Skip to content
downpipes docs

Engine admin API explorer

This explorer is generated from the engine admin router and committed into the documentation. It proves the integrity of the documentation build, not the engine you are running, and it does not detect drift from a deployed engine. If the engine changes after this snapshot was generated, this page will not know. A separate roadmap item has the engine emit and sign its own specification so you can verify the running engine directly; that is not what this page does today. The routes below carry the method, path, a summary read from the path, and the area tag. Request and response shapes are not asserted here, because the router alone does not prove them.

downpipes engine admin API

Version r170.19910072d2be

This specification is generated from the engine admin router at docs-build time and committed into the documentation repository. A digest pinned over the published documentation artefact therefore proves the integrity of the documentation build, not the provenance of the engine you are running. It does not detect drift from a deployed engine: if the engine changes after this snapshot was generated, this page will not know. A separate roadmap item has the engine emit and cryptographically sign its own specification, which would let you verify the running engine directly; that is not what this page does today. The route set below (paths, methods, summaries and tags) is read from the router source; request and response shapes are deliberately not asserted here, because they are not proven by the router alone.

Download the OpenAPI spec

Base URLs

  • https://console.example.com/admin Your console's custom domain, suffixed with /admin. The console proxies these routes to the in-account engine over a service binding; the engine has no public host of its own.

attest

Endpoints under /attest.

POST/attest/session/abort

Submit attest session abort

post-attest-session-abort

POST/attest/session/capsules

Submit attest session capsules

post-attest-session-capsules

POST/attest/session/create

Submit attest session create

post-attest-session-create

POST/attest/session/prove

Submit attest session prove

post-attest-session-prove

GET/attest/session/status

Read attest session status

get-attest-session-status

POST/attest/session/verify

Submit attest session verify

post-attest-session-verify

audit

Endpoints under /audit.

GET/audit

Read audit

get-audit

GET/audit/export

Read audit export

get-audit-export

POST/audit/intent

Submit audit intent

post-audit-intent

GET/audit/verify

Read audit verify

get-audit-verify

canary

Endpoints under /canary.

GET/canary

Read canary

get-canary

POST/canary/config

Submit canary config

post-canary-config

POST/canary/run

Submit canary run

post-canary-run

config

Endpoints under /config.

GET/config/approval-policy

Read config approval policy

get-config-approval-policy

POST/config/approval-policy

Submit config approval policy

post-config-approval-policy

GET/config/attended-cadence

Read config attended cadence

get-config-attended-cadence

POST/config/attended-cadence

Submit config attended cadence

post-config-attended-cadence

POST/config/change-number-policy

Submit config change number policy

post-config-change-number-policy

GET/config/changes

Read config changes

get-config-changes

POST/config/changes/{id}/approve

Submit config changes by id approve

post-config-changes-id-approve

POST/config/changes/{id}/reject

Submit config changes by id reject

post-config-changes-id-reject

GET/config/diff

Read config diff

get-config-diff

GET/config/history

Read config history

get-config-history

POST/config/signin-context-policy

Submit config signin context policy

post-config-signin-context-policy

POST/config/snapshot

Submit config snapshot

post-config-snapshot

GET/config/version

Read config version

get-config-version

control-plane

Endpoints under /control-plane.

POST/control-plane/apply-staged

Submit control plane apply staged

post-control-plane-apply-staged

GET/control-plane/export-download

Read control plane export download

get-control-plane-export-download

POST/control-plane/import

Submit control plane import

post-control-plane-import

POST/control-plane/import-sealed

Submit control plane import sealed

post-control-plane-import-sealed

POST/control-plane/restore

Submit control plane restore

post-control-plane-restore

POST/control-plane/restore-sealed

Submit control plane restore sealed

post-control-plane-restore-sealed

GET/control-plane/status

Read control plane status

get-control-plane-status

cost

Endpoints under /cost.

GET/cost/estate-size

Read cost estate size

get-cost-estate-size

coverage

Endpoints under /coverage.

GET/coverage

Read coverage

get-coverage

POST/coverage/inventory

Submit coverage inventory

post-coverage-inventory

custody

Endpoints under /custody.

POST/custody/send-share

Submit custody send share

post-custody-send-share

custom-roles

Endpoints under /custom-roles.

GET/custom-roles

Read custom roles

get-custom-roles

POST/custom-roles

Submit custom roles

post-custom-roles

POST/custom-roles/delete

Submit custom roles delete

post-custom-roles-delete

demo

Endpoints under /demo.

POST/demo/reset

Submit demo reset

post-demo-reset

destination

Endpoints under /destination.

GET/destination

Read destination

get-destination

POST/destination

Submit destination

post-destination

POST/destination/verify

Submit destination verify

post-destination-verify

destinations

Endpoints under /destinations.

GET/destinations

Read destinations

get-destinations

POST/destinations

Submit destinations

post-destinations

POST/destinations/default

Submit destinations default

post-destinations-default

POST/destinations/remove

Submit destinations remove

post-destinations-remove

downpipes

Endpoints under /downpipes.

