REST API Reference
The Strongly REST API provides programmatic access to all platform resources. All endpoints are served at https://<your-instance>/api/v1.
Base URL
https://<your-instance>/api/v1
Replace <your-instance> with your Strongly instance hostname (e.g., mycompany.strongly.ai).
Authentication
All API requests require authentication via an API key. Include your key in the X-API-Key header:
curl -H "X-API-Key: sk-prod-your-key-here" \
https://<your-instance>/api/v1/me
Creating an API Key
Create API keys in the Strongly UI under Profile > Security > API Keys, or via the session-authenticated API key endpoints.
Scopes
API keys are scoped to specific permissions. Available scopes:
| Scope | Description |
|---|---|
apps:read | Read app information |
apps:write | Create, update, delete apps |
apps:deploy | Deploy, start, stop, restart apps |
addons:read | Read addon information |
addons:write | Create, update, delete addons |
addons:deploy | Start, stop, restart addons |
datasources:read | Read data source information |
datasources:write | Create, update, delete data sources |
workflows:read | Read workflows and executions |
workflows:write | Create, update, delete workflows |
workflows:execute | Execute and stop workflows |
streaming-workflows:read | Read streaming workflows and their sessions |
streaming-workflows:deploy | Deploy and stop streaming workflows |
streaming-sessions:read | Read streaming sessions |
streaming-sessions:write | Start and end streaming sessions |
projects:read | Read project information |
projects:write | Create, update, delete projects |
workspaces:read | Read workspace information |
workspaces:write | Create, update, delete workspaces |
jobs:read | Read project jobs and their runs |
jobs:write | Create, run and manage project jobs |
volumes:read | Read volume information |
volumes:write | Create, update, delete volumes |
code-sessions:read | Read code sessions |
code-sessions:write | Create and manage code sessions |
code-sessions:deploy | Deploy what a code session built |
compute:read | Read compute clusters |
compute:write | Create and manage compute clusters |
agents:read | Read agents and their runs |
agents:write | Create, run and manage agents |
stan:execute | Run STAN |
avatars:read | Read avatars |
avatars:write | Create and manage avatars |
ai-gateway:read | Read AI models and analytics |
ai-gateway:write | Create, update, delete AI models |
ai-gateway:inference | Run chat completions, embeddings |
fine-tuning:read | Read fine-tuning jobs |
fine-tuning:write | Create, manage fine-tuning jobs |
data-forge:read | Read Data Forge projects and datasets |
data-forge:write | Create and run Data Forge generations |
guardrails:read | Read guardrail policies |
guardrails:write | Create and manage guardrail policies |
ml-workbench:read | Read experiments and AutoML jobs |
ml-workbench:write | Create, manage experiments and AutoML |
model-registry:read | Read model registry |
model-registry:write | Register and deploy models |
mlops:read | Read drift monitoring, A/B tests and feature stores, and read features (online and historical) |
mlops:write | Manage drift monitoring and A/B tests; apply feature definitions, write, push and materialize features |
memory:read | Read memories |
memory:write | Create and manage memories |
skills:read | Read skills |
skills:write | Create and manage skills |
rules:read | Read rules |
rules:write | Create and manage rules |
tasks:read | Read tasks |
tasks:write | Create and manage tasks |
artifacts:read | Read artifacts |
artifacts:write | Create and manage artifacts |
prompts:read | Read prompts |
prompts:write | Create and manage prompts |
preferences:read | Read preferences |
preferences:write | Change preferences |
governance:read | Read governance policies, solutions, requirements, reviews, evidence, enforcement checks, and (administrators) the audit log |
governance:write | Create and change policies and solutions, submit requirements, upload evidence, decide approvals, and (administrators) waive requirements |
finops:read | Read cost and budget data (budgets are read-only) |
finops:write | Create and manage schedules and resource groups |
users:read | Read user information |
users:write | Update own profile |
organizations:read | Read organization information |
organizations:write | Manage org members and invitations |
marketplace:read | Read marketplace offerings |
marketplace:deploy | Deploy marketplace offerings |
offering-usage:write | Report a marketplace app's metered usage |
notifications:read | Read notifications |
notifications:write | Mark notifications read |
dashboard:read | Read the dashboard |
admin | Full admin access |
* | Wildcard -- all scopes |
users:admin and marketplace:admin are reserved for platform administrators and cannot be granted to a key.
