Skip to content

REST API Reference Cloud ​

Control plane required

The REST API endpoints documented below are exposed by the Intutic Control Plane: Intutic Cloud, a Self-host deployment, or a local dev stack on port 3001.

The Intutic control plane exposes a RESTful API under /api/v1/. All endpoints use JSON request/response bodies.

Base URL ​

https://your-control-plane.example/api/v1

For local development:

http://localhost:3001/api/v1

Authentication ​

Most endpoints require a JWT access token in the Authorization header:

Authorization: Bearer <access_token>

Public endpoints (signup, login, refresh) do not require authentication.


Auth Endpoints ​

POST /api/v1/auth/signup ​

Self-serve signup with workspace auto-provisioning. Creates a user, provisions a free_trial workspace, and issues a virtual API key.

Auth: None (public)

Request body:

json
{
  "email": "dev@example.com",
  "password": "securepassword",
  "name": "Jane Developer",
  "workspaceName": "My Team"
}
FieldTypeRequiredNotes
emailstring✅Valid email
passwordstring✅8–128 chars
namestring✅1–128 chars
workspaceNamestring❌1–64 chars, optional

Response: 201 Created

Error codes: 409 EMAIL_ALREADY_EXISTS, 422 validation, 503 SIGNUP_DISABLED


POST /api/v1/auth/login ​

Authenticate with email and password.

Auth: None (public)

Request body:

json
{
  "email": "dev@example.com",
  "password": "securepassword"
}

Response: 200 OK with access token and refresh token

Error codes: 400 validation, 401 invalid credentials


POST /api/v1/auth/refresh ​

Refresh an access token using a refresh token.

Auth: None (public)

Request body:

json
{
  "refreshToken": "rt_..."
}

Response: 200 OK with new access token

Error codes: 400 validation, 401 expired or invalid token


POST /api/v1/auth/verify-email ​

Verify email address with a token.

Auth: None (public)

Request body:

json
{
  "token": "<64-char-verification-token>"
}

Response: 200 OK

Error codes: 400 TOKEN_INVALID, 410 TOKEN_EXPIRED


POST /api/v1/auth/resend-verification ​

Resend the email verification link. Rate limited to 2 req/min per email.

Auth: None (public)

Request body:

json
{
  "email": "dev@example.com"
}

Response: 200 OK

Error codes: 404 USER_NOT_FOUND, 409 ALREADY_VERIFIED, 429 RATE_LIMITED


POST /api/v1/auth/logout ​

Invalidate the current session.

Auth: JWT required

Response: 200 OK

json
{ "loggedOut": true }

POST /api/v1/auth/change-password ​

Change the authenticated user's password.

Auth: JWT required

Request body:

json
{
  "currentPassword": "oldpassword",
  "newPassword": "newpassword"
}

Response: 200 OK

json
{ "changed": true }

Error codes: 400 validation, 401 current password incorrect


GET /api/v1/auth/me ​

Get the current authenticated user's info.

Auth: JWT required

Response: 200 OK with member object

Error codes: 404 member not found


Trace Endpoints ​

GET /api/v1/traces ​

List execution traces for the workspace.

Auth: JWT required

Query parameters:

ParamTypeDefaultDescription
limitnumber201–100
offsetnumber0Pagination offset
sinceISO 8601—Only traces after this timestamp
enforcementenum—BYPASS, ENHANCE, HIJACK, KILL
modelstring—Filter by model name

Response: 200 OK

json
{
  "traces": [...],
  "total": 142,
  "limit": 20,
  "offset": 0
}

GET /api/v1/traces/:id ​

Get a single execution trace by ID.

Auth: JWT required

Response: 200 OK — full trace with token counts, costs, compliance scores, anomaly data

Error codes: 404 trace not found


SOP Endpoints ​

POST /api/v1/sops ​

Create a new SOP.

Auth: JWT required

Request body:

json
{
  "title": "Code Review Requirements",
  "markdown_content": "## Rules\n\nAll code must have tests...",
  "risk_tier": "MEDIUM",
  "complexity_tier": "MEDIUM",
  "version": "1.0.0",
  "dependencies": ["sop_abc123"]
}
FieldTypeRequiredNotes
titlestring✅1–500 chars
markdown_contentstring✅1–100,000 chars
risk_tierenum✅LOW, MEDIUM, HIGH, CRITICAL
complexity_tierenum✅LOW, MEDIUM, HIGH
versionstring❌1–50 chars
dependenciesstring[]❌SOP IDs this depends on

Response: 201 Created


GET /api/v1/sops ​

List SOPs with pagination and filters.