GET/downpipes

Read downpipes

get-downpipes

POST/downpipes

Submit downpipes

post-downpipes

POST/downpipes/bulk

Submit downpipes bulk

post-downpipes-bulk

POST/downpipes/cf-config/mode

Submit downpipes cf config mode

post-downpipes-cf-config-mode

POST/downpipes/cf-config/rediscover

Submit downpipes cf config rediscover

post-downpipes-cf-config-rediscover

POST/downpipes/delete

Submit downpipes delete

post-downpipes-delete

POST/downpipes/reconcile-roster

Submit downpipes reconcile roster

post-downpipes-reconcile-roster

GET/downpipes/roster-hygiene

Read downpipes roster hygiene

get-downpipes-roster-hygiene

drill

Endpoints under /drill.

POST/drill

Submit drill

post-drill

drill-all

Endpoints under /drill-all.

GET/drill-all

Read drill all

get-drill-all

POST/drill-all

Submit drill all

post-drill-all

drill-evidence

Endpoints under /drill-evidence.

GET/drill-evidence

Read drill evidence

get-drill-evidence

POST/drill-evidence

Submit drill evidence

post-drill-evidence

email

Endpoints under /email.

POST/email/test

Submit email test

post-email-test

expiry

Endpoints under /expiry.

GET/expiry

Read expiry

get-expiry

POST/expiry

Submit expiry

post-expiry

POST/expiry/cleanup-attest

Submit expiry cleanup attest

post-expiry-cleanup-attest

POST/expiry/delete

Submit expiry delete

post-expiry-delete

group-roles

Endpoints under /group-roles.

GET/group-roles

Read group roles

get-group-roles

POST/group-roles

Submit group roles

post-group-roles

POST/group-roles/delete

Submit group roles delete

post-group-roles-delete

history

Endpoints under /history.

GET/history

Read history

get-history

idp

Endpoints under /idp.

GET/idp/connections

Read idp connections

get-idp-connections

POST/idp/connections

Submit idp connections

post-idp-connections

POST/idp/connections/cert

Submit idp connections cert

post-idp-connections-cert

POST/idp/connections/delete

Submit idp connections delete

post-idp-connections-delete

POST/idp/connections/enabled

Submit idp connections enabled

post-idp-connections-enabled

GET/idp/presets

Read idp presets

get-idp-presets

POST/idp/test

Submit idp test

post-idp-test

POST/idp/test-saved

Submit idp test saved

post-idp-test-saved

keys

Endpoints under /keys.

POST/keys/add-operational

Submit keys add operational

post-keys-add-operational

POST/keys/break-glass-only

Submit keys break glass only

post-keys-break-glass-only

POST/keys/install

Submit keys install

post-keys-install

POST/keys/posture-acknowledgement

Submit keys posture acknowledgement

post-keys-posture-acknowledgement

POST/keys/rotate

Submit keys rotate

post-keys-rotate

GET/keys/vintages

Read keys vintages

get-keys-vintages

licence

Endpoints under /licence.

GET/licence

Read licence

get-licence

POST/licence

Submit licence

post-licence

notify

Endpoints under /notify.

GET/notify/channels

Read notify channels

get-notify-channels

POST/notify/channels

Submit notify channels

post-notify-channels

POST/notify/channels/delete

Submit notify channels delete

post-notify-channels-delete

GET/notify/history

Read notify history

get-notify-history

GET/notify/rules

Read notify rules

get-notify-rules

POST/notify/rules

Submit notify rules

post-notify-rules

POST/notify/rules/delete

Submit notify rules delete

post-notify-rules-delete

POST/notify/test

Submit notify test

post-notify-test

otlp-push

Endpoints under /otlp-push.

GET/otlp-push

Read otlp push

get-otlp-push

POST/otlp-push

Submit otlp push

post-otlp-push

POST/otlp-push/delete

Submit otlp push delete

post-otlp-push-delete

owner-actions

Endpoints under /owner-actions.

GET/owner-actions

Read owner actions

get-owner-actions

POST/owner-actions/{id}/approve

Submit owner actions by id approve

post-owner-actions-id-approve

POST/owner-actions/{id}/reject

Submit owner actions by id reject

post-owner-actions-id-reject

passkey

Endpoints under /passkey.

GET/passkey/credentials

Read passkey credentials

get-passkey-credentials

GET/passkey/credentials/all

Read passkey credentials all

get-passkey-credentials-all

POST/passkey/credentials/delete

Submit passkey credentials delete

post-passkey-credentials-delete

policy

Endpoints under /policy.

POST/policy/require-access

Submit policy require access

post-policy-require-access

POST/policy/retire-break-glass-token

Submit policy retire break glass token

post-policy-retire-break-glass-token

posture

Endpoints under /posture.

GET/posture

Read posture

get-posture

POST/posture/accept

Submit posture accept

post-posture-accept

POST/posture/unaccept

Submit posture unaccept

post-posture-unaccept

preflight

Endpoints under /preflight.

