Get started
Quickstart
From nothing to your first answer in a minute, then what every answer looks like.
Every call goes to https://api.inorbit.hr under /v1, carries a bearer token, and
sends and receives JSON.
Create a token
An API token is one bearer string for every call. Signed in, make a test token right here: it belongs to your own account, holds every read scope and lives seven days. It is kept in this browser, and the console lists it under API tokens and keys, where you can revoke it.
For anything that runs longer, make a token in the console with only the scopes it
needs and the lifetime it needs (7, 30, 90 or 365 days), or describe what it is for and
let the console propose one. From a terminal, the command line
does the same: iohr login, then iohr token create.
Make your first call
Send the token on every call. From here, with the token the bar selected:
Or from a terminal, with the token copied from the bar:
export TOKEN=… # the token you copied
curl https://api.inorbit.hr/v1/me \
-H "Authorization: Bearer $TOKEN"{
"subject": "ak_7f3k…",
"kind": "client",
"client_id": "ak_7f3k…",
"org": "…",
"key": "…",
"scopes": ["identity:read", "account:read", "usage:read", "radar:read"],
"role": null
}GET /v1/me answers the caller the gateway verified: the token, its scopes, and under
org the account the call counts against.
Every page of the API reference has the same bar and a playground under it: the fields of the request, filled with your own values where the page knows them (your accounts, your webhook endpoints, inboxes and deliveries, the event types, what your audit log holds, the latest digests, this month's dates), a Send button, and the answer. The code samples beside it carry the token too, so what you copy is what ran. Explore every route that way before writing a line.
For production, use a key
A server that keeps a secret should hold an API key instead: an id and a secret it exchanges for a token that lives fifteen minutes, so what travels on the network expires fast. Authentication has the exchange in curl, JavaScript, Python and Go.
Next: Authentication for scopes, rotation and an app that acts as a person, and the API reference for every route a key may call.
What every answer looks like
- The body is JSON on every route and every transport. A request body must be
application/jsontoo. - Field names are the ones in the reference. 64-bit integers travel as decimal strings, timestamps as RFC 3339, enumerations by name, bytes as base64. Every field is present in an answer, defaults included.
- An error is one envelope everywhere,
{"code", "error", "details"}:codeis a fixed slug and the HTTP status follows it. The slugs are on Errors. - A value marked
stub: trueis a placeholder the platform labels as such, never a measurement.
Four ways to call
The same routes are served as a request and an answer
(REST), as a request and a stream of events
(server-sent events, on routes ending in /events), over
one WebSocket that carries any call by name, and over
MQTT, where every stream is a topic. Agents can
reach the same calls as tools over MCP.
To hear when something happens without holding a connection, add an endpoint and the platform sends you signed webhooks.
Versioning
Every path starts with /v1. Within a version a field is added, never renamed or
removed; a change that would break a client gets a new prefix, and the old one keeps
answering until the changelog says otherwise.