Auth: JWT required

Query parameters:

ParamTypeDefaultDescription
pagenumber1Page number (min 1)
limitnumber501–100
lifecycle_stateenum—Filter by state
risk_tierenum—LOW, MEDIUM, HIGH, CRITICAL
complexity_tierenum—LOW, MEDIUM, HIGH

Lifecycle states: DRAFT, PENDING_REVIEW, GENERATED, HYPOTHESIZED, REFINED, VALIDATED, INVALIDATED


GET /api/v1/sops/:sopId ​

Get SOP detail.

Auth: JWT required

Response: 200 OK with full SOP object

Error codes: 404 SOP not found


PUT /api/v1/sops/:sopId ​

Update SOP (with anti-gaming gate).

Auth: JWT required

Request body: Same fields as create, all optional.

Response: 200 OK

Error codes: 404 SOP not found


DELETE /api/v1/sops/:sopId ​

Soft-delete SOP.

Auth: JWT required

Response: 200 OK

json
{ "deleted": true }

Error codes: 404 SOP not found


POST /api/v1/sops/:sopId/transition ​

Lifecycle state transition.

Auth: JWT required

Request body:

json
{
  "target_state": "VALIDATED",
  "reason": "Passed team review"
}
FieldTypeRequiredNotes
target_stateenum✅Target lifecycle state
reasonstring❌Max 1,000 chars

Response: 200 OK on success

Error codes: 409 transition not allowed


POST /api/v1/sops/:sopId/invalidate ​

Cascade invalidation — invalidates this SOP and all dependents.

Auth: JWT required

Response: 200 OK


GET /api/v1/sops/:sopId/dependencies ​

Get SOP dependency graph.

Auth: JWT required

Response: 200 OK

json
{
  "sop_id": "sop_abc123",
  "dependencies": [...]
}

GET /api/v1/sops/:sopId/health ​

Get SOP health metrics.

Auth: JWT required

Response: 200 OK with health metrics


Usage / FinOps Endpoints ​

GET /api/v1/usage/summary ​

Aggregated usage summary by period.

Auth: JWT required

Query parameters:

ParamTypeRequiredDescription
periodenum✅daily, weekly, monthly
startISO 8601✅Start date (with offset)
endISO 8601✅End date (with offset)

GET /api/v1/usage/events ​

Paginated raw execution trace events.

Auth: JWT required

Query parameters:

ParamTypeDefaultDescription
pagenumber1Page number
limitnumber501–100
session_idstring—Filter by session

Response: 200 OK

json
{
  "events": [
    {
      "trace_id": "tr_abc123",
      "timestamp": "2026-06-11T22:24:00.000Z",
      "model": "claude-4-sonnet",
      "input_tokens": 1234,
      "output_tokens": 567,
      "cost_usd": 0.0037,
      "enforcement_action": "BYPASS",
      "token_utility": "USEFUL"
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 50,
    "total": 142,
    "has_more": true
  }
}

GET /api/v1/usage/models ​

Per-model cost breakdown.

Auth: JWT required

Query parameters:

ParamTypeRequiredDescription
periodenum✅daily or monthly

Response: 200 OK

json
{
  "models": [...]
}

POST /api/v1/usage/classify ​

Classify tokens as USEFUL or WASTED.

Auth: JWT required

Request body:

json
{
  "trace_ids": ["tr_abc123", "tr_def456"],
  "classification": "WASTED",
  "reason": "Agent was looping"
}
FieldTypeRequiredNotes
trace_idsstring[]✅1–500 trace IDs
classificationenum✅USEFUL or WASTED
reasonstring✅1–1,000 chars

Response: 200 OK

json
{ "classified": 2 }

Route Catalog ​

Generated from services/control-plane/src/routes/*.ts by generate-api-catalog.mjs. 334 routes across 69 route files. Do not hand-edit this section — re-run the generator instead.

agentcoreGateway.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/integrations/agentcore/gateway-checkAuthenticated

agents.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/agentsAuthenticatedlist agents in the workspace
GET/api/v1/agents/:idAuthenticatedone agent, its facets, posture, live sessions
POST/api/v1/agents/:id/judge-scoreAuthenticated
GET/api/v1/agents/graphAuthenticatednodes + edges + posture for the viz
POST/api/v1/agents/reportAuthenticateddaemon upserts an agent + facets (rescored)

anomaly.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/anomaliesOWNER/ADMIN/EMPaginated anomaly list
GET/api/v1/capability-missesOWNER/ADMIN/EMCapability miss events
POST/api/v1/capability-missesAuthenticated
POST/api/v1/capability-misses/:missId/reviewOWNER/ADMIN/EM

attenuate.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/attenuateAuthenticatedAttenuate parent key to child key (team+)
GET/api/v1/attenuate/chain/:chainIdAuthenticatedResolve delegation lineage (ADMIN+)
POST/api/v1/auth/obo-tokenAuthenticatedIssue OBO ephemeral session token (pro+)

audit.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/audit/timelineOWNER/ADMINJoined login/enforcement/decision/incident/ settings-change report for a workspace over a date range.

