Klineo/Docs
Open app ↗

API reference

Platform, credentials and webhooks

Paths on this page are relative to /api/liquidity-studio/v2. Authentication and required headers vary by operation.

API reference overview · OpenAPI download

Operations on this page#

Method Path Operation
GET /public/plans listWorkspacePlans
GET /public/acp/offering getPublicAcpOffering
GET /developer-credentials listDeveloperCredentials
POST /developer-credentials createDeveloperCredentials
GET /developer-credentials/{id} getDeveloperCredentials
PATCH /developer-credentials/{id} supersedeDeveloperCredentials
GET /webhooks listWebhooks
POST /webhooks createWebhooks
GET /webhooks/{id} getWebhooks
PATCH /webhooks/{id} supersedeWebhooks
GET /openapi.json getOperatingSystemOpenApi
GET /status getOperatingSystemStatus
POST /oauth/token issueOperatingSystemOAuthToken
GET /workspace getOperatingSystemWorkspace
GET /providers listOperatingSystemProviders
POST /providers putOperatingSystemProvider
GET /artifacts listOperatingSystemArtifacts
POST /developer-credentials/{id}/rotate rotateDeveloperCredential
GET /jobs listOperatingSystemJobs
GET /public/brands/current getVerifiedHostBrand
GET /public/partner-brand/logo/{contentHash} getVerifiedPartnerBrandLogo

Inspect configured workspace plan previews without a login or payment#

GET /public/plans

Operation ID: listWorkspacePlans

Authentication: No authentication is required by this operation’s contract.

Read-only public terms, separate from vault billing. Missing or expired configuration returns NOT_CONFIGURED with no plans or version. PREVIEW requires a nonexpired timestamp, version and 1–12 unique plans. Does not create orders, accept terms, start checkout, establish allowances or grant financial authority. No deployment prices are assumed.

This operation declares no parameters.

Responses#

Status Description Content type and schema
200 Current read-only catalog or explicit unconfigured state. application/json: object
429 Public request limit exceeded. application/json: object

200 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes WorkspacePlanCatalog —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

429 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —
Retry-After Yes string Pattern: ^[0-9]+$

429 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
error Yes object Additional properties rejected
error.code Yes Constant PUBLIC_PLANS_BUSY —
error.message Yes string —
error.retryable Yes Constant true —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Inspect the configured ACP public-analysis offering without a login or payment#

GET /public/acp/offering

Operation ID: getPublicAcpOffering

Authentication: No authentication is required by this operation’s contract.

Deployment-owned, read-only offering preview. Missing or expired configuration returns NOT_CONFIGURED with null offering, catalogVersion and validUntil. PREVIEW requires a nonexpired timestamp, version and one public-only offering. No purchase, job, escrow, settlement, fund transfer, private tenant access or financial authority is created. No deployment price or SLA is assumed.

This operation declares no parameters.

Responses#

Status Description Content type and schema
200 Current read-only offering preview or explicit unconfigured state. application/json: object
429 Public request limit exceeded. application/json: object

200 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes AcpOfferingPreview —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

429 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —
Retry-After Yes string Pattern: ^[0-9]+$

429 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
error Yes object Additional properties rejected
error.code Yes Constant PUBLIC_ACP_OFFERING_BUSY —
error.message Yes string —
error.retryable Yes Constant true —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List developer credentials#

GET /developer-credentials

Operation ID: listDeveloperCredentials

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Latest tenant-isolated aggregate versions application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of All of: RecordEnvelope; object —
data[].allOf[2].payload Yes DeveloperCredential —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Create a hashed developer credential and return its secret once#

POST /developer-credentials

Operation ID: createDeveloperCredentials

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —

Request body#

Required: yes.

application/json

DeveloperCredentialRequest

Responses#

Status Description Content type and schema
201 Secret returned once; durable idempotency state contains only resource metadata application/json: object
409 Identical retry cannot replay the already-returned secret No response body declared

201 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes object Additional properties rejected
data.credential Yes All of: RecordEnvelope; object —
data.credential.allOf[2].payload Yes DeveloperCredential —
data.secret Yes string —
data.secretReturnedOnce Yes Constant true —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Get one developer credentials aggregate#

