Skip to main content

Agent access

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: agent-access · 22 operations

GET /v1/tenants/{tenant_slug}/agent-keys​

List agent keys

An agent key is the credential an AI agent presents to Apiome's MCP agent runtime. It is bound to one agent toolset, may only list and call the tools named in its allowlist (and enabled in the toolset), and can expire. It is not a REST credential: the REST API refuses it on every route.

Responses carry metadata only (name, prefix, toolset, allowlist, status, timestamps); the secret is returned once, by create, and never again.

Newest first. toolsetId narrows the list to one toolset's keys; revoked keys are left out unless includeRevoked=true.

Requires api_keys:view.

Operation id: list_agent_keys_route_v1_tenants__tenant_slug__agent_keys_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolsetIdquerystring (uuid) or nullnoQuery parameter: toolset id.
includeRevokedquerybooleannoQuery parameter: include revoked.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list agent keys.application/json AgentKeyListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/agent-keys​

Create an agent key

An agent key is the credential an AI agent presents to Apiome's MCP agent runtime. It is bound to one agent toolset, may only list and call the tools named in its allowlist (and enabled in the toolset), and can expire. It is not a REST credential: the REST API refuses it on every route.

The body names the key, the toolsetId it is bound to, its toolAllowlist (MCP tool names, ^[A-Za-z0-9_-]{1,64}$, at most 1024; no wildcard, and an empty list permits nothing) and an optional future expiresAt.

The response includes secret (ak_…): it is shown only once. Present it to the MCP agent runtime as Authorization: Bearer <secret>.

Requires api_keys:create. Audited as agent.key.create.

Operation id: create_agent_key_route_v1_tenants__tenant_slug__agent_keys_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create an agent key.

Responses

StatusDescriptionBody
201Successful response for create an agent key.application/json AgentKeyCreated
404No such agent toolset in this tenant.—
409The tenant already has an API key with that name.—
422A tool name, the name or the expiry is not acceptable.—

GET /v1/tenants/{tenant_slug}/agent-keys/{key_id}​

Describe an agent key

Responses carry metadata only (name, prefix, toolset, allowlist, status, timestamps); the secret is returned once, by create, and never again. Revoked keys are described too, with status: revoked.

Requires api_keys:view.

Operation id: get_agent_key_route_v1_tenants__tenant_slug__agent_keys__key_id__get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for describe an agent key.application/json AgentKeyOut
404No such agent key in this tenant.—
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/tenants/{tenant_slug}/agent-keys/{key_id}​

Revoke an agent key

Revoke the key. The MCP runtime checks the key on every request, so the agent's next request is refused. Revoking a revoked key is a no-op 204; the key stays listable with includeRevoked=true.

Requires api_keys:delete. Audited once as agent.key.revoke.

Operation id: revoke_agent_key_route_v1_tenants__tenant_slug__agent_keys__key_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for revoke an agent key.—
404No such agent key in this tenant.—
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/agent-keys/{key_id}/allowlist​

Replace an agent key's tool allowlist

Replace the whole allowlist with toolAllowlist. The MCP runtime reads it on every request, so the agent's next tools/list shows the new set and its next tools/call is judged against it.

Requires api_keys:edit. Audited as agent.key.allowlist_update, with the list before and after.

Operation id: update_agent_key_allowlist_route_v1_tenants__tenant_slug__agent_keys__key_id__allowlist_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for replace an agent key's tool allowlist.

Responses

StatusDescriptionBody
200Successful response for replace an agent key's tool allowlist.application/json AgentKeyOut
404No such agent key in this tenant.—
409The key is revoked; its allowlist can no longer change.—
422An entry is not an MCP tool name.—

GET /v1/tenants/{tenant_slug}/agent-keys/{key_id}/usage​

Agent key usage vs caps

An agent key's limits and how much of them it has used today (AGX-3.2). Both limits come from the tenant's license tier and change when the tier changes: rps.cap is the sustained calls per second (burst of one second's worth), dailyCalls.cap the calls per UTC day. null means unlimited.

dailyCalls.used counts today's (UTC) tools/call invocations recorded for the key, without calls refused by a limit. It is the same number the agent usage rollups report for the key and day. Over either limit, the MCP agent runtime refuses calls with an agent_rate_limited / agent_daily_cap_reached error that says when to retry.

