Developers

Praesidia API reference

Every customer-facing REST operation, generated from the API's OpenAPI description: 1226 operations in 142 groups.

Using this reference

Paths are relative to your Praesidia API origin. Organization-scoped operations take your organization ID in the {orgId} path segment.

Requests authenticate with a Praesidia API key in the X-API-Key header (or as an Authorization: Bearer credential), or with a session access token. The OpenAPI file lists the accepted scheme, parameters, request bodies and response schemas for each operation; load it into any OpenAPI-compatible client or code generator.

The file covers the operations your workspace can call. Platform-operator, service-to-service and inbound webhook endpoints are not part of it. Spec version 0.0.1.

Operations

Operations by group

A2A Protocol

MethodPathOperation
POST/a2a/tasksSubmit a task (A2A)
POST/a2a/tasks/{taskId}/resultReport task result (A2A)
GET/a2a/tasks/{taskId}/execution-contextRead current execution admission for the assigned polling server
GET/a2a/tasks/pending/{clientId}Poll for pending tasks (A2A)

Access Review

MethodPathOperation
POST/organizations/{orgId}/access-reviews/generateGenerate reviews
POST/organizations/{orgId}/access-reviews/generate/inactivityGenerate inactivity reviews
GET/organizations/{orgId}/access-reviewsFind all
GET/organizations/{orgId}/access-reviews/pendingFind pending
POST/organizations/{orgId}/access-reviews/{reviewId}/approveApprove
POST/organizations/{orgId}/access-reviews/{reviewId}/revokeRevoke
POST/organizations/{orgId}/access-reviews/generate/entitlementsOpen a certification campaign over agent entitlements
POST/organizations/{orgId}/access-reviews/{reviewId}/attestSign the owner or security attestation on a certification
POST/organizations/{orgId}/access-reviews/{reviewId}/certifyClose an agent entitlement certification (retain/revoke/modify)

Account

MethodPathOperation
POST/account/email-changeRequest email change
POST/account/email-change/confirmConfirm email change
GET/account/exportExport account
GET/account/legal-acceptancesList legal acceptances
DELETE/accountDelete account
POST/account/api-keys/{id}/rotateRotate api key

Agent Attestations

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/attestationsList attestations for an agent
POST/organizations/{orgId}/agents/{agentId}/attestationsSubmit a new attestation
GET/organizations/{orgId}/agents/{agentId}/attestations/{id}Fetch a single attestation by id
GET/organizations/{orgId}/agents/{agentId}/attestations/{id}/verifyOffline verify an attestation
POST/organizations/{orgId}/agents/{agentId}/attestations/{id}/revokeRevoke an attestation

Agent Cards & Discovery

MethodPathOperation
GET/agents/{id}/agent-cardGet A2A agent card
GET/agents/discoveryDiscover agents

Agent Communication

MethodPathOperation
POST/organizations/{orgId}/agents/{agentId}/communication/enableEnable A2A communication
POST/organizations/{orgId}/agents/{agentId}/communication/disableDisable A2A communication
GET/organizations/{orgId}/agents/{agentId}/communication/statusGet communication status

Agent Deployments

MethodPathOperation
GET/organizations/{orgId}/agent-deploymentsList agent deployments for the organization
POST/organizations/{orgId}/agent-deploymentsCreate a new agent deployment
GET/organizations/{orgId}/agent-deployments/{id}Get a specific agent deployment
DELETE/organizations/{orgId}/agent-deployments/{id}Delete an agent deployment (tears down platform resources)
PATCH/organizations/{orgId}/agent-deployments/{id}Update a DRAFT agent deployment
POST/organizations/{orgId}/agent-deployments/generateGenerate agent config from a natural language idea
POST/organizations/{orgId}/agent-deployments/{id}/deployTrigger deployment of the agent to the target platform
POST/organizations/{orgId}/agent-deployments/{id}/test-connectionValidate the deployment's resolved LLM credentials before deploying
POST/organizations/{orgId}/agent-deployments/{id}/stopStop and tear down the deployed agent

Agent Drift Detection

MethodPathOperation
GET/organizations/{orgId}/agents/drift/alertsList drift alerts for an organization
GET/organizations/{orgId}/agents/drift/alerts/{alertId}Get a single drift alert
POST/organizations/{orgId}/agents/drift/alerts/{alertId}/acknowledgeAcknowledge a drift alert
POST/organizations/{orgId}/agents/drift/alerts/{alertId}/resolveResolve a drift alert
POST/organizations/{orgId}/agents/drift/alerts/{alertId}/dismissDismiss a drift alert
GET/organizations/{orgId}/agents/drift/{agentId}/healthGet agent health with baseline and active alerts
GET/organizations/{orgId}/agents/drift/{agentId}/behaviorGet an agent behavioral profile (known tools, chain-role norm, arg-shape norm) and recent per-call deviations
POST/organizations/{orgId}/agents/drift/{agentId}/baselineManually rebuild baseline for an agent

Agent Federation

MethodPathOperation
POST/organizations/{orgId}/federation-manifestsPublish a new federation manifest version
GET/organizations/{orgId}/federation-manifests/currentFetch the org's most recent federation manifest
GET/organizations/{orgId}/federation-manifests/revocationsList delta revocations published by this org
POST/organizations/{orgId}/federation-manifests/revocationsPublish a signed delta revocation for a federated agent
GET/organizations/{orgId}/federation-manifests/peer-pins/pendingList federation peer pins requiring operator action
POST/organizations/{orgId}/federation-manifests/peer-pins/{peerOrgId}/approveApprove a PENDING_APPROVAL federation peer pin

Agent Memory

MethodPathOperation
GET/organizations/{orgId}/memoriesList memories (org-scoped, paginated, decrypted).
POST/organizations/{orgId}/memoriesWrite a memory (PII-redacted + poisoning-blocked on the write path, encrypted per-org).
POST/organizations/{orgId}/memories/searchRelevance search over memories (provenance surfaced per hit).
POST/organizations/{orgId}/memories/eraseRequest two-person GDPR Art-17 erasure (legacy memory alias; no immediate destruction).
GET/organizations/{orgId}/memories/{id}Fetch a single memory (org-scoped, decrypted).
DELETE/organizations/{orgId}/memories/{id}Soft-delete a single memory (org-scoped).
GET/organizations/{orgId}/memory-sourcesList the connector owner’s source authorization leases.
POST/organizations/{orgId}/memory-sources/synchronizeSynchronize a current upstream document ACL, content version or revocation using a bounded authorization lease.

Agent Policies

MethodPathOperation
GET/organizations/{orgId}/policiesList all policies
POST/organizations/{orgId}/policiesCreate a new agent policy
GET/organizations/{orgId}/policies/{policyId}Get a single policy by ID
DELETE/organizations/{orgId}/policies/{policyId}Delete a policy
PATCH/organizations/{orgId}/policies/{policyId}Update a policy
POST/organizations/{orgId}/policies/apply-defaultsSeed default policies for the organization
POST/organizations/{orgId}/policies/detect-conflictsDetect conflicts between multiple policies
POST/organizations/{orgId}/policies/{policyId}/assignAssign policy to agents
DELETE/organizations/{orgId}/policies/agents/{agentId}Remove the policy assigned to one agent
POST/organizations/{orgId}/policies/{policyId}/rollout/rollbackRoll an agent policy's rollout stage back to OBSERVE
POST/organizations/{orgId}/policies/{policyId}/rollout/advanceAdvance a agent policy's rollout to the next stage
PUT/organizations/{orgId}/policies/{policyId}/rollout/auto-rollbackSet a agent policy's auto-rollback opt-in

Agent Posture

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/postureGet the posture record for an agent
POST/organizations/{orgId}/agents/{agentId}/postureSubmit a posture declaration for an agent
GET/organizations/{orgId}/posture/summaryOrg-wide posture status summary

Agent Reviews

MethodPathOperation
GET/organizations/{orgId}/agents/{id}/reviewsGet reviews
POST/organizations/{orgId}/agents/{id}/reviewsCreate review
GET/agents/{id}/public-ratingGet the public cross-org aggregate rating for a marketplace agent

Agent Sharing

MethodPathOperation
POST/organizations/{orgId}/sharing/agents/{agentId}/shareShare an agent with another organization
POST/organizations/{orgId}/sharing/acceptAccept an incoming share
DELETE/organizations/{orgId}/sharing/{shareId}Revoke a share
GET/organizations/{orgId}/sharing/outgoingList outgoing shares
GET/organizations/{orgId}/sharing/incomingList incoming shares
PATCH/organizations/{orgId}/sharing/{shareId}/policyUpdate share policy

Agent Tasks

MethodPathOperation
GET/organizations/{orgId}/tasksList agent tasks
POST/organizations/{orgId}/tasksSubmit a task to a server agent
GET/organizations/{orgId}/tasks/statsGet task statistics
GET/organizations/{orgId}/tasks/{taskId}Get task details
POST/organizations/{orgId}/tasks/{taskId}/approveApprove a pending-approval task
POST/organizations/{orgId}/tasks/{taskId}/cancelCancel a pending task
GET/organizations/{orgId}/tasks/{taskId}/traceGet prompt trace for a task
GET/organizations/{orgId}/tasks/{taskId}/treeGet task execution tree

Agent Templates

MethodPathOperation
GET/organizations/{orgId}/agent-templatesList agent templates (org-scoped, paginated)
GET/organizations/{orgId}/agent-templates/{slug}Get agent template by slug (org-scoped)
GET/agent-templatesList agent templates
GET/agent-templates/{slug}Get agent template by slug
POST/organizations/{orgId}/agent-templates/{slug}/useCreate an agent from a template

Agent Timeline

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/timelinePer-agent action timeline

Agent Tool Policies

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/tool-policiesList tool policy rules for an agent
POST/organizations/{orgId}/agents/{agentId}/tool-policiesCreate a per-(agent, tool) policy rule
GET/organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}Get a tool policy rule
DELETE/organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}Delete a tool policy rule
PATCH/organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}Update a tool policy rule

Agent Versions

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/versionsList
POST/organizations/{orgId}/agents/{agentId}/versionsCreate
GET/organizations/{orgId}/agents/{agentId}/versions/diffDiff
GET/organizations/{orgId}/agents/{agentId}/versions/compareCompare
GET/organizations/{orgId}/agents/{agentId}/versions/{versionId}Get one
POST/organizations/{orgId}/agents/{agentId}/versions/{versionId}/rollbackRollback

Agents

MethodPathOperation
POST/agents/heartbeatAgent heartbeat
GET/organizations/{orgId}/agentsGet all agents
POST/organizations/{orgId}/agentsCreate a new agent
GET/organizations/{orgId}/agents/{agentId}Get agent by ID
DELETE/organizations/{orgId}/agents/{agentId}Delete an agent
PATCH/organizations/{orgId}/agents/{agentId}Update an agent
PATCH/organizations/{orgId}/agents/{agentId}/statusUpdate status
POST/organizations/{orgId}/agents/{agentId}/webhook-signing-secret/rotateRotate agent webhook signing secret
POST/organizations/{orgId}/agents/{agentId}/revokeRevoke (quarantine) a single agent — blast-radius containment
POST/organizations/{orgId}/agents/{agentId}/quarantineQuarantine a single agent — reversible containment
POST/organizations/{orgId}/agents/{agentId}/restoreRestore a revoked/suspended agent
GET/organizations/{orgId}/agents/{agentId}/revocation-previewPreview the blast radius of revoking an agent
POST/organizations/{orgId}/agents/{agentId}/transfer-ownershipTransfer ownership
GET/organizations/{orgId}/agents/{agentId}/collaboratorsGet collaborators
POST/organizations/{orgId}/agents/{agentId}/collaboratorsAdd collaborator
DELETE/organizations/{orgId}/agents/{agentId}/collaborators/{userId}Remove collaborator
POST/organizations/{orgId}/agents/{agentId}/installInstall an agent
POST/organizations/{orgId}/agents/{agentId}/tokenIssue a short-lived RS256 agent-identity JWT
POST/organizations/{orgId}/agents/{agentId}/chatChat with an agent

AI Assets

MethodPathOperation
GET/organizations/{orgId}/ai-systems/provenance/task/{taskId}Unified delegation-chain provenance for one agent task
GET/organizations/{orgId}/ai-systems/decisions/{decisionId}/explainExplain one policy decision across six dimensions
GET/organizations/{orgId}/ai-assetsFind all
POST/organizations/{orgId}/ai-assetsCreate
POST/organizations/{orgId}/ai-assets/adoptAdopt
GET/organizations/{orgId}/ai-assets/{id}Find one
PATCH/organizations/{orgId}/ai-assets/{id}Update
POST/organizations/{orgId}/ai-assets/{id}/archiveArchive
POST/organizations/{orgId}/ai-assets/{id}/restoreRestore
GET/organizations/{orgId}/ai-assets/{id}/blast-radiusBlast radius
GET/organizations/{orgId}/asset-relationshipsFind all
POST/organizations/{orgId}/asset-relationshipsCreate
GET/organizations/{orgId}/asset-relationships/graph/traverseTraverse
GET/organizations/{orgId}/asset-relationships/{id}Find one
PATCH/organizations/{orgId}/asset-relationships/{id}Update
POST/organizations/{orgId}/asset-relationships/{id}/archiveArchive
POST/organizations/{orgId}/asset-relationships/{id}/restoreRestore

AI Intake

MethodPathOperation
GET/organizations/{orgId}/ai-intakeList AI intake submissions
POST/organizations/{orgId}/ai-intakeSubmit an AI intake request
GET/organizations/{orgId}/ai-intake/{intakeId}Get one AI intake submission
POST/organizations/{orgId}/ai-intake/{intakeId}/reviewApprove or reject an AI intake submission