GET /developer-credentials/{id}

Operation ID: getDeveloperCredentials

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
id path Yes string —

Responses#

Status Description Content type and schema
200 Current immutable aggregate version application/json: object
404 Not found No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes DeveloperCredential —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Immediately revoke a developer credential#

PATCH /developer-credentials/{id}

Operation ID: supersedeDeveloperCredentials

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
If-Match header Yes string —
id path Yes string —

Request body#

Required: yes.

application/json

object — Additional properties rejected

Field Required at this level Type Description and constraints
status No string Allowed: REVOKED
evidenceHashes No Array of Hash Max items: 256
reason Yes string Min length: 3; Max length: 500

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
200 Append-only bounded supersession accepted with deterministic evidence application/json: object
400 Payload or safety transition is outside this bounded operation No response body declared
409 Typed authority workflow is required No response body declared
412 Strong precondition failed No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes DeveloperCredential —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List webhook subscriptions#

GET /webhooks

Operation ID: listWebhooks

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)

Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
cursor query No string Opaque cursor returned in the previous response metadata.
limit query No integer Default: 50; Minimum: 1; Maximum: 100

Responses#

Status Description Content type and schema
200 Latest tenant-isolated aggregate versions application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of All of: RecordEnvelope; object —
data[].allOf[2].payload Yes WebhookSubscription —
meta Yes object Additional properties rejected
meta.count Yes integer Minimum: 0
meta.hasMore Yes boolean —
meta.nextCursor No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Create a signed webhook and return its signing secret once#

POST /webhooks

Operation ID: createWebhooks

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)

Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —

Request body#

Required: yes.

application/json

WebhookRequest

Responses#

Status Description Content type and schema
201 Signing secret returned once; durable idempotency state contains only resource metadata application/json: object
409 Identical retry cannot replay the already-returned signing secret No response body declared

201 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes object Additional properties rejected
data.subscription Yes All of: RecordEnvelope; object —
data.subscription.allOf[2].payload Yes WebhookSubscription —
data.signingSecret Yes string —
data.signatureInput Yes Constant timestamp.deliveryId.body —
data.secretReturnedOnce Yes Constant true —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Get one webhook subscriptions aggregate#

GET /webhooks/{id}

Operation ID: getWebhooks

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with webhooks:manage (serviceCredential)

Service scope: webhooks:manage. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
id path Yes string —

Responses#

Status Description Content type and schema
200 Current immutable aggregate version application/json: object
404 Not found No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes WebhookSubscription —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Immediately pause or revoke a webhook subscription#

PATCH /webhooks/{id}

Operation ID: supersedeWebhooks

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
If-Match header Yes string —
id path Yes string —

Request body#

Required: yes.

application/json

object — Additional properties rejected

Field Required at this level Type Description and constraints
status No string Allowed: PAUSED, REVOKED
evidenceHashes No Array of Hash Max items: 256
reason Yes string Min length: 3; Max length: 500

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
200 Append-only bounded supersession accepted with deterministic evidence application/json: object
400 Payload or safety transition is outside this bounded operation No response body declared
409 Typed authority workflow is required No response body declared
412 Strong precondition failed No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes All of: RecordEnvelope; object —
data.allOf[2].payload Yes WebhookSubscription —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Download the checked-in v2 OpenAPI contract#

GET /openapi.json

Operation ID: getOperatingSystemOpenApi

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

This operation declares no parameters.

Responses#

Status Description Content type and schema
200 OpenAPI 3.1 contract application/json: OpenApiDocument

Read fail-closed v2 service readiness#

GET /status

Operation ID: getOperatingSystemStatus

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

This operation declares no parameters.

