Zanii Agents API 0.16.1

Rentable, receipted agents: the client console (session), the A2A JSON-RPC surface (Bearer) and the extensions. Every error body is {"error": {"code", "message"}}.

A2A

GET/.well-known/agent.jsonThe A2A agent card (public)
GET/healthzLiveness (public)
GET/readyzReadiness (503 while draining or when the DB ping fails) (public)
POST/v1/JSON-RPC 2.0: message/send, tasks/get, tasks/list

Access

GET/api/tokenslist tokens
POST/api/tokens/{id}/policyset policy
POST/api/tokens/{id}/rotaterotate

Admin

POST/api/admin/agents/{did}/halthalt agent
GET/api/admin/auditget audit
GET/api/admin/clientslist clients
GET/api/admin/clients/{id}get client
POST/api/admin/clients/{id}/reactivatereactivate
POST/api/admin/clients/{id}/suspendsuspend
GET/api/admin/drainget drain
POST/api/admin/drainpost drain
GET/api/admin/healthget health
GET/api/admin/maintenanceget maintenance
POST/api/admin/maintenancepost maintenance
GET/api/admin/metricsget metrics
GET/api/admin/queuesget queues
POST/api/admin/queues/{name}/actact queue

Agents

GET/api/agents/{did}/cvThe signed AgentCV and its verification
GET/api/agents/{did}/evidenceEvidence pack (?framework=&format=md|json)
GET/api/agents/{did}/receiptsThe client's slice of the agent's ledger receipts
POST/api/agents/{did}/revokeKill switch: {reason}; audited

Assurance

GET/api/agents/{did}/ratingsget agent ratings
GET/api/agents/{did}/referencesget agent references
GET/api/disputesget disputes
POST/api/disputespost dispute
GET/api/disputes/{id}get dispute
POST/api/disputes/{id}/resolveresolve
POST/api/disputes/{id}/respondrespond
POST/api/disputes/{id}/withdrawwithdraw
GET/api/engagements/{id}/insuranceget insurance
POST/api/engagements/{id}/insurancepost insurance
POST/api/engagements/{id}/insurance/claimspost claim
GET/api/engagements/{id}/referenceget reference body
POST/api/engagements/{id}/referencepost reference
GET/api/engagements/{id}/slaget sla
GET/api/sla/eventsget sla events
POST/api/tasks/{id}/ratingpost rating

AuditChain

POST/api/admin/audit/anchorpost anchor
GET/api/admin/audit/anchorsget anchors
GET/api/admin/audit/exportJSON lines from `from` to `to` (default: the head), at most EXPORT_MAX_ROWS per reply:
GET/api/admin/audit/verifyget verify

Auth

GET/auth/callbackFinish the code flow: iss + state checked, one token exchange, session cookie (public)
GET/auth/loginStart the Zanii ID code flow (302 to the issuer, PKCE S256) (public)
POST/auth/logoutEnd the session

Backup

POST/api/admin/backup202 with a job id. The run happens on a thread; when it finishes within `wait_s`
POST/api/admin/backup/drillroute drill
GET/api/admin/backupsroute list

Connect

POST/api/connect/actions/{id}/refreshrefresh route
DELETE/api/engagements/{id}/connectrevoke
GET/api/engagements/{id}/connectget
POST/api/engagements/{id}/connectbind
GET/api/engagements/{id}/connect/actionsactions route
GET/api/engagements/{id}/connect/approvalsapprovals
GET/api/engagements/{id}/connect/connectionsconnections
POST/api/engagements/{id}/connect/previewValidate a key without storing it and list what it can do (the console's allowlist picker).
GET/api/engagements/{id}/connect/toolstools

Console

GET/api/jobsCatalogue: profiles x outcomes, AED prices, serving agents
GET/api/meThe signed-in client, its CSRF token and the ledger URL

DataRoom

GET/api/engagements/{id}/fileslist
POST/api/engagements/{id}/filesupload
DELETE/api/files/{id}delete

Durable

POST/api/tasks/{id}/retrypost retry
GET/api/tasks/{id}/runsThe attempt counters; `runs` is null for a task that never failed or was re-queued.

