Skip to main content

REST API Reference

The Strongly REST API provides programmatic access to all platform resources. All endpoints are served at https://<your-instance>/api/v1.

Base URL​

https://<your-instance>/api/v1

Replace <your-instance> with your Strongly instance hostname (e.g., mycompany.strongly.ai).

Authentication​

All API requests require authentication via an API key. Include your key in the X-API-Key header:

curl -H "X-API-Key: sk-prod-your-key-here" \
https://<your-instance>/api/v1/me

Creating an API Key​

Create API keys in the Strongly UI under Profile > Security > API Keys, or via the session-authenticated API key endpoints.

Scopes​

API keys are scoped to specific permissions. Available scopes:

ScopeDescription
apps:readRead app information
apps:writeCreate, update, delete apps
apps:deployDeploy, start, stop, restart apps
addons:readRead addon information
addons:writeCreate, update, delete addons
addons:deployStart, stop, restart addons
datasources:readRead data source information
datasources:writeCreate, update, delete data sources
workflows:readRead workflows and executions
workflows:writeCreate, update, delete workflows
workflows:executeExecute and stop workflows
streaming-workflows:readRead streaming workflows and their sessions
streaming-workflows:deployDeploy and stop streaming workflows
streaming-sessions:readRead streaming sessions
streaming-sessions:writeStart and end streaming sessions
projects:readRead project information
projects:writeCreate, update, delete projects
workspaces:readRead workspace information
workspaces:writeCreate, update, delete workspaces
jobs:readRead project jobs and their runs
jobs:writeCreate, run and manage project jobs
volumes:readRead volume information
volumes:writeCreate, update, delete volumes
code-sessions:readRead code sessions
code-sessions:writeCreate and manage code sessions
code-sessions:deployDeploy what a code session built
compute:readRead compute clusters
compute:writeCreate and manage compute clusters
agents:readRead agents and their runs
agents:writeCreate, run and manage agents
stan:executeRun STAN
avatars:readRead avatars
avatars:writeCreate and manage avatars
ai-gateway:readRead AI models and analytics
ai-gateway:writeCreate, update, delete AI models
ai-gateway:inferenceRun chat completions, embeddings
fine-tuning:readRead fine-tuning jobs
fine-tuning:writeCreate, manage fine-tuning jobs
data-forge:readRead Data Forge projects and datasets
data-forge:writeCreate and run Data Forge generations
guardrails:readRead guardrail policies
guardrails:writeCreate and manage guardrail policies
ml-workbench:readRead experiments and AutoML jobs
ml-workbench:writeCreate, manage experiments and AutoML
model-registry:readRead model registry
model-registry:writeRegister and deploy models
mlops:readRead drift monitoring, A/B tests and feature stores, and read features (online and historical)
mlops:writeManage drift monitoring and A/B tests; apply feature definitions, write, push and materialize features
memory:readRead memories
memory:writeCreate and manage memories
skills:readRead skills
skills:writeCreate and manage skills
rules:readRead rules
rules:writeCreate and manage rules
tasks:readRead tasks
tasks:writeCreate and manage tasks
artifacts:readRead artifacts
artifacts:writeCreate and manage artifacts
prompts:readRead prompts
prompts:writeCreate and manage prompts
preferences:readRead preferences
preferences:writeChange preferences
governance:readRead governance policies, solutions, requirements, reviews, evidence, enforcement checks, and (administrators) the audit log
governance:writeCreate and change policies and solutions, submit requirements, upload evidence, decide approvals, and (administrators) waive requirements
finops:readRead cost and budget data (budgets are read-only)
finops:writeCreate and manage schedules and resource groups
users:readRead user information
users:writeUpdate own profile
organizations:readRead organization information
organizations:writeManage org members and invitations
marketplace:readRead marketplace offerings
marketplace:deployDeploy marketplace offerings
offering-usage:writeReport a marketplace app's metered usage
notifications:readRead notifications
notifications:writeMark notifications read
dashboard:readRead the dashboard
adminFull admin access
*Wildcard -- all scopes

users:admin and marketplace:admin are reserved for platform administrators and cannot be granted to a key.

Scope Bundles:

Bundles expand to a set of individual scopes when assigned to a key.

