- authenticate every product request;
- send stable idempotency keys for retryable mutations;
- preserve correlation IDs;
- treat
cannot_runand abstention as first-class outcomes; - page or bound audit and list requests;
- never infer workspace access from identifier shape.
Overview
API overview
Durable, workspace-scoped control-plane contracts
The REST API exposes identity, workspaces, repositories, reviews and evidence,
findings and fixes, scans and schedules, policies, usage, audit, integrations,
OAuth, and admin governance.
The generated pages in this section come from the committed OpenAPI 3.1 schema.
Clients should:
Last modified on July 28, 2026
⌘I

