Skip to main content
EVOKORE// SKILLS / api-surface
Agent-33markdownsha 54C41D8A8F8A

api-surface

documentation

API Surface

Source of truth:

  • Route modules in engine/src/agent33/api/routes/
  • Auth middleware in engine/src/agent33/security/middleware.py
  • Scope checks in engine/src/agent33/security/permissions.py

1. Authentication Rules

Public (no auth required):

  • GET /health
  • GET /health/channels
  • GET /healthz
  • GET /readyz
  • GET /metrics
  • POST /v1/auth/token
  • GET /v1/dashboard/
  • GET /v1/dashboard/metrics
  • GET /v1/dashboard/alerts
  • GET /v1/dashboard/lineage/{workflow_id}
  • /docs, /redoc, /openapi.json

All other endpoints require authentication (Bearer JWT or X-API-Key).

Defined scopes:

  • admin
  • agents:read
  • agents:write
  • agents:invoke
  • workflows:read
  • workflows:write
  • workflows:execute
  • tools:execute
  • operator:read
  • operator:write

2. Endpoint Map by Domain

Health

MethodPathScope
GET/healthPublic
GET/health/channelsPublic
GET/healthzPublic
GET/readyzPublic
GET/metricsPublic

Auth

MethodPathScope
POST/v1/auth/tokenPublic
POST/v1/auth/api-keysadmin
DELETE/v1/auth/api-keys/{key_id}Authenticated (ownership/admin logic in handler)

Chat

MethodPathScope
POST/v1/chat/completionsAuthenticated

Agents

MethodPathScope
GET/v1/agents/capabilities/catalogAuthenticated
GET/v1/agents/searchagents:read
GET/v1/agents/by-id/{agent_id}agents:read
GET/v1/agents/agents:read
GET/v1/agents/{name}agents:read
POST/v1/agents/agents:write
POST/v1/agents/{name}/invokeagents:invoke

Workflows

MethodPathScope
GET/v1/workflows/workflows:read
GET/v1/workflows/{name}workflows:read
POST/v1/workflows/workflows:write
POST/v1/workflows/{name}/executeworkflows:execute

Memory

MethodPathScope
POST/v1/memory/searchagents:read
GET/v1/memory/sessions/{session_id}/observationsagents:read
POST/v1/memory/sessions/{session_id}/summarizeagents:write

Reviews

MethodPathScope
POST/v1/reviews/workflows:write
GET/v1/reviews/workflows:read
GET/v1/reviews/{review_id}workflows:read
DELETE/v1/reviews/{review_id}workflows:write
POST/v1/reviews/{review_id}/assessworkflows:write
POST/v1/reviews/{review_id}/readyworkflows:write
POST/v1/reviews/{review_id}/assign-l1workflows:write
POST/v1/reviews/{review_id}/l1workflows:write
POST/v1/reviews/{review_id}/assign-l2workflows:write
POST/v1/reviews/{review_id}/l2workflows:write
POST/v1/reviews/{review_id}/approveworkflows:write
POST/v1/reviews/{review_id}/mergeworkflows:write

Traces

MethodPathScope
POST/v1/traces/tools:execute
GET/v1/traces/workflows:read
GET/v1/traces/{trace_id}workflows:read
POST/v1/traces/{trace_id}/actionstools:execute
POST/v1/traces/{trace_id}/completetools:execute
POST/v1/traces/{trace_id}/failurestools:execute
GET/v1/traces/{trace_id}/failuresworkflows:read

Evaluations

MethodPathScope
GET/v1/evaluations/golden-tasksworkflows:read
GET/v1/evaluations/golden-casesworkflows:read
GET/v1/evaluations/gates/{gate}/tasksworkflows:read
POST/v1/evaluations/runstools:execute
GET/v1/evaluations/runsworkflows:read
GET/v1/evaluations/runs/{run_id}workflows:read
POST/v1/evaluations/runs/{run_id}/resultstools:execute
POST/v1/evaluations/runs/{run_id}/baselinetools:execute
GET/v1/evaluations/baselinesworkflows:read
GET/v1/evaluations/regressionsworkflows:read
PATCH/v1/evaluations/regressions/{regression_id}/triagetools:execute
POST/v1/evaluations/regressions/{regression_id}/resolvetools:execute

Scheduled Gates

MethodPathScope
POST/v1/evaluations/schedulestools:execute
GET/v1/evaluations/schedulesworkflows:read
GET/v1/evaluations/schedules/{schedule_id}workflows:read
DELETE/v1/evaluations/schedules/{schedule_id}tools:execute
POST/v1/evaluations/schedules/{schedule_id}/triggertools:execute
GET/v1/evaluations/schedules/{schedule_id}/historyworkflows:read

Autonomy

MethodPathScope
POST/v1/autonomy/budgetstools:execute
GET/v1/autonomy/budgetsworkflows:read
GET/v1/autonomy/budgets/{budget_id}workflows:read
DELETE/v1/autonomy/budgets/{budget_id}tools:execute
POST/v1/autonomy/budgets/{budget_id}/transitiontools:execute
POST/v1/autonomy/budgets/{budget_id}/activatetools:execute
POST/v1/autonomy/budgets/{budget_id}/suspendtools:execute
POST/v1/autonomy/budgets/{budget_id}/completetools:execute
GET/v1/autonomy/budgets/{budget_id}/preflightworkflows:read
POST/v1/autonomy/budgets/{budget_id}/enforcertools:execute
POST/v1/autonomy/budgets/{budget_id}/enforce/filetools:execute
POST/v1/autonomy/budgets/{budget_id}/enforce/commandtools:execute
POST/v1/autonomy/budgets/{budget_id}/enforce/networktools:execute
GET/v1/autonomy/escalationsworkflows:read
POST/v1/autonomy/budgets/{budget_id}/escalatetools:execute
POST/v1/autonomy/escalations/{escalation_id}/acknowledgetools:execute
POST/v1/autonomy/escalations/{escalation_id}/resolvetools:execute

