REST API

Endpoint index

Every route in the published contract, grouped the way the API groups them, each pointing at the page that explains it.

Every route in the published contract, grouped the way the OpenAPI document groups them, with the page that explains each one. Paths are shown in their /v1 form, which is the one to build against. Each also exists unversioned for the clients already written that way, except where a row says otherwise.

The same list is machine-readable, so you can generate a client rather than hand-write one:

curl https://api.engramdynamics.org/openapi.json -o engram-openapi.json

It is browsable at /docs. To check what a particular key is allowed to reach, call something harmless with it and read the refusal:

curl -i https://api.engramdynamics.org/v1/corpora   -H "Authorization: Bearer <your key>" 

A 200 means the credential is live. A 403 names the scope it is missing, and a 401 means the key is revoked, expired or mistyped.

Service and versions

MethodPathWhat it doesExplained on
GET/Which contracts this deployment servesOverview
GET/v1The version document, with any scheduled deprecationsOverview
GET/v1/statusPublic service statusConventions
GET/v1/status/sloPublished service objectives and how we are trackingConventions

Document bases

MethodPathWhat it doesExplained on
POST/v1/corporaCreate a document baseDocument bases
GET/v1/corporaList document bases, paginatedDocument bases
GET/v1/corpora/{id}One base, with its readiness countsDocument bases
DELETE/v1/corpora/{id}Delete a base and everything in itDocument bases
POST/v1/corpora/{id}/documentsUpload files as multipart form dataDocuments and ingest
GET/v1/corpora/{id}/documentsList documents, paginatedDocuments and ingest
DELETE/v1/corpora/{id}/documents/{doc_id}Delete one document everywhereDocuments and ingest
POST/v1/corpora/{id}/importImport a connected Drive or SharePoint folderGoogle Drive
GET/v1/corpora/{id}/import-statusLatest import run for this baseGoogle Drive

Documents and ingest

MethodPathWhat it doesExplained on
POST/v1/corpora/{id}/documents/diffAsk which files are new, changed, unchanged or missingDocuments and ingest
POST/v1/corpora/{id}/documents/upload-urlsGet presigned PUT URLs for a manifestDocuments and ingest
PUT/v1/corpora/{id}/documents/rawUpload one file body (used where presigning is not available)Documents and ingest
POST/v1/corpora/{id}/documents/commitRegister the manifest and start the workDocuments and ingest
POST/v1/corpora/{id}/documents/upsertWrite one document by path, content includedDocuments and ingest
GET/v1/corpora/{id}/sync-runsIngestion history for this baseDocuments and ingest
GET/v1/corpora/{id}/sync-runs/{run_id}One ingestion run and its countersDocuments and ingest

Onboarding and jobs

MethodPathWhat it doesExplained on
POST/v1/corpora/{id}/trainStart onboardingOnboarding and jobs
POST/v1/corpora/{id}/cancelCancel the run in flightOnboarding and jobs
POST/v1/corpora/{id}/describeRegenerate the base's catalog descriptionOnboarding and jobs
GET/v1/jobs/{job_id}One job, with progress and estimateOnboarding and jobs
GET/v1/corpora/{id}/jobsThe run and its batches, newest firstOnboarding and jobs

Answers, MCP and feedback

MethodPathWhat it doesExplained on
POST/v1/corpora/{id}/chatAsk a question, get an answer with sourcesAnswers and chat
POST/v1/corpora/{id}/chat/streamThe same, streamed as server-sent eventsAnswers and chat
POST/v1/mcp/{id}/queryAsk, with sources attributed by pinnable doc idAnswers and chat
GET/v1/mcp/{id}/metaBase identity, status and catalog descriptionTools reference
GET/v1/mcp/{id}/documentsThe base's document inventoryTools reference
POST/corpora/{id}/feedbackRate an answer. Unversioned path onlyAnswers and chat