Responses#

Status Description Content type and schema
200 Service and adapter readiness application/json: object
503 PostgreSQL or v1 dependency unavailable No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes OperatingSystemStatus —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Exchange OAuth client credentials for a scoped one-hour token#

POST /oauth/token

Operation ID: issueOperatingSystemOAuthToken

Authentication: HTTP Basic client credentials (clientBasic)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —

Request body#

Required: yes.

application/x-www-form-urlencoded

object — Additional properties rejected

Field Required at this level Type Description and constraints
grant_type Yes Constant client_credentials —
scope No string —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
200 Scoped bearer token application/json: OAuthTokenResponse
401 Invalid or inactive OAuth client No response body declared

Get all release-train availability and aggregate counts#

GET /workspace

Operation ID: getOperatingSystemWorkspace

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —

Responses#

Status Description Content type and schema
200 Role-aware workspace application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes OperatingSystemWorkspace —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List tenant-scoped signed provider registrations and health#

GET /providers

Operation ID: listOperatingSystemProviders

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —

Responses#

Status Description Content type and schema
200 Provider registry application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of OperatingSystemProvider —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Register or rotate an attested provider generation#

POST /providers

Operation ID: putOperatingSystemProvider

Authentication: __Host-klineo_session cookie (sessionCookie)

Conditional version precondition: The providerId and capability generation already exists.

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
If-Match header No string Pattern: ^"[^"\\ ]+"$

Request body#

Required: yes.

application/json

ProviderRegistrationRequest

Responses#

Status Description Content type and schema
201 Provider generation registered application/json: object
412 Existing provider generation changed No response body declared

201 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes OperatingSystemProvider —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List immutable object-storage lineage for reports and large evidence#

GET /artifacts

Operation ID: listOperatingSystemArtifacts

Authentication: __Host-klineo_session cookie (sessionCookie) OR OAuth bearer token with proof:read (serviceCredential)

Service scope: proof:read. Session access and workspace roles are evaluated separately.

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —
recordType query No string —
recordId query No string —

Responses#

Status Description Content type and schema
200 Tenant-isolated content-addressed artifact lineage application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of OperatingSystemArtifact —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Rotate a hashed API key or OAuth client secret#

POST /developer-credentials/{id}/rotate

Operation ID: rotateDeveloperCredential

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
Idempotency-Key header Yes string Min length: 8; Max length: 160
x-klineo-organization-id header Yes string —
id path Yes string —
If-Match header Yes string Pattern: ^"[^"\\ ]+"$

Request body#

Required: yes.

application/json

object — Additional properties rejected

Field Required at this level Type Description and constraints
reason Yes string Min length: 3; Max length: 500

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Responses#

Status Description Content type and schema
200 New secret returned exactly once; prior secret revoked; durable idempotency is metadata-only application/json: object
409 Identical retry cannot replay the already-returned replacement secret No response body declared

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes object Additional properties rejected
data.credential Yes All of: RecordEnvelope; object —
data.credential.allOf[2].payload Yes DeveloperCredential —
data.secret Yes string —
data.priorSecretRevoked Yes Constant true —
data.secretReturnedOnce Yes Constant true —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

List fenced worker jobs and dead-letter visibility#

GET /jobs

Operation ID: listOperatingSystemJobs

Authentication: __Host-klineo_session cookie (sessionCookie)

Parameters#

Name Location Required Type Description and constraints
x-klineo-organization-id header Yes string —

Responses#

Status Description Content type and schema
200 Worker job states application/json: object

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes Array of OperatingSystemJob —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

Resolve a privacy-safe brand only for the exact verified request host#

GET /public/brands/current

Operation ID: getVerifiedHostBrand

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

This operation declares no parameters.

Responses#

Status Description Content type and schema
200 Host-bound accessible brand tokens application/json: object
404 No unique verified brand is bound to this host No response body declared

200 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —

200 application/json body

object — Additional properties rejected

Field Required at this level Type Description and constraints
data Yes PublicPartnerBrand —

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

404 response headers

Header Required Type Description and constraints
Cache-Control Yes Constant no-store —

GET /public/partner-brand/logo/{contentHash}

Operation ID: getVerifiedPartnerBrandLogo

Authentication: No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

Parameters#

Name Location Required Type Description and constraints
contentHash path Yes string —

Responses#

Status Description Content type and schema
200 Hash-verified immutable PNG logo image/png: string
404 No current verified host brand owns this exact logo hash No response body declared

200 response headers

Header Required Type Description and constraints
ETag Yes string —
Cache-Control Yes Constant no-store —
X-Content-Type-Options Yes Constant nosniff —
Cross-Origin-Resource-Policy Yes Constant same-origin —

200 image/png body

string — Format: binary