auth.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/auth/change-passwordAuthenticatedChange password (requires JWT)
GET/api/v1/auth/key-contextAuthenticated
POST/api/v1/auth/loginPublicLogin with email/password
POST/api/v1/auth/logoutAuthenticatedLogout (requires JWT)
POST/api/v1/auth/magic-link/loginPublic
POST/api/v1/auth/magic-link/requestPublic
GET/api/v1/auth/meAuthenticatedGet current user info (requires JWT)
POST/api/v1/auth/refreshPublicRefresh access token
POST/api/v1/auth/resend-verificationPublic
GET/api/v1/auth/sessionAuthenticated
POST/api/v1/auth/signupPublicSelf-serve signup with workspace auto-provisioning
POST/api/v1/auth/signup/orgPublic
POST/api/v1/auth/verify-emailPublic

billing.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/billing/checkoutAuthenticatedCreate Stripe Checkout Session (ADMIN)
GET/api/v1/billing/invoicesAuthenticated
POST/api/v1/billing/marketplace/aws/registerAuthenticated
POST/api/v1/billing/marketplace/aws/webhookPublic
POST/api/v1/billing/marketplace/gcp/registerAuthenticated
POST/api/v1/billing/marketplace/gcp/webhookPublic
GET/api/v1/billing/usage-rateAuthenticatedThis workspace's rate per 1,000 Governed Requests
GET/api/v1/billing/usage/currentAuthenticatedCurrent metered usage summary (team+)
POST/api/v1/billing/webhookPublicHandle Stripe webhook (public)

breakGlass.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/break-glass/approveAuthenticated
POST/api/v1/break-glass/requestAuthenticated
GET/api/v1/break-glass/requestsAuthenticated

budget.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/budgetAuthenticatedCurrent budget status
PUT/api/v1/budgetAuthenticatedUpdate budget settings
GET/api/v1/budget/alertsAuthenticatedBudget alert history
POST/api/v1/budget/alerts/:alertId/acknowledgeAuthenticatedAcknowledge an alert

compliance.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/compliance/probes/historyAuthenticated
GET/api/v1/compliance/probes/latestAuthenticated
POST/api/v1/compliance/probes/runAuthenticated
POST/api/v1/compliance/soc2-collectOWNER/ADMIN
GET/api/v1/compliance/soc2-export/:runIdOWNER/ADMIN
GET/api/v1/compliance/soc2-statusAuthenticated

connectors.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/connectorsAuthenticatedList connectors
POST/api/v1/connectorsAuthenticatedCreate connector
DELETE/api/v1/connectors/:connectorIdAuthenticated
PATCH/api/v1/connectors/:connectorIdAuthenticated
POST/api/v1/connectors/:connectorId/syncAuthenticated
POST/api/v1/connectors/:connectorId/testAuthenticated (OWNER/ADMIN for gdrive)Probe a memory provider, or a Google Drive source (lists one document with the stored credential)
DELETE/api/v1/connectors/virustotalOWNER/ADMINRemove the stored VT API key (OWNER/ADMIN)
GET/api/v1/connectors/virustotalOWNER/ADMINRead masked VT credential status (OWNER/ADMIN)
POST/api/v1/connectors/virustotalOWNER/ADMINUpsert the workspace's VT API key (OWNER/ADMIN)
GET/api/v1/connectors/virustotal/budgetOWNER/ADMINToday's lookup budget usage (OWNER/ADMIN)
POST/api/v1/connectors/virustotal/testOWNER/ADMINValidate the stored key against a benign hash (OWNER/ADMIN)