Revoked keys are reported too. Requires api_keys:view.

Operation id: get_agent_key_usage_route_v1_tenants__tenant_slug__agent_keys__key_id__usage_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for agent key usage vs caps.application/json AgentKeyUsageOut
404No such agent key in this tenant.—
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/agent-toolsets​

List agent toolsets

An agent toolset is Agent Access for one published version: which of its operations AI agents may call as MCP tools. Reads (GET/HEAD, GraphQL queries) are exposed by default; write operations are opt-in, one at a time, with an explicit confirmation.

Newest first, with tool counts. versionId narrows the list to one version's toolset.

Requires api_keys:view.

Operation id: list_agent_toolsets_route_v1_tenants__tenant_slug__agent_toolsets_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
versionIdquerystring (uuid) or nullnoQuery parameter: version id.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list agent toolsets.application/json AgentToolsetListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/agent-toolsets​

Create an agent toolset for a published version

An agent toolset is Agent Access for one published version: which of its operations AI agents may call as MCP tools. Reads (GET/HEAD, GraphQL queries) are exposed by default; write operations are opt-in, one at a time, with an explicit confirmation.

Creates the toolset for versionId, which must be a published, undeleted version in this tenant, and seeds one tool per callable operation: reads enabled (deprecated ones excepted), write operations disabled. target is prod (default) or mock; enabled defaults to true.

Requires api_keys:create. Audited as agent.toolset.create.

Operation id: create_agent_toolset_route_v1_tenants__tenant_slug__agent_toolsets_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create an agent toolset for a published version.

Responses

StatusDescriptionBody
201Successful response for create an agent toolset for a published version.application/json AgentToolsetDetail
404No such version in this tenant.—
409The version is unpublished or deleted, or already has a toolset.—
422The version's operations could not be read.—

GET /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}​

Describe an agent toolset

The toolset's settings and every tool row.

Requires api_keys:view.

Operation id: get_agent_toolset_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for describe an agent toolset.application/json AgentToolsetDetail
404No such agent toolset in this tenant.—
422Validation Errorapplication/json HTTPValidationError

PATCH /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}​

Change an agent toolset's settings

Switch the whole toolset on or off (enabled; a disabled toolset exposes no tools) and/or change its target (prod | mock), and/or opt out of description enrichment (descriptionEnrichment: false serves the spec-derived descriptions even where a proposal was accepted). Tool selections are untouched.

Requires api_keys:edit. Audited as agent.toolset.update, before and after.

Operation id: update_agent_toolset_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__patch

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for change an agent toolset's settings.

Responses

StatusDescriptionBody
200Successful response for change an agent toolset's settings.application/json AgentToolsetOut
404No such agent toolset in this tenant.—
422The body changes nothing.—

DELETE /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}​

Delete an agent toolset

Delete the toolset and its tool selections. Its upstream credentials and agent keys are deleted with it: an agent holding one of its keys is refused on its next request.

Requires api_keys:delete. Audited as agent.toolset.delete.

Operation id: delete_agent_toolset_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for delete an agent toolset.—
404No such agent toolset in this tenant.—
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/compiled​

Compile an agent toolset

The toolset as agents are served it: the enabled tools as MCP tools/list entries. While descriptionEnrichment is on, accepted description proposals replace the spec-derived text (enrichedTargets lists which); proposed and rejected ones never do. A disabled toolset compiles to no tools.

Requires api_keys:view.

Operation id: compile_agent_toolset_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__compiled_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for compile an agent toolset.application/json CompiledToolsetOut
404No such agent toolset in this tenant.—
422The version's operations could not be read or compiled.—

GET /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/enrichment​

Describe an agent toolset's enrichment

The enrichment pass looks for tools an agent will struggle with. Each flag lists machine-readable reasons: missing-description, thin-description, missing-examples, undocumented-errors, missing-parameter-description, thin-parameter-description. When the copilot (an Ollama model, APIOME_AGENT_ENRICHMENT_MODEL) is configured, it also proposes descriptions for the thin ones, written only from the spec's own documentation. Proposals are never served until a person accepts them. Without the copilot, mode is flag-only.