AI Systems

MethodPathOperation
GET/organizations/{orgId}/ai-systems/entitlements/agent/{agentId}/reachWhat can this agent access? Downstream reachability from the agent over the projected entitlement graph.
GET/organizations/{orgId}/ai-systems/entitlements/agent/{agentId}/delegatorsWho delegated authority to this agent? Upstream DELEGATES_TO chain into the agent.
GET/organizations/{orgId}/ai-systems/entitlements/assetsWhich tools can move money / which agents can access PII? Assets tagged with the requested capability, plus the agents that can invoke them.
GET/organizations/{orgId}/ai-systems/entitlements/escalation-pathsWhich agents have privilege escalation paths? Every agent A -> ... -> agent B delegation chain where B’s CAN_INVOKE scope set is a strict superset of A’s.
PUT/organizations/{orgId}/ai-systems/by-external-id/{externalId}Upsert ai system
DELETE/organizations/{orgId}/ai-systems/by-external-id/{externalId}Archive ai system
PUT/organizations/{orgId}/ai-assets/by-external-id/{externalId}Upsert ai asset
DELETE/organizations/{orgId}/ai-assets/by-external-id/{externalId}Archive ai asset
PUT/organizations/{orgId}/asset-relationships/by-external-id/{externalId}Upsert asset relationship
DELETE/organizations/{orgId}/asset-relationships/by-external-id/{externalId}Archive asset relationship
GET/organizations/{orgId}/ai-systems/modification-thresholdsResolved EU AI Act substantial-modification thresholds
PATCH/organizations/{orgId}/ai-systems/modification-thresholdsOverride this org's substantial-modification thresholds
GET/organizations/{orgId}/ai-systems/material-change-reactions/rulesEffective material-change reaction rules
PUT/organizations/{orgId}/ai-systems/material-change-reactions/rules/{changeType}/{reaction}Override one material-change reaction cell
DELETE/organizations/{orgId}/ai-systems/material-change-reactions/rules/{changeType}/{reaction}Revert one material-change reaction cell to the default
GET/organizations/{orgId}/ai-systemsFind all
POST/organizations/{orgId}/ai-systemsCreate
GET/organizations/{orgId}/ai-systems/lifecycle-requestsList lifecycle requests
POST/organizations/{orgId}/ai-systems/lifecycle-requests/{requestId}/approveApprove lifecycle request
POST/organizations/{orgId}/ai-systems/lifecycle-requests/{requestId}/rejectReject lifecycle request
POST/organizations/{orgId}/ai-systems/{id}/lifecycle-requestsRequest lifecycle transition
POST/organizations/{orgId}/ai-systems/{id}/reapproveRe-approve a production AI System after a material change
GET/organizations/{orgId}/ai-systems/{id}Find one
DELETE/organizations/{orgId}/ai-systems/{id}Remove
PATCH/organizations/{orgId}/ai-systems/{id}Update
GET/organizations/{orgId}/ai-systems/{id}/summaryGet summary
PATCH/organizations/{orgId}/ai-systems/{id}/ownersUpdate owners
PATCH/organizations/{orgId}/ai-systems/{id}/lifecycleTransition lifecycle
GET/organizations/{orgId}/ai-systems/{id}/ai-act-roleGet ai act role
PATCH/organizations/{orgId}/ai-systems/{id}/ai-act-roleSet ai act role
POST/organizations/{orgId}/ai-systems/{id}/archiveArchive
POST/organizations/{orgId}/ai-systems/{id}/restoreRestore
GET/organizations/{orgId}/ai-systems/{id}/retire/previewPreview the blast radius of retiring an AI System
POST/organizations/{orgId}/ai-systems/{id}/retireRequest retirement of an AI System
POST/organizations/{orgId}/ai-systems/entitlements/reprojectReproject entitlements
GET/organizations/{orgId}/ai-systems/{aiSystemId}/assetsList
POST/organizations/{orgId}/ai-systems/{aiSystemId}/assetsAttach
PATCH/organizations/{orgId}/ai-systems/{aiSystemId}/assets/{assetId}/roleChange role
DELETE/organizations/{orgId}/ai-systems/{aiSystemId}/assets/{assetId}Detach
GET/organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/policiesList the deployment gate rules for an AI System
PUT/organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/policiesReplace the deployment gate rules for an AI System
POST/organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluateEvaluate the gate against an existing eval run (CI entry point; works with an organization API key)
GET/organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluationsList past gate verdicts for an AI System
POST/organizations/{orgId}/ai-systems/{aiSystemId}/quality-gate/evaluations/{evaluationId}/overrideOverride a failing gate verdict, with a mandatory reason
GET/organizations/{orgId}/ai-systems/{aiSystemId}/snapshotsList this AI System snapshots, newest first
POST/organizations/{orgId}/ai-systems/{aiSystemId}/snapshotsTake a material-change snapshot of this AI System now
GET/organizations/{orgId}/ai-systems/{aiSystemId}/material-changesThe material change feed for this AI System
POST/organizations/{orgId}/ai-systems/{aiSystemId}/material-changes/{changeId}/acknowledgeAcknowledge one detected material change
GET/organizations/{orgId}/entitlement-recommendationsList least-privilege recommendations
POST/organizations/{orgId}/entitlement-recommendations/{id}/acceptAccept a recommendation. Records the decision only; the grant is not changed.
POST/organizations/{orgId}/entitlement-recommendations/{id}/dismissDismiss a recommendation
GET/organizations/{orgId}/ai-systems/{aiSystemId}/modificationsDetected substantial-modification classifications for this AI System
GET/organizations/{orgId}/ai-systems/{id}/risk-pathsRanked risk paths through an AI System, with per-hop reasons
GET/organizations/{orgId}/ai-systems/{aiSystemId}/aibomList versions
POST/organizations/{orgId}/ai-systems/{aiSystemId}/aibomGenerate
GET/organizations/{orgId}/ai-systems/{aiSystemId}/aibom/latestGet latest
GET/organizations/{orgId}/ai-systems/{aiSystemId}/aibom/{snapshotId}Get version
GET/organizations/{orgId}/ai-systems/{aiSystemId}/aibom/{snapshotId}/exportExport snapshot
GET/organizations/{orgId}/aibom/diffDiff
GET/organizations/{orgId}/aibom/{snapshotId}/verifyVerify a signed AIBOM snapshot
POST/organizations/{orgId}/ai-systems/{aiSystemId}/aibom/importImport a pipeline-built CycloneDX BOM into an AI System's AIBOM
GET/organizations/{orgId}/ai-systems/{id}/data-flowsData-flow lineage of an AI System, down to classified data

Alert Rules

MethodPathOperation
GET/organizations/{orgId}/alert-rulesList alert rules for an organization.
POST/organizations/{orgId}/alert-rulesCreate an alert rule.
GET/organizations/{orgId}/alert-rules/{id}Fetch a single alert rule by id.
DELETE/organizations/{orgId}/alert-rules/{id}Delete an alert rule.
PATCH/organizations/{orgId}/alert-rules/{id}Update an alert rule.
POST/organizations/{orgId}/alert-rules/{id}/testBack-test a predicate against the most recent events of a given type. Informational only; does not persist a rule fire.
POST/organizations/{orgId}/alert-rules/testTest inline

Alert Webhook Allowlist

MethodPathOperation
GET/organizations/{orgId}/alert-webhook-allowlistList allowed webhook hostnames for the org.
POST/organizations/{orgId}/alert-webhook-allowlistAdd a hostname to the org's alert-webhook allowlist.
DELETE/organizations/{orgId}/alert-webhook-allowlist/{domainId}Remove a domain from the org's alert-webhook allowlist.

Analytics

MethodPathOperation
GET/organizations/{orgId}/analyticsGet organization analytics
GET/organizations/{orgId}/analytics/capture-stateGet capture state
GET/organizations/{orgId}/analytics/agents/{agentId}Get agent analytics
GET/organizations/{orgId}/analytics/eventsGet recent events
POST/organizations/{orgId}/analytics/eventsRecord event
GET/organizations/{orgId}/analytics/activity-logGet recent events activity log
GET/organizations/{orgId}/analytics/advanced/agent-performanceGet agent performance metrics
GET/organizations/{orgId}/analytics/advanced/securityGet security metrics
GET/organizations/{orgId}/analytics/advanced/cost-trendsGet cost trends
GET/organizations/{orgId}/analytics/advanced/usage-heatmapGet usage heatmap
GET/organizations/{orgId}/analytics/advanced/top-agentsGet top agents
GET/organizations/{orgId}/analytics/advanced/complianceGet compliance metrics
GET/organizations/{orgId}/analytics/advanced/anomaliesGet anomalies
GET/organizations/{orgId}/analytics/advanced/cost-by-teamGet cost by team
GET/organizations/{orgId}/analytics/exportExport csv
GET/organizations/{orgId}/analytics/advanced/model-comparisonCompare models

Applications

MethodPathOperation
GET/organizations/{orgId}/applicationsList applications
POST/organizations/{orgId}/applicationsRegister a new application
GET/organizations/{orgId}/applications/{id}Get application details
DELETE/organizations/{orgId}/applications/{id}Delete application
PATCH/organizations/{orgId}/applications/{id}Update application
GET/organizations/{orgId}/applications/{id}/metricsGet usage metrics for an application
POST/organizations/{orgId}/applications/{id}/regenerate-keyRegenerate API key
POST/organizations/{orgId}/applications/{id}/revoke-keyRevoke API key
POST/organizations/{orgId}/applications/{id}/agents/{agentId}Allow app to call an agent
DELETE/organizations/{orgId}/applications/{id}/agents/{agentId}Revoke app access to an agent

Approval Workflow

MethodPathOperation
GET/organizations/{orgId}/approvalsFind all
POST/organizations/{orgId}/approvalsCreate
GET/organizations/{orgId}/approvals/pending/countCount pending
GET/organizations/{orgId}/approvals/{approvalId}Find one
POST/organizations/{orgId}/approvals/{approvalId}/approveApprove
POST/organizations/{orgId}/approvals/{approvalId}/rejectReject
POST/organizations/{orgId}/approvals/{approvalId}/cancelCancel
GET/organizations/{orgId}/approval-escalationGet
PUT/organizations/{orgId}/approval-escalationUpdate

Audit

MethodPathOperation
GET/organizations/{orgId}/audit-logsFind all
GET/organizations/{orgId}/audit-logs/exportExport all
GET/organizations/{orgId}/teams/{teamId}/audit-logsFind by team
GET/organizations/{orgId}/teams/{teamId}/audit-logs/exportExport by team
GET/organizations/{orgId}/agents/{agentId}/audit-logsFind by agent
GET/organizations/{orgId}/audit/{rowId}/verifyVerify a single signed audit row
GET/organizations/{orgId}/audit/{rowId}/proofGet an inclusion proof for a signed audit row
GET/organizations/{orgId}/audit/{rowId}/receiptGet the Decision Receipt for one audit row
GET/organizations/{orgId}/audit/decisions/{decisionId}/receiptGet the Decision Receipt for one decisionId
GET/organizations/{orgId}/audit/receiptsList Decision Receipts
GET/organizations/{orgId}/audit/anchor-freshnessGet the org’s external-anchor freshness status
GET/organizations/{orgId}/audit/bundleExport a signed audit bundle for offline verification
POST/organizations/{orgId}/audit/packagesRequest a multi-artifact audit package
GET/organizations/{orgId}/audit/packages/{id}Get the status of an audit package export
GET/organizations/{orgId}/audit/packages/{id}/downloadDownload a finished audit package

Audit trust anchor

MethodPathOperation
GET/.well-known/praesidia-audit-keys.jsonAudit-bundle platform attestation public keys

Auth

MethodPathOperation
POST/auth/signupSignup
POST/auth/verify-emailVerify email
POST/auth/resend-verification-emailResend verification email
POST/auth/verify-otpVerify otp
POST/auth/resend-otpResend otp
POST/auth/forgot-passwordForgot password
POST/auth/reset-passwordReset password
POST/auth/loginLogin
POST/auth/mfa/verifyMfa verify
POST/auth/refreshRefresh token
POST/auth/organizations/{orgId}/switchSwitch organization
GET/auth/profileGet profile
GET/auth/meGet me
GET/auth/sessionGet session
PATCH/auth/change-passwordChange password
GET/auth/organizations/{orgId}/permissionsGet organization permissions
POST/auth/logoutLogout
POST/auth/logout-allLogout all
POST/auth/sudoSudo
GET/auth/sudo/methodsSudo methods
POST/auth/sudo/idp/initiateSudo idp initiate
POST/auth/sso/initiateSso initiate
POST/auth/sso/logoutSso logout
GET/auth/sessionsList the caller's active sessions/devices
DELETE/auth/sessionsRevoke every other session for the caller
DELETE/auth/sessions/{id}Revoke one of the caller's sessions

Auth Monitoring

MethodPathOperation
GET/organizations/{orgId}/auth-monitoring/activityGet activity
GET/organizations/{orgId}/auth-monitoring/statsGet stats
GET/organizations/{orgId}/auth-monitoring/connectionsGet connection status
GET/organizations/{orgId}/auth-monitoring/tokensGet tokens
GET/organizations/{orgId}/auth-monitoring/tokens/statsGet token stats
GET/organizations/{orgId}/auth-monitoring/tokens/activeGet active tokens
POST/organizations/{orgId}/auth-monitoring/tokens/{tokenId}/revokeRevoke token
GET/organizations/{orgId}/auth-monitoring/rate-limitsGet rate limit stats
GET/organizations/{orgId}/auth-monitoring/performanceGet performance metrics

Benchmarks

MethodPathOperation
GET/benchmarksList industry benchmark segments (public, aggregate-only)
GET/benchmarks/trendsBenchmark metric trend over time (public, aggregate-only)
GET/organizations/{orgId}/benchmarks/compareCompare an org agent against anonymous industry benchmark segment