BundleIncludes
read-onlyEvery :read scope above, plus users:write, offering-usage:write and notifications:write (your own profile, an app's metering, marking notifications read)
developerEvery scope above except admin and * (what a signed-in non-admin user's calls carry; each route's own access rules still apply)
ci-cdapps:read, apps:write, apps:deploy, workflows:read, workflows:write, workflows:execute, addons:read, datasources:read, marketplace:read, marketplace:deploy
ml-opsai-gateway:read, ai-gateway:write, ai-gateway:inference, fine-tuning:read, fine-tuning:write, ml-workbench:read, ml-workbench:write, model-registry:read, model-registry:write, mlops:read, mlops:write
full-accessWildcard * (all scopes)

Rate Limiting​

Requests are rate-limited per API key using a sliding window:

TierLimitApplied To
Standard120 req/minDefault for all endpoints
Inference300 req/minAI chat, completions, embeddings endpoints
Bulk30 req/minBulk import endpoints
Admin600 req/minKeys with admin or * scope

Rate limit headers are included in every response:

X-RateLimit-Limit: 120
X-RateLimit-Remaining: 119
X-RateLimit-Reset: 1706000000

When rate limited, the API returns 429 Too Many Requests with a Retry-After header.

How the API is organized​

Every route follows one design (the platform's API_DESIGN.md), so a call you know tells you how the others look:

  • Paths are grouped by product area, in the dashboard's words: /apps, /workflows, /agents, /library/… (prompts, skills, imprints, artifacts, knowledge bases, pools), /primitives/… (memories, rules, tasks, preferences), /ai-gateway/…, /mlops/…, /finops/…, /governance/…, /stan/…, and /me for your own account.

  • Collections are plural nouns (/data-sources, /fine-tuning-jobs). Only the last path parameter is :id; the ones before it name their resource (/agents/:agentId/threads/:id). To list children across every parent you can see, the parent id is - (GET /workflows/-/executions).

  • Methods. GET reads, POST on a collection creates (201), PATCH updates only the fields you send, PUT replaces a whole thing (a few singletons such as an app's environment), DELETE removes (204). Anything else is an action: POST …/:id/{verb} (start, stop, deploy, cancel, restore, …). There are no toggles: set a boolean with PATCH ({ "enabled": false }).

  • Sharing is the same on every shareable resource:

    MethodPathDoes
    GET…/:id/permissionsOwner, members (userId, role) and visibility
    POST…/:id/permissions/membersShare with a user: { "userId", "role": "editor" | "user" } ("editor" may change it, "user" may only use it)
    DELETE…/:{name}Id/permissions/members/:userIdStop sharing with a user (/apps/:appId/permissions/members/:userId)
    PATCH…/:id/permissions{ "visibility": "public" | "private" }
  • JSON is camelCase, ids are each document's _id, and timestamps are ISO 8601. The AI Gateway's inference routes (/ai-gateway/chat/completions, /embeddings, /audio/…) are the exception: they speak the OpenAI format, so an OpenAI client with its base URL set to https://<your-instance>/api/v1/ai-gateway works unchanged.

  • The whole contract is served as OpenAPI 3.1, without authentication: GET /api/v1/openapi.json. Every route, its parameters and its scope are in it.

Pagination​

Every list pages the same way: limit (default 50, max 200) and cursor, the meta.nextCursor of the previous page. Filters are query parameters named after the field, free-text search is q, and the order is sort (-createdAt,name; - for descending). A fixed catalog the platform defines (templates, base models, hardware tiers) and a computed ranking (top cost drivers, search results) are plain arrays, not paged lists.

ParameterTypeDefaultDescription
limitinteger50Items per page (max: 200)
cursorstringmeta.nextCursor of the previous page; omit for the first page
qstringFree-text search, where the list supports it
sortstringthe list's ownFields to order by, comma-separated; prefix - for descending

Paginated Response Format:

{
"data": [ ... ],
"meta": {
"total": 150,
"limit": 50,
"nextCursor": "eyJvIjo1MH0",
"requestId": "req_abc123"
}
}

nextCursor is null on the last page, and meta.total (also the X-Total-Count header) counts every item, so nothing is cut off silently.

Response Format​

Success Response (200/201/202)​

{
"data": { ... },
"meta": {
"requestId": "req_abc123"
}
}

A request that starts long work (a deploy, a training job) answers 202 with the resource whose status reports its progress; poll that resource.

Delete Response (204)​

Empty body with 204 No Content status.

