All paths start with /api/developer-portal and need a session token. Request bodies are validated; an invalid body returns 400 Invalid request payload.
| Method | Path | Description |
|---|
GET | /me | {user, workspace, organization, role} for the current session |
GET | /account | Your account |
PATCH | /account | {name} |
GET | /notifications | {items, unreadCount} (up to 50) |
POST | /notifications/:id/read | Marks a notification read |
GET | /workspace | The current workspace |
PATCH | /workspace | {name} |
GET | /workspaces | Workspaces you belong to |
POST | /workspaces | Creates a workspace |
| Method | Path | Body and notes |
|---|
GET | /workspace/members | Members and roles |
PATCH | /workspace/members/:memberId | {role?, status?} |
POST | /workspace/members/:memberId/suspend | — |
POST | /workspace/members/:memberId/reactivate | — |
POST | /workspace/members/:memberId/transfer-ownership | — |
DELETE | /workspace/members/:memberId | Removes the member |
GET | /workspace/invitations | Pending invitations |
POST | /workspace/invitations | {email, role} (default role DEVELOPER) |
POST | /workspace/invitations/accept | {token} |
POST | /workspace/invitations/:id/revoke | — |
| Method | Path | Body and notes |
|---|
GET | /projects | All projects |
POST | /projects | {name, key, description?}. The key is 2–32 characters, starts with a letter and is upper-cased. |
GET | /projects/:id | One project |
PATCH | /projects/:id | Partial update |
GET | /projects/:id/activity | Recent activity |
GET | /projects/:id/environments | Project environments |
POST | /projects/:id/environments | Creates a project environment |
POST | /projects/:id/imports/postman/preview | {applicationId, sourceName?, collection, selectedRequestIds?}. Postman v2.0 or v2.1, up to 1 MB and 500 requests. |
POST | /projects/:id/imports/postman | Same body; imports into a sandbox request collection. Scripts are stored but never run. |
GET | /projects/:id/imports | Import history |
| Method | Path | Permission | Body and notes |
|---|
GET | /apps | apps.read | Applications with their credentials (prefix and last four characters only) |
POST | /apps | apps.manage | See the application fields below |
GET | /apps/:appId | apps.read | One application, including productionAccess |
PATCH | /apps/:appId | apps.manage | Partial update |
DELETE | /apps/:appId | Workspace admin | {confirmation: "<exact app name>", reason?}. Retires the app; it is not deleted. |
POST | /apps/:appId/archive | Workspace admin | Archives the app |
POST | /apps/:appId/restore | Workspace admin | Restores it |
GET | /apps/:appId/members | apps.read | App members |
POST | /apps/:appId/members | apps.manage | {tenantMemberId, accessLevel: manager, developer or viewer} |
PATCH, DELETE | /apps/:appId/members/:assignmentId | apps.manage | Change or remove access |
GET | /apps/:appId/production-access-requests | apps.read | Requests and their status |
POST | /apps/:appId/production-access-requests | apps.manage | {useCase (20–2,000 characters), securityContactEmail} |
An application has these fields:
| Field | Notes |
|---|
name | 1–120 characters |
description | Optional |
projectId | Optional |
applicationType | server, spa, mobile or service |
redirectUris[] | Up to 20 |
allowedOrigins[] | Up to 20 |
scopes[] | Up to 50 |
productIds[] | Up to 50 |
| Method | Path | Permission | Body and notes |
|---|
GET | /apps/:appId/keys | credentials.manage | Keys without secrets |
POST | /apps/:appId/keys | credentials.manage | {name?, environment: sandbox or live, scopes: ["read"], ["write"] or both, expiresAt?} |
POST | /apps/:appId/keys/:keyId/rotate | credentials.manage | Returns a new secret for an active key |
POST | /apps/:appId/keys/:keyId/revoke | credentials.manage | Revokes the key |
Create and rotate return {credential, secret, revealPolicy}. The secret is shown once. Live keys need a workspace administrator and an application already approved for production.
| Method | Path | Body and notes |
|---|
GET | /apps/:appId/sandbox/catalogue | Endpoints the app can call |
POST | /apps/:appId/sandbox/test | {method, path, body?, credentialId?}. Returns {request, response: {statusCode, body, durationMs, headers}, log}. Limited to 30 requests a minute. |
GET, POST | /apps/:appId/sandbox/collections | Saved request collections |
PATCH, DELETE | /apps/:appId/sandbox/collections/:collectionId | Update or remove a collection |
POST | /apps/:appId/sandbox/collections/:collectionId/requests | Saves a request |
PATCH, DELETE | /apps/:appId/sandbox/collections/:collectionId/requests/:requestId | Update or remove a saved request |
GET | /apps/:appId/request-logs | The 100 most recent requests |
credentialId must be an active sandbox key with the scope the method needs. The endpoint must belong to a product the application subscribes to. Synthetic errors are sandbox_credential_required (401) and sandbox_operation_unavailable (404).
| Method | Path | Permission | Description |
|---|
GET | /usage/summary | usage.read | API requests, MCP calls, AI usage, webhook deliveries and billing usage |
GET | /usage/analytics?days=7, 30 or 90 | usage.read | Time series, status distribution, top endpoints, and breakdowns by application, environment and credential |
GET | /logs/requests | usage.read | Filters appId, status (success, error or a code), environment; limit 1–100 |
GET | /logs/mcp, /logs/ai, /logs/webhooks | usage.read | Same filters, plus eventType for webhooks |
GET | /audit-events | audit.read | q, action, cursor, limit; returns {events, nextCursor} |
GET | /audit-events/export | audit.export | action, from, to (up to 366 days, 10,000 events). Returns signed NDJSON: {content, sha256, hmac, algorithm, count, window}. Enabled per deployment. |
| Method | Path | Body and notes |
|---|
GET | /documentation-sites | Sites with page counts |
POST | /documentation-sites | {name, slug?, description?, projectId?, apiProductId?, logoUrl?, visibility?, branding?} |
GET | /documentation-sites/:siteId | One site |
PATCH | /documentation-sites/:siteId | Same fields, all optional |
GET | /documentation-sites/:siteId/pages | Pages in navigation order |
POST | /documentation-sites/:siteId/pages | {title, section, description, content, format?, visibility?, navigationOrder?, parentId?, apiVersionId?} |
See Custom documentation for the review and publish workflow.
These paths start with /api/developer-portal/sdk.
| Method | Path | Description |
|---|
GET | /sdk/targets | Languages, runtimes and generator versions |
POST | /sdk/generate | {apiProductSlug, apiVersion?, language, targetId?, applicationId?, environment, options?}. Returns a job. |
GET | /sdk/jobs | Jobs |
GET | /sdk/jobs/:jobId | One job |
POST | /sdk/jobs/:jobId/cancel | Cancels a job |
GET | /sdk/artifacts | Artefacts |
GET | /sdk/artifacts/:artifactId/download | The file, with X-SDK-SHA256 |
GET | /sdk/compatibility?apiProductSlug=&fromApiVersion=&toApiVersion= | Compatibility report between two versions |
GET | /sdk/releases | Releases |
POST | /sdk/releases | {artifactId, sdkVersion, channel: preview or stable, releaseNotes?} |
POST | /sdk/releases/:id/deprecate, /quarantine or /retire | Changes the release state |