API reference
The CloudRaker gateway API: spaces, files, actions, playbooks, objects, and knowledge graphs. One tenant per token.
Base URL
Every call goes to the one gateway base:
The API returns opaque string ids. See Versioning and compatibility for what can change without warning.
Authentication
Every request carries a bearer token in the Authorization header. The developer credential is an organization API key. Create the key in the app under Admin > API keys. See the API keys guide.
An API key is an org-level machine credential. It resolves to your organization and can call any org-wide or admin route. The app shows the plaintext value once, when you create the key. You cannot retrieve it again. Store it in a safe place. The API also accepts session JWTs from the web app, but use API keys for integrations.
API keys carry no per-user membership. A key cannot satisfy a route gated on a specific person’s fine-grained resource grant. Use keys for server-to-server, org-wide automation.
Auth responses
GET /health is the only unauthenticated endpoint you normally touch.
Endpoint groups
How scoping and authorization work
- One organization = one tenant. Your token’s org determines which data you reach. There is no cross-tenant access.
- The gateway enforces fine-grained per-resource permissions. Missing
space:readreturns 404, which hides existence. Missingspace:contributereturns 403. Org admins bypass space checks. - Errors are JSON
{ "error": "<snake_case_code>" }. Pagination is per-group. See each endpoint for itslimit/offset/cursor shape.
The Developer guide covers authentication, the file-upload flow, and reacting to events. Browse each endpoint in the sidebar, with parameters, schemas, and a runnable example.