Requires api_keys:view.

Operation id: get_agent_toolset_enrichment_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__enrichment_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for describe an agent toolset's enrichment.application/json EnrichmentReport
404No such agent toolset in this tenant.—
422The version's operations could not be read.—

POST /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/enrichment​

Run the enrichment pass

The enrichment pass looks for tools an agent will struggle with. Each flag lists machine-readable reasons: missing-description, thin-description, missing-examples, undocumented-errors, missing-parameter-description, thin-parameter-description. When the copilot (an Ollama model, APIOME_AGENT_ENRICHMENT_MODEL) is configured, it also proposes descriptions for the thin ones, written only from the spec's own documentation. Proposals are never served until a person accepts them. Without the copilot, mode is flag-only.

The pass is idempotent: a description that already has a proposal, whatever its status, is not asked about again. Each run asks the copilot about at most 20 operations and reports remainingOperations; run it again to continue, or pass operations to choose which.

Requires api_keys:edit. Audited as agent.toolset.enrichment.run.

Operation id: run_agent_toolset_enrichment_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__enrichment_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (optional)

Request body for run the enrichment pass.

Responses

StatusDescriptionBody
200Successful response for run the enrichment pass.application/json EnrichmentRunResult
404No such agent toolset in this tenant.—
422The version's operations could not be read, or operations names an operation the toolset does not have.—

PATCH /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/enrichment/{proposal_id}​

Accept or reject a description proposal

decision: accept serves the proposal in the compiled toolset; pass description to serve an edited text instead. decision: reject withdraws it, including a previously accepted one. The reviewer and time are recorded on the proposal.

Requires api_keys:edit. Audited as agent.toolset.enrichment.review.

Operation id: review_agent_toolset_enrichment_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__enrichment__proposal_id__patch

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
proposal_idpathstring (uuid)yesPath parameter identifying the proposal id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for accept or reject a description proposal.

Responses

StatusDescriptionBody
200Successful response for accept or reject a description proposal.application/json EnrichmentProposalOut
404No such proposal in this tenant's agent toolset.—
422A blank or over-long edit, or an edit with reject.—

GET /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/tools​

List an agent toolset's tools

One row per callable operation of the toolset's version, ordered by operation key: the MCP tool name, whether it is a write op, and whether it is exposed.

Requires api_keys:view.

Operation id: list_agent_toolset_tools_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__tools_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list an agent toolset's tools.application/json AgentToolListResponse
404No such agent toolset in this tenant.—
422Validation Errorapplication/json HTTPValidationError

PATCH /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/tools/{tool_id}​

Enable or disable one tool

Set enabled on one tool. Enabling a write operation requires confirmWriteOp: true; without it the request is refused with agent-toolset-write-op-unconfirmed and nothing changes. The confirmation is recorded on the tool (writeConfirmedBy, writeConfirmedAt) and cleared when the tool is disabled, so re-enabling needs a fresh one.

Requires api_keys:edit. Audited as agent.toolset.tool.update.

Operation id: update_agent_toolset_tool_route_v1_tenants__tenant_slug__agent_toolsets__toolset_id__tools__tool_id__patch

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
tool_idpathstring (uuid)yesPath parameter identifying the tool id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for enable or disable one tool.

Responses

StatusDescriptionBody
200Successful response for enable or disable one tool.application/json AgentToolOut
404No such tool in this tenant's agent toolset.—
422A write operation was enabled without confirmWriteOp: true.—

GET /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/upstream-credentials​

List a toolset's upstream credentials (metadata only)

The credentials the AGX-2.1 invocation proxy injects when this toolset calls its upstream APIs.

A credential is write-only: the secret is stored envelope-encrypted and no route ever returns it. Responses carry metadata only: the server URL it is bound to, its kind and placement, the master-key version that sealed it, whether it currently opens (readable), and when it was created, rotated and last used.

Requires api_keys:view.

Operation id: list_upstream_credentials_v1_tenants__tenant_slug__agent_toolsets__toolset_id__upstream_credentials_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list a toolset's upstream credentials (metadata only).application/json UpstreamCredentialListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/upstream-credentials​

Store an upstream credential for a toolset

Bind a new credential to this toolset and one upstream server. The credential is only ever injected into requests under serverUrl: an https:// origin plus an optional base path. https://api.example.com/v1 covers /v1 and /v1/… on that exact host and port, and nothing else.

