Resources
Changelog
What changed on the API and on these pages, by date.
- 2026-10-09: on MCP,
accounts_get_me("Who am I",account:read, which MCP clients may now ask for) says who is calling and which accounts they reach.decisions_get_document(andGET /v1/decisions/spaces/{space_id}/documents/{document_id}) takes a document by its kind and number (RFC 0102.1,prd-12) or its repository path as well as its id, anddecisions_list_documentstakescompact: truefor a short listing. Monitors are readable over MCP withconnections:read: the list, one monitor, its check runs, its health and a time range. - 2026-10-08: the RFCs API is the Decisions API, replaced in one
release with no old names kept. Routes move from
/v1/rfcs/...to/v1/decisions/...(same resources, fields and ids:/v1/decisions/spaces/{space_id}/documents/...,/v1/decisions/reviews,/v1/decisions/diagrams,/v1/decisions/public/...), the gRPC service fromiohr.rfcs.v1.RfcsServicetoiohr.decisions.v1.DecisionsService(same messages), the scopes fromrfc:readandrfc:writetodecisions:readanddecisions:write(keys that held the old ones were given the new ones), and the MCP tools fromrfcs_*todecisions_*. The command line'siohr rfcisiohr decisions, and each SDK'srfcsmodule isdecisions. The deprecated/v1/labsroutes,lab:*scopes andlabs_*tools are gone too. - 2026-10-07: the developer tools are open to everyone: the command line, the SDKs, extensions, the agent and connections, with a Tools tab in the header. Versions as of today: command line 0.1.0-alpha.11 (extensions declare their privileges and ask before install), Rust, TypeScript, Python, C# and Java 0.2.2, Go 0.2.3, the agent 0.1.0-alpha.7.
- 2026-10-05: command line 0.1.0-alpha.10 adds
iohr sdk add: it adds the SDK to the project in the current directory with the package manager the project already uses (cargo, pnpm, yarn, bun, npm, deno, uv, poetry, pdm, pip in an active virtualenv, go). It prints the command first, then runs it directly: no shell, never sudo.--dry-runonly prints it;--versionpicks a release. - 2026-10-05: SDK 0.2.2 brings the same configuration and middleware to all six
languages: one
loadthat reads code,INORBIT_*variables, theiohrconfig file and defaults in that order, a credential chain, proxy, CA bundle and mTLS settings, and a middleware pipeline for logging, OpenTelemetry, rate limits and retries (Generate an SDK). Writes that take anIdempotency-Keyare now retried with one key per call, and calls have a 120 s total deadline by default. Rust, TypeScript, Python and Go 0.2.2 are on their registries. - 2026-10-05: the RFC tools on MCP take the API's new
names:
rfcs_list_spaces,rfcs_get_space,rfcs_get_documentand the rest, withspace_id, underrfc:readandrfc:write. The oldlabs_*tools and a token withlab:readorlab:writekeep working until the next release; each old tool is titled "(deprecated)" and names the tool to call instead. - 2026-10-05: the RFCs API says what it holds:
spaces of RFCs. Its routes are under
/v1/rfcs(/v1/rfcs/spaces/{space_id}/...,/v1/rfcs/reviews), its answers namespace_id,spaceandspaces, and its scopes arerfc:readandrfc:write. The old/v1/labsroutes and the scopeslab:readandlab:writekeep working, unchanged, until the next release: each old answer carries aDeprecationheader and aLinkto its new route. A new key is given the new scopes. - 2026-10-04: your RFCs over MCP. With
lab:readan assistant lists your spaces and reads their documents, versions, comments, reviews and diagrams; withmcp:writeandlab:writeit starts documents, saves drafts, comments, asks for reviews, asks for changes and draws diagrams. A save on a stale version is aconflictthe assistant reads, never an overwrite. Approving, deciding and publishing stay in the console. A document is also a resource,inorbit://spaces/{space}/documents/{document}. - 2026-10-04: every reference page shows the call made with the
SDK first, in Rust, TypeScript, Python, Go, C# or Java, then the raw request for curl,
fetch, Python (httpx or requests) and Go's net/http. The SDK samples are generated by
iohr sdk examplesand compile against each library; the raw ones carry the token selected in the token bar. Your choice of language is kept across pages. - 2026-10-04: MCP has the setup for Cursor, GitHub Copilot
in VS Code and Gemini CLI next to Claude Code, and a project's
.mcp.jsonfor Claude Code. claude.ai, Claude Desktop's custom connectors and ChatGPT need sign-in from the assistant itself, which is not built yet. - 2026-10-04: the SDKs stream. The libraries have the account's events as a
method that yields one event at a time (
stream_events,streamEvents,StreamEvents,StreamEventsAsync), over server-sent events or, withstreams: socket, over one WebSocket that reopens by itself. Rust, TypeScript, Python and Go 0.2.1 are on their registries; Generate an SDK has an example in each language. - 2026-10-04: assistants connect to MCP by signing in.
