HTTP route reference
Every HTTP route the CORE console registers, taken from registerRoutes in
grpc/operators/core/internal/console/console.go. All routes are served by the core-operator process
on the console’s own origin. There is no separate API host and no bearer-token API for browsers: the
web app authenticates with the session cookie.
The per-category references give the request and response detail and the exact authorisation of each route:
How routes are authorised
| Class | Rule | Examples |
|---|---|---|
| Open | no session needed | /healthz, /api/me, /api/plans |
| Session read | a GET needs a signed-in session when sign-in is configured (requireSession); on an open console it is served | /api/dashboard, /api/namespaces, /api/gitops |
| Privileged write | a session and the adminRefusal predicate against an allowlist env var; audited on success, failure and refusal | PUT /api/agent-schedules/{name} (CONSOLE_AGENT_ADMINS), POST /api/connections (CORE_CONNECTION_ADMINS) |
| Machine ingest | a shared token generated once in core-system; unset means the door refuses everything | POST /api/agent-health (CORE_HEALTH_INGEST_TOKEN), POST /api/rules-recon/report (CORE_RECON_INGEST_TOKEN), POST /api/judgement/submissions (CORE_JUDGEMENT_INGEST_TOKEN) |
| Agent report | a GitHub App installation token for the console’s org (authorizeReporter) | POST /api/session-runs, POST /api/data-governance-findings, POST /api/judgements, POST /api/playbook-runs/step-report |
An allowlist that is unset means “every identity this console admits”. That is not a wildcard,
because sign-in itself fails closed. CONSOLE_SESSION_ADMINS is the exception: unset means
nobody. GET /api/access lists every allowlist. See
Trust and access.
Reads that could not reach their source still answer 200, with source: "unavailable" and
complete: false in the body. See Status and provenance.
Sign-in and sessions
| Route | Methods | Purpose |
|---|---|---|
/healthz | GET | liveness: answers ok |
/auth/callback | POST | Google Identity Services credential, with the double-submit g_csrf_token |
/auth/google | POST | the Flutter app’s Google token exchange (JSON) |
/auth/password | POST | username and password sign-in, when CONSOLE_ADMIN_PASSWORD is set |
/auth/logout | any | revokes the server-side session |
/api/me | GET | sign-in state and client config: authed, email, authRequired, passwordAuth, googleAuth, googleClientId, recaptchaSiteKey, voiceTts, voiceStt |
/api/sessions/revoke-all | POST | end every session of a subject |
/api/session-admins | GET, PUT | who may read the audit trail and end other people’s sessions |
Audit and access
| Route | Methods | Purpose |
|---|---|---|
/api/audit | GET | newest-first page of the audit chain and its verdict |
/api/audit/{seq} | GET | one record in full, with its neighbours’ hashes |
/api/audit/verify | GET | walk the persisted chain and name the first break |
/api/access | GET | which allowlists are live, their sizes, and your own membership only |
Reading the audit trail requires a session admin (CONSOLE_SESSION_ADMINS).
Chat and voice
| Route | Methods | Purpose |
|---|---|---|
/chat | POST | the orchestration chat: one tool call per message; mutating calls need confirm <code> |
/api/tts | POST | sovereign text-to-speech through TTSD_URL |
/api/stt | POST | sovereign speech-to-text through VOICE_REMOTE_URL |
Platform and cluster (DevEx)
| Route | Methods | Purpose |
|---|---|---|
/api/dashboard | GET | tracked workloads and client instances |
/api/control-planes | GET | FACE and PULSE control-plane CRDs |
/api/cluster-nodes | GET | Kubernetes Nodes and dedicated-taint isolation |
/api/namespaces | GET | per-namespace workloads, pods, events, quotas and a verdict |
/api/nodes/{name} | GET | one node: conditions, capacity, taints, pods by namespace |
/api/services | GET | serving status: ready/desired, and whether a readiness probe backs it |
/api/routes | GET | edge routes and /forge/, traced to Service, endpoints and workload |
/api/gitops | GET | Argo Applications when Argo CD is installed, else the GitHub Actions delivery view |
/api/lineage | GET | per image: merged → agents → built → registry → rolled → running; ?sha= answers “did my commit ship” |
/api/doctor | GET | the ops doctor CronJob: state, runs, tracking issue |
/api/metrics | GET | measured process and workload metrics |
/api/devex | GET | DevEx indicators from the persisted run-outcome series |
/api/security | GET | mesh CA fingerprint and expiry per namespace |
Agents and runs
| Route | Methods | Purpose |
|---|---|---|
/api/agents | GET | the agent roster and the inference tiers |
/api/agent-config | GET | the app agents’ settings and OpenBias rules, read from each repo’s HEAD |
/api/agent-runs | GET | PR-triggered agent runs per repo (GitHub Actions) |
/api/agent-runs/logs | GET | one run’s unzipped log text |
/api/runs | GET | every agent run across kinds, repos, CronJobs and app agents |
/api/reviews | GET | running and past reviews, with findings per review type |
/api/reviews/{type}/{runId}[/detail] | GET | one review run’s findings; /detail adds what the agents posted on GitHub |
/api/agent-schedules | GET | fleet cadence and enablement, and what of it is editable |
/api/agent-schedules/{name} | PUT | arm or disarm an agent (privileged) |
/api/agent-health | POST | the apps’ rolled-up agent health (machine ingest) |