Kinds: apiKey (sent as the header or query parameter named by in / name, secret {value}), bearer (Authorization: Bearer, secret {token}) and basic (Authorization: Basic, secret {username, password}).

A credential is write-only: the secret is stored envelope-encrypted and no route ever returns it. Responses carry metadata only: the server URL it is bound to, its kind and placement, the master-key version that sealed it, whether it currently opens (readable), and when it was created, rotated and last used.

One credential per toolset and server: storing a second is a 409; rotate the existing one instead.

Requires api_keys:create. Audited as agent.upstream_credential.create, with metadata only.

Operation id: create_upstream_credential_v1_tenants__tenant_slug__agent_toolsets__toolset_id__upstream_credentials_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for store an upstream credential for a toolset.

Responses

StatusDescriptionBody
201Successful response for store an upstream credential for a toolset.application/json UpstreamCredentialOut
404No such agent toolset in this tenant.—
409This toolset already has a credential for that server.—
422The server URL, placement or secret is not acceptable.—
503No upstream-credential encryption key is configured.—

DELETE /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/upstream-credentials/{credential_id}​

Delete an upstream credential

Remove the credential. The toolset's next call to that server goes out without it. Its use history is kept.

Requires api_keys:delete. Audited as agent.upstream_credential.delete.

Operation id: delete_upstream_credential_v1_tenants__tenant_slug__agent_toolsets__toolset_id__upstream_credentials__credential_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
credential_idpathstring (uuid)yesPath parameter identifying the credential id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for delete an upstream credential.—
404No such credential for this toolset.—
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/agent-toolsets/{toolset_id}/upstream-credentials/{credential_id}/rotate​

Rotate an upstream credential's secret

Replace the secret in place, atomically. The credential keeps its id, binding and placement. Invocations already in flight finish with the secret they opened, and the next invocation uses the new one: no window without a credential.

The body is {secret}, in the same shape as at creation. A credential is write-only: the secret is stored envelope-encrypted and no route ever returns it. Responses carry metadata only: the server URL it is bound to, its kind and placement, the master-key version that sealed it, whether it currently opens (readable), and when it was created, rotated and last used.

Requires api_keys:edit. Audited as agent.upstream_credential.rotate.

Operation id: rotate_upstream_credential_v1_tenants__tenant_slug__agent_toolsets__toolset_id__upstream_credentials__credential_id__rotate_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
toolset_idpathstring (uuid)yesPath parameter identifying the toolset id segment.
credential_idpathstring (uuid)yesPath parameter identifying the credential id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for rotate an upstream credential's secret.

Responses

StatusDescriptionBody
200Successful response for rotate an upstream credential's secret.application/json UpstreamCredentialOut
404No such credential for this toolset.—
422The secret does not fit the credential's kind.—
503No upstream-credential encryption key is configured.—

GET /v1/tenants/{tenant_slug}/agent-usage​

Agent usage rollups

The tenant's agent tools/call usage over the last days UTC days, today included, from the daily rollups: daily (zero-filled, oldest first), tools and agents (most calls first) and totals with errors broken down by outcome.

errors counts every call that did not succeed, quota rejections included. Latency is the calls-weighted mean (latencyAvgMs) and the worst p95 among the rollup groups covered (latencyP95MaxMs); percentiles cannot be merged exactly.

days is 1–366 (default 30). Requires api_keys:view.

Operation id: get_agent_usage_route_v1_tenants__tenant_slug__agent_usage_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
daysqueryintegernoQuery parameter: days.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for agent usage rollups.application/json AgentUsageOut
422Validation Errorapplication/json HTTPValidationError

Schemas used​

AgentKeyAllowlistUpdate​

Body of PUT /v1/tenants/{t}/agent-keys/{id}/allowlist: the whole new list.

PropertyTypeRequiredDescription
toolAllowlistarray of stringyesTool Allowlist.

AgentKeyCreate​

Body of POST /v1/tenants/{t}/agent-keys.

