Skip to content
API Reference

API Reference

Every route below is registered in registerRoutes (grpc/operators/core/internal/console/console.go) and served by the console on the same origin as the Flutter app. The auth class of each was checked in its handler.

Auth classes

  • session: a console session cookie (requireSession). Without one the answer is 401 {"error":"unauthorized"}.
  • admin (LIST): a session plus adminRefusal against that allowlist. The answer is 403 with the refusal sentence. See Trust & access.
  • App token: a bearer GitHub App token carrying the App’s rights for the console’s org (authorizeReporter). A missing bearer is 401 {"error":"missing bearer token"}.
  • ingest token: a shared machine secret. Unset means the door refuses everything.

Most report GETs answer 200 even when their source is unreadable, and say so in the body (source:"unavailable", complete:false, unmeasured[]). GET /api/connections and GET /api/runners are the exceptions. Both answer 503 with the report in the body.

Models, agents, inference

RouteMethodAuthPurpose
/api/modelsGETsessionmodel cards joined with live tier state, a health verdict, token use and tenant compute units
/api/inferenceGETsessionthe inference plane as deployed (engine, model, quantization, context, memory, OOM history) plus the persisted benchmark
/api/agentsGETsessionthe 17-entry agent roster and the inference tiers, including the inference.router block
/api/agent-configGETsessionapp agents’ ini settings and OpenBias rules, read from each repo’s HEAD
/api/swarmGETsessionfleet health, roster and run/latency rollup across apps
/api/agent-schedulesGETsessionfleet cadence and enablement, and what of it is editable
/api/agent-schedules/{name}PUTadmin (CONSOLE_AGENT_ADMINS)arm or disarm an agent
/api/agent-healthPOSTingest token CORE_HEALTH_INGEST_TOKENapp agents’ rolled-up health

Connections and connectors

RouteMethodAuthPurpose
/api/connection-typesGETsessionthe connector catalog: settings and credential keys per type
/api/connectionsGETsessionlist registry records
/api/connectionsPOSTadmin (CORE_CONNECTION_ADMINS)create
/api/connections/{id}GETsessionone record
/api/connections/{id}PUT, DELETEadmin (CORE_CONNECTION_ADMINS)update or delete. Omitting credentials keeps the stored bundle
/api/providersGETsessioncloud-provider config (GCP/AWS/Azure) and the connectors CORE publishes
/api/providersPOSTadmin (CORE_CONNECTION_ADMINS)merge by section
/api/providers/gcp/statusGETsessionthe live GCP fleet link (opt-in)
/api/connectors/statusGETsessionthe cached connector probe. Never dials
/api/connectors/status/refreshPOSTadmin (CORE_CONNECTION_ADMINS)the one path that dials a published connector

The JSON connection and runner routes are deprecated aliases kept for one release. The pages use the gRPC services below.

Data-access runners

RouteMethodAuthPurpose
/api/runnersGETsessionthe registry, with per-runner health measured on CORE’s own connection. Never dials
/api/runnersPOSTadmin (CORE_RUNNER_ADMINS)create a PENDING runner. Returns {runner, ticket, command}, and the ticket is shown once
/api/runners/{id}PATCHadmin (CORE_RUNNER_ADMINS)change address, zone or labels
/api/runners/{id}/tokenPOSTadmin (CORE_RUNNER_ADMINS)re-issue a ticket for a PENDING runner
/api/runners/{id}/connectPOSTadmin (CORE_RUNNER_ADMINS)dial now
/api/runners/{id}/revokePOSTadmin (CORE_RUNNER_ADMINS)revoke. CORE never dials the runner again
/api/runner-tokens/{id}DELETEadmin (CORE_RUNNER_ADMINS)revoke an unused token

Trust

RouteMethodAuthPurpose
/api/accessGETsessionthe allowlists (set?, size, your membership), instance grants, and the ReBAC-not-wired notice
/api/harnessGETsessionmeasures and compliance joined into actionable findings
/api/harness/{id}/actPOSTadmin (CONSOLE_AGENT_ADMINS)run dispatch_agent, file_issue or needs_human. Audited before it acts, and idempotent
/api/guardrailsGETsessionautonomy per action class, hard guardrails and modelGuardrails
/api/guardrailsPUTadmin (CONSOLE_AGENT_ADMINS)change an autonomy level
/api/measuresGETsessionthe platform self-assessment
/api/complianceGETsessionper-control findings. Never a score, never a framework mapping
/api/securityGETsessionthe mesh CA per namespace, and the model-guardrails rail

Governance and judgement

RouteMethodAuthPurpose
/api/data-governance-findingsGETsessionthe datagov findings store
/api/data-governance-findingsPOSTApp tokenthe datagov agent’s findings in
/api/data-governance-estateGETApp tokenResolve descriptions projected to structure and counts, for the datagov agent
/api/judgementGETsessionthe docket and CORE’s verdicts
/api/judgement/submissionsPOSTingest token CORE_JUDGEMENT_INGEST_TOKENfindings in from an external platform. Verdicts on the wire are discarded
/api/judgementsGETsessionthe judge agent’s runs
/api/judgementsPOSTApp tokenverdicts in from CORE’s judge agent. The ingest token is refused by name

gRPC-web services behind the pages

These are served in-process, on the console’s own origin and session, through the gRPC-web server dispatched by content type in atlas_grpc.go. There is no separate port and no CORS.

ServicePackagePage
ConnectionsService, RunnersService, ListenersServicerunink.ui.datasources.v1 (org-runink/ui, mounted by datasources_ui.go)Connections, Runners. Listeners have no controller yet: settings are stored, and the panel says nothing runs them
AccessServicerunink.ui.access.v1 (mounted by access_ui.go)Admin

Runner protocol (runink/core/runners/v1/runners.proto)

Here the runner is the gRPC server and CORE is the client.

ServiceRPCWhat
RunnerBootstrapServiceEnroll (bidi stream)CORE sends EnrollChallenge, the runner sends EnrollProof (its proof, a CSR and its version), CORE sends EnrollIssued (server leaf and runner CA), and the runner sends EnrollInstalled. The token is consumed only after both proofs verify
RunnerServiceHealththe runner measuring itself. It never touches a source
RunnerServiceRenewa CSR over a fresh keypair
RunnerServiceInstallCertificatehand over the renewed leaf. The old one is then refused
RunnerServiceGoodbyewhy CORE is dropping the runner. On REVOKED the runner stops for good
RunnerServiceExecuteruns one work assignment. Declared for rollout step 6 and unimplemented: core-runner answers UNIMPLEMENTED

The Atlas services (Capex, Governance, Workspace, Playbook, Resolve) and Ask are documented under Intelligence › API reference.