API Endpoint Catalog
Source-derived is not deployed. Every route below was found in service source code. That does not mean it is deployed, reachable from outside the platform, publicly supported, or that its declared authentication is enforced in any particular deployment.
Paths shown are service-local (effective_source_path). A gateway path is shown only where the API gateway's routing
table and catch-all handler support it. See Authentication and conventions for how to
read the auth column. Use the site search to find a route by name or path.
api-gateway
6 of 16 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /{service}/{path:path}Generic proxy. Which upstream services it reaches is defined by the gateway routing table; it does not by itself make any upstream route externally available. | gateway | -- | INDIRECT · AuthMiddleware | AUTHENTICATED_PUBLIC | source |
| POST | /{service}/{path:path}Generic proxy. Which upstream services it reaches is defined by the gateway routing table; it does not by itself make any upstream route externally available. | gateway | -- | INDIRECT · AuthMiddleware | AUTHENTICATED_PUBLIC | source |
| PUT | /{service}/{path:path}Generic proxy. Which upstream services it reaches is defined by the gateway routing table; it does not by itself make any upstream route externally available. | gateway | -- | INDIRECT · AuthMiddleware | AUTHENTICATED_PUBLIC | source |
| DELETE | /{service}/{path:path}Generic proxy. Which upstream services it reaches is defined by the gateway routing table; it does not by itself make any upstream route externally available. | gateway | -- | INDIRECT · AuthMiddleware | AUTHENTICATED_PUBLIC | source |
| GET | /healthExempted from the gateway auth middleware by its path skip-list in source. | health | -- | INDIRECT · AuthMiddleware | PUBLIC | source |
| GET | /versionExempted from the gateway auth middleware by its path skip-list in source. | version | -- | INDIRECT · AuthMiddleware | PUBLIC | source |
auth
48 of 143 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /.well-known/jwks.json | jwks | jwks | UNKNOWN · -- | PUBLIC | source |
| POST | /auth/login | login | auth | UNKNOWN · -- | PUBLIC | source |
| POST | /auth/logout | logout | auth | UNKNOWN · -- | PUBLIC | source |
| POST | /auth/refresh | refresh | auth | UNKNOWN · -- | PUBLIC | source |
| GET | /me | get_my_identity | identity | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| GET | /organizations/{organization_id}/members | list_organization_members | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| GET | /organizations/{organization_id}/members/{user_id}/effective-permissions | get_organization_member_effective_permissions | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| GET | /organizations/{organization_id}/members/{user_id}/roles | get_organization_member_roles | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| POST | /organizations/{organization_id}/members/{user_id}/roles | assign_organization_member_roles | organizations | EXPLICIT · get_current_user, _require_org_manager | AUTHENTICATED_PUBLIC | source |
| DELETE | /organizations/{organization_id}/members/{user_id}/roles/{role_name} | remove_organization_member_role | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| GET | /organizations/{organization_id}/permissions | list_organization_permissions | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| GET | /organizations/{organization_id}/roles | list_organization_roles | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| POST | /organizations/{organization_id}/roles | create_organization_role | organizations | EXPLICIT · get_current_user, _require_org_manager | AUTHENTICATED_PUBLIC | source |
| PUT | /organizations/{organization_id}/roles/{role_id} | update_organization_role | organizations | EXPLICIT · get_current_user, _require_org_manager | AUTHENTICATED_PUBLIC | source |
| DELETE | /organizations/{organization_id}/roles/{role_id} | delete_organization_role | organizations | EXPLICIT · _require_org_manager | AUTHENTICATED_PUBLIC | source |
| GET | /orgs | list_my_orgs | orgs | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /orgs | create_org | orgs | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id} | get_org | orgs | EXPLICIT · get_org_membership_or_platform_admin | AUTHENTICATED_PUBLIC | source |
| PATCH | /orgs/{org_id} | update_org | orgs | EXPLICIT · get_current_user, require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| POST | /orgs/{org_id}/invite | invite_member | orgs | EXPLICIT · get_current_user, require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/members | list_members | orgs | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/members/{user_id}/roles | get_member_roles | orgs | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| POST | /orgs/{org_id}/members/{user_id}/roles | assign_member_role | orgs | EXPLICIT · get_current_user, require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| PUT | /orgs/{org_id}/members/{user_id}/roles | update_member_roles | orgs | EXPLICIT · get_current_user, require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| DELETE | /orgs/{org_id}/members/{user_id}/roles/{role_id} | remove_member_role | orgs | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/roles | list_org_roles | orgs | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_ORG) | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/teams | list_teams | teams | EXPLICIT · get_org_membership_or_platform_admin | AUTHENTICATED_PUBLIC | source |
