Skip to main content
The running deployment publishes its OpenAPI 3.1 contract at /api/openapi.json and Swagger UI at /api/docs. Send a root or scoped broker credential on authenticated server requests:

Connections

An access body may contain:
configuration contains non-secret input accepted by the trusted provider. Provider selection always comes from the final path segment, never the body. The provider list describes credential acquisition and input controls:
Authentication is oauth or secret. Identity fields become path segments; configuration fields become immutable, non-secret connection configuration; scope fields become requested OAuth scopes. Clients should render input_schema.fields.

Broker administration

Browser facade

When application auth is configured, /api/client exposes provider metadata, connection metadata, authorization starts, write-only secret storage, and disconnect. It rejects credential access, callbacks, and administration. All application responses set Cache-Control: no-store. List and get responses never include stored secrets, refresh tokens, OAuth client secrets, or bearer values. Secret writes return only storage status.