Reference: API, CLI and the rest of the record
This section is the record you check rather than read start to finish: the API and CLI surfaces, the terms the rest of the docs use, and the limits of what downpipes guarantees. Two subsections group the largest parts of it; everything else sits at the top level.
API
The engine’s HTTP surface, for a developer integrating directly or an operator reading the audit feed into a SIEM. Start at the API overview for the conventions every endpoint follows, then go to the admin endpoint catalogue, authentication and authorisation, sign-in flows, restore and recovery, or support diagnostics and audit-feed pull endpoints.
CLI
The offline reader and provisioner shipped as the open-source downpipe binary. Start at the CLI command reference for every flag. The exit codes and verification outcomes page covers what a drill script should check.
Everything else
- Browser requirements: the security features an operator’s browser must support, and what the console does on each path when one is missing.
- Glossary: definitions of the terms used across these docs.
- Engine error and status codes and troubleshooting.
- Changelog and versioning.
- How downpipe relates to the source-available engine: the MIT reader and the Elastic-2.0 platform, and which licence covers which part.
- Security properties and their limits: the limit on each security property.
- Accessibility statement.
- Use these docs in your AI tools: the MCP search server,
llms.txtand the OpenAPI spec, for a coding agent or an AI-assisted workflow.
Last updated .