Attributes: name: Human name, unique in the tenant (across workspace and agent keys, revoked included). description: Optional purpose note. toolset_id: The agent toolset the key is bound to. tool_allowlist: MCP tool names the key may list and call. expires_at: Optional expiry; must be in the future. A naive value is read as UTC.

PropertyTypeRequiredDescription
namestringyesHuman-readable name.
descriptionstring or nullnoFree-text description.
toolsetIdstring (uuid)yesToolset ID.
toolAllowlistarray of stringyesTool Allowlist.
expiresAtstring (date-time) or nullnoExpires At.

AgentKeyCreated​

The create response: the key's metadata plus its plaintext secret, shown this once.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
idstringyesStable resource identifier.
kind"agent"noKind.
namestringyesHuman-readable name.
descriptionstring or nullnoFree-text description.
keyPrefixstringyesKey Prefix.
toolsetIdstringyesToolset ID.
toolAllowlistarray of stringyesTool Allowlist.
statusenum "active", "disabled", "expired", "revoked"yesStatus.
enabledbooleanyesWhether the resource is active.
expiresAtstring (date-time) or nullnoExpires At.
revokedAtstring (date-time) or nullnoRevoked At.
lastUsedAtstring (date-time) or nullnoLast Used At.
createdAtstring (date-time)yesCreated At.
updatedAtstring (date-time) or nullnoUpdated At.
createdBystring or nullnoCreated By.
secretstringyesThe agent key. Shown only in this response; store it now.

AgentKeyListResponse​

A tenant's agent keys, described.

Attributes: schema_version: The projection's shape. keys: One entry per key, newest first.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
keysarray of AgentKeyOutyesKeys.

AgentKeyOut​

An agent key, described. Never carries the secret or its hash.

Attributes: schema_version: The projection's shape. id: The key id. kind: Always agent. name: Human name. description: Purpose note, if any. key_prefix: The first 12 characters of the secret plus ..., for recognising it. toolset_id: The toolset the key is bound to. tool_allowlist: The tool names it may use, sorted. status: active, disabled, expired or revoked (see :func:key_status). enabled: The key's enabled flag. expires_at: When it stops working, if ever. revoked_at: When it was revoked, if it was. last_used_at: When it last authenticated, if ever. created_at: When it was created. updated_at: When its row last changed. created_by: The user who created it, if known.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
idstringyesStable resource identifier.
kind"agent"noKind.
namestringyesHuman-readable name.
descriptionstring or nullnoFree-text description.
keyPrefixstringyesKey Prefix.
toolsetIdstringyesToolset ID.
toolAllowlistarray of stringyesTool Allowlist.
statusenum "active", "disabled", "expired", "revoked"yesStatus.
enabledbooleanyesWhether the resource is active.
expiresAtstring (date-time) or nullnoExpires At.
revokedAtstring (date-time) or nullnoRevoked At.
lastUsedAtstring (date-time) or nullnoLast Used At.
createdAtstring (date-time)yesCreated At.
updatedAtstring (date-time) or nullnoUpdated At.
createdBystring or nullnoCreated By.

AgentKeyUsageOut​

An agent key's current usage against its license-tier caps.

Attributes: schema_version: The projection's shape. key_id: The key. license_type: The tenant's license tier (free / paid / sponsor), or None without a license (Free caps apply). rps: The rate limit. daily_calls: The daily cap and today's usage. as_of: When this was computed.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
keyIdstringyesKey ID.
licenseTypestring or nullnoLicense Type.
rpsAgentKeyRateLimityesRps.
dailyCallsAgentKeyDailyCallsyesDaily Calls.
asOfstring (date-time)yesAs Of.

AgentToolListResponse​

A toolset's tool rows.

Attributes: schema_version: The projection's shape. toolset_id: The toolset addressed. tools: One entry per callable operation, ordered by operation key.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetIdstringyesToolset ID.
toolsarray of AgentToolOutyesTools.

AgentToolOut​

One operation's exposure decision.

