Skip to content

API reference

  • Versioned under /v1, JSON over HTTPS.
  • Authentication with OIDC sessions or scoped API tokens; every route declares the permission it needs (see RBAC).
  • Resources: agents, runs and steps, events and sources, connections, policies, audit (read, verify, export), costs, users, tokens, settings.
  • Run steps stream over Server-Sent Events.

Workers talk to the control node with a signed run token (Authorization: Bearer oaxrt.…): POST /v1/worker/runs/{runId}/gate before every tool call, …/steps to report steps, …/approvals for approval requests, GET …/status and POST …/complete. See Control node and worker nodes.