Loading API reference…
/internal/agent/organizations/{organizationId}/integrationsReturns control-plane readiness, enabled capabilities, access mode, department tags, and profile availability. Includes sanitized, generation-fenced provider health evidence. It never returns credentials, provider endpoints, or OAuth subjects.
Token used by trusted agent runtimes.
In: header
uuidcurl -X GET "https://example.com/internal/agent/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations?authorizationEpoch=1"/internal/agent/organizations/{organizationId}/integrations/{integrationKey}Reads the authorization-fenced safe registry snapshot without contacting the provider.
Token used by trusted agent runtimes.
In: header
uuid^[a-z0-9]+(?:-[a-z0-9]+)*$curl -X GET "https://example.com/internal/agent/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string?authorizationEpoch=1"/organizations/{organizationId}/integrations/preferencesOne organization-owned revisioned order. First usable connections append; reconnects preserve position. Disconnected providers remain in the order but cannot be selected. Preferences rank only providers eligible for the requested operation, account, resources, permissions, and readiness.
uuidapplication/json
curl -X GET "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/preferences"{ "success": true, "statusCode": 0, "message": "string", "data": { "revision": 0, "order": { "property1": [ "string" ], "property2": [ "string" ] } }, "meta": {}}/organizations/{organizationId}/integrations/preferences/{purpose}Owner mutation; requires the current document revision and an exact permutation of existing connector keys for this purpose. Concurrent connection changes return 409 rather than overwriting either order. Refreshes future runtime context without changing authorization or in-progress action receipts. All configured sources continue collecting metrics.
uuidValue in
application/json
TypeScript Definitions
Use the request body type in TypeScript.
application/json
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/preferences/email_delivery" \ -H "Content-Type: application/json" \ -d '{ "expectedRevision": 0, "connectorKeys": [ "string" ] }'{ "success": true, "statusCode": 0, "message": "string", "data": { "revision": 0, "order": { "property1": [ "string" ], "property2": [ "string" ] } }, "meta": {}}/organizations/{organizationId}/integrations/{integrationRef}/resourcesLists connected GitHub repositories in pages of 100, including their exact owner/name and default branch. Uses a fixed GitHub API origin, existing scoped credentials and read-only requests. The owner selects resources and saves them through the revision-fenced operating-context endpoint. Other providers retain their specialized selectors or exact-ID entry.
uuid1 <= value <= 100application/json
curl -X GET "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/resources"{ "success": true, "statusCode": 0, "message": "string", "data": { "context": { "departments": [ "growth" ], "organizationPurpose": "string", "departmentPurposes": { "property1": "string", "property2": "string" }, "policy": "string", "businessFunctions": [ "string" ], "taskPatterns": [ "string" ], "workflowKeys": [ "string" ], "resources": [ { "kind": "repository", "externalId": "string", "name": "string", "url": "http://example.com", "defaultBranch": "string", "departments": [ "growth" ] } ] }, "nextPage": -9007199254740991 }, "meta": {}}/organizations/{organizationId}/integrationsRetired catalog entries without credentials are omitted from the directory. Their retained records remain readable by ID for history and audit.
uuidOpaque alphabetical pagination cursor.
1 <= value <= 20020application/json
curl -X GET "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations"{ "success": true, "statusCode": 0, "message": "string", "data": [ { "contextRevision": 0, "credentialMetadata": { "kind": "api_key", "connectedAt": "2019-08-24T14:15:22Z", "details": { "provider": "resend", "domains": { "status": "missing_permission" } } }, "purposes": [ "email_delivery" ], "description": "string", "operatingContext": {}, "hasReportingCredentials": true, "readOnlyProfileKeys": [ "string" ], "reviewRequiredTools": [ "string" ], "readiness": "ready", "health": { "kind": "integration_health", "generation": "string", "observations": [ { "scope": "string", "status": "verified", "checkedAt": "2019-08-24T14:15:22Z" } ] }, "settings": { "kind": "aws", "accountId": "string", "region": "string", "kubernetesEnabled": true, "metrics": [] } } ], "meta": {}, "pagination": {}}/organizations/{organizationId}/integrationsRequires a public HTTPS endpoint on a deployment-approved origin. Connections use direct HTTPS unless the deployment configures an optional egress proxy.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations" \ -H "Content-Type: application/json" \ -d '{}'/organizations/{organizationId}/integrations/{integrationRef}uuidapplication/json
curl -X GET "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string"{ "success": true, "statusCode": 0, "message": "string", "data": { "contextRevision": 0, "credentialMetadata": { "kind": "api_key", "connectedAt": "2019-08-24T14:15:22Z", "details": { "provider": "resend", "domains": { "status": "missing_permission" } } }, "purposes": [ "email_delivery" ], "description": "string", "operatingContext": {}, "hasReportingCredentials": true, "readOnlyProfileKeys": [ "string" ], "reviewRequiredTools": [ "string" ], "readiness": "ready", "health": { "kind": "integration_health", "generation": "string", "observations": [ { "scope": "string", "status": "verified", "checkedAt": "2019-08-24T14:15:22Z" } ] }, "settings": { "kind": "aws", "accountId": "string", "region": "string", "kubernetesEnabled": true, "metrics": [] } }, "meta": {}}/organizations/{organizationId}/integrations/{integrationRef}Updated endpoints must use public HTTPS and a deployment-approved origin. An egress proxy is optional.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PATCH "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string" \ -H "Content-Type: application/json" \ -d '{}'/organizations/{organizationId}/integrations/{integrationRef}uuidcurl -X DELETE "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string"/organizations/{organizationId}/integrations/{integrationRef}/google-analytics/propertiesReturns bounded, non-secret property options used to configure the Google Analytics integration. A Google Analytics credential must already be connected.
