Skip to content
HTTP route reference

HTTP route reference

Every HTTP route the CORE console registers, taken from registerRoutes in grpc/operators/core/internal/console/console.go. All routes are served by the core-operator process on the console’s own origin. There is no separate API host and no bearer-token API for browsers: the web app authenticates with the session cookie.

The per-category references give the request and response detail and the exact authorisation of each route:

How routes are authorised

ClassRuleExamples
Openno session needed/healthz, /api/me, /api/plans
Session reada GET needs a signed-in session when sign-in is configured (requireSession); on an open console it is served/api/dashboard, /api/namespaces, /api/gitops
Privileged writea session and the adminRefusal predicate against an allowlist env var; audited on success, failure and refusalPUT /api/agent-schedules/{name} (CONSOLE_AGENT_ADMINS), POST /api/connections (CORE_CONNECTION_ADMINS)
Machine ingesta shared token generated once in core-system; unset means the door refuses everythingPOST /api/agent-health (CORE_HEALTH_INGEST_TOKEN), POST /api/rules-recon/report (CORE_RECON_INGEST_TOKEN), POST /api/judgement/submissions (CORE_JUDGEMENT_INGEST_TOKEN)
Agent reporta GitHub App installation token for the console’s org (authorizeReporter)POST /api/session-runs, POST /api/data-governance-findings, POST /api/judgements, POST /api/playbook-runs/step-report

An allowlist that is unset means “every identity this console admits”. That is not a wildcard, because sign-in itself fails closed. CONSOLE_SESSION_ADMINS is the exception: unset means nobody. GET /api/access lists every allowlist. See Trust and access.

Reads that could not reach their source still answer 200, with source: "unavailable" and complete: false in the body. See Status and provenance.

Sign-in and sessions

RouteMethodsPurpose
/healthzGETliveness: answers ok
/auth/callbackPOSTGoogle Identity Services credential, with the double-submit g_csrf_token
/auth/googlePOSTthe Flutter app’s Google token exchange (JSON)
/auth/passwordPOSTusername and password sign-in, when CONSOLE_ADMIN_PASSWORD is set
/auth/logoutanyrevokes the server-side session
/api/meGETsign-in state and client config: authed, email, authRequired, passwordAuth, googleAuth, googleClientId, recaptchaSiteKey, voiceTts, voiceStt
/api/sessions/revoke-allPOSTend every session of a subject
/api/session-adminsGET, PUTwho may read the audit trail and end other people’s sessions

Audit and access

RouteMethodsPurpose
/api/auditGETnewest-first page of the audit chain and its verdict
/api/audit/{seq}GETone record in full, with its neighbours’ hashes
/api/audit/verifyGETwalk the persisted chain and name the first break
/api/accessGETwhich allowlists are live, their sizes, and your own membership only

Reading the audit trail requires a session admin (CONSOLE_SESSION_ADMINS).

Chat and voice

RouteMethodsPurpose
/chatPOSTthe orchestration chat: one tool call per message; mutating calls need confirm <code>
/api/ttsPOSTsovereign text-to-speech through TTSD_URL
/api/sttPOSTsovereign speech-to-text through VOICE_REMOTE_URL

Platform and cluster (DevEx)

RouteMethodsPurpose
/api/dashboardGETtracked workloads and client instances
/api/control-planesGETFACE and PULSE control-plane CRDs
/api/cluster-nodesGETKubernetes Nodes and dedicated-taint isolation
/api/namespacesGETper-namespace workloads, pods, events, quotas and a verdict
/api/nodes/{name}GETone node: conditions, capacity, taints, pods by namespace
/api/servicesGETserving status: ready/desired, and whether a readiness probe backs it
/api/routesGETedge routes and /forge/, traced to Service, endpoints and workload
/api/gitopsGETArgo Applications when Argo CD is installed, else the GitHub Actions delivery view
/api/lineageGETper image: merged → agents → built → registry → rolled → running; ?sha= answers “did my commit ship”
/api/doctorGETthe ops doctor CronJob: state, runs, tracking issue
/api/metricsGETmeasured process and workload metrics
/api/devexGETDevEx indicators from the persisted run-outcome series
/api/securityGETmesh CA fingerprint and expiry per namespace

Agents and runs

RouteMethodsPurpose
/api/agentsGETthe agent roster and the inference tiers
/api/agent-configGETthe app agents’ settings and OpenBias rules, read from each repo’s HEAD
/api/agent-runsGETPR-triggered agent runs per repo (GitHub Actions)
/api/agent-runs/logsGETone run’s unzipped log text
/api/runsGETevery agent run across kinds, repos, CronJobs and app agents
/api/reviewsGETrunning and past reviews, with findings per review type
/api/reviews/{type}/{runId}[/detail]GETone review run’s findings; /detail adds what the agents posted on GitHub
/api/agent-schedulesGETfleet cadence and enablement, and what of it is editable
/api/agent-schedules/{name}PUTarm or disarm an agent (privileged)
/api/agent-healthPOSTthe apps’ rolled-up agent health (machine ingest)
/api/session-runsPOSTcore session run reports (agent report)
/api/session-commandsPOST, GETthe remote-control queue a workstation pulls from: enqueue for yourself, or long-poll a claim
/api/session-commands/{id}/resultPOSTa claimed command’s result
/api/session-queueGET, POSTthe browser’s view of your queue, and the browser’s enqueue path (cookie)
/api/governance-runsGETrun history of the governance-family agents; ?repo= filters