decisions.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/decisionsAuthenticatedList decisions (paginated)
POST/api/v1/decisionsAuthenticatedIngest review holds from the daemon
GET/api/v1/decisions/:entryIdAuthenticatedGet decision detail
POST/api/v1/decisions/:entryId/reviewAuthenticated
GET/api/v1/decisions/analysisAuthenticatedAggregated pattern analysis
GET/api/v1/decisions/approved-bypassesAuthenticated
POST/api/v1/decisions/substitutionsAuthenticatedIngest tool calls the proxy rewrote
POST/api/v1/rule-candidates/:candidateId/bundleAuthenticated
POST/api/v1/rule-candidates/:candidateId/mocksAuthenticated
POST/api/v1/rule-candidates/:candidateId/promoteAuthenticated
GET/api/v1/workspaces/:workspaceId/hold-candidatesAuthenticated
GET/api/v1/workspaces/:workspaceId/rule-candidatesAuthenticated

devices.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/devicesOWNER/ADMINlist enrolled devices
DELETE/api/v1/devices/:idOWNER/ADMINsoft-retire a device
GET/api/v1/devices/:idOWNER/ADMINget a single device
POST/api/v1/devices/reportAuthenticatedany authenticated member, upserts on (workspaceId, fingerprint)

domainVerification.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/domain-verification/:idAuthenticated
POST/api/v1/domain-verification/startAuthenticated

dreamCycle.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/dream-cycle/queueAuthenticated
POST/api/v1/dream-cycle/queue/:id/approveAuthenticated
POST/api/v1/dream-cycle/queue/:id/rejectAuthenticated
GET/api/v1/dream-cycle/settingsAuthenticated
PUT/api/v1/dream-cycle/settingsAuthenticated
POST/api/v1/dream-cycle/triggerAuthenticated

enterpriseTrial.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/enterprise/trial/:id/convertAuthenticatedSales conversion (internal)
POST/api/v1/enterprise/trial/startAuthenticatedStart trial (canonical implemented path)
GET/api/v1/enterprise/trial/statusAuthenticatedTrial status for workspace
GET/api/v1/enterprise/usageAuthenticatedCurrent period usage summary
GET/api/v1/enterprise/usage/historyAuthenticatedHistorical daily meters

evaluate.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/policy/checkPublicCheck if a model check is allowed
GET/api/v1/policy/resolveAuthenticatedResolve active rules for workspace

evaluatorSandbox.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/evaluator/sandbox/:runId/deployAuthenticated
GET/api/v1/evaluator/sandbox/:runId/resultsAuthenticated
GET/api/v1/evaluator/sandbox/datasetsAuthenticated
POST/api/v1/evaluator/sandbox/datasetsAuthenticated
POST/api/v1/evaluator/sandbox/runAuthenticated

findings.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/findingsAuthenticated
POST/api/v1/findings/:findingId/adjudicateAuthenticated
GET/api/v1/findings/:findingId/snippetOWNER/ADMIN
GET/api/v1/findings/adjudicatedAuthenticated
GET/api/v1/findings/response-echo/reportAuthenticated
GET/api/v1/findings/statsAuthenticated

fixEnhance.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/fix/enhanceAuthenticated

gatewayHeartbeat.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/gateways/:id/configAuthenticated
POST/api/v1/gateways/:id/config-ackAuthenticated
POST/api/v1/gateways/:id/heartbeatAuthenticated

gateways.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/gatewaysAuthenticated
POST/api/v1/gatewaysOWNER/ADMIN
DELETE/api/v1/gateways/:idOWNER/ADMIN
PATCH/api/v1/gateways/:id/configOWNER/ADMIN
POST/api/v1/gateways/:id/rotateOWNER/ADMIN
POST/api/v1/gateways/:id/self-rotateAuthenticated
GET/api/v1/gateways/:id/statusAuthenticated
PATCH/api/v1/workspace/gatewayOWNER/ADMIN
GET/api/v1/workspace/gateway-resolutionAuthenticated

governanceCoverage.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/governance-coverageAuthenticated
GET/api/v1/governance-coverage/:harnessTypeAuthenticated
POST/api/v1/governance-coverage/snapshotAuthenticated

harnessConfig.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/config/captureAuthenticatedCapture config snapshot
POST/api/v1/skillopt/:suggestionId/applyAuthenticated
POST/api/v1/skillopt/:suggestionId/apply-resultAuthenticatedSync daemon's ack of an apply attempt
POST/api/v1/skillopt/:suggestionId/dismissAuthenticated
GET/api/v1/workspaces/:workspaceId/config-snapshotsAuthenticated
GET/api/v1/workspaces/:workspaceId/config-snapshots/:snapshotId/diffAuthenticated
GET/api/v1/workspaces/:workspaceId/skillopt-suggestionsAuthenticated
POST/api/v1/workspaces/:workspaceId/skillopt/generateAuthenticated
GET/api/v1/workspaces/:workspaceId/skills/reportAuthenticated
POST/api/v1/workspaces/:workspaceId/skills/reportAuthenticated

