API reference
Everything the UI does goes through the control plane's HTTP API, and that API is described by a generated OpenAPI document.
Where it lives
Open the API entry in the header — the interactive reference
(/reference, Scalar over the live document) renders inside the
app once you are signed in. The raw document is at /_openapi.json, and the
generated /_scalar and /_swagger pages exist too.
Why it is behind sign-in
This is a session-authenticated internal API, and the document maps the whole surface — including destructive routes like project deletion and pipeline submission. Every route checks your session (and project routes check your membership), and the reference itself is gated the same way: it describes your attack surface, so it is not served anonymously.
Calling it yourself
The API speaks the same session cookies the app uses; there are no separate API tokens yet. Per-user API tokens — and an MCP server in front of this API, so agents can drive your platform the way the UI does — are on the roadmap as a product feature of the paid plans.