Scope Bundles:
Bundles expand to a set of individual scopes when assigned to a key.
| Bundle | Includes |
|---|---|
read-only | Every :read scope above, plus users:write, offering-usage:write and notifications:write (your own profile, an app's metering, marking notifications read) |
developer | Every scope above except admin and * (what a signed-in non-admin user's calls carry; each route's own access rules still apply) |
ci-cd | apps:read, apps:write, apps:deploy, workflows:read, workflows:write, workflows:execute, addons:read, datasources:read, marketplace:read, marketplace:deploy |
ml-ops | ai-gateway:read, ai-gateway:write, ai-gateway:inference, fine-tuning:read, fine-tuning:write, ml-workbench:read, ml-workbench:write, model-registry:read, model-registry:write, mlops:read, mlops:write |
full-access | Wildcard * (all scopes) |
Rate Limiting
Requests are rate-limited per API key using a sliding window:
| Tier | Limit | Applied To |
|---|---|---|
| Standard | 120 req/min | Default for all endpoints |
| Inference | 300 req/min | AI chat, completions, embeddings endpoints |
| Bulk | 30 req/min | Bulk import endpoints |
| Admin | 600 req/min | Keys with admin or * scope |
Rate limit headers are included in every response:
X-RateLimit-Limit: 120
X-RateLimit-Remaining: 119
X-RateLimit-Reset: 1706000000
When rate limited, the API returns 429 Too Many Requests with a Retry-After header.
How the API is organized
Every route follows one design (the platform's API_DESIGN.md), so a call you know
tells you how the others look:
-
Paths are grouped by product area, in the dashboard's words:
/apps,/workflows,/agents,/library/…(prompts, skills, imprints, artifacts, knowledge bases, pools),/primitives/…(memories, rules, tasks, preferences),/ai-gateway/…,/mlops/…,/finops/…,/governance/…,/stan/…, and/mefor your own account. -
Collections are plural nouns (
/data-sources,/fine-tuning-jobs). Only the last path parameter is:id; the ones before it name their resource (/agents/:agentId/threads/:id). To list children across every parent you can see, the parent id is-(GET /workflows/-/executions). -
Methods.
GETreads,POSTon a collection creates (201),PATCHupdates only the fields you send,PUTreplaces a whole thing (a few singletons such as an app's environment),DELETEremoves (204). Anything else is an action:POST …/:id/{verb}(start,stop,deploy,cancel,restore, …). There are no toggles: set a boolean withPATCH({ "enabled": false }). -
Sharing is the same on every shareable resource:
Method Path Does GET …/:id/permissionsOwner, members ( userId,role) andvisibilityPOST …/:id/permissions/membersShare with a user: { "userId", "role": "editor" | "user" }("editor" may change it, "user" may only use it)DELETE …/:{name}Id/permissions/members/:userIdStop sharing with a user ( /apps/:appId/permissions/members/:userId)PATCH …/:id/permissions{ "visibility": "public" | "private" } -
JSON is camelCase, ids are each document's
_id, and timestamps are ISO 8601. The AI Gateway's inference routes (/ai-gateway/chat/completions,/embeddings,/audio/…) are the exception: they speak the OpenAI format, so an OpenAI client with its base URL set tohttps://<your-instance>/api/v1/ai-gatewayworks unchanged. -
The whole contract is served as OpenAPI 3.1, without authentication:
GET /api/v1/openapi.json. Every route, its parameters and its scope are in it.
Pagination
Every list pages the same way: limit (default 50, max 200) and cursor, the
meta.nextCursor of the previous page. Filters are query parameters named after
the field, free-text search is q, and the order is sort (-createdAt,name;
- for descending). A fixed catalog the platform defines (templates, base models,
hardware tiers) and a computed ranking (top cost drivers, search results) are plain
arrays, not paged lists.
| Parameter | Type | Default | Description |
|---|---|---|---|
limit | integer | 50 | Items per page (max: 200) |
cursor | string | meta.nextCursor of the previous page; omit for the first page | |
q | string | Free-text search, where the list supports it | |
sort | string | the list's own | Fields to order by, comma-separated; prefix - for descending |
Paginated Response Format:
{
"data": [ ... ],
"meta": {
"total": 150,
"limit": 50,
"nextCursor": "eyJvIjo1MH0",
"requestId": "req_abc123"
}
}
nextCursor is null on the last page, and meta.total (also the
X-Total-Count header) counts every item, so nothing is cut off silently.
Response Format
Success Response (200/201/202)
{
"data": { ... },
"meta": {
"requestId": "req_abc123"
}
}
A request that starts long work (a deploy, a training job) answers 202 with the
resource whose status reports its progress; poll that resource.
Delete Response (204)
Empty body with 204 No Content status.