hookEvents.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/hook-eventsAuthenticated
POST/api/v1/hook-gateAuthenticated

incidents.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/incidentsOWNER/ADMIN/EMPaginated incident list
GET/api/v1/incidents/:idOWNER/ADMIN/EMSingle incident detail
POST/api/v1/incidents/:id/resolveOWNER/ADMIN/EMResolve an incident

integrity.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/integrity/chainAuthenticated
GET/api/v1/integrity/config-chainAuthenticated
GET/api/v1/integrity/rootsAuthenticated
GET/api/v1/integrity/roots/:rootIdAuthenticated
GET/api/v1/integrity/roots/:rootId/proof/:traceIdAuthenticated
POST/api/v1/integrity/roots/:rootId/recomputeAuthenticated
GET/api/v1/integrity/traces/:traceId/leafAuthenticated

intelligence.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/predict-costAuthenticatedCost prediction
POST/api/v1/recommendations/:recommendationId/applyAuthenticated
POST/api/v1/recommendations/:recommendationId/dismissAuthenticated
GET/api/v1/traces/:traceId/token-breakdownAuthenticatedPer-tool token breakdown
GET/api/v1/workspaces/:workspaceId/optimization-recommendationsAuthenticated
GET/api/v1/workspaces/:workspaceId/waste-patternsAuthenticated

judge.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/judge/chunkPublic
POST/api/v1/judge/finalizePublic

keys.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/keysAuthenticatedList API keys for the workspace
POST/api/v1/keysAuthenticatedCreate a new API key
DELETE/api/v1/keys/:idAuthenticatedRevoke an API key

loops.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/loopsAuthenticated
GET/api/v1/loops/:loopRunIdAuthenticated
POST/api/v1/loops/:loopRunId/completeAuthenticated
GET/api/v1/loops/:loopRunId/duplicatesAuthenticated
POST/api/v1/loops/:loopRunId/killAuthenticated
POST/api/v1/loops/:loopRunId/reviewAuthenticated
POST/api/v1/loops/:loopRunId/verifyAuthenticated
GET/api/v1/loops/reviewsAuthenticated
POST/api/v1/loops/startAuthenticated
GET/api/v1/ontology/proposalsAuthenticated
POST/api/v1/ontology/proposals/:proposalId/resolveAuthenticated

mcpDaemon.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/mcp-daemon/policy-invalidateAuthenticatedbumps the workspace config version, the same signal wasmRules/SOP writes use. Sync daemons poll that counter and re-pull policy, which flushes their local policy LRU.
POST/api/v1/mcp-daemon/reportAuthenticateddaemon-side upload of one status snapshot, authenticated with the workspace API key. A daemon that stops reporting reads as running: false after a few missed intervals rather than showing a stale snapshot forever.
GET/api/v1/mcp-daemon/statusAuthenticateddashboard projection of the stored snapshot. Absence is a valid state, not an error: it renders as a not-running daemon with empty counters.

members.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/membersAuthenticatedList workspace members
DELETE/api/v1/members/:idOWNER/ADMINDeactivate a member
POST/api/v1/members/:id/reactivateOWNER/ADMIN
PUT/api/v1/members/:id/roleOWNER/ADMINUpdate a member's role
POST/api/v1/members/inviteOWNER/ADMINInvite a new member to the workspace

metaclaw.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/metaclaw/proposalsAuthenticated
GET/api/v1/metaclaw/runsAuthenticated
GET/api/v1/metaclaw/runs/:idAuthenticated
POST/api/v1/metaclaw/triggerAuthenticated

notifications.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/notifications/logAuthenticatedNotification history
GET/api/v1/notifications/rulesAuthenticatedList rules
POST/api/v1/notifications/rulesAuthenticatedCreate rule
DELETE/api/v1/notifications/rules/:ruleIdAuthenticatedDelete rule
PUT/api/v1/notifications/rules/:ruleIdAuthenticatedUpdate rule

oauth.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/auth/oauth/githubPublicRedirect to GitHub authorize URL
GET/api/v1/auth/oauth/github/callbackPublicHandle GitHub callback
GET/api/v1/auth/oauth/googlePublicRedirect to Google authorize URL
GET/api/v1/auth/oauth/google/callbackPublicHandle Google callback

orgs.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/orgsAuthenticated
POST/api/v1/orgs/:orgId/billing/checkoutAuthenticated
PATCH/api/v1/orgs/:orgId/gatewayAuthenticated
GET/api/v1/orgs/regionsAuthenticated