Attributes: id: The tool row id (what the update route addresses). operation: The canonical operation key (GET /pets/{id}). tool_name: The MCP tool name agents see. write_op: Whether the operation mutates. A write op is opt-in. enabled: Whether agents may list and call it. write_confirmed_at: When enabling this write op was confirmed (only while enabled). write_confirmed_by: Who confirmed it. updated_at: When the row last changed. updated_by: Who last changed it.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
operationstringyesHTTP method name (GET, POST, PUT, PATCH, DELETE, …).
toolNamestringyesTool Name.
writeOpbooleanyesWrite Op.
enabledbooleanyesWhether the resource is active.
writeConfirmedAtstring (date-time) or nullnoWrite Confirmed At.
writeConfirmedBystring or nullnoWrite Confirmed By.
updatedAtstring (date-time) or nullnoUpdated At.
updatedBystring or nullnoUpdated By.

AgentToolUpdate​

Body of PATCH /v1/tenants/{t}/agent-toolsets/{id}/tools/{toolId}.

Attributes: enabled: Expose the operation to agents, or stop exposing it. confirm_write_op: Must be true to enable a write op. It is ignored when disabling, and when enabling a read.

PropertyTypeRequiredDescription
enabledbooleanyesWhether the resource is active.
confirmWriteOpbooleannoConfirm Write Op.

AgentToolsetCreate​

Body of POST /v1/tenants/{t}/agent-toolsets.

Attributes: version_id: The published version (versions.id) to give Agent Access. enabled: Whether the toolset serves agents straight away (default True). target: prod (default) or mock.

PropertyTypeRequiredDescription
versionIdstring (uuid)yesVersion ID.
enabledbooleannoWhether the resource is active.
targetenum "prod", "mock"noTarget.

AgentToolsetDetail​

A toolset with every tool row, ordered by operation key.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
idstringyesStable resource identifier.
versionIdstringyesVersion ID.
projectIdstringyesProject ID.
versionLabelstring or nullnoVersion Label.
enabledbooleanyesWhether the resource is active.
targetenum "prod", "mock"yesTarget.
descriptionEnrichmentbooleannoDescription Enrichment.
toolCountintegeryesNumber of tool.
enabledToolCountintegeryesNumber of enabled tool.
enabledWriteOpCountintegeryesNumber of enabled write op.
createdAtstring (date-time)yesCreated At.
updatedAtstring (date-time) or nullnoUpdated At.
createdBystring or nullnoCreated By.
updatedBystring or nullnoUpdated By.
toolsarray of AgentToolOutyesTools.

AgentToolsetListResponse​

A tenant's toolsets, described.

Attributes: schema_version: The projection's shape. toolsets: One entry per toolset, newest first.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetsarray of AgentToolsetOutyesToolsets.

AgentToolsetOut​

A toolset, described with its tool counts.

Attributes: schema_version: The projection's shape. id: The toolset id (what agent keys and upstream credentials bind to). version_id: The published version it exposes. project_id: That version's project. version_label: The version's label (1.0.0). enabled: Whether it serves agents at all. target: prod or mock. description_enrichment: Whether accepted description-enrichment proposals are served (AGX-1.3). False serves the spec-derived descriptions unchanged. tool_count: Callable operations in the version. enabled_tool_count: How many of them are exposed. enabled_write_op_count: How many exposed ones are write ops. created_at: When it was created. updated_at: When its settings last changed. created_by: Who created it. updated_by: Who last changed its settings.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
idstringyesStable resource identifier.
versionIdstringyesVersion ID.
projectIdstringyesProject ID.
versionLabelstring or nullnoVersion Label.
enabledbooleanyesWhether the resource is active.
targetenum "prod", "mock"yesTarget.
descriptionEnrichmentbooleannoDescription Enrichment.
toolCountintegeryesNumber of tool.
enabledToolCountintegeryesNumber of enabled tool.
enabledWriteOpCountintegeryesNumber of enabled write op.
createdAtstring (date-time)yesCreated At.
updatedAtstring (date-time) or nullnoUpdated At.
createdBystring or nullnoCreated By.
updatedBystring or nullnoUpdated By.

AgentToolsetUpdate​

Body of PATCH /v1/tenants/{t}/agent-toolsets/{id}. At least one field is required.

Attributes: enabled: Switch the whole toolset on or off. target: prod or mock. description_enrichment: Serve accepted description-enrichment proposals (AGX-1.3), or opt out and serve the spec-derived descriptions unchanged.