/api/session-runs | POST | core session run reports (agent report) |
/api/session-commands | POST, GET | the remote-control queue a workstation pulls from: enqueue for yourself, or long-poll a claim |
/api/session-commands/{id}/result | POST | a claimed command’s result |
/api/session-queue | GET, POST | the browser’s view of your queue, and the browser’s enqueue path (cookie) |
/api/governance-runs | GET | run history of the governance-family agents; ?repo= filters |
Models and inference (DataEx)
| Route | Methods | Purpose |
|---|---|---|
/api/inference | GET | the inference plane as deployed: model, quantisation, context, engine, OOM history |
/api/models | GET | model cards joined with live tier state, a health verdict, token use and tenant CU |
/api/finops | GET | allocated compute attributed by initiative and tenant |
Connections, runners and providers (DataEx)
| Route | Methods | Purpose |
|---|---|---|
/api/connections | GET, POST | list or create tenant data-source connections |
/api/connections/{id} | GET, PUT, DELETE | one connection |
/api/connection-types | GET | the connector catalog: settings and credential keys per type |
/api/runners | GET, POST | data-access runners: list, or enrol (a one-time ticket is shown once) |
/api/runners/{id}/… | POST, PATCH | token, connect, revoke, and address or label changes |
/api/runner-tokens/{id} | DELETE | revoke an unused enrolment token |
/api/connectors/status | GET | the cached connector probe; never dials |
/api/connectors/status/refresh | POST | run the connector probe (the one path here that dials; privileged) |
/api/providers | GET, POST | cloud-provider config and the connectors CORE publishes |
/api/providers/gcp/status | GET | the live GCP fleet link (opt-in) |
/api/github | GET, POST | the GitHub configuration shown on Account |
The DataEx Connections and Runners pages now use the shared gRPC-web services; the /api/connections*,
/api/runners* and /api/runner-tokens/* routes stay for one release as deprecated aliases (the
core connection register CLI uses /api/connections).
Trust (DataEx)
| Route | Methods | Purpose |
|---|---|---|
/api/harness | GET | measures and compliance joined into actionable findings |
/api/harness/{id}/act | POST | act on a finding: admin, audit-before-act, idempotent |
/api/guardrails | GET, PUT | autonomy per action class, and the hard guardrails |
/api/measures | GET | the platform self-assessment: judged categories and one remediation measure per failing one |
Intelligence
| Route | Methods | Purpose |
|---|---|---|
/api/swarm | GET | agent swarm: fleet health, roster, run and latency rollup across apps |
/api/domains | GET | data domains clustered from the connection registry |
/api/governance | GET | estate governance: ownership, credential storage, namespace posture |
/api/data-lineage | GET | declared topology and observed flows |
/api/data-lineage/edges | POST | the apps’ observed-lineage ingest (machine token) |
/api/compliance | GET | per-control findings; never a score |
/api/maturity | GET | five measured dimensions, and a composite only when all five are measured |
/api/rules-recon | GET | business-rule reconciliation; ?tenant= |
/api/rules-recon/inputs | GET | the recon agent’s read door (CORE_RECON_INGEST_TOKEN) |
/api/rules-recon/report | POST | the recon agent’s report (CORE_RECON_INGEST_TOKEN) |
/api/data-governance-findings | GET, POST | the datagov findings: session read, agent-report write |
/api/data-governance-estate | GET | the datagov agent’s read door: structure and counts only (agent report token) |
/api/judgement | GET | submitted findings and CORE’s verdicts on them |
/api/judgement/submissions | POST | an external platform’s findings (CORE_JUDGEMENT_INGEST_TOKEN); any verdict on the wire is discarded |
/api/judgements | GET, POST | the judge agent’s verdicts (agent report token for POST) |
/api/playbook-runs/step-report | POST | a dispatched agent reports its playbook step |
/api/playbook-events | POST | an agent raises a playbook event |
FORGE
| Route | Methods | Purpose |
|---|---|---|
/forge/… | any | the FORGE service, reverse-proxied under CORE’s origin and sign-in |
/api/forge | GET | forged apps and their build stage from core/ci; no console page reads it any more |
Billing
| Route | Methods | Purpose |
|---|---|---|
/api/plans | GET | the public subscription-plan catalog |
/api/signup | POST | public self-serve signup: a pending subscription and a checkout |
/api/checkout | POST | a quote and, when configured, a Stripe checkout for the signed-in person |
/api/billing/seats | GET, POST, DELETE | who holds the seats on the signed-in purchaser’s subscription |
/api/stripe/webhook | POST | Stripe events into the subscription store |
gRPC-web on /
The root handler serves, in order: gRPC-web (dispatched by content type, so it needs no route of
its own), the Flutter bundle from CONSOLE_WEB_DIR, and else the HTML dashboard fallback. The
gRPC-web services run in the same process, on the same origin and session, with no CORS: a foreign
Origin is refused with 403. They are:
- CORE’s own:
CapexService,GovernanceService,WorkspaceService,PlaybookService,ResolveService(deprecated alias) andAskService, fromgrpc/operators/core/api/proto/runink/core/; - the shared
org-runink/uiservices CORE mounts:runink.ui.estate.v1.EstateService,runink.ui.profile.v1.ProfileService, and the datasourcesConnectionsService,RunnersServiceandListenersService.