orgSops.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/workspace/org-sopsAuthenticated
POST/api/v1/workspace/org-sopsAuthenticated
DELETE/api/v1/workspace/org-sops/:orgSopIdAuthenticated

plans.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/plans/:planIdAuthenticatedGet plan details
GET/api/v1/plans/:planId/adherenceAuthenticatedGet adherence score
POST/api/v1/plans/:planId/approveOWNER/ADMIN/EMApprove plan (OWNER/ADMIN/EM)
POST/api/v1/plans/:planId/closeOWNER/ADMIN/EMClose plan with a final outcome (OWNER/ADMIN/EM)
GET/api/v1/plans/:planId/deviationAuthenticatedGet deviation log
POST/api/v1/plans/:planId/rejectOWNER/ADMIN/EMReject plan before it executes (OWNER/ADMIN/EM)
POST/api/v1/plans/captureAuthenticatedCapture a plan artifact
GET/api/v1/plans/session/:sessionIdAuthenticated
GET/api/v1/sops/:sopId/proof-treeAuthenticatedGet latest proof tree
POST/api/v1/sops/:sopId/proof-treeAuthenticatedCreate/update proof tree
GET/api/v1/sops/:sopId/proof-tree/diffAuthenticatedDiff proof tree versions

policies.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/policiesOWNER/ADMIN/EMList live (non-deleted) policies
POST/api/v1/policiesOWNER/ADMINCreate a policy (records version 1)
PUT/api/v1/policies/:policyIdOWNER/ADMINPartial update; bumps version + snapshots
DELETE/api/v1/policies/:policyIdOWNER/ADMINSoft delete (version history kept for audit)
GET/api/v1/policies/:policyId/versionsOWNER/ADMIN/EMVersion history, newest first
POST/api/v1/policies/:policyId/disableOWNER/ADMIN
POST/api/v1/policies/:policyId/enableOWNER/ADMIN
POST/api/v1/policies/:policyId/rollbackOWNER/ADMINBody {"version": N} — restores as a new version

providerCredentials.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/workspace/provider-credentialsAuthenticatedprovisioning status, every registry provider
DELETE/api/v1/workspace/provider-credentials/:providerOWNER/ADMINde-provision (OWNER/ADMIN only)
PUT/api/v1/workspace/provider-credentials/:providerOWNER/ADMINprovision/rotate (OWNER/ADMIN only)
POST/api/v1/workspace/provider-credentials/:provider/verifyOWNER/ADMINtest the stored credential against the provider's own API.

providerIncidents.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/provider-incidentsAuthenticated
POST/api/v1/provider-incidents/sla-evidenceOWNER/ADMIN
GET/api/v1/provider-incidents/sla-evidence/:runIdOWNER/ADMIN

qmSecurityScreen.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/integrations/qm/security-screenPublic

routing.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/routing/bandit/statusAuthenticatedarm table + convergence summary
GET/api/v1/routing/cache/statsAuthenticatedcache counters
GET/api/v1/routing/mirror-adoption-reportAuthenticatedwin/loss/ tie, fault-rate delta, cost delta, latency delta for one mirror candidate

saml.ts Biz Org+ ​

MethodPathAuthDescription
POST/api/v1/auth/saml/acsPublicAssertion Consumer Service
GET/api/v1/auth/saml/login/:providerIdPublicredirect to the IdP
GET/api/v1/auth/saml/metadata/:providerIdPublicSP metadata XML for the IdP admin

scim.ts Enterprise ​

"Public" in the Auth column means these routes bypass the global workspace JWT middleware — not that they're unauthenticated. Every SCIM request still authenticates via a bearer token the handler itself validates, per the SCIM 2.0 protocol's own auth model.

MethodPathAuthDescription
POST/api/v1/admin/offboarding/retryPublic
GET/scim/v2/GroupsPublic
POST/scim/v2/GroupsPublic
DELETE/scim/v2/Groups/:idPublic
GET/scim/v2/Groups/:idPublic
PATCH/scim/v2/Groups/:idPublic
PUT/scim/v2/Groups/:idPublic
GET/scim/v2/UsersPublicList users with filter/pagination
POST/scim/v2/UsersPublicProvision new user
DELETE/scim/v2/Users/:idPublicDeprovision (full offboarding cascade)
GET/scim/v2/Users/:idPublicGet single user
PATCH/scim/v2/Users/:idPublicPartial update (e.g., deactivate)
PUT/scim/v2/Users/:idPublic