PropertyTypeRequiredDescription
enabledboolean or nullnoWhether the resource is active.
targetenum "prod", "mock" or nullnoTarget.
descriptionEnrichmentboolean or nullnoDescription Enrichment.

AgentUsageOut​

A tenant's agent usage over a window of UTC days.

Attributes: schema_version: The projection's shape. start_day: First UTC day of the window (inclusive). end_day: Last UTC day of the window (inclusive; today). days: Window length in days. totals: The whole window. daily: One entry per day, oldest first, zero-filled. tools: One entry per tool that was called, most calls first. agents: One entry per agent key that called, most calls first. as_of: When this was computed.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
startDaystring (date)yesStart Day.
endDaystring (date)yesEnd Day.
daysintegeryesDays.
totalsAgentUsageTotalsyesTotals.
dailyarray of AgentUsageDayyesDaily.
toolsarray of AgentUsageToolyesTools.
agentsarray of AgentUsageAgentyesAgents.
asOfstring (date-time)yesAs Of.

CompiledToolsetOut​

The toolset as agents are served it: enabled tools, accepted descriptions applied.

Attributes: schema_version: The projection's shape. toolset_id: The toolset. version_id: Its published version. enabled: Whether the toolset serves agents (a disabled one compiles to no tools). description_enrichment: Whether accepted proposals were applied. enriched_targets: The target keys whose accepted text was applied. fingerprint: The compiled toolset's content hash. tools: The MCP tools/list entries, in canonical order.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetIdstringyesToolset ID.
versionIdstringyesVersion ID.
enabledbooleanyesWhether the resource is active.
descriptionEnrichmentbooleanyesDescription Enrichment.
enrichedTargetsarray of stringyesEnriched Targets.
fingerprintstringyesFingerprint.
toolsarray of objectyesTools.

EnrichmentProposalOut​

One description proposal and its review.

Attributes: id: The proposal id (what the review route addresses). operation: The operation the description belongs to. target_kind: tool or parameter. target_key: The operation key, or the canonical parameter key. parameter: For a parameter, its location.name label. original_description: The spec's description when the proposal was made. proposed_description: What the copilot proposed. Never served as is. model: The model that proposed it. status: proposed, accepted or rejected. accepted_description: The text served once accepted (the proposal or an edit of it). reviewed_by: Who accepted or rejected it. reviewed_at: When. created_at: When it was proposed.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
operationstringyesHTTP method name (GET, POST, PUT, PATCH, DELETE, …).
targetKindenum "tool", "parameter"yesTarget Kind.
targetKeystringyesTarget Key.
parameterstring or nullnoParameter.
originalDescriptionstring or nullnoOriginal Description.
proposedDescriptionstringyesProposed Description.
modelstringyesModel.
statusenum "proposed", "accepted", "rejected"yesStatus.
acceptedDescriptionstring or nullnoAccepted Description.
reviewedBystring or nullnoReviewed By.
reviewedAtstring (date-time) or nullnoReviewed At.
createdAtstring (date-time) or nullnoCreated At.

EnrichmentReport​

A toolset's enrichment state: flags, proposals and whether the copilot is on.

Attributes: schema_version: The projection's shape. toolset_id: The toolset. description_enrichment: Whether accepted proposals are served. mode: copilot when a model is configured, else flag-only. model: The configured model, if any. flags: The agent-hostile tools, ordered by operation key. proposals: Every proposal, ordered by operation. counts: flagged tools and proposals by status.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetIdstringyesToolset ID.
descriptionEnrichmentbooleanyesDescription Enrichment.
modeenum "copilot", "flag-only"yesMode.
modelstring or nullnoModel.
flagsarray of EnrichmentFlagOutyesFlags.
proposalsarray of EnrichmentProposalOutyesProposals.
countsmap of integeryesCounts.

EnrichmentReview​

Body of PATCH …/agent-toolsets/{id}/enrichment/{proposalId}.

Attributes: decision: accept serves the description; reject withdraws it. description: With accept, an edited text to serve instead of the proposal.

PropertyTypeRequiredDescription
decisionenum "accept", "reject"yesDecision.
descriptionstring or nullnoFree-text description.

EnrichmentRun​

Body of POST …/agent-toolsets/{id}/enrichment. Every field is optional.