Egress

GET/api/engagements/{id}/egressget
POST/api/engagements/{id}/egressset

Engagements

GET/api/engagementsThe client's engagements
POST/api/engagementsHire: {job_id, agent_did, client_did?} -> pending engagement + the package to sign
GET/api/engagements/{id}One engagement with its SLA and offer package
POST/api/engagements/{id}/signatures{sla_signature?, escrow_signatures?}: activate / open escrows; forgery is 400

Finance

GET/api/budgetsget budgets
POST/api/budgetspost budget
DELETE/api/budgets/{id}delete budget
POST/api/budgets/{id}update budget
GET/api/invoicesget invoices
POST/api/invoicespost invoice
GET/api/invoices/{id}get invoice
POST/api/invoices/{id}/paidinvoice paid
GET/api/refundsget refunds
POST/api/refundsA goodwill refund request by the client; the operator approves (signs) or rejects it.
POST/api/refunds/{id}/acceptrefund accept
POST/api/refunds/{id}/approveOperator: sign the client's goodwill request with the provider key and settle it.
POST/api/refunds/{id}/rejectrefund reject
GET/api/statementsget statement

I18n

GET/api/i18n.jsget js (public)
GET/api/i18n/{lang}get catalog (public)
GET/api/localeget locale
POST/api/localeset locale

Lifecycle

POST/api/agents/{did}/versionsrelease version
POST/api/clients/eraseerase
GET/api/engagements/{id}/capacityget capacity
POST/api/engagements/{id}/capacitypost capacity
POST/api/engagements/{id}/endend engagement
GET/api/engagements/{id}/exportexport
GET/api/engagements/{id}/versionget version
POST/api/engagements/{id}/version/acceptaccept version
GET/api/incidentslist incidents
POST/api/incidentsreport incident
GET/api/incidents/{id}get incident
POST/api/incidents/{id}/notenote incident
POST/api/incidents/{id}/resolveresolve incident
GET/api/retentionget retention
POST/api/retentionpost retention
POST/api/retention/holdpost hold
GET/statusstatus json (public)
GET/status.htmlstatus html (public)

MarketExtension

GET/api/engagements/{id}/configget config
POST/api/engagements/{id}/configput config
GET/api/market/listingssearch listings
POST/api/market/listingspublish listing
POST/api/market/listings/externalpublish external
GET/api/market/listings/{id}get listing
POST/api/market/listings/{id}/availabilityset availability
POST/api/onboarding/kya/{agent_did}kya
POST/api/onboarding/kyb/{id}/reviewkyb review
GET/api/trialslist trials
POST/api/trialscreate trial
GET/api/trials/{id}get trial
POST/api/trials/{id}/convertconvert trial
POST/api/trials/{id}/taskstrial task
GET/marketpublic market (public)

Models

GET/api/agents/{did}/buildget build
GET/api/engagements/{id}/modelget policy
POST/api/engagements/{id}/modelpost policy
GET/api/modelslist models
GET/api/tasks/{id}/modelget task model

Notify

GET/api/eventslist events
GET/api/notificationsget prefs
POST/api/notificationsset prefs
POST/api/notifications/testtest
POST/api/webhooks/{id}/replayreplay

OpenApi

GET/docsHuman-readable route list rendered from the OpenAPI document. (public)
GET/openapi.jsonThe OpenAPI 3.1 document for this deployment. (public)

Operators

GET/api/admin/operatorslist operators

Plans

POST/api/admin/clients/{id}/planpost client plan
GET/api/admin/usageget admin usage
GET/api/planget plan
GET/api/plansget catalogue (public)
GET/api/usageget usage

Provenance

GET/api/tasks/{id}/credentialget task
GET/verify/credentialNo session: the recipient of a document checks who signed it. Nothing about the client. (public)

Releases

POST/api/engagements/{id}/releases{escrow_hash, instruction}: the client-signed release; paid over the rail once
GET/api/engagements/{id}/releases/pendingEscrows to sign and release requests to verify

Sentinel

POST/api/admin/agents/{did}/sentinel/rebaselinepost rebaseline
GET/api/agents/{did}/sentinelget agent
POST/api/sentinel/findings/{id}/ackpost ack

Slo

GET/api/sloThe signed-in client's SLO numbers per window.