Error Response (4xx/5xx)​

Errors are RFC 9457 problem details, Content-Type: application/problem+json:

{
"type": "urn:strongly:problem:not-found",
"title": "Not found",
"status": 404,
"detail": "App not found",
"code": "not-found",
"requestId": "req_abc123"
}

code is stable and machine-readable; detail is for people. A validation error lists each field's problem in errors; other problems add their own members:

{
"type": "urn:strongly:problem:scope-required",
"title": "Missing API scope",
"status": 403,
"detail": "Scope 'apps:read' is required for this operation",
"code": "scope-required",
"requestId": "req_abc123",
"requiredScope": "apps:read",
"currentScopes": ["workflows:read"]
}

Error Codes:

CodeStatusDescription
unauthorized401Invalid or missing API key
forbidden403Insufficient permissions
scope-required403API key missing required scope (the problem carries requiredScope and currentScopes)
governance-blocked403The resource's governance requirements are not met yet; detail says which
payment-required402A budget or credit limit refuses the launch; detail is the reason
not-found404Resource does not exist (or you may not see it)
method-not-allowed405The path exists but not with that method (the Allow header lists the ones it takes)
validation-error400Invalid request parameters (or 413 if body exceeds 10 MB)
duplicate409Resource conflict (e.g., duplicate name)
resource-in-use422Resource is currently in use
action-in-progress422An action is already in progress
rate-limited429Too many requests
backend-unavailable502Backend service unreachable (or 504 on timeout)
internal-error500Internal server error

Quick Start​

Test your API key with a single curl command:

curl -H "X-API-Key: sk-prod-your-key-here" \
https://<your-instance>/api/v1/me

A successful response returns you (_id, username, email, role), your organization and the apiKey the call used. If you get a 401 error, see the Authentication Troubleshooting guide.

API Sections​

Core​

SectionDescription
AuthenticationAPI keys and identity
UsersUser management
OrganizationsOrganization management
ProjectsProject management
JobsProject jobs: commands run on demand or on a schedule
WorkspacesDevelopment environments
EnvironmentsSaved sizes and container images for workloads
VolumesPersistent storage
DashboardDashboard summary metrics
ComputeCompute resource overview
NotificationsUser notifications
Client EndpointsThe Strongly Bridge relay and the web app's activity beacon

Apps and Data​

SectionDescription
AppsApplication lifecycle
AddonsManaged databases and services
Data SourcesExternal data connections
MarketplaceMarketplace apps and templates
PluginsPlatform extensions: DataHub and Stripe App Payments
Code SessionsBrowser-based code editing sessions
AvatarsUser and entity avatars

Workflows​

SectionDescription
WorkflowsWorkflow pipelines
Streaming WorkflowsReal-time streaming workflows
ExecutionsWorkflow execution history
Workflow AlertsAlert rules on how a workflow's runs end, and the alerts they sent
Workflow NodesNode catalog
Workflow ExportExport workflows for portability

AI​

SectionDescription
AI InferenceChat completions, embeddings
AI ModelsAI model catalog and lifecycle
AI Provider KeysProvider API key management
GuardrailsRules on a model's requests and responses
AI AnalyticsAI usage analytics
PromptsPrompt templates
SkillsSkill library for agents
AgentsAgent definitions
Agent MessagesAgent conversation history
MemoryLong-term agent memory
RulesBehavioral rules
TasksUser-owned one-shot and recurring tasks
Knowledge BasesDocuments agents answer from
ArtifactsFiles agents produce and you upload
Imprints and PoolsBundles of library items an agent learns at once

ML and Model Lifecycle​

SectionDescription
Fine-TuningFine-tune language models
ExperimentsML experiment tracking
AutoMLAutomated machine learning
Model RegistryModel versioning and deployment
A/B TestsModel A/B testing
Drift DetectionData and model drift monitoring
Data ForgeData preparation pipelines

Governance and FinOps​

SectionDescription
Governance PoliciesPolicies, solutions, requirements, reviews, enforcement checks, metrics, and audit
Governance EvidenceDownload and delete evidence files uploaded to evidence gates
FinOps -- BudgetsCost budgets and thresholds
FinOps -- CostsCost figures, breakdowns, forecasts, and anomalies
FinOps -- Resource GroupsResource groups for budgets and schedules
FinOps -- SchedulesAuto-shutdown schedules

STAN (Personal AI Assistant)​

SectionDescription
STANSTAN runtime
STAN -- TasksSTAN task management
STAN -- MemoriesSTAN personal memory
STAN -- SettingsSTAN user settings