Billing

MethodPathOperation
GET/organizations/{orgId}/billing/plansList available billing plans with current-plan marker
GET/organizations/{orgId}/billing/subscriptionGet subscription details
POST/organizations/{orgId}/billing/subscriptionUpdate subscription plan
GET/organizations/{orgId}/billing/subscription/previewPreview a plan change: proration from Stripe and usage over the target caps
POST/organizations/{orgId}/billing/subscription/cancelCancel subscription
GET/organizations/{orgId}/billing/invoicesList invoices (paginated, default 20, max 100)
GET/organizations/{orgId}/billing/payment-methodsGet payment methods
POST/organizations/{orgId}/billing/payment-methodsAdd payment method
POST/organizations/{orgId}/billing/setup-intentCreate setup intent
POST/organizations/{orgId}/billing/portal-sessionCreate a Stripe Billing Portal session
DELETE/organizations/{orgId}/billing/payment-methods/{id}Delete a payment method
GET/organizations/{orgId}/billing/creditsGet credit balance
POST/organizations/{orgId}/billing/credits/purchasePurchase credits
GET/organizations/{orgId}/billing/usage-reportsGet usage reports
GET/organizations/{orgId}/billing/cost-analyticsGet cost analytics
GET/organizations/{orgId}/billing/spending-forecastsGet spending forecasts
GET/organizations/{orgId}/billing/contactsGet billing contacts
PATCH/organizations/{orgId}/billing/contactsUpdate billing contacts
PATCH/organizations/{orgId}/billing/currencyUpdate preferred billing currency
POST/organizations/{orgId}/billing/metered-subscriptionCreate metered subscription
GET/organizations/{orgId}/billing/usage-summaryGet usage summary
POST/organizations/{orgId}/billing/connect-accountCreate connect account
POST/organizations/{orgId}/billing/connect-account/onboarding-linkGet connect onboarding link
POST/organizations/{orgId}/billing/payoutCreate payout
GET/organizations/{orgId}/billing/contractsList enterprise contracts (paginated, default 20, max 100)
POST/organizations/{orgId}/billing/contractsCreate contract
PATCH/organizations/{orgId}/billing/contracts/{contractId}/statusUpdate contract status
GET/organizations/{orgId}/billing/exportExport billing data
GET/organizations/{orgId}/billing/spend-alert-rulesList all spend alert rules for the organization
POST/organizations/{orgId}/billing/spend-alert-rulesCreate a spend alert rule
GET/organizations/{orgId}/billing/spend-alert-rules/{ruleId}Get a spend alert rule by ID
DELETE/organizations/{orgId}/billing/spend-alert-rules/{ruleId}Delete a spend alert rule
PATCH/organizations/{orgId}/billing/spend-alert-rules/{ruleId}Update a spend alert rule

Budget Policies

MethodPathOperation
GET/organizations/{orgId}/budget-policiesFind all
POST/organizations/{orgId}/budget-policiesCreate
GET/organizations/{orgId}/budget-policies/summaryGet summary
GET/organizations/{orgId}/budget-policies/{id}Find one
DELETE/organizations/{orgId}/budget-policies/{id}Remove
PATCH/organizations/{orgId}/budget-policies/{id}Update
POST/organizations/{orgId}/budget-policies/{id}/resetReset period

Business Value

MethodPathOperation
GET/organizations/{orgId}/business-value/kpisList KPI definitions, optionally by AI System
POST/organizations/{orgId}/business-value/kpisDefine a KPI for an AI System
GET/organizations/{orgId}/business-value/kpis/by-ai-system/{aiSystemId}Every KPI defined for an AI System, resolved to a value for the requested period (manual/imported lookup, or derived computation)
GET/organizations/{orgId}/business-value/kpis/{id}Get one KPI definition
DELETE/organizations/{orgId}/business-value/kpis/{id}Soft-delete a KPI definition
PATCH/organizations/{orgId}/business-value/kpis/{id}Update a KPI definition
GET/organizations/{orgId}/business-value/kpis/{id}/valuesList recorded values for a KPI definition
POST/organizations/{orgId}/business-value/kpis/{id}/valuesRecord a manual/imported value for a period
GET/organizations/{orgId}/business-value/roiCost (cost-monitoring) vs. value (KPIs) for one AI System over one period, with an ROI percentage when both sides are available
GET/organizations/{orgId}/business-value/risk-adjustedBusiness value and AI cost for one AI System next to its security, compliance and operational risk, with the weighting used

Chains

MethodPathOperation
GET/organizations/{orgId}/chains/{chainId}Get a chain trace

Compliance

MethodPathOperation
GET/organizations/{orgId}/compliance/security-eventsGet security events
POST/organizations/{orgId}/compliance/security-events/{id}/resolveResolve security event
GET/organizations/{orgId}/compliance/access-policiesGet access policies
POST/organizations/{orgId}/compliance/access-policiesCreate access policy
GET/organizations/{orgId}/compliance/reportsGet reports
POST/organizations/{orgId}/compliance/reportsGenerate a NIST AI RMF or ISO 42001 framework report
POST/organizations/{orgId}/compliance/reports/generateGenerate report
GET/organizations/{orgId}/compliance/iso42001Get iso42001 mapping
GET/organizations/{orgId}/compliance/iso42001/gapsGet coverage gaps
GET/organizations/{orgId}/compliance/evidence-coverageGet evidence coverage
GET/organizations/{orgId}/compliance/readiness/{framework}Get readiness
GET/organizations/{orgId}/compliance/evidenceGet evidence
POST/organizations/{orgId}/compliance/evidenceAdd manual evidence
POST/organizations/{orgId}/compliance/evidence/collectCollect evidence
POST/organizations/{orgId}/compliance/iso42001/gaps/{controlId}/evidenceAttach manual/uploaded evidence to an ISO 42001 control gap
GET/organizations/{orgId}/compliance/retention-policyGet retention policy
PATCH/organizations/{orgId}/compliance/retention-policyUpdate retention policy
GET/organizations/{orgId}/compliance/gdpr/dpiaFind all
POST/organizations/{orgId}/compliance/gdpr/dpiaCreate
GET/organizations/{orgId}/compliance/gdpr/dpia/{id}Find one
PATCH/organizations/{orgId}/compliance/gdpr/dpia/{id}Update
GET/organizations/{orgId}/compliance/gdpr/dpia/{id}/exportExport record
POST/organizations/{orgId}/compliance/gdpr/dpia/{id}/linkLink
POST/organizations/{orgId}/compliance/gdpr/dpia/{id}/submitSubmit
POST/organizations/{orgId}/compliance/gdpr/dpia/{id}/approveApprove
POST/organizations/{orgId}/compliance/gdpr/dpia/{id}/rejectReject
GET/organizations/{orgId}/compliance/eu-ai-act/articlesOrg roll-up of the per-entity EU AI Act article matrix (all entities)
GET/organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/articlesPer-entity EU AI Act article matrix (Art. 9/10/12/13/14) with evidence-backed statuses
GET/organizations/{orgId}/compliance/eu-ai-act/oversight-reportEU AI Act Art. 14 oversight evidence report
GET/organizations/{orgId}/compliance/eu-ai-act/statusGet per-article EU AI Act RAG status
GET/organizations/{orgId}/compliance/eu-ai-act/qms-reportGenerate Art. 17 QMS report (JSON)
GET/organizations/{orgId}/compliance/owasp-agentic/coveragePer-ASI OWASP Agentic coverage: risk entry, linked controls, evidence count
GET/organizations/{orgId}/ai-systems/{aiSystemId}/risk-registerList Art. 9 risk register entries for an AI System
GET/organizations/{orgId}/compliance/risk-registerList Art. 9 risk register entries
POST/organizations/{orgId}/compliance/risk-registerCreate Art. 9 risk register entry
PUT/organizations/{orgId}/compliance/risk-register/{id}Update Art. 9 risk register entry
DELETE/organizations/{orgId}/compliance/risk-register/{id}Delete Art. 9 risk register entry
POST/organizations/{orgId}/oversight/suspend-allArt. 14 kill-switch — suspend all active agents for the org
GET/organizations/{orgId}/oversight/kill-switch-testTest Art. 14 kill-switch status (does not suspend agents)
GET/organizations/{orgId}/compliance/risk-exceptionsList risk exceptions for the org
POST/organizations/{orgId}/compliance/risk-exceptionsRequest a time-boxed acceptance of a known risk
GET/organizations/{orgId}/compliance/risk-exceptions/{id}Get one risk exception
POST/organizations/{orgId}/compliance/risk-exceptions/{id}/approveApprove a requested risk exception (approver ≠ requester)
POST/organizations/{orgId}/compliance/risk-exceptions/{id}/rejectReject a requested risk exception
POST/organizations/{orgId}/compliance/risk-exceptions/{id}/revokeRevoke an approved risk exception early
POST/organizations/{orgId}/compliance/readiness/{framework}/exportExport a framework readiness audit package
POST/organizations/{orgId}/compliance/eu-ai-act/reportsQueue an async EU AI Act auditor report (returns id + status)
GET/organizations/{orgId}/compliance/eu-ai-act/reports/{reportId}Poll auditor-report generation status
GET/organizations/{orgId}/compliance/eu-ai-act/reports/{reportId}/jsonDownload the structured JSON auditor report
GET/organizations/{orgId}/compliance/eu-ai-act/reports/{reportId}/pdfDownload the rendered PDF auditor report
GET/organizations/{orgId}/compliance/iso42001/soaISO 42001 Statement of Applicability (JSON or CSV)
PATCH/organizations/{orgId}/compliance/iso42001/soa/{controlId}Record applicability and justification for an Annex A control

Connections

MethodPathOperation
GET/organizations/{orgId}/connectionsFind all
GET/organizations/{orgId}/connections/statsGet stats
GET/organizations/{orgId}/connections/{id}Find one
DELETE/organizations/{orgId}/connections/{id}Disconnect
POST/organizations/{orgId}/connections/agentCreate agent to agent
POST/organizations/{orgId}/connections/mcpCreate agent to mcp
POST/organizations/{orgId}/connections/{id}/testTest connection
PATCH/organizations/{orgId}/connections/{id}/statusUpdate status
PATCH/organizations/{orgId}/connections/{id}/policyUpdate policy
PATCH/organizations/{orgId}/connections/{id}/configurationAtomically update connection policy configuration
PATCH/organizations/{orgId}/connections/{id}/min-trust-levelUpdate min trust level
PATCH/organizations/{orgId}/connections/{id}/backup-connectionClear a legacy backup connection assignment
GET/organizations/{orgId}/connections/{id}/healthGet latest health
GET/organizations/{orgId}/connections/{id}/health/historyGet health history
PATCH/organizations/{orgId}/connections/{id}/guardrailsSet connection guardrails

Connections - ABAC

MethodPathOperation
GET/organizations/{orgId}/connections/{connId}/tool-permissionsList ABAC tool permissions for a connection
POST/organizations/{orgId}/connections/{connId}/tool-permissionsCreate a tool permission for a connection
DELETE/organizations/{orgId}/connections/{connId}/tool-permissions/{id}Delete a tool permission
PATCH/organizations/{orgId}/connections/{connId}/tool-permissions/{id}Update a tool permission
POST/organizations/{orgId}/connections/{connId}/tool-permissions/importBulk-import tool permissions from a YAML policy string
GET/organizations/{orgId}/connections/{connId}/tool-permissions/exportExport all active tool permissions for a connection

Connectors

MethodPathOperation
GET/organizations/{orgId}/connectors/catalogList the named enterprise connector catalogue
GET/organizations/{orgId}/connectors/catalog/{key}Get a single connector catalogue entry
POST/organizations/{orgId}/connectors/registerRegister a named connector with governance pre-wired
GET/organizations/{orgId}/connectors/registrationsList connector registrations for the org
PATCH/organizations/{orgId}/connectors/registrations/{id}/authConfigure connector authentication and activate it
PATCH/organizations/{orgId}/connectors/registrations/{id}/deregisterDeregister (disable) a connector registration

Control Proposals

MethodPathOperation
GET/organizations/{orgId}/control-proposalsList this org's control proposals, newest first, optionally by status and origin.
GET/organizations/{orgId}/control-proposals/{id}Get one control proposal.
POST/organizations/{orgId}/control-proposals/generateGenerate a DRAFT control proposal from a natural-language request. Never applies anything — a human must approve, then apply.
POST/organizations/{orgId}/control-proposals/{id}/approveApprove
POST/organizations/{orgId}/control-proposals/{id}/rejectReject
POST/organizations/{orgId}/control-proposals/{id}/applyMaterialize an APPROVED proposal into a real governance control. Rejected with 409 unless status is APPROVED.

Cost Monitoring

MethodPathOperation
GET/organizations/{orgId}/cost-monitoring/usageGet usage stats
GET/organizations/{orgId}/cost-monitoring/creditsGet credits

Cost Recommendations

MethodPathOperation
GET/organizations/{orgId}/billing/recommendationsList active cost-optimisation recommendations
POST/organizations/{orgId}/billing/recommendations/{recId}/dismissDismiss a cost-optimisation recommendation

Cross-Tenant A2A (Federated)

MethodPathOperation
POST/a2a/cross-tenant/tasksSubmit a federated cross-tenant task

CrossBorder

MethodPathOperation
GET/organizations/{orgId}/ai-systems/{id}/cross-border-flowsCross-border status of each flow of an AI System's data flow
POST/organizations/{orgId}/ai-systems/{id}/cross-border-flows/evaluateStore the cross-border verdict for each flow of an AI System's data flow
GET/organizations/{orgId}/data-security/cross-border-summaryOrg-wide cross-border rollup by destination geography

Dashboard

MethodPathOperation
GET/organizations/{orgId}/dashboard/statsGet stats

Data Assets

MethodPathOperation
GET/organizations/{orgId}/data-assetsList the org's data asset inventory.
POST/organizations/{orgId}/data-assetsRegister a data asset in the org inventory.
GET/organizations/{orgId}/data-assets/by-ai-system/{aiSystemId}Data assets joined through ai_system_assets membership of the given AI System.
GET/organizations/{orgId}/data-assets/{id}Fetch a single data asset by id.
DELETE/organizations/{orgId}/data-assets/{id}Soft-delete a data asset from the inventory.
PATCH/organizations/{orgId}/data-assets/{id}Edit a data asset.
POST/organizations/{orgId}/data-assets/{id}/classifySet/update a data asset's sensitivity classification.

