
Trust
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/trust/score | Get current trust score for an agent |
| GET | /organizations/{orgId}/agents/{agentId}/trust/history | Get trust score history for an agent |
| GET | /organizations/{orgId}/agents/{agentId}/trust/attestations | List trust attestations for an agent |
| POST | /organizations/{orgId}/agents/{agentId}/trust/attestations | Submit a third-party trust attestation |
| POST | /organizations/{orgId}/agents/{agentId}/trust/attestations/{attestationId}/revoke | Revoke a trust attestation for an agent |
| GET | /organizations/{orgId}/trust/agents-summary | Trust scores for every agent in the org, in a single response |
Trust Passport
| Method | Path | Operation |
|---|---|---|
| GET | /trust/passport/{agentId} | Signed, verifiable trust passport for an agent |
| GET | /trust/passport/{agentId}/verify | Trust passport verification bundle |
| GET | /trust/passport/{agentId}/badge.svg | Embeddable SVG trust badge |
| GET | /trust/passport/ai-systems/{aiSystemId} | Signed, verifiable trust passport for an AI System |
| GET | /trust/passport/ai-systems/{aiSystemId}/verify | AI System trust passport verification bundle |
| GET | /trust/passport/ai-systems/{aiSystemId}/passport.pdf | Downloadable PDF rendering of the AI System trust passport |
| GET | /trust/passport/ai-systems/{aiSystemId}/badge.svg | Embeddable SVG trust badge for an AI System |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/trust-passport | The org's own view of an AI System trust passport |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/trust-passport/verify | The org's own AI System trust passport verification bundle |
| GET | /organizations/{orgId}/ai-systems/{aiSystemId}/trust-passport/passport.pdf | PDF of the org's own AI System trust passport |
Trust Passport imports
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/trust-passport/imports | List imported trust passports (no documents) |
| POST | /organizations/{orgId}/trust-passport/imports | Import a vendor trust passport |
| GET | /organizations/{orgId}/trust-passport/imports/{id} | An imported trust passport, with its document |
| PATCH | /organizations/{orgId}/trust-passport/imports/{id} | Set or clear an import's vendor AI asset |
| POST | /organizations/{orgId}/trust-passport/imports/{id}/reverify | Re-verify and re-score an imported trust passport |
| GET | /organizations/{orgId}/trust-passport/pinned-keys | List pinned vendor signing keys |
| POST | /organizations/{orgId}/trust-passport/pinned-keys | Pin a vendor's passport signing key for an issuer |
| DELETE | /organizations/{orgId}/trust-passport/pinned-keys/{id} | Unpin a vendor signing key |
Usage
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/usage | Organization monthly usage |
| GET | /organizations/{orgId}/usage/connections/{connectionId} | Connection current month usage |
| GET | /organizations/{orgId}/usage/connections/{connectionId}/history | Connection usage history |
User delegation consent
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/identity/consents | List your 100 most recent delegation consents in this workspace |
| POST | /organizations/{orgId}/identity/consents | Grant expiring, resource and scope limited consent to a workload |
| DELETE | /organizations/{orgId}/identity/consents/{id} | Withdraw your consent and cancel active tasks using it |
Users
| Method | Path | Operation |
|---|---|---|
| PATCH | /users/profile | Update profile |
| GET | /users/api-keys | List api keys |
| POST | /users/api-keys | Create api key |
| DELETE | /users/api-keys/{id} | Delete api key |
| GET | /users/notification-preferences | Get notification preferences |
| PATCH | /users/notification-preferences | Update notification preferences |
| GET | /users/organizations/{orgId}/users | Find all |
| GET | /users/organizations/{orgId}/users/{userId} | Find one |
| PATCH | /users/organizations/{orgId}/users/{userId} | Update |
| POST | /users/organizations/{orgId}/users/{userId}/teams/{teamId} | Add to team |
| DELETE | /users/organizations/{orgId}/users/{userId}/teams/{teamId} | Remove from team |
Wallets
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/agents/{agentId}/wallet | Get wallet for an agent |
| POST | /organizations/{orgId}/agents/{agentId}/wallet | Create a wallet for an agent |
| GET | /organizations/{orgId}/wallets | List agent wallets in this organisation (paginated) |
| POST | /organizations/{orgId}/wallets/pay | Transfer funds between agent wallets |
| POST | /organizations/{orgId}/wallets/top-up | Deposit funds into an agent wallet from org-budget |
| GET | /organizations/{orgId}/wallets/transactions | List wallet transactions for the organisation (paginated) |
