API Reference
Every route below is registered in registerRoutes (grpc/operators/core/internal/console/console.go) and served by the console on the same origin as the Flutter app. The auth class of each was checked in its handler.
Auth classes
- session: a console session cookie (
requireSession). Without one the answer is401 {"error":"unauthorized"}. - admin (LIST): a session plus
adminRefusalagainst that allowlist. The answer is 403 with the refusal sentence. See Trust & access. - App token: a bearer GitHub App token carrying the App’s rights for the console’s org (
authorizeReporter). A missing bearer is401 {"error":"missing bearer token"}. - ingest token: a shared machine secret. Unset means the door refuses everything.
Most report GETs answer 200 even when their source is unreadable, and say so in the body (source:"unavailable", complete:false, unmeasured[]). GET /api/connections and GET /api/runners are the exceptions. Both answer 503 with the report in the body.
Models, agents, inference
| Route | Method | Auth | Purpose |
|---|---|---|---|
/api/models | GET | session | model cards joined with live tier state, a health verdict, token use and tenant compute units |
/api/inference | GET | session | the inference plane as deployed (engine, model, quantization, context, memory, OOM history) plus the persisted benchmark |
/api/agents | GET | session | the 17-entry agent roster and the inference tiers, including the inference.router block |
/api/agent-config | GET | session | app agents’ ini settings and OpenBias rules, read from each repo’s HEAD |
/api/swarm | GET | session | fleet health, roster and run/latency rollup across apps |
/api/agent-schedules | GET | session | fleet cadence and enablement, and what of it is editable |
/api/agent-schedules/{name} | PUT | admin (CONSOLE_AGENT_ADMINS) | arm or disarm an agent |
/api/agent-health | POST | ingest token CORE_HEALTH_INGEST_TOKEN | app agents’ rolled-up health |
Connections and connectors
| Route | Method | Auth | Purpose |
|---|---|---|---|
/api/connection-types | GET | session | the connector catalog: settings and credential keys per type |
/api/connections | GET | session | list registry records |
/api/connections | POST | admin (CORE_CONNECTION_ADMINS) | create |
/api/connections/{id} | GET | session | one record |
/api/connections/{id} | PUT, DELETE | admin (CORE_CONNECTION_ADMINS) | update or delete. Omitting credentials keeps the stored bundle |
/api/providers | GET | session | cloud-provider config (GCP/AWS/Azure) and the connectors CORE publishes |
/api/providers | POST | admin (CORE_CONNECTION_ADMINS) | merge by section |
/api/providers/gcp/status | GET | session | the live GCP fleet link (opt-in) |
/api/connectors/status | GET | session | the cached connector probe. Never dials |
/api/connectors/status/refresh | POST | admin (CORE_CONNECTION_ADMINS) | the one path that dials a published connector |
The JSON connection and runner routes are deprecated aliases kept for one release. The pages use the gRPC services below.
Data-access runners
| Route | Method | Auth | Purpose |
|---|---|---|---|
/api/runners | GET | session | the registry, with per-runner health measured on CORE’s own connection. Never dials |
/api/runners | POST | admin (CORE_RUNNER_ADMINS) | create a PENDING runner. Returns {runner, ticket, command}, and the ticket is shown once |
/api/runners/{id} | PATCH | admin (CORE_RUNNER_ADMINS) | change address, zone or labels |
/api/runners/{id}/token | POST | admin (CORE_RUNNER_ADMINS) | re-issue a ticket for a PENDING runner |
/api/runners/{id}/connect | POST | admin (CORE_RUNNER_ADMINS) | dial now |
/api/runners/{id}/revoke | POST | admin (CORE_RUNNER_ADMINS) | revoke. CORE never dials the runner again |
/api/runner-tokens/{id} | DELETE | admin (CORE_RUNNER_ADMINS) | revoke an unused token |
Trust
| Route | Method | Auth | Purpose |
|---|---|---|---|
/api/access | GET | session | the allowlists (set?, size, your membership), instance grants, and the ReBAC-not-wired notice |
/api/harness | GET | session | measures and compliance joined into actionable findings |
/api/harness/{id}/act | POST | admin (CONSOLE_AGENT_ADMINS) | run dispatch_agent, file_issue or needs_human. Audited before it acts, and idempotent |
/api/guardrails | GET | session | autonomy per action class, hard guardrails and modelGuardrails |
/api/guardrails | PUT | admin (CONSOLE_AGENT_ADMINS) | change an autonomy level |
/api/measures | GET | session | the platform self-assessment |
/api/compliance | GET | session | per-control findings. Never a score, never a framework mapping |
/api/security | GET | session | the mesh CA per namespace, and the model-guardrails rail |
Governance and judgement
| Route | Method | Auth | Purpose |
|---|---|---|---|
/api/data-governance-findings | GET | session | the datagov findings store |
/api/data-governance-findings | POST | App token | the datagov agent’s findings in |
/api/data-governance-estate | GET | App token | Resolve descriptions projected to structure and counts, for the datagov agent |
/api/judgement | GET | session | the docket and CORE’s verdicts |
/api/judgement/submissions | POST | ingest token CORE_JUDGEMENT_INGEST_TOKEN | findings in from an external platform. Verdicts on the wire are discarded |
/api/judgements | GET | session | the judge agent’s runs |
/api/judgements | POST | App token | verdicts in from CORE’s judge agent. The ingest token is refused by name |
gRPC-web services behind the pages
These are served in-process, on the console’s own origin and session, through the gRPC-web server dispatched by content type in atlas_grpc.go. There is no separate port and no CORS.
| Service | Package | Page |
|---|---|---|
ConnectionsService, RunnersService, ListenersService | runink.ui.datasources.v1 (org-runink/ui, mounted by datasources_ui.go) | Connections, Runners. Listeners have no controller yet: settings are stored, and the panel says nothing runs them |
AccessService | runink.ui.access.v1 (mounted by access_ui.go) | Admin |
Runner protocol (runink/core/runners/v1/runners.proto)
Here the runner is the gRPC server and CORE is the client.
| Service | RPC | What |
|---|---|---|
RunnerBootstrapService | Enroll (bidi stream) | CORE sends EnrollChallenge, the runner sends EnrollProof (its proof, a CSR and its version), CORE sends EnrollIssued (server leaf and runner CA), and the runner sends EnrollInstalled. The token is consumed only after both proofs verify |
RunnerService | Health | the runner measuring itself. It never touches a source |
RunnerService | Renew | a CSR over a fresh keypair |
RunnerService | InstallCertificate | hand over the renewed leaf. The old one is then refused |
RunnerService | Goodbye | why CORE is dropping the runner. On REVOKED the runner stops for good |
RunnerService | Execute | runs one work assignment. Declared for rollout step 6 and unimplemented: core-runner answers UNIMPLEMENTED |
The Atlas services (Capex, Governance, Workspace, Playbook, Resolve) and Ask are documented under Intelligence › API reference.