Data Subjects

MethodPathOperation
GET/organizations/{orgId}/data-subjects/eraseList data-subject erasure requests
POST/organizations/{orgId}/data-subjects/eraseInitiate a two-person GDPR Art-17 erasure (erases nothing yet)
POST/organizations/{orgId}/data-subjects/erase/{requestId}/confirmConfirm a pending erasure; the confirmer must differ from the initiator, unless the org has one eligible confirmer (new session, >= 24h after initiating)
POST/organizations/{orgId}/data-subjects/erase/{requestId}/cancelCancel a pending erasure (initiator only); erases nothing
GET/organizations/{orgId}/data-subjects/erase/{requestId}Status of one data-subject erasure request
POST/organizations/{orgId}/data-subjects/exportExport one data subject's records held by this organization (GDPR Art-15/20, JSON)

DID Documents

MethodPathOperation
GET/agents/{agentId}/did.jsonAgent DID document
GET/.well-known/did.jsonPlatform DID document

Discovery

MethodPathOperation
GET/organizations/{orgId}/discovered-entitiesList discovered (unregistered) entities
GET/organizations/{orgId}/discovered-entities/{id}Inspect a single discovered entity
POST/organizations/{orgId}/discovered-entities/{id}/claimClaim a discovered entity (promote to the registered flow)
POST/organizations/{orgId}/discovered-entities/{id}/ignoreIgnore a discovered entity (suppress it)
POST/organizations/{orgId}/discovered-entities/{id}/restoreRestore an ignored entity to the discovery inbox
POST/organizations/{orgId}/discovered-entities/{id}/adoptAdopt a discovered entity into the AI-asset graph
POST/organizations/{orgId}/discovered-entities/{id}/mergeMerge a discovered entity into another entity or an AI asset
POST/organizations/{orgId}/discovered-entities/{id}/associateAttach the sighting's AI asset to an AI System
POST/organizations/{orgId}/discovered-entities/{id}/mark-expectedFlag a sighting as known/sanctioned
POST/organizations/{orgId}/discovered-entities/{id}/assign-ownerAssign (or clear) the accountable owner of a sighting
POST/organizations/{orgId}/discovered-entities/{id}/investigateOpen an AI incident investigation for a sighting
GET/organizations/{orgId}/discovered-entities/{id}/suggestionsDeterministic dedup candidates for a sighting
GET/organizations/{orgId}/discovery/connectorsList discovery connectors
POST/organizations/{orgId}/discovery/connectorsRegister a discovery connector
GET/organizations/{orgId}/discovery/connectors/aws/role-policiesAWS discovery role IAM policies for this org
GET/organizations/{orgId}/discovery/connectors/typesDiscovery connector types this build can run
GET/organizations/{orgId}/discovery/connectors/{connectorId}Get one discovery connector
DELETE/organizations/{orgId}/discovery/connectors/{connectorId}Delete a discovery connector
PATCH/organizations/{orgId}/discovery/connectors/{connectorId}Update a discovery connector
POST/organizations/{orgId}/discovery/connectors/{connectorId}/runRun a discovery connector now
POST/organizations/{orgId}/discovery/connector-secretsStore a discovery connector secret
PUT/organizations/{orgId}/discovery/connector-secrets/{secretId}Rotate a discovery connector secret
DELETE/organizations/{orgId}/discovery/connector-secrets/{secretId}Delete a discovery connector secret

Domains

MethodPathOperation
GET/organizations/{orgId}/domainsList domains
GET/organizations/{orgId}/domains/verifiedList verified domains
POST/organizations/{orgId}/domains/verify/initInit verification
POST/organizations/{orgId}/domains/verify/checkCheck verification
GET/organizations/{orgId}/domains/{domain}/statusGet status
DELETE/organizations/{orgId}/domains/{domain}Remove domain
GET/organizations/{orgId}/domains/{domain}/is-verifiedIs verified

DSPM Connectors

MethodPathOperation
POST/organizations/{orgId}/dspm/{vendor}/test-connectionProbe a DSPM/governance vendor connection. Credentials are request-scoped only, never persisted.
POST/organizations/{orgId}/dspm/{vendor}/importImport a DSPM/governance vendor's catalog into the org's data_assets inventory.
GET/organizations/{orgId}/dspm/connectionsList the org's DSPM connections.
POST/organizations/{orgId}/dspm/connectionsStore a DSPM vendor connection (key sealed).
GET/organizations/{orgId}/dspm/connections/{connectionId}Fetch one DSPM connection.
DELETE/organizations/{orgId}/dspm/connections/{connectionId}Delete a DSPM connection and its sealed key.
PATCH/organizations/{orgId}/dspm/connections/{connectionId}Change the host and/or rotate the key.
POST/organizations/{orgId}/dspm/connections/{connectionId}/importImport the vendor's catalog using the stored connection.

Email

MethodPathOperation
GET/email/preferencesRead the authenticated user's email category preferences
PUT/email/preferencesToggle one email category for the authenticated user

Emergency

MethodPathOperation
POST/organizations/{orgId}/emergency/freezeEmergency freeze — kill switch for an org (or a selection)
POST/organizations/{orgId}/emergency/unfreezeLift an emergency freeze
GET/organizations/{orgId}/emergency/statusCurrent emergency-freeze state for the org
POST/organizations/{orgId}/emergency/previewPreview the blast radius of a freeze

EU AI Act Compliance

MethodPathOperation
POST/organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/assessAssess entity risk
POST/organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}/classifyClassify entity
GET/organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}Get entity classification
PATCH/organizations/{orgId}/compliance/eu-ai-act/entities/{entityType}/{entityId}Update entity compliance
POST/organizations/{orgId}/compliance/eu-ai-act/agents/{agentId}/assessAssess agent risk
GET/organizations/{orgId}/compliance/eu-ai-act/agents/{agentId}Get agent classification
PATCH/organizations/{orgId}/compliance/eu-ai-act/agents/{agentId}Update agent compliance
GET/organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparencyGet transparency
POST/organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparencyAssess transparency
PATCH/organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparencyUpdate transparency
POST/organizations/{orgId}/compliance/eu-ai-act/systems/{aiSystemId}/transparency/reviewReview transparency
GET/organizations/{orgId}/compliance/eu-ai-act/roleGet org ai act role
PATCH/organizations/{orgId}/compliance/eu-ai-act/roleSet org ai act role
GET/organizations/{orgId}/compliance/eu-ai-actList classifications
GET/organizations/{orgId}/compliance/eu-ai-act/summaryGet compliance summary
GET/organizations/{orgId}/compliance/eu-ai-act/reportGet compliance report
GET/organizations/{orgId}/compliance/eu-ai-act/friaFind all
POST/organizations/{orgId}/compliance/eu-ai-act/friaCreate
GET/organizations/{orgId}/compliance/eu-ai-act/fria/{id}Find one
PATCH/organizations/{orgId}/compliance/eu-ai-act/fria/{id}Update
GET/organizations/{orgId}/compliance/eu-ai-act/fria/{id}/exportExport assessment
POST/organizations/{orgId}/compliance/eu-ai-act/fria/{id}/submitSubmit
POST/organizations/{orgId}/compliance/eu-ai-act/fria/{id}/approveApprove
POST/organizations/{orgId}/compliance/eu-ai-act/fria/{id}/rejectReject
GET/organizations/{orgId}/compliance/eu-ai-act/technical-documentationFind all
POST/organizations/{orgId}/compliance/eu-ai-act/technical-documentationCreate
GET/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}Find one
PATCH/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/sections/{sectionKey}Update section
POST/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/versionsCreate new version
POST/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/approveApprove
GET/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/completenessCompleteness
GET/organizations/{orgId}/compliance/eu-ai-act/technical-documentation/{docId}/exportExport document
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-marketPost-market overview: plan, incidents, drift, performance, risk changes, complaints, corrective actions
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/planGet plan
PUT/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/planCreate or update the monitoring plan
DELETE/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/planDelete plan
POST/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/plan/reviewRecord a plan review; rolls nextReviewDueAt
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaintsList complaints
POST/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaintsCreate complaint
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id}Get complaint
DELETE/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id}Delete complaint
PATCH/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/complaints/{id}Update complaint
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actionsList corrective actions
POST/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actionsCreate corrective action
GET/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id}Get corrective action
DELETE/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id}Delete corrective action
PATCH/organizations/{orgId}/ai-systems/{aiSystemId}/post-market/corrective-actions/{id}Update a corrective action; DONE requires verification evidence
GET/organizations/{orgId}/ai-literacy/coverageMembers with and without a current AI-literacy record
GET/organizations/{orgId}/ai-literacy/recordsList
POST/organizations/{orgId}/ai-literacy/recordsCreate
GET/organizations/{orgId}/ai-literacy/records/{id}Get
DELETE/organizations/{orgId}/ai-literacy/records/{id}Remove
PATCH/organizations/{orgId}/ai-literacy/records/{id}Update

Eval Datasets

MethodPathOperation
GET/organizations/{orgId}/evaluations/datasetsList all EvalDatasets for the organization
POST/organizations/{orgId}/evaluations/datasetsCreate a new EvalDataset (golden regression suite)
GET/organizations/{orgId}/evaluations/datasets/{datasetId}Get a single EvalDataset by ID
DELETE/organizations/{orgId}/evaluations/datasets/{datasetId}Soft-delete an EvalDataset
GET/organizations/{orgId}/evaluations/datasets/{datasetId}/casesList cases in a dataset (paginated)
POST/organizations/{orgId}/evaluations/datasets/{datasetId}/casesAdd a test case to a dataset
DELETE/organizations/{orgId}/evaluations/datasets/{datasetId}/cases/{caseId}Remove a test case from a dataset
POST/organizations/{orgId}/evaluations/datasets/{datasetId}/sample-from-prodSample recent production agent tasks and import them as EvalCases into the dataset
GET/organizations/{orgId}/evaluations/datasets/{datasetId}/compareCompare two EvalRuns over this dataset: regressed / improved / unchanged cases

Eval Reviews

MethodPathOperation
GET/organizations/{orgId}/evaluations/reviewsList the caller's review assignments (paginated)
POST/organizations/{orgId}/evaluations/reviews/{reviewId}Submit a human or pairwise review verdict
POST/organizations/{orgId}/evaluations/outcomesReport an externally-observed business outcome

Evaluations

MethodPathOperation
GET/organizations/{orgId}/evaluationsList Evaluations for the organization (paginated)
POST/organizations/{orgId}/evaluationsCreate a new Evaluation definition
GET/organizations/{orgId}/evaluations/production-configsList production-eval sampling configs for the org, with spend-to-date, skipped-for-privacy count, and disabled-reason
POST/organizations/{orgId}/evaluations/production-configsCreate a production-eval sampling config
GET/organizations/{orgId}/evaluations/runs/{runId}Get an EvalRun by ID (includes evaluationId)
GET/organizations/{orgId}/evaluations/{evaluationId}Get a single Evaluation by ID
GET/organizations/{orgId}/evaluations/{evaluationId}/casesList test cases for an Evaluation (paginated)
POST/organizations/{orgId}/evaluations/{evaluationId}/casesAdd a test case to an Evaluation
GET/organizations/{orgId}/evaluations/{evaluationId}/runsList EvalRuns for an Evaluation (paginated)
POST/organizations/{orgId}/evaluations/{evaluationId}/runsTrigger a new EvalRun for an Evaluation
GET/organizations/{orgId}/evaluations/{evaluationId}/runs/{runId}/resultsGet paginated EvalResults for a specific EvalRun
GET/organizations/{orgId}/evaluations/{evaluationId}/runs/compareCompare two EvalRuns: pass-rate and mean-score deltas
DELETE/organizations/{orgId}/evaluations/production-configs/{configId}Delete a production-eval sampling config
PATCH/organizations/{orgId}/evaluations/production-configs/{configId}Update a production-eval sampling config

Executive Reports

MethodPathOperation
GET/organizations/{orgId}/executive-reportsGet report
GET/organizations/{orgId}/executive-reports/exportExport csv
POST/organizations/{orgId}/executive-reports/generateQueue an async executive report (returns id + status)
GET/organizations/{orgId}/executive-reports/reportsList generated executive reports (paginated)
GET/organizations/{orgId}/executive-reports/reports/{reportId}Poll executive-report generation status
GET/organizations/{orgId}/executive-reports/reports/{reportId}/pdfDownload the rendered executive-report PDF

Feature Flags

MethodPathOperation
GET/organizations/{orgId}/featuresGet features for organization

Federated identity administration

MethodPathOperation
GET/organizations/{orgId}/identityInspect configured trust, consent, active credential inventory and task revocation backlog
POST/organizations/{orgId}/identity/providersPin an external issuer and public verification keys
PATCH/organizations/{orgId}/identity/providers/{id}Rotate or disable issuer trust and revoke existing derived authority
POST/organizations/{orgId}/identity/bindingsBind one exact external subject to a tenant workload or user
DELETE/organizations/{orgId}/identity/bindings/{id}Disable a binding and revoke all derived credentials and active tasks
DELETE/organizations/{orgId}/identity/grants/{id}Revoke one grant, descendants, and active linked tasks
POST/organizations/{orgId}/identity/revocations/retryRetry durable task cancellation and return remaining cleanup backlog

Federated OAuth authority

MethodPathOperation
POST/oauth/token-exchangeExchange a pinned external JWT or down-exchange resource-bound authority (RFC 8693)
POST/identity/introspectValidate the presented API resource credential against live authority state

Financial

MethodPathOperation
GET/organizations/{orgId}/financial/positionGet unified financial position for an organization

Findings

MethodPathOperation
GET/organizations/{orgId}/findingsList findings
GET/organizations/{orgId}/findings/{id}Get one finding
POST/organizations/{orgId}/findings/{id}/triageMark a finding as triaged by a human reviewer
POST/organizations/{orgId}/findings/{id}/accept-as-riskAccept a finding as risk against an existing risk-register entry
POST/organizations/{orgId}/findings/{id}/false-positiveDismiss a finding as a false positive

Forensics

MethodPathOperation
POST/organizations/{orgId}/forensics/searchForensic search over `mcp_tool_calls`
GET/organizations/{orgId}/forensics/timestamp-skewPer-hour timestamp-skew report for `audit_logs`

Governance Badge

MethodPathOperation
GET/agents/{agentId}/governance-badgeSigned "Governed by Praesidia" trust-mark badge
GET/verify/{agentId}Public badge verification data

Governance Packs

MethodPathOperation
GET/organizations/{orgId}/governance-packsList available governance packs (with this org install state)
GET/organizations/{orgId}/governance-packs/installedList governance packs installed for this org
GET/organizations/{orgId}/governance-packs/{packId}Get a governance pack (with this org install state)
POST/organizations/{orgId}/governance-packs/{packId}/installInstall (or idempotently re-install) a governance pack
GET/organizations/{orgId}/governance-packs/{packId}/upgradePreview upgrading an installed governance pack (read-only diff)
POST/organizations/{orgId}/governance-packs/{packId}/upgradeUpgrade an installed governance pack to an explicit version

Governance Timeline

MethodPathOperation
GET/organizations/{orgId}/governance/timelineList recent governance events (gates, approvals, exports)
GET/organizations/{orgId}/governance/timeline/summary24h counts grouped by governance event name

Governance Versions

MethodPathOperation
GET/organizations/{orgId}/guardrails/{guardrailId}/versionsList the version history of a guardrail
GET/organizations/{orgId}/guardrails/{guardrailId}/versions/{version}Get one version of a guardrail
GET/organizations/{orgId}/policies/{policyId}/versionsList the version history of an agent policy
GET/organizations/{orgId}/policies/{policyId}/versions/{version}Get one version of an agent policy
GET/organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}/versionsList the version history of a tool policy rule
GET/organizations/{orgId}/agents/{agentId}/tool-policies/{policyId}/versions/{version}Get one version of a tool policy rule