| POST | /organizations/{orgId}/wallets/transactions/{txId}/reverse | Reverse a settled payment transaction (admin only) |
WebAuthn
| Method | Path | Operation |
|---|---|---|
| POST | /webauthn/register/start | Register start |
| POST | /webauthn/register/finish | Register finish |
| GET | /webauthn/credentials | List credentials |
| DELETE | /webauthn/credentials/{id} | Delete credential |
| POST | /webauthn/authenticate/start | Authenticate start |
| POST | /webauthn/authenticate/finish | Authenticate finish |
| POST | /webauthn/sudo/start | Sudo start |
| POST | /webauthn/sudo/finish | Sudo finish |
Webhook Deliveries
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/integrations/webhooks/{webhookId}/deliveries | Find all |
| GET | /organizations/{orgId}/integrations/webhooks/{webhookId}/deliveries/{deliveryId} | Find one |
| POST | /organizations/{orgId}/integrations/webhooks/{webhookId}/deliveries/{deliveryId}/replay | Replay |
Workflow Templates
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/workflow-templates | List workflow templates (org-scoped) |
| GET | /organizations/{orgId}/workflow-templates/{slug} | Get a workflow template by slug (org-scoped) |
| GET | /workflow-templates | List all published workflow templates |
| GET | /workflow-templates/{slug} | Get a single workflow template by slug |
| POST | /organizations/{orgId}/workflow-templates/{slug}/use | Create a new workflow from a template |
Workflow Webhooks
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/workflows/{workflowId}/webhook/configure | Generate webhook URL and HMAC secret for a workflow |
| POST | /organizations/{orgId}/workflows/{workflowId}/webhook/rotate-secret | Rotate the HMAC secret for webhook signature verification |
| GET | /organizations/{orgId}/workflows/{workflowId}/webhook/deliveries | List recent webhook deliveries for a workflow |
| POST | /organizations/{orgId}/workflows/{workflowId}/webhook/deliveries/{deliveryId}/redeliver | Re-trigger a previous webhook delivery |
Workflows
| Method | Path | Operation |
|---|---|---|
| GET | /organizations/{orgId}/workflows | List all workflows for the organization |
| POST | /organizations/{orgId}/workflows | Create a new workflow |
| POST | /organizations/{orgId}/workflows/generate | Enqueue async generation of a workflow from a natural language prompt |
| GET | /organizations/{orgId}/workflows/generate/{jobId} | Poll the status/result of an async workflow generation job |
| GET | /organizations/{orgId}/workflows/{id} | Get a specific workflow |
| DELETE | /organizations/{orgId}/workflows/{id} | Delete a specific workflow |
| PATCH | /organizations/{orgId}/workflows/{id} | Update a specific workflow |
| GET | /organizations/{orgId}/workflows/{id}/cost-forecast | Get forecasted cost for a workflow run |
| GET | /organizations/{orgId}/workflows/{id}/runs | List runs for a workflow |
| POST | /organizations/{orgId}/workflows/{id}/runs | Start a workflow run |
| GET | /organizations/{orgId}/workflows/{id}/runs/{runId} | Get a specific workflow run with accumulated context |
| POST | /organizations/{orgId}/workflows/{id}/runs/{runId}/retry | Retry a failed or cancelled workflow run with the same initial input |
| POST | /organizations/{orgId}/workflows/{id}/runs/{runId}/cancel | Cancel a RUNNING or PAUSED workflow run (e.g. a budget auto-paused run) |
| GET | /organizations/{orgId}/workflows/{id}/runs/{runId}/approvals | List pending approvals for a workflow run |
| POST | /organizations/{orgId}/workflows/{id}/runs/{runId}/approvals/{approvalId}/approve | Approve a pending approval |
| POST | /organizations/{orgId}/workflows/{id}/runs/{runId}/approvals/{approvalId}/reject | Reject a pending approval |
| GET | /organizations/{orgId}/workflows/{id}/versions | List all versions of a workflow |
| GET | /organizations/{orgId}/workflows/{id}/versions/{versionId} | Get a specific workflow version |
| POST | /organizations/{orgId}/workflows/{id}/versions/{versionId}/rollback | Rollback workflow to a previous version |
Zeroclaw
| Method | Path | Operation |
|---|---|---|
| POST | /organizations/{orgId}/zeroclaw/pair | Pair |
| GET | /organizations/{orgId}/zeroclaw/health | Health |
| GET | /organizations/{orgId}/zeroclaw/pairings | List |
| POST | /organizations/{orgId}/zeroclaw/pairings/{pairingId}/verify | Verify |
| POST | /organizations/{orgId}/zeroclaw/pairings/{pairingId}/rotate | Rotate |
| DELETE | /organizations/{orgId}/zeroclaw/pairings/{pairingId} | Revoke |
| POST | /organizations/{orgId}/zeroclaw/pairings/{pairingId}/bind | Bind |
| POST | /organizations/{orgId}/zeroclaw/pairings/{pairingId}/repair | Repair |
Read next: all docs · developer quickstart · integrations · security
Make your first call
Create a workspace, issue an API key and follow the quickstart with a harmless test request.