Sign in
Docs
0%

Get started

Quickstart

From nothing to your first answer in a minute, then what every answer looks like.

Every call goes to https://api.inorbit.hr under /v1, carries a bearer token, and sends and receives JSON.

Create a token

An API token is one bearer string for every call. Signed in, make a test token right here: it belongs to your own account, holds every read scope and lives seven days. It is kept in this browser, and the console lists it under API tokens and keys, where you can revoke it.

Have a token? Manage tokens in the console

For anything that runs longer, make a token in the console with only the scopes it needs and the lifetime it needs (7, 30, 90 or 365 days), or describe what it is for and let the console propose one. From a terminal, the command line does the same: iohr login, then iohr token create.

Make your first call

Send the token on every call. From here, with the token the bar selected:

Run it from here
Create or paste a token above, then send the call from this browser.

Or from a terminal, with the token copied from the bar:

export TOKEN=…   # the token you copied
curl https://api.inorbit.hr/v1/me \
  -H "Authorization: Bearer $TOKEN"
{
  "subject": "ak_7f3k…",
  "kind": "client",
  "client_id": "ak_7f3k…",
  "org": "…",
  "key": "…",
  "scopes": ["identity:read", "account:read", "usage:read", "radar:read"],
  "role": null
}

GET /v1/me answers the caller the gateway verified: the token, its scopes, and under org the account the call counts against.

Every page of the API reference has the same bar and a playground under it: the fields of the request, filled with your own values where the page knows them (your accounts, your webhook endpoints, inboxes and deliveries, the event types, what your audit log holds, the latest digests, this month's dates), a Send button, and the answer. The code samples beside it carry the token too, so what you copy is what ran. Explore every route that way before writing a line.

For production, use a key

A server that keeps a secret should hold an API key instead: an id and a secret it exchanges for a token that lives fifteen minutes, so what travels on the network expires fast. Authentication has the exchange in curl, JavaScript, Python and Go.

Next: Authentication for scopes, rotation and an app that acts as a person, and the API reference for every route a key may call.

What every answer looks like

  • The body is JSON on every route and every transport. A request body must be application/json too.
  • Field names are the ones in the reference. 64-bit integers travel as decimal strings, timestamps as RFC 3339, enumerations by name, bytes as base64. Every field is present in an answer, defaults included.
  • An error is one envelope everywhere, {"code", "error", "details"}: code is a fixed slug and the HTTP status follows it. The slugs are on Errors.
  • A value marked stub: true is a placeholder the platform labels as such, never a measurement.

Four ways to call

The same routes are served as a request and an answer (REST), as a request and a stream of events (server-sent events, on routes ending in /events), over one WebSocket that carries any call by name, and over MQTT, where every stream is a topic. Agents can reach the same calls as tools over MCP.

To hear when something happens without holding a connection, add an endpoint and the platform sends you signed webhooks.

Versioning

Every path starts with /v1. Within a version a field is added, never renamed or removed; a change that would break a client gets a new prefix, and the old one keeps answering until the changelog says otherwise.