Guardrail sample

MethodPathOperation
POST/organizations/{orgId}/guardrails/sample-evaluationEvaluate two fixed local rule samples and persist an owned audit record
GET/organizations/{orgId}/guardrails/sample-evaluation/latestRead your own recorded local sample result in this organization

Guardrails

MethodPathOperation
GET/organizations/{orgId}/guardrailsGet all guardrails for the organization
POST/organizations/{orgId}/guardrailsCreate a new guardrail
GET/organizations/{orgId}/guardrails/templatesGet available guardrail templates
GET/organizations/{orgId}/guardrails/default-templatesGet recommended default guardrail templates
POST/organizations/{orgId}/guardrails/apply-defaultsApply recommended default guardrails
GET/organizations/{orgId}/guardrails/statsGet guardrail statistics
GET/organizations/{orgId}/guardrails/healthGet health
POST/organizations/{orgId}/guardrails/validateValidate content against guardrails
GET/organizations/{orgId}/guardrails/logsGet logs
GET/organizations/{orgId}/guardrails/defaultsGet default guardrails applied by Praesidia
GET/organizations/{orgId}/guardrails/{guardrailId}Find one
DELETE/organizations/{orgId}/guardrails/{guardrailId}Delete a guardrail
PATCH/organizations/{orgId}/guardrails/{guardrailId}Update
POST/organizations/{orgId}/guardrails/presets/{preset}/applyApply an industry preset pack
PATCH/organizations/{orgId}/guardrails/{guardrailId}/custom-modelSet custom ML model URL for a guardrail
POST/organizations/{orgId}/guardrails/{guardrailId}/rollout/rollbackRoll a guardrail's rollout stage back to OBSERVE
POST/organizations/{orgId}/guardrails/{guardrailId}/rollout/advanceAdvance a guardrail's rollout to the next stage
PUT/organizations/{orgId}/guardrails/{guardrailId}/rollout/auto-rollbackSet a guardrail's auto-rollback opt-in

Health

MethodPathOperation
GET/residency-regionsResidency regions served by this deployment

HIPAA

MethodPathOperation
POST/organizations/{orgId}/hipaa/baa/signRecord the organization's attestation of a BAA it holds with a third party (Praesidia is not a party)
GET/organizations/{orgId}/hipaa/baaGet the organization's recorded attestation of a BAA it holds with a third party (Praesidia is not a party)
GET/organizations/{orgId}/hipaa/breachesList breach events for the organization
POST/organizations/{orgId}/hipaa/breachesReport a new HIPAA breach event (starts the 60-day HHS notification clock)
PUT/organizations/{orgId}/hipaa/breaches/{id}Update breach event status or notes
GET/organizations/{orgId}/hipaa/audit-exportExport PHI audit logs for the organization (HIPAA 6-year retention window). Requires signed BAA.

Incidents

MethodPathOperation
GET/organizations/{orgId}/incidents/{incidentId}/regressionList an incident's regression cases, proposed, accepted and rejected, across its regression sets (paginated)
POST/organizations/{orgId}/incidents/{incidentId}/regressionTurn an incident into proposed regression cases (original + deterministic variants)
POST/organizations/{orgId}/incidents/{incidentId}/regression/cases/{caseId}/acceptAccept a proposed regression case so it runs and gates releases (human actor required)
POST/organizations/{orgId}/incidents/{incidentId}/regression/cases/{caseId}/rejectReject a proposed regression case with an audited reason; it never runs or gates (human actor required)
GET/organizations/{orgId}/regression-casesList the organization's incident regression cases, newest first, filterable by status and incident (paginated)
GET/organizations/{orgId}/incidentsList incidents (paginated)
POST/organizations/{orgId}/incidentsCreate an AI incident
GET/organizations/{orgId}/incidents/by-ai-system/{aiSystemId}List incidents for one AI System (paginated)
GET/organizations/{orgId}/incidents/signalsList incident signals sharing one correlation key (paginated)
GET/organizations/{orgId}/incidents/{incidentId}/signalsList an incident's correlated signals (paginated)
POST/organizations/{orgId}/incidents/{incidentId}/signals/{signalId}/detachDetach a correlated signal from this incident (false positive). 404 if the signal does not exist, is another org’s, or is not currently attached to this incident.
GET/organizations/{orgId}/incidents/{incidentId}/timelineOrdered timeline of an incident (derived, not stored)
GET/organizations/{orgId}/incidents/{incidentId}Get an incident by ID
PUT/organizations/{orgId}/incidents/{incidentId}Update an incident (including status transitions)
POST/organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/startStart one of the nine incident response stages
POST/organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/completeComplete an incident response stage. root_cause writes the incident's root cause; generate_evidence generates a signed evidence bundle and links it as the step's linkedRecordId.
POST/organizations/{orgId}/incidents/{incidentId}/response-steps/{stage}/skipSkip an incident response stage, recording why
GET/organizations/{orgId}/incidents/{incidentId}/evidence-bundles/{bundleId}Get one of an incident's signed evidence bundles and verify it. 404 unless the bundle belongs to this incident and organization.
POST/organizations/{orgId}/incidents/{incidentId}/reviewRecord the review of the impact assessment. The reviewer is the authenticated user and may not be the incident reporter (409).
POST/organizations/{orgId}/incidents/{incidentId}/regulator-reportGenerate the regulator-ready report (deterministic serialization of stored fields + derived timeline, SHA-256 hashed). 409 until an impact assessment is recorded AND reviewed.
POST/organizations/{orgId}/incidents/{incidentId}/generate-forensic-reportGenerate a tamper-evident forensic / post-mortem report (JSON) for the incident. Assembles audit trail summary, trust score history, supervision events, and posture attestation for verified affected agents/tasks. Includes SHA-256 report hash for tamper-evidence.
GET/organizations/{orgId}/incidents/{incidentId}/proposalsControls this incident suggests (new policy, changed control, new eval, monitoring rule), derived from its signals and root cause
POST/organizations/{orgId}/incidents/{incidentId}/proposals/{proposalId}/acceptAccept a proposal: create its record in the owning module and complete the update_control response step linked to it
POST/organizations/{orgId}/incidents/{incidentId}/proposals/{proposalId}/dismissDismiss a proposal (recorded on the audit trail)

Integrations

MethodPathOperation
GET/organizations/{orgId}/integrations/api-keysList api keys
POST/organizations/{orgId}/integrations/api-keysCreate api key
POST/organizations/{orgId}/integrations/api-keys/{id}/rotateRotate api key
GET/organizations/{orgId}/integrations/api-keys/{id}/metricsGet api key metrics
DELETE/organizations/{orgId}/integrations/api-keys/{id}Revoke api key
GET/organizations/{orgId}/integrations/webhooksList webhooks
POST/organizations/{orgId}/integrations/webhooksCreate webhook
DELETE/organizations/{orgId}/integrations/webhooks/{id}Delete webhook
PATCH/organizations/{orgId}/integrations/webhooks/{id}Update webhook
POST/organizations/{orgId}/integrations/webhooks/{id}/testTest webhook
POST/organizations/{orgId}/integrations/webhooks/{id}/rotate-secretRotate webhook secret
GET/organizations/{orgId}/integrations/siemGet siem config
POST/organizations/{orgId}/integrations/siemUpdate siem config
DELETE/organizations/{orgId}/integrations/siemDelete siem config
POST/organizations/{orgId}/integrations/siem/testTest siem config
GET/organizations/{orgId}/integrations/scm/github/connectionsList GitHub connections
POST/organizations/{orgId}/integrations/scm/github/connectionsConnect GitHub. The response carries the webhook secret once; the token is never returned
GET/organizations/{orgId}/integrations/scm/github/statusWhether GitHub App mode is configured
GET/organizations/{orgId}/integrations/scm/github/connections/{connectionId}Get a GitHub connection
DELETE/organizations/{orgId}/integrations/scm/github/connections/{connectionId}Disconnect GitHub: destroys the stored credentials and removes the scanned repositories
PATCH/organizations/{orgId}/integrations/scm/github/connections/{connectionId}Enable/disable, replace the token, or rotate the webhook secret (returned once)
GET/organizations/{orgId}/integrations/scm/github/connections/{connectionId}/repositoriesList the repositories a discovery scan found
POST/organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/adoptAdopt a discovered repository as a REPOSITORY asset, optionally attaching it to an AI System
POST/organizations/{orgId}/integrations/scm/github/connections/{connectionId}/discovery-scanScan the connection’s repositories for agent/MCP/LLM configuration and send findings to the discovery inbox
POST/organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/commit-statusPost a recorded quality-gate verdict to GitHub as a commit status
POST/organizations/{orgId}/integrations/scm/github/repositories/{repositoryId}/aibomAttach a CI-built CycloneDX AIBOM to the repository's asset
GET/organizations/{orgId}/ai-systems/{aiSystemId}/scm/aibom-artifactsAIBOMs CI uploaded for the AI System's assets
GET/organizations/{orgId}/ai-systems/{aiSystemId}/scm/release-annotationsReleases and tags recorded for the AI System, newest first
GET/organizations/{orgId}/integrations/scm/gitlab/connectionsList GitLab connections
POST/organizations/{orgId}/integrations/scm/gitlab/connectionsConnect GitLab (gitlab.com or self-hosted). The response carries the webhook secret token once; the API token is never returned
GET/organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}Get a GitLab connection
DELETE/organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}Disconnect GitLab: destroys the stored credentials and removes the scanned repositories
PATCH/organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}Enable/disable, replace the token, or rotate the webhook secret token (returned once)
GET/organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}/repositoriesList the GitLab projects a discovery scan found
POST/organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/adoptAdopt a discovered GitLab project as a REPOSITORY asset, optionally attaching it to an AI System
POST/organizations/{orgId}/integrations/scm/gitlab/connections/{connectionId}/discovery-scanScan the connection’s GitLab projects for agent/MCP/LLM configuration and send findings to the discovery inbox
POST/organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/commit-statusPost a recorded quality-gate verdict to GitLab as an external commit status
POST/organizations/{orgId}/integrations/scm/gitlab/repositories/{repositoryId}/aibomAttach a CI-built CycloneDX AIBOM to the GitLab project's asset
GET/organizations/{orgId}/integrations/servicenow/connectionsList ServiceNow connections (credentials omitted)
POST/organizations/{orgId}/integrations/servicenow/connectionsConnect a ServiceNow instance (starts disabled until tested)
POST/organizations/{orgId}/integrations/servicenow/connections/instance-proofsIssue the proof a sovereign-cloud instance (*.servicenowservices.com) serves before it can be connected
GET/organizations/{orgId}/integrations/servicenow/connections/{connectionId}Get a ServiceNow connection (credentials omitted)
DELETE/organizations/{orgId}/integrations/servicenow/connections/{connectionId}Remove a ServiceNow connection: destroys its credential, releases its record links, stops its webhook
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/credentialsRotate the stored credential; disables the connection until test passes again
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/testProbe the stored credential; enables the connection on success
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/disableDisable a ServiceNow connection
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/incidents/{incidentId}/pushCreate the ServiceNow incident for an AI incident, or update the linked one
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/approvals/{approvalId}/raiseRaise a pending approval request as a ServiceNow sysapproval_approver record
POST/organizations/{orgId}/integrations/servicenow/connections/{connectionId}/assets/{assetId}/cmdb-linkLink an AI asset to its ServiceNow cmdb_ci record
GET/organizations/{orgId}/integrations/chat-connectionsList chat connections (webhook URL omitted)
POST/organizations/{orgId}/integrations/chat-connectionsConnect a Slack or Teams incoming webhook, or a PagerDuty Events API v2 routing key
GET/organizations/{orgId}/integrations/chat-connections/{id}Get a chat connection (webhook URL omitted)
DELETE/organizations/{orgId}/integrations/chat-connections/{id}Remove a chat connection and destroy its stored webhook URL
PATCH/organizations/{orgId}/integrations/chat-connections/{id}Update a chat connection
POST/organizations/{orgId}/integrations/chat-connections/{id}/testSend one test message; records lastDeliveryAt / lastError on the connection
GET/organizations/{orgId}/integrations/chat-connections/slack/oauthWhether the Praesidia Slack app is configured
POST/organizations/{orgId}/integrations/chat-connections/slack/oauth/installStart an "Add to Slack" install
POST/organizations/{orgId}/integrations/chat-connections/slack/oauth/install/callbackComplete an "Add to Slack" install (creates or updates the connection)
POST/organizations/{orgId}/integrations/chat-connections/slack/oauth/linkStart linking your Slack account (Sign in with Slack) to approve from Slack
POST/organizations/{orgId}/integrations/chat-connections/slack/oauth/link/callbackComplete linking your Slack account
GET/organizations/{orgId}/integrations/chat-connections/slack/links/meYour linked Slack accounts in this organization
DELETE/organizations/{orgId}/integrations/chat-connections/slack/links/meUnlink your Slack accounts in this organization
GET/organizations/{orgId}/integrations/chat-connections/slack/linksEvery member's linked Slack accounts in this organization
DELETE/organizations/{orgId}/integrations/chat-connections/slack/links/{linkId}Revoke a member's Slack account link

Intelligence

MethodPathOperation
POST/organizations/{orgId}/intelligence/queryAnswer a governance question over this organization

Intent Labels

MethodPathOperation
GET/organizations/{orgId}/intent-labelsList captured intent labels (org-scoped)
POST/organizations/{orgId}/intent-labelsAttach an FP/FN/correct label to an intent decision
GET/organizations/{orgId}/intent-labels/aggregateFP/FN aggregation for the org (overall + per source)
GET/organizations/{orgId}/intent-labels/spot-check-candidatesSpot check candidates
POST/organizations/{orgId}/intent-labels/promotePromote labels into an eval dataset (consent-gated, anonymized)

Intent Rules

MethodPathOperation
GET/organizations/{orgId}/intent-rulesList intent-detection rules
POST/organizations/{orgId}/intent-rulesCreate an intent-detection rule
POST/organizations/{orgId}/intent-rules/apply-defaultsApply the starter-pack intent rules for this org
GET/organizations/{orgId}/intent-rules/{ruleId}Get an intent-detection rule
DELETE/organizations/{orgId}/intent-rules/{ruleId}Delete an intent-detection rule
PATCH/organizations/{orgId}/intent-rules/{ruleId}Update an intent-detection rule

