Skip to documentation
Integrations & eventsDeveloper tools

Developer tools

Methods, permissions, request fields and response schemas for developer tools.

Read and search

Retrieve current records, history and status.

Read the deployed API capabilitiesDiscover the actions and scopes enabled by the deployed API before automating them.GET/developer/capabilities
Token scope organization:readActor permission ownerAction type read
Explore this request

Edit example fields and validate the request against its schema.

What you receive

{enabled:boolean,financialActionsEnabled:boolean,version:string,actorId:string,organizationId:string,scopes:string[],operations:[{id,method,path,scopes,capability}]}. Catalog of enabled actions and issuing actor/organization identity; financial write actions and scopes are absent unless separately enabled. Each call still checks the token's granted scopes and actor permissions.

Request example · cURL

Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.

curl -X GET "$BASE/developer/capabilities" \
  -H "Authorization: Bearer $ALLPROFILES_API_TOKEN"
Success response schema · HTTP 200
{
  "application/json": {
    "schema": {
      "type": "object",
      "properties": {
        "enabled": {
          "type": "boolean"
        },
        "financialActionsEnabled": {
          "type": "boolean"
        },
        "version": {
          "type": "string",
          "minLength": 0,
          "maxLength": 5000
        },
        "actorId": {
          "type": "string",
          "format": "uuid"
        },
        "organizationId": {
          "type": "string",
          "format": "uuid"
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 0,
            "maxLength": 5000
          }
        },
        "operations": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              },
              "method": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              },
              "path": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              },
              "scopes": {
                "type": "array",
                "items": {
                  "type": "string",
                  "minLength": 0,
                  "maxLength": 5000
                }
              },
              "capability": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              }
            },
            "required": [],
            "additionalProperties": false
          }
        }
      },
      "required": [
        "enabled",
        "financialActionsEnabled",
        "version",
        "actorId",
        "organizationId",
        "scopes",
        "operations"
      ],
      "additionalProperties": false
    }
  }
}
Errors and recovery
400
Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401
Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403
Token scope or actor capability denied, disabled/banned account, or action unavailable.
404
Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409
Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410
event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422
Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429
API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500
Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503
Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.

These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.

Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.

Download the current OpenAPI contractOpenAPI 3.1 document generated from this exact route allowlist. This is the contract for the deployed API version.GET/developer/openapi.json
Token scope organization:readActor permission memberAction type read
Explore this request

Edit example fields and validate the request against its schema.

What you receive

OpenAPI 3.1 document generated from this exact route allowlist. This is the contract for the deployed API version.

Request example · cURL

Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.

curl -X GET "$BASE/developer/openapi.json" \
  -H "Authorization: Bearer $ALLPROFILES_API_TOKEN"
Success response schema · HTTP 200
{
  "application/json": {
    "schema": {
      "type": "object",
      "properties": {
        "openapi": {
          "type": "string",
          "minLength": 0,
          "maxLength": 5000
        },
        "info": {
          "type": "object",
          "properties": {
            "title": {
              "type": "string",
              "minLength": 0,
              "maxLength": 5000
            },
            "version": {
              "type": "string",
              "minLength": 0,
              "maxLength": 5000
            },
            "description": {
              "type": "string",
              "minLength": 0,
              "maxLength": 5000
            }
          },
          "required": [],
          "additionalProperties": false
        },
        "servers": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "url": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              },
              "description": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              }
            },
            "required": [],
            "additionalProperties": false
          }
        },
        "tags": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "name": {
                "type": "string",
                "minLength": 0,
                "maxLength": 5000
              }
            },
            "required": [],
            "additionalProperties": false
          }
        },
        "paths": {
          "type": "object",
          "additionalProperties": true,
          "description": "Platform scrape metadata. Keep credentials out of this field."
        },
        "components": {
          "type": "object",
          "additionalProperties": true,
          "description": "Platform scrape metadata. Keep credentials out of this field."
        }
      },
      "required": [
        "openapi",
        "info",
        "servers",
        "paths",
        "components"
      ],
      "additionalProperties": false
    }
  }
}
Errors and recovery
400
Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401
Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403
Token scope or actor capability denied, disabled/banned account, or action unavailable.
404
Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409
Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410
event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422
Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429
API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500
Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503
Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.

These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.

Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.

Read organization API execution historyArray of the latest 100 executions: {id,operation,state,statusCode,createdAt,finishedAt}. Bodies, tokens and signing secrets are excluded; state is executing/completed/uncertain. No pagination query is supported by this legacy journal view.GET/developer/operations
Token scope organization:readActor permission ownerAction type read
Explore this request

Edit example fields and validate the request against its schema.

What you receive

Array of the latest 100 executions: {id,operation,state,statusCode,createdAt,finishedAt}. Bodies, tokens and signing secrets are excluded; state is executing/completed/uncertain. No pagination query is supported by this legacy journal view.

Request example · cURL

Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.

curl -X GET "$BASE/developer/operations" \
  -H "Authorization: Bearer $ALLPROFILES_API_TOKEN"
Success response schema · HTTP 200
{
  "application/json": {
    "schema": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "operation": {
            "type": "string",
            "minLength": 0,
            "maxLength": 5000
          },
          "state": {
            "type": "string",
            "enum": [
              "executing",
              "completed",
              "uncertain"
            ]
          },
          "statusCode": {
            "type": [
              "integer",
              "null"
            ],
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          },
          "finishedAt": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "operation",
          "state",
          "createdAt"
        ],
        "additionalProperties": false
      }
    }
  }
}
Errors and recovery
400
Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401
Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403
Token scope or actor capability denied, disabled/banned account, or action unavailable.
404
Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409
Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410
event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422
Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429
API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500
Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503
Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.

These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.

Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.

Read one organization API executionInspect a write receipt without exposing request bodies, API tokens or signing secrets.GET/developer/operations/:id
Token scope organization:readActor permission ownerAction type read

Path parameters

FieldTypeDescription and constraints
idRequiredstring · uuid

Resource UUID scoped to the current organization.

Explore this request

Edit example fields and validate the request against its schema.

What you receive

One execution receipt with id,operation,state,statusCode,createdAt,finishedAt. It remains discoverable after newer writes push it beyond the recent history view. Bodies and secrets are excluded.

Request example · cURL

Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.

curl -X GET "$BASE/developer/operations/$ID" \
  -H "Authorization: Bearer $ALLPROFILES_API_TOKEN"
Success response schema · HTTP 200
{
  "application/json": {
    "schema": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "operation": {
          "type": "string",
          "minLength": 0,
          "maxLength": 5000
        },
        "state": {
          "type": "string",
          "enum": [
            "executing",
            "completed",
            "uncertain"
          ]
        },
        "statusCode": {
          "type": [
            "integer",
            "null"
          ],
          "minimum": 0,
          "maximum": 9007199254740991
        },
        "createdAt": {
          "type": "string",
          "format": "date-time"
        },
        "finishedAt": {
          "type": [
            "string",
            "null"
          ],
          "format": "date-time"
        }
      },
      "required": [
        "id",
        "operation",
        "state",
        "createdAt"
      ],
      "additionalProperties": false
    }
  }
}
Errors and recovery
400
Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401
Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403
Token scope or actor capability denied, disabled/banned account, or action unavailable.
404
Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409
Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410
event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422
Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429
API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500
Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503
Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.

These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.

Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.