Attributes: operations: Only ask about these operation keys (GET /pets). Default: every operation with an undescribed target, in canonical order.

PropertyTypeRequiredDescription
operationsarray of string or nullnoOperations.

EnrichmentRunResult​

What one run of the pass did, plus the resulting report.

Attributes: generated: Proposals stored by this run. attempted_operations: Operations the copilot was asked about. failed_operations: Of those, how many got no usable answer (unreachable model, bad reply). remaining_operations: Operations with undescribed targets left for a later run.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetIdstringyesToolset ID.
descriptionEnrichmentbooleanyesDescription Enrichment.
modeenum "copilot", "flag-only"yesMode.
modelstring or nullnoModel.
flagsarray of EnrichmentFlagOutyesFlags.
proposalsarray of EnrichmentProposalOutyesProposals.
countsmap of integeryesCounts.
generatedintegeryesGenerated.
attemptedOperationsintegeryesAttempted Operations.
failedOperationsintegeryesFailed Operations.
remainingOperationsintegeryesRemaining Operations.

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

UpstreamCredentialCreate​

Body for storing a new upstream credential.

Attributes: server_url: The only upstream the credential will be sent to. kind: apiKey, bearer or basic. api_key_in: apiKey only: header or query. api_key_name: apiKey only: the header or query-parameter name. secret: The secret material. Sealed on arrival and never returned.

PropertyTypeRequiredDescription
serverUrlstringyesThe upstream server this credential is bound to: an https:// origin plus an optional base path, e.g. https://api.example.com/v1. The credential is only injected into requests under this URL.
kindenum "apiKey", "bearer", "basic"yesHow the secret is presented, in OpenAPI security-scheme terms.
inenum "header", "query" or nullnoapiKey only: send the key as a header or a query parameter.
namestring or nullnoapiKey only: the header or query-parameter name, e.g. X-Api-Key.
secretUpstreamSecretInputyesWrite-only secret material: {value} for apiKey, {token} for bearer, {username, password} for basic. Stored encrypted; never returned by any route.

UpstreamCredentialListResponse​

A toolset's upstream credentials, described.

Attributes: schema_version: The projection's shape. toolset_id: The toolset addressed. encryption_configured: Whether this deployment can store credentials at all. kinds: The credential kinds the vault accepts. api_key_locations: Where an apiKey credential may be sent. credentials: One entry per stored credential, by server URL.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
toolsetIdstringyesToolset ID.
encryptionConfiguredbooleanyesEncryption Configured.
kindsarray of stringyesKinds.
apiKeyLocationsarray of stringyesAPI Key Locations.
credentialsarray of UpstreamCredentialOutyesCredentials.

UpstreamCredentialOut​

A stored credential, described without being revealed.

Attributes: schema_version: The projection's shape. id: The credential id. toolset_id: The agent toolset it serves. server_url: The only upstream it is sent to. kind: apiKey, bearer or basic. api_key_in: apiKey only: header or query. api_key_name: apiKey only: the header or parameter name. key_version: Which master key sealed the secret. readable: Whether the secret can be opened with the keys configured now. False means the credential is present but unusable: every call through it would fail closed. created_at: When it was stored. created_by: Who stored it. rotated_at: When its secret was last replaced, or None. rotated_by: Who last replaced it. last_used_at: When it was last injected into a request, or None.

PropertyTypeRequiredDescription
schemaVersionstringnoSchema Version.
idstringyesStable resource identifier.
toolsetIdstringyesToolset ID.
serverUrlstringyesServer URL.
kindstringyesKind.
instring or nullnoIn.
namestring or nullnoHuman-readable name.
keyVersioninteger or nullnoKey Version.
readablebooleannoReadable.
createdAtstring (date-time) or nullnoCreated At.
createdBystring or nullnoCreated By.
rotatedAtstring (date-time) or nullnoRotated At.
rotatedBystring or nullnoRotated By.
lastUsedAtstring (date-time) or nullnoLast Used At.

UpstreamCredentialRotate​

Body for rotating a credential's secret in place.

Attributes: secret: The replacement secret. Must have the fields the credential's kind needs.

PropertyTypeRequiredDescription
secretUpstreamSecretInputyesThe replacement secret, in the same shape as at creation.