Intent Sequence Rules

MethodPathOperation
GET/organizations/{orgId}/intent/sequence-rulesList sequence rules
POST/organizations/{orgId}/intent/sequence-rulesCreate a sequence rule
POST/organizations/{orgId}/intent/sequence-rules/validateValidate a sequence rule (DSL text or structured fields) without persisting it
GET/organizations/{orgId}/intent/sequence-rules/{id}Get a sequence rule
DELETE/organizations/{orgId}/intent/sequence-rules/{id}Delete a sequence rule
PATCH/organizations/{orgId}/intent/sequence-rules/{id}Update a sequence rule

Interaction Decisions

MethodPathOperation
POST/organizations/{orgId}/interaction-decisionsDecide whether an agent may perform an SDK-hooked interaction
POST/organizations/{orgId}/interaction-decisions/outcomeReport the result of an approved SDK interaction, once

Issue Trackers

MethodPathOperation
GET/organizations/{orgId}/integrations/issue-trackersList all issue-tracker connections for an organization
POST/organizations/{orgId}/integrations/issue-trackersCreate a new issue-tracker connection
GET/organizations/{orgId}/integrations/issue-trackers/{connId}Get one issue-tracker connection
DELETE/organizations/{orgId}/integrations/issue-trackers/{connId}Delete (soft-delete) an issue-tracker connection
PATCH/organizations/{orgId}/integrations/issue-trackers/{connId}Update an issue-tracker connection
POST/organizations/{orgId}/integrations/issue-trackers/{connId}/testTest connectivity for an issue-tracker connection
POST/organizations/{orgId}/integrations/issue-trackers/{connId}/create-issueManually create an issue in the connected tracker

Lifecycle Hooks

MethodPathOperation
GET/organizations/{orgId}/lifecycle/hooksList lifecycle hooks for the organization
POST/organizations/{orgId}/lifecycle/hooksCreate a new lifecycle hook
DELETE/organizations/{orgId}/lifecycle/hooks/{hookId}Delete a lifecycle hook
PATCH/organizations/{orgId}/lifecycle/hooks/{hookId}Update a lifecycle hook
GET/organizations/{orgId}/lifecycle/historyList lifecycle event history for the organization
POST/organizations/{orgId}/lifecycle/inbound/{hookId}Receive an inbound lifecycle event (HMAC-signed, no JWT required)

LLM Configurations

MethodPathOperation
GET/organizations/{orgId}/llm-configsList LLM configurations (paginated)
POST/organizations/{orgId}/llm-configsCreate an LLM configuration
GET/organizations/{orgId}/llm-configs/providersList LLM providers and whether the gateway can route each
GET/organizations/{orgId}/llm-configs/{configId}Get a single LLM configuration
DELETE/organizations/{orgId}/llm-configs/{configId}Delete an LLM configuration
PATCH/organizations/{orgId}/llm-configs/{configId}Update an LLM configuration
GET/organizations/{orgId}/llm-configs/{configId}/metricsGet usage metrics for an LLM configuration
PUT/organizations/{orgId}/llm-configs/{configId}/api-keyStore an encrypted BYOK API key for this LLM config
DELETE/organizations/{orgId}/llm-configs/{configId}/api-keyRemove the BYOK API key from this LLM config

Marketplace

MethodPathOperation
GET/marketplace/listingsBrowse the public marketplace catalogue (approved listings only)
GET/organizations/{orgId}/marketplace/publisherGet this organisation's publisher profile
POST/organizations/{orgId}/marketplace/publisherRegister as a publisher for this organisation
GET/organizations/{orgId}/marketplace/listingsList this organisation's own marketplace listings (all statuses)
POST/organizations/{orgId}/marketplace/listingsCreate a marketplace listing (starts in draft status)
PUT/organizations/{orgId}/marketplace/listings/{id}Update a draft or rejected listing
POST/organizations/{orgId}/marketplace/listings/{id}/submitSubmit a listing for certification review
POST/organizations/{orgId}/marketplace/listings/{id}/installInstall an approved marketplace listing into this organisation
GET/organizations/{orgId}/marketplace/earningsList this publisher's revenue-share earnings
POST/organizations/{orgId}/marketplace/listings/{id}/purchaseBuy a one-time marketplace listing: charges the listing's price to the org's default payment method
GET/organizations/{orgId}/marketplace/tasksList the organization's posted marketplace tasks
POST/organizations/{orgId}/marketplace/tasksPost a marketplace task and hold its budget
POST/organizations/{orgId}/marketplace/tasks/{id}/cancelCancel an open task and refund its escrow
POST/organizations/{orgId}/marketplace/tasks/{id}/acceptAccept an open marketplace task
POST/organizations/{orgId}/marketplace/tasks/{id}/submitSubmit completed marketplace work
POST/organizations/{orgId}/marketplace/tasks/{id}/confirmConfirm work and release marketplace escrow
POST/organizations/{orgId}/marketplace/tasks/{id}/disputeOpen a marketplace task dispute
POST/organizations/{orgId}/marketplace/tasks/{id}/rateRate a confirmed marketplace task
PUT/organizations/{orgId}/marketplace/profiles/{agentId}Create or update an owned agent's hire profile
GET/marketplace/tasksBrowse public open marketplace tasks
GET/marketplace/agentsDiscover public agents available for hire

MCP inventory

MethodPathOperation
GET/organizations/{orgId}/mcp-servers/{serverId}/inventoryInspect live observations, approved baseline and tool-policy exposure
POST/organizations/{orgId}/mcp-servers/{serverId}/inventory/refreshDiscover current schemas without approving them
POST/organizations/{orgId}/mcp-servers/{serverId}/inventory/reviewApprove the exact recently observed fingerprint and revision
POST/organizations/{orgId}/mcp-servers/{serverId}/inventory/dependenciesImport declared CycloneDX dependencies; tools and privileges remain unapproved

MCP Registry

MethodPathOperation
POST/organizations/{orgId}/mcp-registry/installInstall a marketplace listing for this org
GET/organizations/{orgId}/mcp-registry/install-policyThe org's install-time verification policy
PUT/organizations/{orgId}/mcp-registry/install-policyReplace the org's install-time verification policy
GET/organizations/{orgId}/mcp-registry/installationsList all installations for the org
PATCH/organizations/{orgId}/mcp-registry/installations/{installationId}/deactivateDeactivate an installation
GET/mcp-registryList public MCP server marketplace catalogue
GET/mcp-registry/{id}Get a catalogue listing with its verification
GET/mcp-registry/{id}/versionsList versions for a catalogue listing

MCP Server Discovery

MethodPathOperation
GET/mcp-servers/discoverList public MCP servers
GET/mcp-servers/discover/{id}Get a public MCP server by ID
PATCH/organizations/{orgId}/mcp-servers/{id}/publishPublish an MCP server to public discovery
PATCH/organizations/{orgId}/mcp-servers/{id}/unpublishUnpublish an MCP server from public discovery
POST/organizations/{orgId}/mcp-servers/{serverId}/rateRate a public MCP server
GET/organizations/{orgId}/mcp-servers/{serverId}/rating-eligibilityCheck whether the current user can rate a public MCP server

MCP Servers

MethodPathOperation
GET/organizations/{orgId}/mcp-serversFind all
POST/organizations/{orgId}/mcp-serversCreate
GET/organizations/{orgId}/mcp-servers/statsGet stats
GET/organizations/{orgId}/mcp-servers/{id}Find one
DELETE/organizations/{orgId}/mcp-servers/{id}Remove
PATCH/organizations/{orgId}/mcp-servers/{id}Update
POST/organizations/{orgId}/mcp-servers/{id}/health-checkHealth check
PATCH/organizations/{orgId}/mcp-servers/{id}/statusUpdate status
POST/organizations/{orgId}/mcp-servers/{id}/connectConnect
DELETE/organizations/{orgId}/mcp-servers/{id}/connectDisconnect
GET/organizations/{orgId}/mcp-servers/{id}/toolsList tools
POST/organizations/{orgId}/mcp-servers/{id}/tools/{toolName}/callCall tool
GET/organizations/{orgId}/mcp-servers/{id}/resourcesList resources
POST/organizations/{orgId}/mcp-servers/{id}/resources/readRead resource
DELETE/organizations/{orgId}/mcp-servers/{id}/cacheInvalidate cache
POST/organizations/{orgId}/mcp-servers/{id}/discoverDiscover capabilities
POST/organizations/{orgId}/mcp-servers/discover-urlsDiscover servers
GET/organizations/{orgId}/mcp-servers/client/statsGet client stats
PATCH/organizations/{orgId}/mcp-servers/{id}/tool-rate-limitsUpdate tool rate limits
GET/organizations/{orgId}/mcp-servers/{id}/tool-analyticsGet tool analytics

Measured Governance Controls

MethodPathOperation
GET/organizations/{orgId}/governance-controlsInspect reviewed control definitions and measured connected-path outcomes
POST/organizations/{orgId}/governance-controlsCreate
GET/organizations/{orgId}/governance-controls/catalogList scoped control setup choices (at most 500 per category)
GET/organizations/{orgId}/governance-controls/{id}Get
PATCH/organizations/{orgId}/governance-controls/{id}Update
POST/organizations/{orgId}/governance-controls/{id}/reviewAssigned owner reviews the exact fixture, current path configuration, and next review deadline
GET/organizations/{orgId}/governance-controls/{id}/runsHistory
POST/organizations/{orgId}/governance-controls/{id}/runsRun a reviewed fixture on the actual connected task path
POST/organizations/{orgId}/governance-controls/{id}/runs/{runId}/refreshRefresh

Metrics Export

MethodPathOperation
GET/org-metricsOrg-scoped Prometheus metrics scrape endpoint

MFA

MethodPathOperation
GET/mfa/statusGet status
POST/mfa/setupSetup
POST/mfa/setup/confirmConfirm setup
POST/mfa/enroll/setupEnroll setup
POST/mfa/enroll/confirmEnroll confirm
DELETE/mfa/disableDisable
POST/mfa/backup-codes/regenerateRegenerate backup codes

Model Routing

MethodPathOperation
GET/organizations/{orgId}/model-routing/policiesFind all
POST/organizations/{orgId}/model-routing/policiesCreate
GET/organizations/{orgId}/model-routing/policies/{id}Find one
PUT/organizations/{orgId}/model-routing/policies/{id}Update
DELETE/organizations/{orgId}/model-routing/policies/{id}Remove
GET/organizations/{orgId}/llm-providers/healthGet health
GET/organizations/{orgId}/model-routing/decisionsFind recent

Notifications

MethodPathOperation
GET/notificationsFind all
GET/notifications/unread-countGet unread count
POST/notifications/{id}/readMark as read
POST/notifications/read-allMark all as read
POST/notifications/read-manyMark many as read
DELETE/notifications/{id}Delete
GET/notifications/push/vapid-public-keyGet vapid public key
POST/notifications/push/subscribeSubscribe push
DELETE/notifications/push/subscribeUnsubscribe push

OAuth

MethodPathOperation
POST/oauth/tokenIssue an OAuth access token for a registered authorization flow
GET/.well-known/jwks.jsonJwks
GET/.well-known/oauth-authorization-serverRFC 8414 OAuth authorization-server metadata
POST/oauth/introspectIntrospect
POST/oauth/revokeRevoke

OAuth browser authorization

MethodPathOperation
GET/oauth/authorizeBegin registered-client authorization code and S256 consent
GET/oauth/authorization-requests/{request}Review this registered client request and your allowed identity bindings
POST/oauth/authorization-requests/{request}/approveRecord explicit user consent and return a registered redirect with a single-use code
POST/oauth/authorization-requests/{request}/denyDeny this request and preserve OAuth state on the registered redirect

OAuth browser client registration

MethodPathOperation
GET/organizations/{orgId}/oauth/browser-clientsList the 100 most recent browser client registrations in this workspace
POST/organizations/{orgId}/oauth/browser-clientsRegister
DELETE/organizations/{orgId}/oauth/browser-clients/{clientId}Disable

OAuth Registration (RFC 7591)

MethodPathOperation
POST/oauth/registerRFC 7591 — Register a new agent (requires IAT)
GET/oauth/register/{clientId}RFC 7591 — Read registration metadata
PUT/oauth/register/{clientId}RFC 7591 — Update registration metadata
DELETE/oauth/register/{clientId}RFC 7591 — Deregister an agent
GET/organizations/{orgId}/oauth/registration-tokensList Initial Access Tokens
POST/organizations/{orgId}/oauth/registration-tokensCreate an Initial Access Token for RFC 7591 registration
DELETE/organizations/{orgId}/oauth/registration-tokens/{tokenId}Revoke an Initial Access Token

Observed Agents

MethodPathOperation
GET/organizations/{orgId}/observed-agentsList OBSERVED agents (telemetry-materialised, ungoverned)
POST/organizations/{orgId}/observed-agents/{id}/adoptAdopt an observed agent (promote OBSERVED → MANAGED)

Organizations

MethodPathOperation
GET/organizationsFind all
POST/organizationsCreate
GET/organizations/{orgId}Find one
DELETE/organizations/{orgId}Remove
PATCH/organizations/{orgId}Update
GET/organizations/{orgId}/exportExport organization
GET/organizations/{orgId}/legal-acceptancesList legal acceptances
POST/organizations/{orgId}/legal-acceptancesAccept dpa
POST/organizations/{orgId}/inviteInvite user
POST/organizations/accept-inviteAccept invite
GET/organizations/invites/by-token/{token}Get invite by token
GET/organizations/{orgId}/invitesGet pending invites
POST/organizations/{orgId}/invites/{inviteId}/resendResend invite
DELETE/organizations/invites/{inviteId}Cancel invite
POST/organizations/{orgId}/transfer-ownershipTransfer ownership
PATCH/organizations/{orgId}/members/{userId}/roleUpdate member role
DELETE/organizations/{orgId}/members/{userId}Remove member
POST/organizations/{orgId}/leaveLeave
GET/organizations/{orgId}/byokGet config
PUT/organizations/{orgId}/byokSet config
DELETE/organizations/{orgId}/byokRevoke config
GET/organizations/{orgId}/governance-modeGet this organization's governance mode
POST/organizations/{orgId}/governance-mode/enforceOpt this organization into governance `enforce` (tighten only)
POST/organizations/{orgId}/data-exportsStart a full organization data export
GET/organizations/{orgId}/data-exports/{id}Status of a data export; signed download links when done
GET/organization-data-exports/downloadDownload one file of a data export (signed link)
GET/organizations/{orgId}/notices/activePlatform notices active for this organization