| POST | /orgs/{org_id}/teams | create_team | teams | EXPLICIT · get_current_user, require_org_permission_or_platform_admin(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/teams/{team_id} | get_team_detail | teams | EXPLICIT · get_org_membership_or_platform_admin | AUTHENTICATED_PUBLIC | source |
| PATCH | /orgs/{org_id}/teams/{team_id} | rename_team | teams | EXPLICIT · require_team_manage_permission(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| DELETE | /orgs/{org_id}/teams/{team_id} | delete_team | teams | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| POST | /orgs/{org_id}/teams/{team_id}/invite | invite_team_member | teams | EXPLICIT · get_current_user, require_team_manage_permission(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| POST | /orgs/{org_id}/teams/{team_id}/leave | leave_team | teams | EXPLICIT · get_current_user, get_org_membership_or_platform_admin | AUTHENTICATED_PUBLIC | source |
| GET | /orgs/{org_id}/teams/{team_id}/members | get_team_members | teams | EXPLICIT · get_org_membership_or_platform_admin | AUTHENTICATED_PUBLIC | source |
| PUT | /orgs/{org_id}/teams/{team_id}/members | set_team_members | teams | EXPLICIT · require_org_permission_or_platform_admin(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| DELETE | /orgs/{org_id}/teams/{team_id}/members/{user_id} | remove_team_member | teams | EXPLICIT · require_team_manage_permission(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| PUT | /orgs/{org_id}/teams/{team_id}/members/{user_id}/role | update_team_member_role | teams | EXPLICIT · require_team_manage_permission(MANAGE_TEAMS) | AUTHENTICATED_PUBLIC | source |
| GET | /sessions | list_my_sessions | sessions | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| GET | /sessions/{session_id} | get_my_session | sessions | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /sessions/{session_id}/revoke | revoke_my_session | sessions | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /users/me/mfa/challenge | verify_mfa_challenge | mfa | INDIRECT · verify_mfa_challenge | AUTHENTICATED_PUBLIC | source |
| GET | /users/me/mfa/devices | list_mfa_devices | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| DELETE | /users/me/mfa/devices/{device_id} | remove_mfa_device | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| GET | /users/me/mfa/recovery-codes | recovery_codes_status | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /users/me/mfa/recovery-codes | generate_recovery_codes | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /users/me/mfa/recovery-codes/regenerate | regenerate_recovery_codes | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /users/me/mfa/totp/enroll | start_totp_enrollment | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
| POST | /users/me/mfa/totp/verify | verify_totp_enrollment | mfa | EXPLICIT · get_current_user | AUTHENTICATED_PUBLIC | source |
billing
14 of 19 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /billing/invoices/{invoice_id} | read_invoice_detail | billing | EXPLICIT · get_authorized_invoice | AUTHENTICATED_PUBLIC | source |
| GET | /billing/invoices/{invoice_id}/line-items | read_invoice_line_items | billing | EXPLICIT · get_authorized_invoice | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/allowances | read_allowance_usage | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/cost-breakdown | read_cost_breakdown | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/cost-history | read_cost_history | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/costs | read_cost_summary | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/invoices | read_invoices | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/payment-method | read_payment_method | billing | EXPLICIT · get_authorized_billing_caller | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/subscription | read_subscription_summary | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/subscription/usage-limits | read_subscription_usage_limits | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/summary | read_organization_billing_summary | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/usage | read_usage_summary | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /billing/organizations/{organization_id}/usage-events | read_usage_events | billing | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
| GET | /entitlements/{organization_id}/check | read_entitlement_check | entitlements | EXPLICIT · get_authorized_organization_id | AUTHENTICATED_PUBLIC | source |
model-registry
21 of 24 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /v1/aliasesvia gateway: /model-registry/v1/aliases | api_aliases | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/artifactsvia gateway: /model-registry/v1/artifacts | api_artifacts | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/comparevia gateway: /model-registry/v1/compare | api_compare | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/hf/pushvia gateway: /model-registry/v1/hf/push | hf_push | huggingface | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/hf/push/status/{job_id}via gateway: /model-registry/v1/hf/push/status/{job_id} | hf_push_status | huggingface | EXPLICIT · require_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/metricsvia gateway: /model-registry/v1/metrics | api_metrics | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/modelsvia