uuidcurl -X GET "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/google-analytics/properties"/organizations/{organizationId}/integrations/{integrationRef}/lemon-squeezy/storesUses the optional write-only API key, or the integration's stored credential when omitted. Returns at most 200 non-secret store options without persisting the supplied key or discovery response.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
application/json
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/lemon-squeezy/stores" \ -H "Content-Type: application/json" \ -d '{}'{ "success": true, "statusCode": 0, "message": "string", "data": { "items": [ { "id": "string", "name": "string", "slug": "string", "domain": "string", "currency": "string" } ], "truncated": true }, "meta": {}}/organizations/{organizationId}/integrations/{integrationRef}/mongodb/resourcesUses supplied structured Atlas credentials, or the integration's stored credential when omitted. Returns collection and sampled dotted-field names only; document values are never returned and no setup state is persisted.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/mongodb/resources" \ -H "Content-Type: application/json" \ -d '{ "databaseName": "string" }'/organizations/{organizationId}/integrations/{integrationRef}/credentialuuidcurl -X DELETE "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/credential"/organizations/{organizationId}/integrations/{integrationRef}/credentialuuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/credential" \ -H "Content-Type: application/json" \ -d '{}'/organizations/{organizationId}/integrations/{integrationRef}/settingsValidates provider-specific resource boundaries and rediscovery before atomically updating settings.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/settings" \ -H "Content-Type: application/json" \ -d '{ "settings": { "kind": "aws", "accountId": "string", "region": "string", "metrics": [] } }'/organizations/{organizationId}/integrations/{integrationRef}/oauth/google/startStarts a runtime-bound Google authorization. Workspace requires selected services and an access mode; Google Analytics uses its fixed read-only scope and accepts an empty body.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/oauth/google/start" \ -H "Content-Type: application/json" \ -d '{ "accessMode": "read_only", "enabledTools": [ "gmail" ] }'/organizations/{organizationId}/integrations/{integrationRef}/oauth/mcp/startStarts provider authorization with the runtime's reviewed dynamic-registration or deployment-client policy. Deployment client IDs are backend configuration and are never accepted from this request.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/oauth/mcp/start" \ -H "Content-Type: application/json" \ -d '{ "accessMode": "read_only" }'/oauth/google/callbackOAuth state for OAuth 2.0 providers. OAuth 1.0a providers return oauth_token instead.
curl -X GET "https://example.com/oauth/google/callback"curl -X GET "https://example.com/oauth/mcp/callback?state=string"/organizations/{organizationId}/integrations/{integrationRef}/oauth/google/grantOwner-only destructive operation. Revokes the combined Google grant and unlinks unchanged Google connections for the same account in this organization. Other connections using this Google application grant also require reconnection. Ordinary credential removal only unlinks one local connector and never invokes provider revocation. Returns revoked, disconnected connector keys, changed connector keys, and a human-readable message. A changed connection must be checked again; it is never overwritten by stale cleanup.
