Paths on this page are relative to /api/liquidity-studio/v2. Authentication and required headers vary by operation.
API reference overview · OpenAPI download
Operations on this page#
| Method | Path | Operation |
|---|---|---|
GET |
/public/plans |
listWorkspacePlans |
GET |
/public/acp/offering |
getPublicAcpOffering |
GET |
/developer-credentials |
listDeveloperCredentials |
POST |
/developer-credentials |
createDeveloperCredentials |
GET |
/developer-credentials/{id} |
getDeveloperCredentials |
PATCH |
/developer-credentials/{id} |
supersedeDeveloperCredentials |
GET |
/webhooks |
listWebhooks |
POST |
/webhooks |
createWebhooks |
GET |
/webhooks/{id} |
getWebhooks |
PATCH |
/webhooks/{id} |
supersedeWebhooks |
GET |
/openapi.json |
getOperatingSystemOpenApi |
GET |
/status |
getOperatingSystemStatus |
POST |
/oauth/token |
issueOperatingSystemOAuthToken |
GET |
/workspace |
getOperatingSystemWorkspace |
GET |
/providers |
listOperatingSystemProviders |
POST |
/providers |
putOperatingSystemProvider |
GET |
/artifacts |
listOperatingSystemArtifacts |
POST |
/developer-credentials/{id}/rotate |
rotateDeveloperCredential |
GET |
/jobs |
listOperatingSystemJobs |
GET |
/public/brands/current |
getVerifiedHostBrand |
GET |
/public/partner-brand/logo/{contentHash} |
getVerifiedPartnerBrandLogo |
Inspect configured workspace plan previews without a login or payment#
GET /public/plans
Operation ID: listWorkspacePlans
Authentication: No authentication is required by this operation’s contract.
Read-only public terms, separate from vault billing. Missing or expired configuration returns NOT_CONFIGURED with no plans or version. PREVIEW requires a nonexpired timestamp, version and 1–12 unique plans. Does not create orders, accept terms, start checkout, establish allowances or grant financial authority. No deployment prices are assumed.
This operation declares no parameters.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Current read-only catalog or explicit unconfigured state. | application/json: object |
429 |
Public request limit exceeded. | application/json: object |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | WorkspacePlanCatalog | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
429 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
Retry-After |
Yes | string |
Pattern: ^[0-9]+$ |
429 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
error |
Yes | object |
Additional properties rejected |
error.code |
Yes | Constant PUBLIC_PLANS_BUSY |
— |
error.message |
Yes | string |
— |
error.retryable |
Yes | Constant true |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Inspect the configured ACP public-analysis offering without a login or payment#
GET /public/acp/offering
Operation ID: getPublicAcpOffering
Authentication: No authentication is required by this operation’s contract.
Deployment-owned, read-only offering preview. Missing or expired configuration returns NOT_CONFIGURED with null offering, catalogVersion and validUntil. PREVIEW requires a nonexpired timestamp, version and one public-only offering. No purchase, job, escrow, settlement, fund transfer, private tenant access or financial authority is created. No deployment price or SLA is assumed.
This operation declares no parameters.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Current read-only offering preview or explicit unconfigured state. | application/json: object |
429 |
Public request limit exceeded. | application/json: object |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | AcpOfferingPreview | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
429 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
Retry-After |
Yes | string |
Pattern: ^[0-9]+$ |
429 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
error |
Yes | object |
Additional properties rejected |
error.code |
Yes | Constant PUBLIC_ACP_OFFERING_BUSY |
— |
error.message |
Yes | string |
— |
error.retryable |
Yes | Constant true |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
List developer credentials#
GET /developer-credentials
Operation ID: listDeveloperCredentials
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
cursor |
query | No | string |
Opaque cursor returned in the previous response metadata. |
limit |
query | No | integer |
Default: 50; Minimum: 1; Maximum: 100 |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Latest tenant-isolated aggregate versions | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | Array of All of: RecordEnvelope; object |
— |
data[].allOf[2].payload |
Yes | DeveloperCredential | — |
meta |
Yes | object |
Additional properties rejected |
meta.count |
Yes | integer |
Minimum: 0 |
meta.hasMore |
Yes | boolean |
— |
meta.nextCursor |
No | string |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Create a hashed developer credential and return its secret once#
POST /developer-credentials
Operation ID: createDeveloperCredentials
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
Request body#
Required: yes.