StepUp

GET/api/auth/step-upA fresh PKCE login (the console's pre-session mechanics) asking the IdP for `acr_values`

TaskOps

GET/api/approvalslist approvals
GET/api/approvals/{id}get approval
POST/api/approvals/{id}/approveapprove
POST/api/approvals/{id}/rejectreject
POST/api/batchescreate batch
GET/api/batches/{id}get batch
GET/api/batches/{id}/exportexport batch
GET/api/scheduleslist schedules
POST/api/schedulescreate schedule
DELETE/api/schedules/{id}delete schedule
GET/api/schedules/{id}get schedule
POST/api/schedules/{id}/pausepause schedule
POST/api/schedules/{id}/resumeresume schedule
POST/api/tasks/{id}/cancelcancel
GET/api/tasks/{id}/eventsPolled SSE. `after=N` continues after the task's N-th trace line: the Observability

Tasks

GET/api/tasksPage the client's tasks (limit <= 100, offset)
POST/api/tasks{engagement_id, text, async?} -> the task and the escrow body to sign
GET/api/tasks/{id}One task (state, receipt, output while cached)

Teams

GET/api/teamslist
POST/api/teamscreate
GET/api/teams/{id}get
POST/api/teams/{id}/endend
POST/api/teams/{id}/hireconsole_api._create_engagement on the lead, with terms.team bound into the SLA body
POST/api/teams/{id}/taskstask
GET/api/teams/{id}/tasks/{task_id}/chainget chain

TenantOps

POST/api/admin/clients/importOperator: {path (a zip on the server), new_client_id?} -> the import report.
POST/api/admin/clients/{id}/exportOperator: the whole tenant as a zip (rows, refs, files, manifest).
GET/api/admin/sloEvery client's SLO numbers (operator).

Tokens

POST/api/tokensIssue an agt_ API token ({label}); plaintext shown once
DELETE/api/tokens/{id}Revoke an API token

Walls

GET/api/agents/{did}/wallget agent
GET/api/tasks/{id}/wallget task

Web

GET/assets/{name}asset (public)
GET/llms.txtllms (public)
GET/robots.txtrobots (public)
GET/sitemap.xmlsitemap (public)

WebTools

GET/api/engagements/{id}/webget policy
POST/api/engagements/{id}/webset policy

Webhooks

GET/api/webhookslist
POST/api/webhookscreate
DELETE/api/webhooks/{id}delete
GET/api/webhooks/{id}/deliverieslist deliveries
POST/api/webhooks/{id}/testtest

ZaniiIdEvents

POST/webhooks/zanii-idreceive (public)

atrest

GET/api/files/{id}download

market

GET/api/onboardingonboarding status
POST/api/onboarding/kybsubmit kyb
GET/api/org/memberslist members
POST/api/org/membersinvite member
DELETE/api/org/members/{id}remove member
POST/api/org/members/{id}/roleset member role

web

GET/<lambda> (public)
GET/404<lambda> (public)
GET/about<lambda> (public)
GET/ar<lambda> (public)
GET/ar/404<lambda> (public)
GET/ar/about<lambda> (public)
GET/ar/contact<lambda> (public)
GET/ar/for<lambda> (public)
GET/ar/for/{type}<lambda> (public)
GET/ar/how-it-works<lambda> (public)
GET/ar/industries<lambda> (public)
GET/ar/industries/{id}<lambda> (public)
GET/ar/pricing<lambda> (public)
GET/ar/privacy<lambda> (public)
GET/ar/security<lambda> (public)
GET/ar/terms<lambda> (public)
GET/contact<lambda> (public)
GET/for<lambda> (public)
GET/for/{type}<lambda> (public)
GET/how-it-works<lambda> (public)
GET/industries<lambda> (public)
GET/industries/{id}<lambda> (public)
GET/pricing<lambda> (public)
GET/privacy<lambda> (public)
GET/security<lambda> (public)
GET/terms<lambda> (public)

JSON-RPC error codes

codemessageHTTP
-32700parse error200
-32602invalid params200
-32601method not found200
-32600invalid request200
-32029rate limited429
-32011body too large413
-32010agent halted200
-32003unauthorized401
-32001task not found200
-32000shutting down503