Error Response (4xx/5xx)
Errors are RFC 9457 problem details, Content-Type: application/problem+json:
{
"type": "urn:strongly:problem:not-found",
"title": "Not found",
"status": 404,
"detail": "App not found",
"code": "not-found",
"requestId": "req_abc123"
}
code is stable and machine-readable; detail is for people. A validation error
lists each field's problem in errors; other problems add their own members:
{
"type": "urn:strongly:problem:scope-required",
"title": "Missing API scope",
"status": 403,
"detail": "Scope 'apps:read' is required for this operation",
"code": "scope-required",
"requestId": "req_abc123",
"requiredScope": "apps:read",
"currentScopes": ["workflows:read"]
}
Error Codes:
| Code | Status | Description |
|---|---|---|
unauthorized | 401 | Invalid or missing API key |
forbidden | 403 | Insufficient permissions |
scope-required | 403 | API key missing required scope (the problem carries requiredScope and currentScopes) |
governance-blocked | 403 | The resource's governance requirements are not met yet; detail says which |
payment-required | 402 | A budget or credit limit refuses the launch; detail is the reason |
not-found | 404 | Resource does not exist (or you may not see it) |
method-not-allowed | 405 | The path exists but not with that method (the Allow header lists the ones it takes) |
validation-error | 400 | Invalid request parameters (or 413 if body exceeds 10 MB) |
duplicate | 409 | Resource conflict (e.g., duplicate name) |
resource-in-use | 422 | Resource is currently in use |
action-in-progress | 422 | An action is already in progress |
rate-limited | 429 | Too many requests |
backend-unavailable | 502 | Backend service unreachable (or 504 on timeout) |
internal-error | 500 | Internal server error |
Quick Start
Test your API key with a single curl command:
curl -H "X-API-Key: sk-prod-your-key-here" \
https://<your-instance>/api/v1/me
A successful response returns you (_id, username, email, role), your organization and the apiKey the call used. If you get a 401 error, see the Authentication Troubleshooting guide.
API Sections
Core
| Section | Description |
|---|---|
| Authentication | API keys and identity |
| Users | User management |
| Organizations | Organization management |
| Projects | Project management |
| Jobs | Project jobs: commands run on demand or on a schedule |
| Workspaces | Development environments |
| Environments | Saved sizes and container images for workloads |
| Volumes | Persistent storage |
| Dashboard | Dashboard summary metrics |
| Compute | Compute resource overview |
| Notifications | User notifications |
| Client Endpoints | The Strongly Bridge relay and the web app's activity beacon |
Apps and Data
| Section | Description |
|---|---|
| Apps | Application lifecycle |
| Addons | Managed databases and services |
| Data Sources | External data connections |
| Marketplace | Marketplace apps and templates |
| Plugins | Platform extensions: DataHub and Stripe App Payments |
| Code Sessions | Browser-based code editing sessions |
| Avatars | User and entity avatars |
Workflows
| Section | Description |
|---|---|
| Workflows | Workflow pipelines |
| Streaming Workflows | Real-time streaming workflows |
| Executions | Workflow execution history |
| Workflow Alerts | Alert rules on how a workflow's runs end, and the alerts they sent |
| Workflow Nodes | Node catalog |
| Workflow Export | Export workflows for portability |
AI
| Section | Description |
|---|---|
| AI Inference | Chat completions, embeddings |
| AI Models | AI model catalog and lifecycle |
| AI Provider Keys | Provider API key management |
| Guardrails | Rules on a model's requests and responses |
| AI Analytics | AI usage analytics |
| Prompts | Prompt templates |
| Skills | Skill library for agents |
| Agents | Agent definitions |
| Agent Messages | Agent conversation history |
| Memory | Long-term agent memory |
| Rules | Behavioral rules |
| Tasks | User-owned one-shot and recurring tasks |
| Knowledge Bases | Documents agents answer from |
| Artifacts | Files agents produce and you upload |
| Imprints and Pools | Bundles of library items an agent learns at once |
ML and Model Lifecycle
| Section | Description |
|---|---|
| Fine-Tuning | Fine-tune language models |
| Experiments | ML experiment tracking |
| AutoML | Automated machine learning |
| Model Registry | Model versioning and deployment |
| A/B Tests | Model A/B testing |
| Drift Detection | Data and model drift monitoring |
| Data Forge | Data preparation pipelines |
Governance and FinOps
| Section | Description |
|---|---|
| Governance Policies | Policies, solutions, requirements, reviews, enforcement checks, metrics, and audit |
| Governance Evidence | Download and delete evidence files uploaded to evidence gates |
| FinOps -- Budgets | Cost budgets and thresholds |
| FinOps -- Costs | Cost figures, breakdowns, forecasts, and anomalies |
| FinOps -- Resource Groups | Resource groups for budgets and schedules |
| FinOps -- Schedules | Auto-shutdown schedules |
STAN (Personal AI Assistant)
| Section | Description |
|---|---|
| STAN | STAN runtime |
| STAN -- Tasks | STAN task management |
| STAN -- Memories | STAN personal memory |
| STAN -- Settings | STAN user settings |