API reference

The management API behind the Agent Authority console, generated from its OpenAPI description. Base URL, credential, stability, and the conventions that apply to every operation.

This API configures the resources, policies, agents, and access rules that govern how AI agents reach your tools. It also reads back the audit, analytics, and anomaly data the console displays. Anything you can do on a console screen has an operation here, because the console is built on it.

Before your first call

Base URLYour organization's own gateway host, then /api/v1. See Authentication.
CredentialAn API key, sent as Authorization: Bearer saai_api_.... See Authentication.
FormatJSON request and response bodies.
Pagingoffset and limit on most list operations. See Conventions for all three shapes.

How stable it is

Every operation is generated from the service's OpenAPI description, so the reference always matches the running gateway. That description is itself compiled from a typed source contract. Each change is checked against the previous one, and a build that would break an existing client fails before it merges. Additive changes, such as a new operation or a new optional field, ship freely.

Two surfaces, two credentials

Agent Authority exposes two separate HTTP surfaces, and they are easy to confuse:

  • This management API (/api/v1) is where you administer the product. You call it with an API key to configure the gateway and to read back what it recorded.
  • The gateway MCP endpoints (/gateway/mcp) are where the work happens. AI agents call those at tool-call time, with their own credential and their own rules. Gateway endpoints and authentication covers them.

A credential for one surface does not work on the other.

Browse or generate

Browse by tag in the sidebar, or download the OpenAPI description to generate a client and explore it in your own tools. The download carries the same operations as these pages.

Next steps

On this page