application/json
Responses#
| Status | Description | Content type and schema |
|---|---|---|
201 |
Secret returned once; durable idempotency state contains only resource metadata | application/json: object |
409 |
Identical retry cannot replay the already-returned secret | No response body declared |
201 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | object |
Additional properties rejected |
data.credential |
Yes | All of: RecordEnvelope; object |
— |
data.credential.allOf[2].payload |
Yes | DeveloperCredential | — |
data.secret |
Yes | string |
— |
data.secretReturnedOnce |
Yes | Constant true |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Get one developer credentials aggregate#
GET /developer-credentials/{id}
Operation ID: getDeveloperCredentials
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
id |
path | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Current immutable aggregate version | application/json: object |
404 |
Not found | No response body declared |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
ETag |
Yes | string |
— |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | All of: RecordEnvelope; object |
— |
data.allOf[2].payload |
Yes | DeveloperCredential | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Immediately revoke a developer credential#
PATCH /developer-credentials/{id}
Operation ID: supersedeDeveloperCredentials
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
If-Match |
header | Yes | string |
— |
id |
path | Yes | string |
— |
Request body#
Required: yes.
application/json
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
status |
No | string |
Allowed: REVOKED |
evidenceHashes |
No | Array of Hash | Max items: 256 |
reason |
Yes | string |
Min length: 3; Max length: 500 |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Append-only bounded supersession accepted with deterministic evidence | application/json: object |
400 |
Payload or safety transition is outside this bounded operation | No response body declared |
409 |
Typed authority workflow is required | No response body declared |
412 |
Strong precondition failed | No response body declared |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | All of: RecordEnvelope; object |
— |
data.allOf[2].payload |
Yes | DeveloperCredential | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
List webhook subscriptions#
GET /webhooks
Operation ID: listWebhooks
Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)
Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
cursor |
query | No | string |
Opaque cursor returned in the previous response metadata. |
limit |
query | No | integer |
Default: 50; Minimum: 1; Maximum: 100 |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Latest tenant-isolated aggregate versions | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | Array of All of: RecordEnvelope; object |
— |
data[].allOf[2].payload |
Yes | WebhookSubscription | — |
meta |
Yes | object |
Additional properties rejected |
meta.count |
Yes | integer |
Minimum: 0 |
meta.hasMore |
Yes | boolean |
— |
meta.nextCursor |
No | string |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Create a signed webhook and return its signing secret once#
POST /webhooks
Operation ID: createWebhooks
Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)
Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
Request body#
Required: yes.
application/json
Responses#
| Status | Description | Content type and schema |
|---|---|---|
201 |
Signing secret returned once; durable idempotency state contains only resource metadata | application/json: object |
409 |
Identical retry cannot replay the already-returned signing secret | No response body declared |
201 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | object |
Additional properties rejected |
data.subscription |
Yes | All of: RecordEnvelope; object |
— |
data.subscription.allOf[2].payload |
Yes | WebhookSubscription | — |
data.signingSecret |
Yes | string |
— |
data.signatureInput |
Yes | Constant timestamp.deliveryId.body |
— |
data.secretReturnedOnce |
Yes | Constant true |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Get one webhook subscriptions aggregate#
GET /webhooks/{id}
Operation ID: getWebhooks
Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)
Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
id |
path | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Current immutable aggregate version | application/json: object |
404 |
Not found | No response body declared |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
ETag |
Yes | string |
— |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | All of: RecordEnvelope; object |
— |
data.allOf[2].payload |
Yes | WebhookSubscription | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Immediately pause or revoke a webhook subscription#
PATCH /webhooks/{id}
Operation ID: supersedeWebhooks
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
If-Match |
header | Yes | string |
— |
id |
path | Yes | string |
— |
Request body#
Required: yes.
application/json
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
status |
No | string |
Allowed: PAUSED, REVOKED |
evidenceHashes |
No | Array of Hash | Max items: 256 |
reason |
Yes | string |
Min length: 3; Max length: 500 |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Append-only bounded supersession accepted with deterministic evidence | application/json: object |
400 |
Payload or safety transition is outside this bounded operation | No response body declared |
409 |
Typed authority workflow is required | No response body declared |
412 |
Strong precondition failed | No response body declared |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | All of: RecordEnvelope; object |
— |
data.allOf[2].payload |
Yes | WebhookSubscription | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Download the checked-in v2 OpenAPI contract#
GET /openapi.json
Operation ID: getOperatingSystemOpenApi
Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.
This operation declares no parameters.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
OpenAPI 3.1 contract | application/json: OpenApiDocument |
Read fail-closed v2 service readiness#
GET /status
Operation ID: getOperatingSystemStatus
Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.