uuidcurl -X DELETE "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/oauth/google/grant"/organizations/{organizationId}/integrations/{integrationRef}/reporting-credentialOwner-only Crisp reporting credentials. Verifies the REST website against the existing MCP website and performs a conversation read before encrypting the credential separately. Send credential:null to remove reporting access. Plaintext is never returned or delivered to agents.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/reporting-credential" \ -H "Content-Type: application/json" \ -d '{ "credential": { "kind": "crisp", "websiteId": "eee0b185-ac19-4fd6-bb45-58b59a8988e9", "identifier": "string", "key": "string", "tier": "website" } }'/organizations/{organizationId}/integrations/{integrationRef}/checkRuns a bounded check and returns the integration projection with sanitized, generation-fenced health. Discovery verifies available tools, not access to every data operation. Actual operation results are tracked separately. Does not change grants, tools or settings.
uuidapplication/json
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/check"{ "success": true, "statusCode": 0, "message": "string", "data": { "contextRevision": 0, "credentialMetadata": { "kind": "api_key", "connectedAt": "2019-08-24T14:15:22Z", "details": { "provider": "resend", "domains": { "status": "missing_permission" } } }, "purposes": [ "email_delivery" ], "description": "string", "operatingContext": {}, "hasReportingCredentials": true, "readOnlyProfileKeys": [ "string" ], "reviewRequiredTools": [ "string" ], "readiness": "ready", "health": { "kind": "integration_health", "generation": "string", "observations": [ { "scope": "string", "status": "verified", "checkedAt": "2019-08-24T14:15:22Z" } ] }, "settings": { "kind": "aws", "accountId": "string", "region": "string", "kubernetesEnabled": true, "metrics": [] } }, "meta": {}}/organizations/{organizationId}/integrations/{integrationRef}/discoveruuidcurl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/discover"/organizations/{organizationId}/integrations/{integrationRef}/statusuuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PATCH "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/status" \ -H "Content-Type: application/json" \ -d '{}'/organizations/{organizationId}/integrations/{integrationRef}/profilesReplaces profile grants and optional read-only restrictions. Read-only profile keys must be granted access. Operator and Chat retain discovery access. Operator remains read-only; Chat can perform explicitly requested owner changes within current access restrictions. Changes invalidate active authorization and apply to MCP, CLI, Git, pending actions, and requirement admission. Built-in catalog upgrades preserve owner selections. Shared business metric aggregates remain available to enabled organizational profiles within current selected resource scope.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/profiles" \ -H "Content-Type: application/json" \ -d '{ "profileGrants": [ "string" ], "readOnlyProfileKeys": [ "string" ] }'/organizations/{organizationId}/integrations/{integrationRef}/toolsuuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PUT "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/tools" \ -H "Content-Type: application/json" \ -d '{}'/organizations/{organizationId}/integrations/{integrationRef}/context-mappingReplaces business usage and resource bindings in PostgreSQL with a context revision fence. No agentic refresh is scheduled. Credentials and tool permissions are unchanged.
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/context-mapping" \ -H "Content-Type: application/json" \ -d '{ "expectedRevision": 0, "context": { "resources": [ { "kind": "repository", "externalId": "string", "name": "string", "departments": [ "growth" ] } ] } }'/internal/agent/organizations/{organizationId}/integrations/{integrationKey}/contextChat and Operator executions may replace purpose, usage, policy and resource bindings. Requires a current authorization epoch, active chat turn or task lease, and matching context revision. Department executions cannot change organization integration context. No semantic refresh is scheduled.
agentExecutionCapability Short-lived capability scoped to one organization, profile, and task run or chat turn.
In: header
uuid^[a-z0-9]+(?:-[a-z0-9]+)*$application/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X PATCH "https://example.com/internal/agent/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/string/context" \ -H "Content-Type: application/json" \ -d '{ "expectedRevision": 0, "context": { "resources": [ { "kind": "repository", "externalId": "string", "name": "string", "departments": [ "growth" ] } ] }, "authorizationEpoch": 1 }'/internal/agent/organizations/{organizationId}/integrations/resolveagentServiceToken Token used by trusted agent runtimes.