Policy Simulation

MethodPathOperation
POST/organizations/{orgId}/policy-simulationsSimulate a draft or saved policy against historical traffic
GET/organizations/{orgId}/policy-simulations/{id}Get a simulation run — status and summary
GET/organizations/{orgId}/policy-simulations/{id}/findingsList a simulation run's per-event findings

Prompt Versions

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/prompt-versionsList
POST/organizations/{orgId}/agents/{agentId}/prompt-versionsCreate
GET/organizations/{orgId}/agents/{agentId}/prompt-versions/compareCompare
PUT/organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/activateActivate
PUT/organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/trafficSet traffic
PUT/organizations/{orgId}/agents/{agentId}/prompt-versions/ab-splitSet ab split
POST/organizations/{orgId}/agents/{agentId}/prompt-versions/{id}/promotePromote a prompt version (CI/CD gate)

Protected Actions

MethodPathOperation
GET/organizations/{orgId}/protected-actionsList protected actions for the organization
GET/organizations/{orgId}/protected-actions/capture-scopeGet the capture-scope registry — the declared denominator for any "% of actions captured" claim
GET/organizations/{orgId}/protected-actions/coverage-summaryExact org-scoped counts per D7 closure value plus open-phase counts — the aggregate counterpart to the list route
GET/organizations/{orgId}/protected-actions/coverageInteraction type coverage
GET/organizations/{orgId}/protected-actions/{actionId}Get one protected action (full projection row)
GET/organizations/{orgId}/protected-actions/{actionId}/eventsGet the full ordered evidence stream for one protected action, including signature bytes for independent hash-chain verification

Protected HTTP Execution

MethodPathOperation
POST/organizations/{orgId}/protected-actions/http/prepareCreate or recover an exact-request durable approval checkpoint
GET/organizations/{orgId}/protected-actions/http/checkpoints/{approvalId}Read an owned checkpoint and its recorded outcome after restart
POST/organizations/{orgId}/protected-actions/http/resumeConsume a signed human approval and dispatch the exact approved HTTP request once
POST/organizations/{orgId}/protected-actions/http/checkpoints/{approvalId}/revokeRevoke an owned pending or approved checkpoint before dispatch consumption
POST/organizations/{orgId}/protected-actions/http/acknowledgeRecord that the authenticated requester observed the committed result

PublicAgents

MethodPathOperation
GET/agents/publicFind public agents
GET/agents/public/{agentId}Find one
GET/agents/{agentId}/trustGet agent trust
POST/agents/{agentId}/cloneClone an agent

Red Team

MethodPathOperation
GET/organizations/{orgId}/redteam/opt-inGet the org-level red-team opt-in (master switch)
PUT/organizations/{orgId}/redteam/opt-inEnable/disable the red-team module for this org (default OFF)
GET/organizations/{orgId}/redteam/target-opt-insList per-target red-team opt-ins for the org
PUT/organizations/{orgId}/redteam/target-opt-insExplicitly opt a single owned target in/out (required before any probe)
GET/organizations/{orgId}/redteam/packsList the packs a campaign can select: built-in packs and this org's installed listing packs
GET/organizations/{orgId}/redteam/campaignsList red-team campaigns for the org
POST/organizations/{orgId}/redteam/campaignsCreate a red-team campaign against an owned target
GET/organizations/{orgId}/redteam/campaigns/{campaignId}Get a single red-team campaign
PATCH/organizations/{orgId}/redteam/campaigns/{campaignId}Update a campaign schedule: enable/disable (kill switch), cron, execution mode
POST/organizations/{orgId}/redteam/campaigns/{campaignId}/runStart an on-demand red-team run (opt-in + scope-guard enforced server-side)
GET/organizations/{orgId}/redteam/runsList red-team runs for the org
GET/organizations/{orgId}/redteam/runs/{runId}Get a single red-team run (status + counts)
GET/organizations/{orgId}/redteam/runs/{runId}/findingsList findings for a run (paginated, filterable)
GET/organizations/{orgId}/redteam/runs/{runId}/reportTamper-evident red-team findings report (SHA-256) for a run

Regulatory Graph

MethodPathOperation
GET/organizations/{orgId}/regulatory-graph/catalog/jurisdictionsList catalog jurisdictions
GET/organizations/{orgId}/regulatory-graph/catalog/regulationsList catalog regulations
GET/organizations/{orgId}/regulatory-graph/catalog/articlesList catalog articles
GET/organizations/{orgId}/regulatory-graph/catalog/obligationsList catalog obligations
GET/organizations/{orgId}/regulatory-graph/traverseTraverse the regulatory graph (Obligation↔Control↔Policy↔Evidence↔AI System) from an anchor node. Depth is clamped, never rejected; an oversized result fails closed with 413 rather than truncating.
GET/organizations/{orgId}/ai-systems/{id}/obligationsObligations reachable from an AI System (direct link, depth 1, or evidence-mediated, depth 2).
GET/organizations/{orgId}/obligations/{id}/ai-systemsAI Systems reachable from an Obligation (direct link, depth 1, or evidence-mediated, depth 2).
POST/organizations/{orgId}/regulatory-graph/impactCompute the impact of a regulation change on one obligation: every affected AI system/control/policy (reusing the same traversal as `GET .../traverse`, no second graph walk), which affected systems are missing fresh evidence, and which downstream review artefacts (risk classification, technical documentation, transparency assessment, FRIA, DPIA) are required.
GET/organizations/{orgId}/regulatory-graph/impact-reportsList this org's stored change-impact reports, newest first, optionally for one obligation.
GET/organizations/{orgId}/regulatory-graph/impact-reports/{id}Get one stored change-impact report.
POST/organizations/{orgId}/regulatory-graph/impact/{reportId}/remediateTurn a stored change-impact report into DRAFT control proposals (origin REGULATORY_REMEDIATION): controls/policies to review, the Annex IV section to revise and the evaluations to re-run, all read from the graph. Nothing is applied — a human approves then applies via the control-proposals endpoints. Idempotent per report: while a non-REJECTED proposal exists for it, that proposal is returned.
POST/organizations/{orgId}/regulatory-graph/importsImport this organization’s own regulatory content (jurisdiction → regulation → articles → obligations) in the curated seed-fixture shape. Rows are origin CUSTOMER and visible to this organization only; curated content is never modified. Idempotent: an identical re-import creates nothing. OWNER only.
GET/organizations/{orgId}/regulatory-graph/obligation-controlsList obligation controls
POST/organizations/{orgId}/regulatory-graph/obligation-controlsCreate obligation control
GET/organizations/{orgId}/regulatory-graph/obligation-controls/{id}Get obligation control
DELETE/organizations/{orgId}/regulatory-graph/obligation-controls/{id}Delete obligation control
GET/organizations/{orgId}/regulatory-graph/control-policiesList control policies
POST/organizations/{orgId}/regulatory-graph/control-policiesCreate control policy
GET/organizations/{orgId}/regulatory-graph/policy-optionsList the org's live policies ({id, name, kind}) across the 7 linkable kinds, for the control→policy picker.
GET/organizations/{orgId}/regulatory-graph/control-policies/{id}Get control policy
DELETE/organizations/{orgId}/regulatory-graph/control-policies/{id}Delete control policy
GET/organizations/{orgId}/regulatory-graph/obligation-ai-systemsList obligation ai systems
POST/organizations/{orgId}/regulatory-graph/obligation-ai-systemsCreate obligation ai system
GET/organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id}Get obligation ai system
DELETE/organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id}Delete obligation ai system
PATCH/organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id}Set a link to NOT_APPLICABLE (reject a suggestion) or APPLICABLE, in one write. A rejected pair is never re-proposed by suggest.
POST/organizations/{orgId}/regulatory-graph/obligation-ai-systems/{id}/confirmConfirm a SUGGESTED obligation-applicability link as APPLICABLE. The only path that writes APPLICABLE.
POST/organizations/{orgId}/regulatory-graph/obligation-ai-systems/suggestSuggest obligations for an AI system from its EU AI Act supply-chain role and its highest linked risk tier. Writes SUGGESTED links only.
GET/organizations/{orgId}/regulatory-graph/obligation-evidenceList obligation evidence
POST/organizations/{orgId}/regulatory-graph/obligation-evidenceCreate obligation evidence
GET/organizations/{orgId}/regulatory-graph/obligation-evidence/{id}Get obligation evidence
DELETE/organizations/{orgId}/regulatory-graph/obligation-evidence/{id}Delete obligation evidence

Remediation

MethodPathOperation
GET/organizations/{orgId}/remediation/proposalsList
POST/organizations/{orgId}/remediation/proposals/{id}/dismissDismiss
POST/organizations/{orgId}/remediation/proposals/{id}/choose-candidateChoose candidate
POST/organizations/{orgId}/remediation/proposals/{id}/simulateSimulate
POST/organizations/{orgId}/remediation/proposals/{id}/request-approvalRequest approval
POST/organizations/{orgId}/remediation/proposals/{id}/approveApprove
POST/organizations/{orgId}/remediation/proposals/{id}/applyApply
POST/organizations/{orgId}/remediation/proposals/{id}/rollbackRollback
GET/organizations/{orgId}/remediation/proposals/{id}/runsRuns

Reputation

MethodPathOperation
GET/reputation/agents/{agentDid}Query global reputation for an agent DID (public, unauthenticated)
POST/organizations/{orgId}/reputation/contributeContribute reputation signal for an installed agent (opt-in orgs only)

Revenue Monitoring

MethodPathOperation
GET/organizations/{orgId}/revenue-monitoring/overviewGet revenue overview
GET/organizations/{orgId}/revenue-monitoring/customersGet top customers
GET/organizations/{orgId}/revenue-monitoring/mrrGet mrr
GET/organizations/{orgId}/revenue-monitoring/balanceGet balance
GET/organizations/{orgId}/revenue-monitoring/payoutsGet payouts
POST/organizations/{orgId}/revenue-monitoring/payoutsRequest payout

Role Elevation

MethodPathOperation
GET/organizations/{orgId}/role-elevationsFind all
POST/organizations/{orgId}/role-elevationsElevate
GET/organizations/{orgId}/role-elevations/activeFind active
POST/organizations/{orgId}/role-elevations/{elevationId}/revokeRevoke

Roles

MethodPathOperation
GET/organizations/{orgId}/roles/permissionsGet available permissions
GET/organizations/{orgId}/rolesFind all roles
POST/organizations/{orgId}/rolesCreate role
GET/organizations/{orgId}/roles/{roleId}Find role
DELETE/organizations/{orgId}/roles/{roleId}Delete role
PATCH/organizations/{orgId}/roles/{roleId}Update role
POST/organizations/{orgId}/roles/assign/{userId}Assign role to user
DELETE/organizations/{orgId}/roles/assign/{userId}/{assignmentId}Remove role from user
GET/organizations/{orgId}/roles/user/{userId}Get user roles
GET/organizations/{orgId}/roles/user/{userId}/permissionsGet user permissions

Runtime installations

MethodPathOperation
GET/organizations/{orgId}/runtime-installationsList organization runtime installations and observed connection state
POST/organizations/{orgId}/runtime-installationsCreate a pending runtime installation; does not attest a host or enable dispatch
GET/organizations/{orgId}/runtime-installations/targetsList registered target identifiers without credentials or destination configuration
GET/organizations/{orgId}/runtime-installations/{id}Read an installation and its bound dispatch evidence
PATCH/organizations/{orgId}/runtime-installations/{id}Update an installation with revision checking; changed bindings require reconnection
POST/organizations/{orgId}/runtime-installations/{id}/challengeIssue a one-use native connection challenge and pause new bound dispatches
POST/organizations/{orgId}/runtime-installations/{id}/disablePermanently disable admission of new installation-bound managed actions
POST/organizations/{orgId}/runtime-installations/{id}/verifyConsume a creator-owned challenge using a non-browser credential; proves credential possession only

Saved Views

MethodPathOperation
GET/organizations/{orgId}/saved-viewsFind all
POST/organizations/{orgId}/saved-viewsCreate
GET/organizations/{orgId}/saved-views/{id}Find one
PUT/organizations/{orgId}/saved-views/{id}Update
DELETE/organizations/{orgId}/saved-views/{id}Remove

SCIM

MethodPathOperation
GET/organizations/{orgId}/scimGet config
PATCH/organizations/{orgId}/scimToggle enabled
POST/organizations/{orgId}/scim/tokenGenerate token
GET/organizations/{orgId}/scim/groupsList groups admin
GET/organizations/{orgId}/scim/group-mappingsList group mappings
POST/organizations/{orgId}/scim/group-mappingsCreate group mapping
PUT/organizations/{orgId}/scim/group-mappings/{mappingId}Update group mapping
DELETE/organizations/{orgId}/scim/group-mappings/{mappingId}Delete group mapping
GET/scim/v2/{orgId}/UsersList users
POST/scim/v2/{orgId}/UsersCreate user
GET/scim/v2/{orgId}/Users/{userId}Get user
PUT/scim/v2/{orgId}/Users/{userId}Replace user
DELETE/scim/v2/{orgId}/Users/{userId}Delete user
PATCH/scim/v2/{orgId}/Users/{userId}Patch user
GET/scim/v2/{orgId}/GroupsList groups
POST/scim/v2/{orgId}/GroupsCreate group
GET/scim/v2/{orgId}/Groups/{groupId}Get group
PUT/scim/v2/{orgId}/Groups/{groupId}Replace group
DELETE/scim/v2/{orgId}/Groups/{groupId}Delete group
PATCH/scim/v2/{orgId}/Groups/{groupId}Patch group

Security Settings

MethodPathOperation
GET/organizations/{orgId}/security/policyGet policy
PUT/organizations/{orgId}/security/policyUpdate policy
GET/organizations/{orgId}/security/ipsGet ip policies
POST/organizations/{orgId}/security/ipsAdd ip policy
DELETE/organizations/{orgId}/security/ips/{id}Delete ip policy
GET/organizations/{orgId}/security/ssoGet sso config
PUT/organizations/{orgId}/security/ssoUpdate sso config
POST/organizations/{orgId}/security/sso/testTest sso config
GET/organizations/{orgId}/security/proof-actionsGet this organization's protected-action evidence state
PUT/organizations/{orgId}/security/proof-actionsEnable or disable protected-action evidence for this organization