This operation declares no parameters.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Service and adapter readiness | application/json: object |
503 |
PostgreSQL or v1 dependency unavailable | No response body declared |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | OperatingSystemStatus | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Exchange OAuth client credentials for a scoped one-hour token#
POST /oauth/token
Operation ID: issueOperatingSystemOAuthToken
Authentication: HTTP Basic client credentials (clientBasic)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
Request body#
Required: yes.
application/x-www-form-urlencoded
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
grant_type |
Yes | Constant client_credentials |
— |
scope |
No | string |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Scoped bearer token | application/json: OAuthTokenResponse |
401 |
Invalid or inactive OAuth client | No response body declared |
Get all release-train availability and aggregate counts#
GET /workspace
Operation ID: getOperatingSystemWorkspace
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Role-aware workspace | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | OperatingSystemWorkspace | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
List tenant-scoped signed provider registrations and health#
GET /providers
Operation ID: listOperatingSystemProviders
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Provider registry | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | Array of OperatingSystemProvider | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Register or rotate an attested provider generation#
POST /providers
Operation ID: putOperatingSystemProvider
Authentication: __Host-klineo_session cookie (sessionCookie)
Conditional version precondition: The providerId and capability generation already exists.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
If-Match |
header | No | string |
Pattern: ^"[^"\\ ]+"$ |
Request body#
Required: yes.
application/json
Responses#
| Status | Description | Content type and schema |
|---|---|---|
201 |
Provider generation registered | application/json: object |
412 |
Existing provider generation changed | No response body declared |
201 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | OperatingSystemProvider | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
List immutable object-storage lineage for reports and large evidence#
GET /artifacts
Operation ID: listOperatingSystemArtifacts
Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with proof:read (serviceCredential)
Service scope: proof:read. Session access and workspace roles are evaluated separately.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
recordType |
query | No | string |
— |
recordId |
query | No | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Tenant-isolated content-addressed artifact lineage | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | Array of OperatingSystemArtifact | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Rotate a hashed API key or OAuth client secret#
POST /developer-credentials/{id}/rotate
Operation ID: rotateDeveloperCredential
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
Idempotency-Key |
header | Yes | string |
Min length: 8; Max length: 160 |
x-klineo-organization-id |
header | Yes | string |
— |
id |
path | Yes | string |
— |
If-Match |
header | Yes | string |
Pattern: ^"[^"\\ ]+"$ |
Request body#
Required: yes.
application/json
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
reason |
Yes | string |
Min length: 3; Max length: 500 |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
New secret returned exactly once; prior secret revoked; durable idempotency is metadata-only | application/json: object |
409 |
Identical retry cannot replay the already-returned replacement secret | No response body declared |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | object |
Additional properties rejected |
data.credential |
Yes | All of: RecordEnvelope; object |
— |
data.credential.allOf[2].payload |
Yes | DeveloperCredential | — |
data.secret |
Yes | string |
— |
data.priorSecretRevoked |
Yes | Constant true |
— |
data.secretReturnedOnce |
Yes | Constant true |
— |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
List fenced worker jobs and dead-letter visibility#
GET /jobs
Operation ID: listOperatingSystemJobs
Authentication: __Host-klineo_session cookie (sessionCookie)
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
x-klineo-organization-id |
header | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Worker job states | application/json: object |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | Array of OperatingSystemJob | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
Resolve a privacy-safe brand only for the exact verified request host#
GET /public/brands/current
Operation ID: getVerifiedHostBrand
Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.
This operation declares no parameters.
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Host-bound accessible brand tokens | application/json: object |
404 |
No unique verified brand is bound to this host | No response body declared |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
200 application/json body
object — Additional properties rejected
| Field | Required at this level | Type | Description and constraints |
|---|---|---|---|
data |
Yes | PublicPartnerBrand | — |
Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
404 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
Cache-Control |
Yes | Constant no-store |
— |
Serve the exact current host-bound content-addressed PNG logo#
GET /public/partner-brand/logo/{contentHash}
Operation ID: getVerifiedPartnerBrandLogo
Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.
Parameters#
| Name | Location | Required | Type | Description and constraints |
|---|---|---|---|---|
contentHash |
path | Yes | string |
— |
Responses#
| Status | Description | Content type and schema |
|---|---|---|
200 |
Hash-verified immutable PNG logo | image/png: string |
404 |
No current verified host brand owns this exact logo hash | No response body declared |
200 response headers
| Header | Required | Type | Description and constraints |
|---|---|---|---|
ETag |
Yes | string |
— |
Cache-Control |
Yes | Constant no-store |
— |
X-Content-Type-Options |
Yes | Constant nosniff |
— |
Cross-Origin-Resource-Policy |
Yes | Constant same-origin |
— |
200 image/png body
string — Format: binary