Base URL
Authentication
All/v1/* requests (except OAuth callbacks and webhooks) require a bearer token:
Two endpoint surfaces
Repo exposes two parallel route surfaces:- Agent API (
/v1/*) — authenticated byrepo_API keys. This is what your agent code calls. - Console API (
/v1/console/*) — authenticated by Supabase Auth bearer tokens. This is what the browser console calls. Documented in [the Console section] (coming soon) — most agent integrations should ignore it.
admin-scoped key instead.
Endpoints at a glance
POST /v1/search
Vector search across your org’s memory. Returns ranked hits.
POST /v1/context
Search + Context Contract with citations, exclusions, and limitations.
POST /v1/ask
Grounded answer generation. Citations included.
GET /v1/memory-canvas
Graph view of entities, relationships, and sources.
GET/POST/DELETE /v1/api-keys
Mint, list, and revoke API keys (admin only).
GET /v1/sources
List connectors and their health.
GET/POST /v1/sync-runs
View sync history; trigger manual syncs.
POST /v1/ingest
Push documents directly without a connector.
GET /v1/audit-events
Pull the audit trail for compliance review.
Conventions
- Request body: JSON. Always include
Content-Type: application/json. - Response body: JSON. UTF-8.
- Timestamps: ISO 8601 UTC, e.g.
2026-05-30T20:14:00.123Z. - IDs: UUIDv4 unless otherwise noted.
- Pagination: cursor-based on endpoints that need it (none yet require it heavily). When introduced, the pattern will be
?cursor=...&limit=...with anextCursorin the response.
Errors
See Errors for the full status code catalog. The short version:
Error bodies are JSON:
{ "error": "human-readable message" } plus optional structured fields.