API reference
What to expect
Section titled “What to expect”- Versioned under
/v1, JSON over HTTPS. - Authentication with OIDC sessions or scoped API tokens; every route declares the permission it needs (see RBAC).
- Resources: agents, runs and steps, events and sources, connections, policies, audit (read, verify, export), costs, users, tokens, settings.
- Run steps stream over Server-Sent Events.
Worker endpoints
Section titled “Worker endpoints”Workers talk to the control node with a signed run token
(Authorization: Bearer oaxrt.…): POST /v1/worker/runs/{runId}/gate before every tool call,
…/steps to report steps, …/approvals for approval requests, GET …/status and
POST …/complete. See Control node and worker nodes.