API Referencev1

Developer portal API

Workspaces, members, projects, applications, API keys, the sandbox explorer, usage and logs, audit events, documentation sites and SDKs.

Updated 07/10/2026

On this page

All paths start with /api/developer-portal and need a session token. Request bodies are validated; an invalid body returns 400 Invalid request payload.

Account and workspace

MethodPathDescription
GET/me{user, workspace, organization, role} for the current session
GET/accountYour account
PATCH/account{name}
GET/notifications{items, unreadCount} (up to 50)
POST/notifications/:id/readMarks a notification read
GET/workspaceThe current workspace
PATCH/workspace{name}
GET/workspacesWorkspaces you belong to
POST/workspacesCreates a workspace

Members and invitations

MethodPathBody and notes
GET/workspace/membersMembers and roles
PATCH/workspace/members/:memberId{role?, status?}
POST/workspace/members/:memberId/suspend—
POST/workspace/members/:memberId/reactivate—
POST/workspace/members/:memberId/transfer-ownership—
DELETE/workspace/members/:memberIdRemoves the member
GET/workspace/invitationsPending invitations
POST/workspace/invitations{email, role} (default role DEVELOPER)
POST/workspace/invitations/accept{token}
POST/workspace/invitations/:id/revoke—

Projects

MethodPathBody and notes
GET/projectsAll projects
POST/projects{name, key, description?}. The key is 2–32 characters, starts with a letter and is upper-cased.
GET/projects/:idOne project
PATCH/projects/:idPartial update
GET/projects/:id/activityRecent activity
GET/projects/:id/environmentsProject environments
POST/projects/:id/environmentsCreates a project environment
POST/projects/:id/imports/postman/preview{applicationId, sourceName?, collection, selectedRequestIds?}. Postman v2.0 or v2.1, up to 1 MB and 500 requests.
POST/projects/:id/imports/postmanSame body; imports into a sandbox request collection. Scripts are stored but never run.
GET/projects/:id/importsImport history

Applications

MethodPathPermissionBody and notes
GET/appsapps.readApplications with their credentials (prefix and last four characters only)
POST/appsapps.manageSee the application fields below
GET/apps/:appIdapps.readOne application, including productionAccess
PATCH/apps/:appIdapps.managePartial update
DELETE/apps/:appIdWorkspace admin{confirmation: "<exact app name>", reason?}. Retires the app; it is not deleted.
POST/apps/:appId/archiveWorkspace adminArchives the app
POST/apps/:appId/restoreWorkspace adminRestores it
GET/apps/:appId/membersapps.readApp members
POST/apps/:appId/membersapps.manage{tenantMemberId, accessLevel: manager, developer or viewer}
PATCH, DELETE/apps/:appId/members/:assignmentIdapps.manageChange or remove access
GET/apps/:appId/production-access-requestsapps.readRequests and their status
POST/apps/:appId/production-access-requestsapps.manage{useCase (20–2,000 characters), securityContactEmail}

An application has these fields:

FieldNotes
name1–120 characters
descriptionOptional
projectIdOptional
applicationTypeserver, spa, mobile or service
redirectUris[]Up to 20
allowedOrigins[]Up to 20
scopes[]Up to 50
productIds[]Up to 50

API keys

MethodPathPermissionBody and notes
GET/apps/:appId/keyscredentials.manageKeys without secrets
POST/apps/:appId/keyscredentials.manage{name?, environment: sandbox or live, scopes: ["read"], ["write"] or both, expiresAt?}
POST/apps/:appId/keys/:keyId/rotatecredentials.manageReturns a new secret for an active key
POST/apps/:appId/keys/:keyId/revokecredentials.manageRevokes the key

Create and rotate return {credential, secret, revealPolicy}. The secret is shown once. Live keys need a workspace administrator and an application already approved for production.

Sandbox explorer

MethodPathBody and notes
GET/apps/:appId/sandbox/catalogueEndpoints the app can call
POST/apps/:appId/sandbox/test{method, path, body?, credentialId?}. Returns {request, response: {statusCode, body, durationMs, headers}, log}. Limited to 30 requests a minute.
GET, POST/apps/:appId/sandbox/collectionsSaved request collections
PATCH, DELETE/apps/:appId/sandbox/collections/:collectionIdUpdate or remove a collection
POST/apps/:appId/sandbox/collections/:collectionId/requestsSaves a request
PATCH, DELETE/apps/:appId/sandbox/collections/:collectionId/requests/:requestIdUpdate or remove a saved request
GET/apps/:appId/request-logsThe 100 most recent requests

credentialId must be an active sandbox key with the scope the method needs. The endpoint must belong to a product the application subscribes to. Synthetic errors are sandbox_credential_required (401) and sandbox_operation_unavailable (404).

Usage, logs and audit

MethodPathPermissionDescription
GET/usage/summaryusage.readAPI requests, MCP calls, AI usage, webhook deliveries and billing usage
GET/usage/analytics?days=7, 30 or 90usage.readTime series, status distribution, top endpoints, and breakdowns by application, environment and credential
GET/logs/requestsusage.readFilters appId, status (success, error or a code), environment; limit 1–100
GET/logs/mcp, /logs/ai, /logs/webhooksusage.readSame filters, plus eventType for webhooks
GET/audit-eventsaudit.readq, action, cursor, limit; returns {events, nextCursor}
GET/audit-events/exportaudit.exportaction, from, to (up to 366 days, 10,000 events). Returns signed NDJSON: {content, sha256, hmac, algorithm, count, window}. Enabled per deployment.

Documentation sites

MethodPathBody and notes
GET/documentation-sitesSites with page counts
POST/documentation-sites{name, slug?, description?, projectId?, apiProductId?, logoUrl?, visibility?, branding?}
GET/documentation-sites/:siteIdOne site
PATCH/documentation-sites/:siteIdSame fields, all optional
GET/documentation-sites/:siteId/pagesPages in navigation order
POST/documentation-sites/:siteId/pages{title, section, description, content, format?, visibility?, navigationOrder?, parentId?, apiVersionId?}

See Custom documentation for the review and publish workflow.

SDKs

These paths start with /api/developer-portal/sdk.

MethodPathDescription
GET/sdk/targetsLanguages, runtimes and generator versions
POST/sdk/generate{apiProductSlug, apiVersion?, language, targetId?, applicationId?, environment, options?}. Returns a job.
GET/sdk/jobsJobs
GET/sdk/jobs/:jobIdOne job
POST/sdk/jobs/:jobId/cancelCancels a job
GET/sdk/artifactsArtefacts
GET/sdk/artifacts/:artifactId/downloadThe file, with X-SDK-SHA256
GET/sdk/compatibility?apiProductSlug=&fromApiVersion=&toApiVersion=Compatibility report between two versions
GET/sdk/releasesReleases
POST/sdk/releases{artifactId, sdkVersion, channel: preview or stable, releaseNotes?}
POST/sdk/releases/:id/deprecate, /quarantine or /retireChanges the release state

Need a hand?

Ask Nexra AI for implementation steps or error guidance.

Ask Nexra AI