scimTokens.ts Enterprise ​

MethodPathAuthDescription
GET/api/v1/scim/tokensOWNER/ADMIN
POST/api/v1/scim/tokensOWNER/ADMIN
DELETE/api/v1/scim/tokens/:idOWNER/ADMIN

sessions.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/sessionsAuthenticated
GET/api/v1/sessions/:sessionIdAuthenticated
PATCH/api/v1/sessions/:sessionId/attest-sandboxAuthenticated
PATCH/api/v1/sessions/:sessionId/endAuthenticated

siem.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/siem/destinationsAuthenticatedList destinations (masks credentials)
POST/api/v1/siem/destinationsOWNER/ADMINCreate a destination (encrypts credentials)
DELETE/api/v1/siem/destinations/:idOWNER/ADMINDeactivate a destination
GET/api/v1/siem/destinations/:idAuthenticatedGet destination details (masks credentials)
PUT/api/v1/siem/destinations/:idOWNER/ADMINUpdate destination details
POST/api/v1/siem/destinations/:id/testOWNER/ADMINHealth-check a destination
GET/api/v1/siem/dlqAuthenticatedList DLQ failed events
POST/api/v1/siem/dlq/retryOWNER/ADMINTrigger a manual DLQ retry pass

slackCommands.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/adapters/slack/commandsPublic

slackEvents.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/adapters/slack/eventsPublic

slackInteractions.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/adapters/slack/interactionsPublic

slackOAuth.ts Cloud ​

MethodPathAuthDescription
DELETE/api/v1/adapters/slackAuthenticatedRemove installation
POST/api/v1/adapters/slack/link-codeAuthenticatedIssue an account-link code
GET/api/v1/adapters/slack/oauth/authorizeAuthenticatedStart OAuth (redirect)
GET/api/v1/adapters/slack/oauth/callbackPublicOAuth callback
GET/api/v1/adapters/slack/oauth/urlAuthenticated
GET/api/v1/adapters/slack/statusAuthenticatedInstallation status

slashCommand.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/slash-commandPublic

sops.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/sop/dependency-graphAuthenticated
GET/api/v1/sop/rulesAuthenticated
GET/api/v1/sopsAuthenticatedList SOPs (paginated)
POST/api/v1/sopsAuthenticatedCreate SOP
DELETE/api/v1/sops/:sopIdAuthenticatedSoft-delete SOP
GET/api/v1/sops/:sopIdAuthenticatedGet SOP detail
PUT/api/v1/sops/:sopIdAuthenticatedUpdate SOP
GET/api/v1/sops/:sopId/dependenciesAuthenticatedGet dependency graph
GET/api/v1/sops/:sopId/duplicatesAuthenticatedTD-125: Similarity dedup scoring
POST/api/v1/sops/:sopId/godel-probeAuthenticated
GET/api/v1/sops/:sopId/healthAuthenticatedGet health metrics
POST/api/v1/sops/:sopId/holdsAuthenticated
POST/api/v1/sops/:sopId/invalidateAuthenticatedCascade invalidation
POST/api/v1/sops/:sopId/transitionAuthenticatedLifecycle transition
GET/api/v1/sops/:sopId/versionsAuthenticated
POST/api/v1/sops/git-drift-reportAuthenticatedRecord sops status drift results

sslCompliance.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/sessions/:sessionId/ssl-auditAuthenticated
GET/api/v1/sessions/:sessionId/ssl-stateAuthenticated
GET/api/v1/workspaces/:workspaceId/ssl-complianceAuthenticated

sso.ts Biz Org+ ​

MethodPathAuthDescription
GET/api/v1/auth/sso/callbackPublicHandle IdP callback (public)
GET/api/v1/auth/sso/login/:providerIdPublicRedirect to IdP (public)
GET/api/v1/auth/sso/providersAuthenticatedList SSO providers (ADMIN+)
POST/api/v1/auth/sso/providersAuthenticatedCreate provider (OWNER)
DELETE/api/v1/auth/sso/providers/:providerIdAuthenticatedDelete provider (OWNER)

sync.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/sync/configAuthenticatedPush workspace config to daemon
GET/api/v1/sync/reportAuthenticated
POST/api/v1/sync/sop-hashAuthenticatedReceive SOP hash integrity report
POST/api/v1/sync/statusAuthenticatedRecord daemon heartbeat
GET/api/v1/sync/wsPublic

taskManagement.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/task-management/connectionsAuthenticatedList task connections
POST/api/v1/task-management/connectionsAuthenticatedCreate task connection
DELETE/api/v1/task-management/connections/:connectionIdAuthenticated
POST/api/v1/task-management/connections/:connectionId/testAuthenticated