gateway: /model-registry/v1/models | list_models | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/ownership/resolvevia gateway: /model-registry/v1/ownership/resolve | api_resolve_ownership | -- | EXPLICIT · require_ownership_resolve_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/promotevia gateway: /model-registry/v1/promote | api_promote | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/registervia gateway: /model-registry/v1/register | api_register | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/resolvevia gateway: /model-registry/v1/resolve | api_resolve | -- | EXPLICIT · require_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/runs/getvia gateway: /model-registry/v1/runs/get | api_run_get | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/runs/listvia gateway: /model-registry/v1/runs/list | api_runs_list | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/runs/log-batchvia gateway: /model-registry/v1/runs/log-batch | api_log_batch | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/runs/log-metricvia gateway: /model-registry/v1/runs/log-metric | api_log_metric | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/runs/log-paramvia gateway: /model-registry/v1/runs/log-param | api_log_param | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| GET | /v1/showvia gateway: /model-registry/v1/show | api_show | -- | EXPLICIT · require_read_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/stagevia gateway: /model-registry/v1/stage | api_set_stage | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| PUT | /v1/tagsvia gateway: /model-registry/v1/tags | api_set_tag | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/verifyvia gateway: /model-registry/v1/verify | api_verify | -- | EXPLICIT · require_auth_with_context | AUTHENTICATED_PUBLIC | source |
| POST | /v1/versions/patchvia gateway: /model-registry/v1/versions/patch | api_patch_version | -- | EXPLICIT · require_write_auth_with_context | AUTHENTICATED_PUBLIC | source |
rag
7 of 13 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| POST | /v1/embedvia gateway: /rag/v1/embed | embed | -- | EXPLICIT · require_permission(DATASET_WRITE) | AUTHENTICATED_PUBLIC | source |
| POST | /v1/ingestvia gateway: /rag/v1/ingest | ingest | -- | EXPLICIT · require_permission(DATASET_WRITE) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/kg/drug-diseasevia gateway: /rag/v1/kg/drug-disease | kg_drug_disease | -- | EXPLICIT · require_dataset_read | AUTHENTICATED_PUBLIC | source |
| GET | /v1/kg/entityvia gateway: /rag/v1/kg/entity | kg_entity | -- | EXPLICIT · require_dataset_read | AUTHENTICATED_PUBLIC | source |
| GET | /v1/kg/statsvia gateway: /rag/v1/kg/stats | kg_stats | -- | EXPLICIT · require_dataset_read | AUTHENTICATED_PUBLIC | source |
| POST | /v1/queryvia gateway: /rag/v1/query | query | -- | EXPLICIT · require_dataset_read | AUTHENTICATED_PUBLIC | source |
| GET | /v1/studiesvia gateway: /rag/v1/studies | list_studies | -- | EXPLICIT · require_dataset_read | AUTHENTICATED_PUBLIC | source |
tes
7 of 18 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /api/runsvia gateway: /tes/api/runs | list_runs | -- | EXPLICIT · require_permission(WORKFLOW_RUNS_READ) | AUTHENTICATED_PUBLIC | source |
| GET | /api/runs/{run_id}via gateway: /tes/api/runs/{run_id} | get_run | -- | EXPLICIT · require_permission(WORKFLOW_RUNS_READ) | AUTHENTICATED_PUBLIC | source |
| POST | /api/runs/{run_id}/cancelvia gateway: /tes/api/runs/{run_id}/cancel | cancel_run | -- | EXPLICIT · require_permission(WORKFLOW_EXECUTE) | AUTHENTICATED_PUBLIC | source |
| GET | /api/runs/{run_id}/logsvia gateway: /tes/api/runs/{run_id}/logs | get_logs | -- | EXPLICIT · require_permission(WORKFLOW_RUNS_READ) | AUTHENTICATED_PUBLIC | source |
| GET | /api/runs/{run_id}/resultsvia gateway: /tes/api/runs/{run_id}/results | get_results | -- | EXPLICIT · require_permission(WORKFLOW_RUNS_READ) | AUTHENTICATED_PUBLIC | source |
| POST | /api/runs/submitvia gateway: /tes/api/runs/submit | submit | -- | EXPLICIT · require_permission(WORKFLOW_EXECUTE) | AUTHENTICATED_PUBLIC | source |
| POST | /api/runs/validatevia gateway: /tes/api/runs/validate | validate | -- | EXPLICIT · require_permission(WORKFLOW_EXECUTE) | AUTHENTICATED_PUBLIC | source |
toolserver
No routes of this service are itemised (8 found in source; see Services).
workflow-bundles
7 of 10 routes itemised.
| Method | Path | Handler | Tags | Auth status · evidence | Visibility | Source |
|---|---|---|---|---|---|---|
| GET | /v1/categories | list_categories | -- | EXPLICIT · require_permission(workflow.read) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/runs | list_runs | -- | EXPLICIT · require_permission(runs.read) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/runs/{run_id} | get_run | -- | EXPLICIT · require_permission(runs.read) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/workflows | list_workflows | -- | EXPLICIT · require_permission(workflow.read) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/workflows/{name} | get_workflow_versions | -- | EXPLICIT · require_permission(workflow.read) | AUTHENTICATED_PUBLIC | source |
| GET | /v1/workflows/{workflow_id}/inputs | get_workflow_inputs | -- | EXPLICIT · require_permission(workflow.read) | AUTHENTICATED_PUBLIC | source |
| POST | /v1/workflows/{workflow_id}/run | run_workflow | -- | EXPLICIT · require_permission(workflow.execute) | AUTHENTICATED_PUBLIC | source |