Models and inference (DataEx)

RouteMethodsPurpose
/api/inferenceGETthe inference plane as deployed: model, quantisation, context, engine, OOM history
/api/modelsGETmodel cards joined with live tier state, a health verdict, token use and tenant CU
/api/finopsGETallocated compute attributed by initiative and tenant

Connections, runners and providers (DataEx)

RouteMethodsPurpose
/api/connectionsGET, POSTlist or create tenant data-source connections
/api/connections/{id}GET, PUT, DELETEone connection
/api/connection-typesGETthe connector catalog: settings and credential keys per type
/api/runnersGET, POSTdata-access runners: list, or enrol (a one-time ticket is shown once)
/api/runners/{id}/…POST, PATCHtoken, connect, revoke, and address or label changes
/api/runner-tokens/{id}DELETErevoke an unused enrolment token
/api/connectors/statusGETthe cached connector probe; never dials
/api/connectors/status/refreshPOSTrun the connector probe (the one path here that dials; privileged)
/api/providersGET, POSTcloud-provider config and the connectors CORE publishes
/api/providers/gcp/statusGETthe live GCP fleet link (opt-in)
/api/githubGET, POSTthe GitHub configuration shown on Account

The DataEx Connections and Runners pages now use the shared gRPC-web services; the /api/connections*, /api/runners* and /api/runner-tokens/* routes stay for one release as deprecated aliases (the core connection register CLI uses /api/connections).

Trust (DataEx)

RouteMethodsPurpose
/api/harnessGETmeasures and compliance joined into actionable findings
/api/harness/{id}/actPOSTact on a finding: admin, audit-before-act, idempotent
/api/guardrailsGET, PUTautonomy per action class, and the hard guardrails
/api/measuresGETthe platform self-assessment: judged categories and one remediation measure per failing one

Intelligence

RouteMethodsPurpose
/api/swarmGETagent swarm: fleet health, roster, run and latency rollup across apps
/api/domainsGETdata domains clustered from the connection registry
/api/governanceGETestate governance: ownership, credential storage, namespace posture
/api/data-lineageGETdeclared topology and observed flows
/api/data-lineage/edgesPOSTthe apps’ observed-lineage ingest (machine token)
/api/complianceGETper-control findings; never a score
/api/maturityGETfive measured dimensions, and a composite only when all five are measured
/api/rules-reconGETbusiness-rule reconciliation; ?tenant=
/api/rules-recon/inputsGETthe recon agent’s read door (CORE_RECON_INGEST_TOKEN)
/api/rules-recon/reportPOSTthe recon agent’s report (CORE_RECON_INGEST_TOKEN)
/api/data-governance-findingsGET, POSTthe datagov findings: session read, agent-report write
/api/data-governance-estateGETthe datagov agent’s read door: structure and counts only (agent report token)
/api/judgementGETsubmitted findings and CORE’s verdicts on them
/api/judgement/submissionsPOSTan external platform’s findings (CORE_JUDGEMENT_INGEST_TOKEN); any verdict on the wire is discarded
/api/judgementsGET, POSTthe judge agent’s verdicts (agent report token for POST)
/api/playbook-runs/step-reportPOSTa dispatched agent reports its playbook step
/api/playbook-eventsPOSTan agent raises a playbook event

FORGE

RouteMethodsPurpose
/forge/…anythe FORGE service, reverse-proxied under CORE’s origin and sign-in
/api/forgeGETforged apps and their build stage from core/ci; no console page reads it any more

Billing

RouteMethodsPurpose
/api/plansGETthe public subscription-plan catalog
/api/signupPOSTpublic self-serve signup: a pending subscription and a checkout
/api/checkoutPOSTa quote and, when configured, a Stripe checkout for the signed-in person
/api/billing/seatsGET, POST, DELETEwho holds the seats on the signed-in purchaser’s subscription
/api/stripe/webhookPOSTStripe events into the subscription store

gRPC-web on /

The root handler serves, in order: gRPC-web (dispatched by content type, so it needs no route of its own), the Flutter bundle from CONSOLE_WEB_DIR, and else the HTML dashboard fallback. The gRPC-web services run in the same process, on the same origin and session, with no CORS: a foreign Origin is refused with 403. They are:

  • CORE’s own: CapexService, GovernanceService, WorkspaceService, PlaybookService, ResolveService (deprecated alias) and AskService, from grpc/operators/core/api/proto/runink/core/;
  • the shared org-runink/ui services CORE mounts: runink.ui.estate.v1.EstateService, runink.ui.profile.v1.ProfileService, and the datasources ConnectionsService, RunnersService and ListenersService.