In: header
uuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/internal/agent/organizations/497f6eca-6276-4993-bfeb-53cbbbba6f08/integrations/resolve" \ -H "Content-Type: application/json" \ -d '{}'/internal/git/integrations/{integrationId}/{owner}/{repository}/info/refsProxies Git smart-HTTP discovery to the fixed GitHub origin. Upload-pack is available to granted non-verification Engineering task runs; receive-pack additionally requires execute mode and full integration access.
integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuid^[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})$^[A-Za-z0-9_.-]{1,100}$Value in
curl -X GET "https://example.com/internal/git/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/string/string/info/refs?service=git-upload-pack""string"/internal/git/integrations/{integrationId}/{owner}/{repository}/git-upload-packintegrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuid^[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})$^[A-Za-z0-9_.-]{1,100}$application/x-git-upload-pack-request
TypeScript Definitions
Use the request body type in TypeScript.
binaryapplication/x-git-upload-pack-result
curl -X POST "https://example.com/internal/git/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/string/string/git-upload-pack" \ -H "Content-Type: application/x-git-upload-pack-request" \ -d 'string'"string"/internal/git/integrations/{integrationId}/{owner}/{repository}/git-receive-packValidates and privately stages a bounded receive-pack, then routes the branch update through the typed action lifecycle. An authorized exact 0000 probe returns an empty successful Git response without staging or creating an action. Shallow-clone boundaries are validated before branch updates and preserved in the staged request. Tags, deletions, push options, and more than 20 ref updates are rejected.
integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuid^[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})$^[A-Za-z0-9_.-]{1,100}$application/x-git-receive-pack-request
TypeScript Definitions
Use the request body type in TypeScript.
binaryapplication/x-git-receive-pack-result
curl -X POST "https://example.com/internal/git/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/string/string/git-receive-pack" \ -H "Content-Type: application/x-git-receive-pack-request" \ -d 'string'"string"/internal/cli/integrations/{integrationId}/invocations/{invocationId}/executeintegrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuiduuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/internal/cli/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/invocations/497f6eca-6276-4993-bfeb-53cbbbba6f08/execute" \ -H "Content-Type: application/json" \ -d '{}'/internal/cli/integrations/{integrationId}/invocations/{invocationId}/files/{fileId}integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuiduuiduuidcurl -X GET "https://example.com/internal/cli/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/invocations/497f6eca-6276-4993-bfeb-53cbbbba6f08/files/497f6eca-6276-4993-bfeb-53cbbbba6f08"/internal/cli/integrations/{integrationId}/invocations/{invocationId}/files/{fileId}integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuiduuiduuidapplication/octet-stream
TypeScript Definitions
Use the request body type in TypeScript.
binarycurl -X PUT "https://example.com/internal/cli/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/invocations/497f6eca-6276-4993-bfeb-53cbbbba6f08/files/497f6eca-6276-4993-bfeb-53cbbbba6f08" \ -H "Content-Type: application/octet-stream" \ -d 'string'/internal/cli/integrations/{integrationId}/invocations/{invocationId}/files/{fileId}/beginCreates a short-lived presigned PUT for one invocation-owned companion file. The runtime applies provider-specific type, size, count, and aggregate limits; no provider receives a public file URL.
integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuiduuiduuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/internal/cli/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/invocations/497f6eca-6276-4993-bfeb-53cbbbba6f08/files/497f6eca-6276-4993-bfeb-53cbbbba6f08/begin" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "contentType": "string", "sizeBytes": 1, "sha256": "string" }'/internal/cli/integrations/{integrationId}/invocations/{invocationId}/files/{fileId}/completeStreams the staged object to verify ownership, size, content type, server-calculated SHA-256, and any provider-specific signature before an action may be proposed.
integrationGatewayCapability Short-lived capability scoped to one organization, profile, integration, and execution.
In: header
uuiduuiduuidapplication/json
TypeScript Definitions
Use the request body type in TypeScript.
curl -X POST "https://example.com/internal/cli/integrations/497f6eca-6276-4993-bfeb-53cbbbba6f08/invocations/497f6eca-6276-4993-bfeb-53cbbbba6f08/files/497f6eca-6276-4993-bfeb-53cbbbba6f08/complete" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "contentType": "string", "sizeBytes": 1, "sha256": "string" }'0 <= value <= 9007199254740991items <= 2001 <= length <= 163841 <= length <= 641 <= length <= 16384Defaults to read_only when omitted.
Value in
When supplied, this explicit non-empty subset wins. When omitted, Oblive preserves a same-mode selection. New custom read-only connections start with no enabled tools; review tools after connecting.
1 <= items <= 200Value in
1 <= items <= 9Value in
items <= 20items <= 20Value in
Value in
1 <= items <= 200items <= 5000 <= value <= 90071992547409910 <= value <= 90071992547409910 < value <= 90071992547409911 <= length <= 2551 <= length <= 2551 <= value <= 1073741824^[a-f0-9]{64}$1 <= length <= 2551 <= length <= 2551 <= value <= 1073741824^[a-f0-9]{64}$