Releases

MethodPathScope
POST/v1/releasestools:execute
GET/v1/releasesworkflows:read
GET/v1/releases/{release_id}workflows:read
POST/v1/releases/{release_id}/freezetools:execute
POST/v1/releases/{release_id}/rctools:execute
POST/v1/releases/{release_id}/validatetools:execute
POST/v1/releases/{release_id}/publishtools:execute
GET/v1/releases/{release_id}/checklistworkflows:read
PATCH/v1/releases/{release_id}/checklisttools:execute
POST/v1/releases/sync/rulestools:execute
GET/v1/releases/sync/rulesworkflows:read
POST/v1/releases/sync/rules/{rule_id}/dry-runtools:execute
POST/v1/releases/sync/rules/{rule_id}/executetools:execute
POST/v1/releases/{release_id}/rollbacktools:execute
GET/v1/releases/rollbacksworkflows:read
POST/v1/releases/rollback/recommendworkflows:read

Improvements

MethodPathScope
POST/v1/improvements/intakesAuthenticated
GET/v1/improvements/intakesAuthenticated
GET/v1/improvements/intakes/{intake_id}Authenticated
POST/v1/improvements/intakes/{intake_id}/transitionAuthenticated
POST/v1/improvements/lessonsAuthenticated
GET/v1/improvements/lessonsAuthenticated
GET/v1/improvements/lessons/{lesson_id}Authenticated
POST/v1/improvements/lessons/{lesson_id}/complete-actionAuthenticated
POST/v1/improvements/lessons/{lesson_id}/verifyAuthenticated
POST/v1/improvements/checklistsAuthenticated
GET/v1/improvements/checklistsAuthenticated
GET/v1/improvements/checklists/{checklist_id}Authenticated
POST/v1/improvements/checklists/{checklist_id}/completeAuthenticated
GET/v1/improvements/checklists/{checklist_id}/evaluateAuthenticated
GET/v1/improvements/metricsAuthenticated
GET/v1/improvements/metrics/historyAuthenticated
POST/v1/improvements/metrics/snapshotAuthenticated
POST/v1/improvements/metrics/default-snapshotAuthenticated
GET/v1/improvements/metrics/trend/{metric_id}Authenticated
POST/v1/improvements/refreshesAuthenticated
GET/v1/improvements/refreshesAuthenticated
GET/v1/improvements/refreshes/{refresh_id}Authenticated
POST/v1/improvements/refreshes/{refresh_id}/completeAuthenticated

Operator

MethodPathScope
GET/v1/operator/statusoperator:read
GET/v1/operator/configoperator:read
GET/v1/operator/doctoroperator:read
POST/v1/operator/resetoperator:write
GET/v1/operator/tools/summaryoperator:read
GET/v1/operator/sessionsoperator:read
GET/v1/operator/backupsoperator:read
GET/v1/operator/onboardingoperator:read

Backups

MethodPathScope
GET/v1/backupsoperator:read
POST/v1/backupsoperator:write
GET/v1/backups/inventoryoperator:read
GET/v1/backups/{backup_id}operator:read
POST/v1/backups/{backup_id}/verifyoperator:read
POST/v1/backups/{backup_id}/restore-planoperator:read
POST/v1/backups/{backup_id}/restoreoperator:write

Restore execution is gated by request body: confirm=true is required, and allow_overwrite=true is additionally required when the restore plan reports overwrite conflicts.

Dashboard

MethodPathScope
GET/metricsPublic
GET/v1/dashboard/Public
GET/v1/dashboard/metricsPublic
GET/v1/dashboard/alertsPublic
GET/v1/dashboard/lineage/{workflow_id}Public

Training

MethodPathScope
POST/v1/training/{agent}/rolloutAuthenticated
POST/v1/training/{agent}/optimizeAuthenticated
GET/v1/training/{agent}/rolloutsAuthenticated
GET/v1/training/{agent}/metricsAuthenticated
POST/v1/training/{agent}/revertAuthenticated

Webhooks

MethodPathScope
POST/v1/webhooks/telegramAuthenticated
POST/v1/webhooks/discordAuthenticated
POST/v1/webhooks/slackAuthenticated
GET/v1/webhooks/whatsappAuthenticated
POST/v1/webhooks/whatsappAuthenticated

Webhook Delivery

MethodPathScope
GET/v1/webhooks/deliveriesadmin
GET/v1/webhooks/deliveries/statsadmin
GET/v1/webhooks/deliveries/dead-lettersadmin
GET/v1/webhooks/deliveries/{delivery_id}admin
POST/v1/webhooks/deliveries/{delivery_id}/retryadmin
DELETE/v1/webhooks/deliveries/purgeadmin

3. Notes

  • A route being "Authenticated" without scope checks means middleware auth is required, but endpoint-level role/scope enforcement is not currently added.
  • The API key delete route enforces ownership/admin logic in handler code rather than route dependency scope.