Sources

MethodPathWhat it doesExplained on
POST/v1/corpora/{id}/sourcesRegister a bucket, Drive folder or SharePoint librarySources
GET/v1/corpora/{id}/sourcesThe sources feeding this baseSources
PUT/v1/corpora/{id}/sources/{source_id}Change a source's inventory configurationAmazon S3 buckets
DELETE/v1/corpora/{id}/sources/{source_id}Stop pulling from a sourceSources
POST/v1/corpora/{id}/sources/{source_id}/validateRe-check access and report what it sawAmazon S3 buckets
POST/v1/corpora/{id}/sources/{source_id}/syncPull now, and return the run to watchSources
GET/v1/sources/s3/setupRender the IAM templates for one sourceAmazon S3 buckets
POST/v1/corpora/{id}/upload-credentialsAn hour of S3 credentials scoped to this baseSources
GET/v1/platform/infoRegion, egress guidance, accepted file types. PublicWhat counts as a document

Webhooks

MethodPathWhat it doesExplained on
POST/v1/webhooksSubscribe an endpoint and receive its signing secretSubscribe an endpoint
GET/v1/webhooksThe workspace's endpoints and their last deliverySubscribe an endpoint
DELETE/v1/webhooks/{webhook_id}UnsubscribeSubscribe an endpoint

Keys, sign-on and network

MethodPathWhat it doesExplained on
POST/v1/api-keysMint a key. The secret is shown onceOverview and authentication
GET/v1/api-keysThe workspace's keys, revoked ones includedAPI keys and scopes
DELETE/v1/api-keys/{key_id}Revoke a key, effective on the next requestAPI keys and scopes
GET/v1/enterprise/ssoRead the single sign-on configurationSingle sign-on
PUT/v1/enterprise/ssoConfigure single sign-onSingle sign-on
DELETE/v1/enterprise/ssoTurn single sign-on offSingle sign-on
POST/v1/enterprise/sso/testTest the configuration before enforcing itSingle sign-on
GET/v1/enterprise/ip-allowlistRead the workspace IP allowlistIP allowlist
PUT/v1/enterprise/ip-allowlistSet the workspace IP allowlistIP allowlist
GET/v1/enterprise/kms-keyRead the customer-managed encryption keyYour own KMS key
PUT/v1/enterprise/kms-keySet the customer-managed encryption keyYour own KMS key

Audit, exports and erasure

MethodPathWhat it doesExplained on
GET/v1/auditThe append-only audit trailAudit log
GET/v1/audit/deletionsDeletion receipts, tier by tierData lifecycle and deletion
GET/v1/audit/exportDownload the audit logExports
GET/v1/usage/exportDownload usage for the workspaceExports
GET/v1/platform/erasure-timelineHow long each copy of a deleted document livesData lifecycle and deletion

Plans, billing and legal

MethodPathWhat it doesExplained on
GET/v1/plansThe published plans and what each includesPlans and allowances
GET/v1/billing/statusThis workspace's plan, subscription state and entitlementsPlans and allowances
POST/v1/billing/checkoutStart checkout for a planCheckout and portal
POST/v1/billing/portalOpen the billing portalCheckout and portal
POST/v1/billing/change-planMove between plansCheckout and portal
GET/v1/legal/statusWhich agreements this workspace has acceptedTerms and DPA acceptance
POST/v1/legal/acceptAccept the current version of an agreementTerms and DPA acceptance
GET/v1/legal/{document}Read an agreement. PublicTerms and DPA acceptance
GET/v1/legal/{document}/receiptThe acceptance receipt for an agreementTerms and DPA acceptance

Accounts

MethodPathWhat it doesExplained on
POST/v1/auth/loginSign in and receive a session tokenSecurity overview
POST/v1/auth/registerCreate an account and a workspaceYour first document base
GET/v1/auth/meThe signed-in user and their workspaceSecurity overview
GET/v1/auth/configWhich sign-in methods this workspace allowsSingle sign-on
POST/v1/auth/sso/startBegin a single sign-on loginSingle sign-on
POST/v1/auth/forgot-passwordSend a reset linkSecurity overview
POST/v1/auth/reset-passwordComplete a resetSecurity overview
POST/v1/auth/resend-verificationResend the email confirmation linkSecurity overview
POST/v1/auth/invite-infoRead an invite before accepting itSecurity overview
POST/v1/auth/accept-inviteJoin a workspace from an inviteSecurity overview

What is not in this index

Some routes exist on the service and are deliberately left out here, because building against them would be building against something that is allowed to move:

Next

If you are wiring an agent rather than a backend, start at MCP. If you want to be told when work finishes rather than polling for it, start at Webhooks.