Semantic Cache

MethodPathOperation
GET/organizations/{orgId}/cache/statsGet stats
DELETE/organizations/{orgId}/cacheInvalidate all
DELETE/organizations/{orgId}/cache/agents/{agentId}Invalidate agent

Service Accounts

MethodPathOperation
GET/organizations/{orgId}/service-accountsFind all
POST/organizations/{orgId}/service-accountsCreate
GET/organizations/{orgId}/service-accounts/{id}Find one
DELETE/organizations/{orgId}/service-accounts/{id}Delete
PATCH/organizations/{orgId}/service-accounts/{id}Update
POST/organizations/{orgId}/service-accounts/{id}/rotate-keyRotate key

SLO

MethodPathOperation
GET/organizations/{orgId}/slo/summaryPer-org SLO indicators (success rate, latency, availability)
GET/organizations/{orgId}/slo/alertsList SLO alert threshold configs (org-wide, or ?aiSystemId=)
POST/organizations/{orgId}/slo/alertsUpsert an SLO alert threshold (one rule per metric per org or AI System)
DELETE/organizations/{orgId}/slo/alerts/{id}Delete an SLO alert threshold config

Supervision

MethodPathOperation
GET/organizations/{orgId}/supervision/sessionsList supervision sessions
POST/organizations/{orgId}/supervision/sessionsStart a supervision session (EU AI Act Art. 14)
POST/organizations/{orgId}/supervision/sessions/{sessionId}/endEnd a supervision session
POST/organizations/{orgId}/supervision/sessions/{sessionId}/interveneIntervene on a task during an active session
POST/organizations/{orgId}/supervision/tasks/{taskId}/pausePause a running task
POST/organizations/{orgId}/supervision/tasks/{taskId}/resumeResume a paused task
POST/organizations/{orgId}/supervision/tasks/{taskId}/terminateTerminate a running or paused task
POST/organizations/{orgId}/supervision/tasks/{taskId}/modify-inputReplace the input of a task before it is processed
GET/organizations/{orgId}/supervision/historyPaginated supervision event history
GET/organizations/{orgId}/supervision/escalationsList human-escalations for autonomous chains (default: pending)
GET/organizations/{orgId}/supervision/escalations/configget the org confidence-band routing config (auto-resolve/queue/escalate thresholds)
PUT/organizations/{orgId}/supervision/escalations/configupdate the org confidence-band routing config (upsert; lowBandMax <= highBandMin)
POST/organizations/{orgId}/supervision/escalations/{escalationId}/approveApprove an escalation — release the held hop to the queue
POST/organizations/{orgId}/supervision/escalations/{escalationId}/rejectReject an escalation — terminate the chain hop (fail-closed)

Supply Chain

MethodPathOperation
POST/organizations/{orgId}/supply-chain/scanRun a static, offline scan of an MCP server / skill manifest and report any hits as findings (source=supply_chain).
GET/organizations/{orgId}/supply-chain/permission-policiesThe org's MCP permission policies: the org-wide default (serverId null) plus any per-server overrides.
PUT/organizations/{orgId}/supply-chain/permission-policiesCreate or replace the permission policy for one MCP server, or the org-wide default when serverId is omitted.
DELETE/organizations/{orgId}/supply-chain/permission-policies/{id}Remove a permission policy. Scans then fall back to the org-wide default, or to the registered server's own capabilities.

Support

MethodPathOperation
POST/organizations/{orgId}/support/requestsSend a support request to Praesidia support

Team Quotas

MethodPathOperation
GET/organizations/{orgId}/teams/{teamId}/quotasGet quota
PATCH/organizations/{orgId}/teams/{teamId}/quotasUpdate quota
GET/organizations/{orgId}/teams/{teamId}/quotas/usageGet usage
POST/organizations/{orgId}/teams/{teamId}/quotas/syncSync counters

Teams

MethodPathOperation
GET/organizations/{orgId}/teamsGet all teams in the organization
POST/organizations/{orgId}/teamsCreate a new team
GET/organizations/{orgId}/teams/{teamId}Get a specific team by ID
DELETE/organizations/{orgId}/teams/{teamId}Delete a team
PATCH/organizations/{orgId}/teams/{teamId}Update
GET/organizations/{orgId}/teams/{teamId}/membersGet team members
POST/organizations/{orgId}/teams/{teamId}/membersAdd a member to a team
DELETE/organizations/{orgId}/teams/{teamId}/members/{userId}Remove a member from a team
PATCH/organizations/{orgId}/teams/{teamId}/members/{userId}/roleUpdate member role
GET/organizations/{orgId}/teams/{teamId}/dashboardGet team dashboard
GET/organizations/{orgId}/teams/{teamId}/agentsGet team agents

Telemetry Ingest

MethodPathOperation
POST/telemetry/otlp/v1/tracesIngest OTLP/HTTP GenAI traces (buffered, org-key auth)

Threat Intelligence

MethodPathOperation
GET/organizations/{orgId}/threat-intel/feedList global threat intelligence feed entries (paginated)
GET/organizations/{orgId}/threat-intel/statusGet org threat intelligence opt-in status and contribution stats

Topology

MethodPathOperation
GET/organizations/{orgId}/topology/graphGet agent dependency graph / topology

Traces

MethodPathOperation
GET/organizations/{orgId}/traces/searchFull-text search across tool-call, guardrail-log, and prompt-trace entries
GET/organizations/{orgId}/traces/{taskId}Get full execution trace for an agent task
GET/organizations/{orgId}/tracesList agent execution traces for the organization
GET/organizations/{orgId}/traces/{taskId}/exportExport task trace as OTLP JSON (Jaeger/Tempo compatible)

Trust

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/trust/scoreGet current trust score for an agent
GET/organizations/{orgId}/agents/{agentId}/trust/historyGet trust score history for an agent
GET/organizations/{orgId}/agents/{agentId}/trust/attestationsList trust attestations for an agent
POST/organizations/{orgId}/agents/{agentId}/trust/attestationsSubmit a third-party trust attestation
POST/organizations/{orgId}/agents/{agentId}/trust/attestations/{attestationId}/revokeRevoke a trust attestation for an agent
GET/organizations/{orgId}/trust/agents-summaryTrust scores for every agent in the org, in a single response

Trust Passport

MethodPathOperation
GET/trust/passport/{agentId}Signed, verifiable trust passport for an agent
GET/trust/passport/{agentId}/verifyTrust passport verification bundle
GET/trust/passport/{agentId}/badge.svgEmbeddable SVG trust badge
GET/trust/passport/ai-systems/{aiSystemId}Signed, verifiable trust passport for an AI System
GET/trust/passport/ai-systems/{aiSystemId}/verifyAI System trust passport verification bundle
GET/trust/passport/ai-systems/{aiSystemId}/passport.pdfDownloadable PDF rendering of the AI System trust passport
GET/trust/passport/ai-systems/{aiSystemId}/badge.svgEmbeddable SVG trust badge for an AI System
GET/organizations/{orgId}/ai-systems/{aiSystemId}/trust-passportThe org's own view of an AI System trust passport
GET/organizations/{orgId}/ai-systems/{aiSystemId}/trust-passport/verifyThe org's own AI System trust passport verification bundle
GET/organizations/{orgId}/ai-systems/{aiSystemId}/trust-passport/passport.pdfPDF of the org's own AI System trust passport

Trust Passport imports

MethodPathOperation
GET/organizations/{orgId}/trust-passport/importsList imported trust passports (no documents)
POST/organizations/{orgId}/trust-passport/importsImport a vendor trust passport
GET/organizations/{orgId}/trust-passport/imports/{id}An imported trust passport, with its document
PATCH/organizations/{orgId}/trust-passport/imports/{id}Set or clear an import's vendor AI asset
POST/organizations/{orgId}/trust-passport/imports/{id}/reverifyRe-verify and re-score an imported trust passport
GET/organizations/{orgId}/trust-passport/pinned-keysList pinned vendor signing keys
POST/organizations/{orgId}/trust-passport/pinned-keysPin a vendor's passport signing key for an issuer
DELETE/organizations/{orgId}/trust-passport/pinned-keys/{id}Unpin a vendor signing key

Usage

MethodPathOperation
GET/organizations/{orgId}/usageOrganization monthly usage
GET/organizations/{orgId}/usage/connections/{connectionId}Connection current month usage
GET/organizations/{orgId}/usage/connections/{connectionId}/historyConnection usage history

Users

MethodPathOperation
PATCH/users/profileUpdate profile
GET/users/api-keysList api keys
POST/users/api-keysCreate api key
DELETE/users/api-keys/{id}Delete api key
GET/users/notification-preferencesGet notification preferences
PATCH/users/notification-preferencesUpdate notification preferences
GET/users/organizations/{orgId}/usersFind all
GET/users/organizations/{orgId}/users/{userId}Find one
PATCH/users/organizations/{orgId}/users/{userId}Update
POST/users/organizations/{orgId}/users/{userId}/teams/{teamId}Add to team
DELETE/users/organizations/{orgId}/users/{userId}/teams/{teamId}Remove from team

Wallets

MethodPathOperation
GET/organizations/{orgId}/agents/{agentId}/walletGet wallet for an agent
POST/organizations/{orgId}/agents/{agentId}/walletCreate a wallet for an agent
GET/organizations/{orgId}/walletsList agent wallets in this organisation (paginated)
POST/organizations/{orgId}/wallets/payTransfer funds between agent wallets
POST/organizations/{orgId}/wallets/top-upDeposit funds into an agent wallet from org-budget
GET/organizations/{orgId}/wallets/transactionsList wallet transactions for the organisation (paginated)
POST/organizations/{orgId}/wallets/transactions/{txId}/reverseReverse a settled payment transaction (admin only)

WebAuthn

MethodPathOperation
POST/webauthn/register/startRegister start
POST/webauthn/register/finishRegister finish
GET/webauthn/credentialsList credentials
DELETE/webauthn/credentials/{id}Delete credential
POST/webauthn/authenticate/startAuthenticate start
POST/webauthn/authenticate/finishAuthenticate finish
POST/webauthn/sudo/startSudo start
POST/webauthn/sudo/finishSudo finish

Webhook Deliveries

MethodPathOperation
GET/organizations/{orgId}/integrations/webhooks/{webhookId}/deliveriesFind all
GET/organizations/{orgId}/integrations/webhooks/{webhookId}/deliveries/{deliveryId}Find one
POST/organizations/{orgId}/integrations/webhooks/{webhookId}/deliveries/{deliveryId}/replayReplay

Workflow Templates

MethodPathOperation
GET/organizations/{orgId}/workflow-templatesList workflow templates (org-scoped)
GET/organizations/{orgId}/workflow-templates/{slug}Get a workflow template by slug (org-scoped)
GET/workflow-templatesList all published workflow templates
GET/workflow-templates/{slug}Get a single workflow template by slug
POST/organizations/{orgId}/workflow-templates/{slug}/useCreate a new workflow from a template

Workflow Webhooks

MethodPathOperation
POST/organizations/{orgId}/workflows/{workflowId}/webhook/configureGenerate webhook URL and HMAC secret for a workflow
POST/organizations/{orgId}/workflows/{workflowId}/webhook/rotate-secretRotate the HMAC secret for webhook signature verification
GET/organizations/{orgId}/workflows/{workflowId}/webhook/deliveriesList recent webhook deliveries for a workflow
POST/organizations/{orgId}/workflows/{workflowId}/webhook/deliveries/{deliveryId}/redeliverRe-trigger a previous webhook delivery

Workflows

MethodPathOperation
GET/organizations/{orgId}/workflowsList all workflows for the organization
POST/organizations/{orgId}/workflowsCreate a new workflow
POST/organizations/{orgId}/workflows/generateEnqueue async generation of a workflow from a natural language prompt
GET/organizations/{orgId}/workflows/generate/{jobId}Poll the status/result of an async workflow generation job
GET/organizations/{orgId}/workflows/{id}Get a specific workflow
DELETE/organizations/{orgId}/workflows/{id}Delete a specific workflow
PATCH/organizations/{orgId}/workflows/{id}Update a specific workflow
GET/organizations/{orgId}/workflows/{id}/cost-forecastGet forecasted cost for a workflow run
GET/organizations/{orgId}/workflows/{id}/runsList runs for a workflow
POST/organizations/{orgId}/workflows/{id}/runsStart a workflow run
GET/organizations/{orgId}/workflows/{id}/runs/{runId}Get a specific workflow run with accumulated context
POST/organizations/{orgId}/workflows/{id}/runs/{runId}/retryRetry a failed or cancelled workflow run with the same initial input
POST/organizations/{orgId}/workflows/{id}/runs/{runId}/cancelCancel a RUNNING or PAUSED workflow run (e.g. a budget auto-paused run)
GET/organizations/{orgId}/workflows/{id}/runs/{runId}/approvalsList pending approvals for a workflow run
POST/organizations/{orgId}/workflows/{id}/runs/{runId}/approvals/{approvalId}/approveApprove a pending approval
POST/organizations/{orgId}/workflows/{id}/runs/{runId}/approvals/{approvalId}/rejectReject a pending approval
GET/organizations/{orgId}/workflows/{id}/versionsList all versions of a workflow
GET/organizations/{orgId}/workflows/{id}/versions/{versionId}Get a specific workflow version
POST/organizations/{orgId}/workflows/{id}/versions/{versionId}/rollbackRollback workflow to a previous version

Zeroclaw

MethodPathOperation
POST/organizations/{orgId}/zeroclaw/pairPair
GET/organizations/{orgId}/zeroclaw/healthHealth
GET/organizations/{orgId}/zeroclaw/pairingsList
POST/organizations/{orgId}/zeroclaw/pairings/{pairingId}/verifyVerify
POST/organizations/{orgId}/zeroclaw/pairings/{pairingId}/rotateRotate
DELETE/organizations/{orgId}/zeroclaw/pairings/{pairingId}Revoke
POST/organizations/{orgId}/zeroclaw/pairings/{pairingId}/bindBind
POST/organizations/{orgId}/zeroclaw/pairings/{pairingId}/repairRepair

Read next: all docs · developer quickstart · integrations · security

Make your first call

Create a workspace, issue an API key and follow the quickstart with a harmless test request.