REST API
Endpoint index
Every route in the published contract, grouped the way the API groups them, each pointing at the page that explains it.
Every route in the published contract, grouped the way the OpenAPI document groups them, with the
page that explains each one. Paths are shown in their /v1 form, which is the one to
build against. Each also exists unversioned for the clients already written that way, except where a
row says otherwise.
The same list is machine-readable, so you can generate a client rather than hand-write one:
curl https://api.engramdynamics.org/openapi.json -o engram-openapi.json
It is browsable at /docs. To check what a
particular key is allowed to reach, call something harmless with it and read the refusal:
curl -i https://api.engramdynamics.org/v1/corpora -H "Authorization: Bearer <your key>"
A 200 means the credential is live. A 403 names the scope it is missing, and a 401 means the key
is revoked, expired or mistyped.
Service and versions
| Method | Path | What it does | Explained on |
GET | / | Which contracts this deployment serves | Overview |
GET | /v1 | The version document, with any scheduled deprecations | Overview |
GET | /v1/status | Public service status | Conventions |
GET | /v1/status/slo | Published service objectives and how we are tracking | Conventions |
Document bases
| Method | Path | What it does | Explained on |
POST | /v1/corpora | Create a document base | Document bases |
GET | /v1/corpora | List document bases, paginated | Document bases |
GET | /v1/corpora/{id} | One base, with its readiness counts | Document bases |
DELETE | /v1/corpora/{id} | Delete a base and everything in it | Document bases |
POST | /v1/corpora/{id}/documents | Upload files as multipart form data | Documents and ingest |
GET | /v1/corpora/{id}/documents | List documents, paginated | Documents and ingest |
DELETE | /v1/corpora/{id}/documents/{doc_id} | Delete one document everywhere | Documents and ingest |
POST | /v1/corpora/{id}/import | Import a connected Drive or SharePoint folder | Google Drive |
GET | /v1/corpora/{id}/import-status | Latest import run for this base | Google Drive |
Documents and ingest
| Method | Path | What it does | Explained on |
POST | /v1/corpora/{id}/documents/diff | Ask which files are new, changed, unchanged or missing | Documents and ingest |
POST | /v1/corpora/{id}/documents/upload-urls | Get presigned PUT URLs for a manifest | Documents and ingest |
PUT | /v1/corpora/{id}/documents/raw | Upload one file body (used where presigning is not available) | Documents and ingest |
POST | /v1/corpora/{id}/documents/commit | Register the manifest and start the work | Documents and ingest |
POST | /v1/corpora/{id}/documents/upsert | Write one document by path, content included | Documents and ingest |
GET | /v1/corpora/{id}/sync-runs | Ingestion history for this base | Documents and ingest |
GET | /v1/corpora/{id}/sync-runs/{run_id} | One ingestion run and its counters | Documents and ingest |
Onboarding and jobs
Answers, MCP and feedback
| Method | Path | What it does | Explained on |
POST | /v1/corpora/{id}/chat | Ask a question, get an answer with sources | Answers and chat |
POST | /v1/corpora/{id}/chat/stream | The same, streamed as server-sent events | Answers and chat |
POST | /v1/mcp/{id}/query | Ask, with sources attributed by pinnable doc id | Answers and chat |
GET | /v1/mcp/{id}/meta | Base identity, status and catalog description | Tools reference |
GET | /v1/mcp/{id}/documents | The base's document inventory | Tools reference |
POST | /corpora/{id}/feedback | Rate an answer. Unversioned path only | Answers and chat |
Sources
| Method | Path | What it does | Explained on |
POST | /v1/corpora/{id}/sources | Register a bucket, Drive folder or SharePoint library | Sources |
GET | /v1/corpora/{id}/sources | The sources feeding this base | Sources |
PUT | /v1/corpora/{id}/sources/{source_id} | Change a source's inventory configuration | Amazon S3 buckets |
DELETE | /v1/corpora/{id}/sources/{source_id} | Stop pulling from a source | Sources |
POST | /v1/corpora/{id}/sources/{source_id}/validate | Re-check access and report what it saw | Amazon S3 buckets |
POST | /v1/corpora/{id}/sources/{source_id}/sync | Pull now, and return the run to watch | Sources |
GET | /v1/sources/s3/setup | Render the IAM templates for one source | Amazon S3 buckets |
POST | /v1/corpora/{id}/upload-credentials | An hour of S3 credentials scoped to this base | Sources |
GET | /v1/platform/info | Region, egress guidance, accepted file types. Public | What counts as a document |
Webhooks
Keys, sign-on and network
Audit, exports and erasure
Plans, billing and legal
Accounts
What is not in this index
Some routes exist on the service and are deliberately left out here, because building against them
would be building against something that is allowed to move:
- Our operations. Platform administration, the serving-hardware controls, the
internal job callbacks and the Prometheus metrics endpoint. None of them belong to a
workspace.
- Payment and email receivers. The Stripe and email-event webhook endpoints are
called by those providers, never by you.
- The console's own surfaces. The onboarding wizard, the connector browse and
picker routes, the model catalog, member and invite administration, and the comparison and
economics demos. They change with the app, so they are not published as a contract. What they do
is reachable another way: connectors through Sources, members and
invites through the app.
Next
If you are wiring an agent rather than a backend, start at MCP. If you want
to be told when work finishes rather than polling for it, start at
Webhooks.