GET/preflight

Read preflight

get-preflight

push

Endpoints under /push.

GET/push

Read push

get-push

POST/push

Submit push

post-push

POST/push/delete

Submit push delete

post-push-delete

POST/push/test

Submit push test

post-push-test

replication

Endpoints under /replication.

GET/replication

Read replication

get-replication

reports

Endpoints under /reports.

GET/reports/{kind}

Read reports by kind

get-reports-kind

restore

Endpoints under /restore.

POST/restore

Submit restore

post-restore

GET/restore/approvals

Read restore approvals

get-restore-approvals

POST/restore/approve

Submit restore approve

post-restore-approve

POST/restore/attest

Submit restore attest

post-restore-attest

POST/restore/capsule

Submit restore capsule

post-restore-capsule

POST/restore/reject

Submit restore reject

post-restore-reject

POST/restore/request

Submit restore request

post-restore-request

POST/restore/verify

Submit restore verify

post-restore-verify

retention-prune

Endpoints under /retention-prune.

POST/retention-prune/apply

Submit retention prune apply

post-retention-prune-apply

GET/retention-prune/approvals

Read retention prune approvals

get-retention-prune-approvals

POST/retention-prune/approve

Submit retention prune approve

post-retention-prune-approve

POST/retention-prune/candidate

Submit retention prune candidate

post-retention-prune-candidate

POST/retention-prune/reject

Submit retention prune reject

post-retention-prune-reject

POST/retention-prune/request

Submit retention prune request

post-retention-prune-request

roles

Endpoints under /roles.

GET/roles

Read roles

get-roles

POST/roles

Submit roles

post-roles

POST/roles/delete

Submit roles delete

post-roles-delete

rto

Endpoints under /rto.

GET/rto

Read rto

get-rto

runs

Endpoints under /runs.

GET/runs/at

Read runs at

get-runs-at

sessions

Endpoints under /sessions.

POST/sessions/terminate-all

Submit sessions terminate all

post-sessions-terminate-all

POST/sessions/terminate-others

Submit sessions terminate others

post-sessions-terminate-others

POST/sessions/terminate-user

Submit sessions terminate user

post-sessions-terminate-user

setup

Endpoints under /setup.

POST/setup/acknowledge

Submit setup acknowledge

post-setup-acknowledge

setup-state

Endpoints under /setup-state.

GET/setup-state

Read setup state

get-setup-state

signin-factors

Endpoints under /signin-factors.

GET/signin-factors

Read signin factors

get-signin-factors

POST/signin-factors/revoke

Submit signin factors revoke

post-signin-factors-revoke

sources

Endpoints under /sources.

POST/sources/attach

Submit sources attach

post-sources-attach

GET/sources/discover

Read sources discover

get-sources-discover

POST/sources/discovery-accounts

Submit sources discovery accounts

post-sources-discovery-accounts

GET/sources/discovery-status

Read sources discovery status

get-sources-discovery-status

POST/sources/discovery-token

Submit sources discovery token

post-sources-discovery-token

POST/sources/enable

Submit sources enable

post-sources-enable

POST/sources/reattach-missing

Submit sources reattach missing

post-sources-reattach-missing

status

Endpoints under /status.

GET/status

Read status

get-status

stepup

Endpoints under /stepup.

POST/stepup/begin

Submit stepup begin

post-stepup-begin

POST/stepup/finish

Submit stepup finish

post-stepup-finish

support

Endpoints under /support.

GET/support

Read support

get-support

GET/support/bundle

Read support bundle

get-support-bundle

POST/support/bundle

Submit support bundle

post-support-bundle

POST/support/credentials

Submit support credentials

post-support-credentials

POST/support/credentials/delete

Submit support credentials delete

post-support-credentials-delete

test-fault

Endpoints under /test-fault.

POST/test-fault/arm

Submit test fault arm

post-test-fault-arm

POST/test-fault/canary-tick

Submit test fault canary tick

post-test-fault-canary-tick

POST/test-fault/disarm

Submit test fault disarm

post-test-fault-disarm

POST/test-fault/retention-tick

Submit test fault retention tick

post-test-fault-retention-tick

GET/test-fault/status

Read test fault status

get-test-fault-status

trigger

Endpoints under /trigger.

POST/trigger

Submit trigger

post-trigger

update

Endpoints under /update.

POST/update/apply

Submit update apply

post-update-apply

POST/update/ramp

Submit update ramp

post-update-ramp

POST/update/ramp/settle

Submit update ramp settle

post-update-ramp-settle

POST/update/rollback

Submit update rollback

post-update-rollback

POST/update/settle

Submit update settle

post-update-settle

GET/update/status

Read update status

get-update-status

updates

Endpoints under /updates.

GET/updates

Read updates

get-updates

whoami

Endpoints under /whoami.

GET/whoami

Read whoami

get-whoami

Last updated .