teams.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/orgs/:orgId/teamsAuthenticated
POST/api/v1/orgs/:orgId/teamsAuthenticated
GET/api/v1/teams/:teamId/workspacesAuthenticated
POST/api/v1/teams/:teamId/workspacesAuthenticated

telemetry.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/telemetry/eventPublicForward a telemetry event

traces.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/tracesAuthenticatedList traces with filtering and pagination
GET/api/v1/traces/:idAuthenticatedGet a single trace by ID
GET/api/v1/traces/:id/dagAuthenticated
POST/api/v1/traces/sync-backAuthenticated

trajectory.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/trajectory/alertsOWNER/ADMIN/EMList trajectory alerts for workspace
GET/api/v1/trajectory/alerts/:alertIdOWNER/ADMIN/EM
POST/api/v1/trajectory/analyzeAuthenticatedSubmit trajectory summary for analysis
GET/api/v1/trajectory/status/:sessionIdOWNER/ADMIN/EM

trial.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/trial/statusAuthenticatedAuthenticated, returns trial/plan status for workspace
GET/api/v1/trial/tiersPublicThe plans on sale, with prices and features

trust.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/trust-scoresAuthenticatedAll trust scores for a workspace
GET/api/v1/trust-scores/:userIdAuthenticatedSingle user trust score

usage.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/usage/classifyAuthenticatedClassify tokens as USEFUL or WASTED
GET/api/v1/usage/eventsAuthenticatedPaginated raw execution trace events
GET/api/v1/usage/modelsAuthenticatedPer-model cost breakdown
GET/api/v1/usage/summaryAuthenticatedAggregated usage summary by period

users.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/users/meAuthenticatedGet current user profile + workspaces
PUT/api/v1/users/meAuthenticatedUpdate display name / avatar

wasmRules.ts Cloud ​

MethodPathAuthDescription
GET/api/v1/wasm-rulesAuthenticated
POST/api/v1/wasm-rulesAuthenticated
DELETE/api/v1/wasm-rules/:ruleIdAuthenticated
GET/api/v1/wasm-rules/:ruleIdAuthenticated
PUT/api/v1/wasm-rules/:ruleIdAuthenticated
POST/api/v1/wasm-rules/:ruleId/replayAuthenticated

workspace.ts Cloud ​

MethodPathAuthDescription
POST/api/v1/workspace/byoc/testAuthenticated
GET/api/v1/workspace/dashboardAuthenticatedAggregated dashboard summary
GET/api/v1/workspace/decisions-digestAuthenticated
GET/api/v1/workspace/egress-policyAuthenticated
GET/api/v1/workspace/leaderboardAuthenticated
GET/api/v1/workspace/onboarding-statusAuthenticated
POST/api/v1/workspace/onboarding/completeAuthenticated
GET/api/v1/workspace/postureAuthenticated
POST/api/v1/workspace/postureAuthenticated
GET/api/v1/workspace/regionAuthenticated
PATCH/api/v1/workspace/regionAuthenticated
GET/api/v1/workspace/settingsAuthenticatedRead workspace settings (resolved with defaults)
PUT/api/v1/workspace/settingsOWNER/ADMINUpdate workspace settings (ADMIN+)
GET/api/v1/workspace/sops-policyAuthenticated

Member Invite Endpoint ​

POST /api/v1/members/invite ​

Provision a new workspace member with a temporary password. The admin must share the credentials out-of-band (Intutic does not send invitation emails).

Auth: JWT required (Owner or Admin role)

Request body:

json
{
  "email": "newdev@example.com",
  "displayName": "Jane Developer",
  "role": "DEVELOPER",
  "tempPassword": "initial-secure-pw-123"
}
FieldTypeRequiredValidation
emailstring✅Valid email, max 256 chars
displayNamestring✅1–128 chars
roleenum✅ADMIN, EM, DEVELOPER, VIEWER
tempPasswordstring✅8–128 chars

INFO

The OWNER role cannot be assigned via invite. Only existing Owners can transfer ownership.

Response: 201 Created

json
{
  "memberId": "mb_abc123",
  "userId": "usr_def456",
  "email": "newdev@example.com",
  "displayName": "Jane Developer",
  "role": "DEVELOPER",
  "workspaceId": "wk_ghi789"
}

Error codes:

CodeMeaning
400Validation failed (missing fields, invalid email, password too short)
403Workspace seat limit reached (upgrade plan to add more members)
409Member already exists or duplicate invitation (DUPLICATE_MEMBER)

The circuit breaker for AI agents