claude.ai, ChatGPT, Cursor, VS Code, Claude Code and Gemini CLI register themselves at
https://auth.inorbit.hr/oauth2/register, named by the sign-in's metadata at/.well-known/oauth-authorization-server, and you allow each on a page that names it, where it returns and what it may do. Its tokens last 15 minutes, open/mcpalone, and end when you revoke the app under Sign-in and security → Connected apps. - 2026-10-04: MCP opens to API tokens. Three scopes,
mcp:read,mcp:writeandmcp:generate, let a token reach/mcp;tools/listlists only the tools the token may call, a tool whose scope it lacks answers403withinsufficient_scope, and every tool carries MCP's annotations. A request without a token is401with aWWW-Authenticatethat names the server's protected resource metadata, served at/.well-known/oauth-protected-resource/mcp. Tools are no longer listed without a token. - 2026-10-04: SDK 0.2.0 follows the API's document as it now states itself: an
answer's field is typed as always present only when the document marks it
required, and every request field is optional and left out when unset. Each runtime gains a helper that reads a timestamp and treats an unset one ("") as no value; Go gainsinorbit.Ptrfor request fields. 0.2.0 is on crates.io, npm and JSR, PyPI and the Go module proxy; C# and Java carry the same version, and command line 0.1.0-alpha.5 generates the same types. Generate an SDK has the table. - 2026-10-04: limits for open streams. A key, API token or person holds at most 32
event streams, sockets and MQTT connections at once, an account 128; a stream lives
at most 24 hours; a revoked key's open streams end within seconds; an idle
WebSocket closes after 5 minutes and the server pings
every 15 seconds. The socket's frames are published as a JSON Schema at
https://api.inorbit.hr/frames.json, and every operation in the OpenAPI document names its socket method inx-iohr-rpc. Limits has the numbers. - 2026-10-04: the SDK runtimes for Rust, TypeScript, Python and Go are on crates.io, npm and JSR, PyPI and the Go module proxy at 0.1.0; Generate an SDK shows how to add each. C# and Java build from source until their NuGet and Maven Central releases.
- 2026-10-03: Generate an SDK for your account covers all six
languages:
iohr sdk generate(command line 0.1.0-alpha.4) writes Rust, TypeScript, Go, Python, C# and Java clients cut to your credentials, each with an iterator over paged lists. The libraries are not on their registries yet. - 2026-10-03: Paging, retries and errors puts the
rules every route follows on one page: paging with
page_token, retrying a write withIdempotency-Key, the headers every answer carries, and which errors to retry. Errors lists422 unprocessableand the envelope'srequest_id. - 2026-10-03: every error from the API is JSON. A missing or invalid token, a scope
the token lacks, the rate limit, an unknown route or a service that is down now
answer the same
{"code", "error", "details", "request_id"}envelope as every other error, never plain text. - 2026-10-03: every list pages one way. Webhook endpoints, test inboxes and what they
received, event types, the audit log, unit categories, and the radar's digests and
items take
page_sizeandpage_tokenand answernext_page_token(empty on the last page), with aLinkheader to the next page. A token is opaque and only valid with the same filters it came from.limit, where a route had it, still works as an older name forpage_size. A spent daily allowance now answersRetry-After, the seconds until it resets. - 2026-10-03: retry a write safely. Every
POSTtakes an optionalIdempotency-Keyheader (a UUID is a good one): a repeat with the same key and body within a day answers what the first call did, withIdempotency-Replayed: true, instead of creating a second endpoint or sending a second test; the same key with another body is422 unprocessable. Every answer also carriesx-request-id, error bodies repeat it asrequest_id, and a list with more pages links to the next one in aLinkheader. - 2026-10-03: the reference is grouped by what you look for: Identity, Accounts, Usage and units, Domains, Webhooks, Test inboxes, Events and Radar, in that order, each listing reads before writes. Pages that moved keep their old address as a redirect. The front page lists every guide in the sidebar.
- 2026-10-03: domains. Prove that an account controls a domain with one DNS TXT
record, in the console's Domains section or over
/v1/accounts/orgs/{org_id}/domains: add it, publish the record, check it, confirm it. The record is looked up through several public resolvers and again every day. Single sign-on for teams, agents and checks from our cloud rely on it. New scopes:domains:read,domains:write; new events:domain.verified,domain.unverified,domain.transferred. Domains has the steps for each DNS provider. - 2026-10-03: an SDK cut to your account.
iohr sdk generate --lang rustwrites a Rust client into your repository with exactly the operations your profiles' credentials may call, for one account or several, and a call a profile may not make does not compile;iohr sdk checkfails in CI when that set has moved. The reference's Your document section describes the document behind it. Guide: Generate an SDK for your account. - 2026-10-03: try every route from these pages. The reference's playground fills each field it can know from your token (your accounts, webhook endpoints, inboxes and deliveries, the event types, your audit log's actions and people, the latest digests, this month's dates), a stream's page has Run and Stop and shows events as they arrive, the front page and the quickstart send the first call from the page, and the API answers this site's browser calls with every method a route has, so a webhook endpoint can be created, tested, rotated and deleted here. Every call carries the token alone, never a cookie, so it does exactly what the token may.
- 2026-10-03:
GET /v1/openapi.jsonis cut to the caller. A key or API token gets its plan's document narrowed to its scopes, so the document lists exactly what that credential may call, andinfo.x-iohr-cutnames the plan, the account, the scopes and a hash of the operations and schemas (prose never moves it). A signed-in person's token gets the whole plan, as before, and?account=<id>asks for one of their teams' documents instead of the personal account's. - 2026-10-02: the command line,
iohr, first pre-release (0.1.0-alpha.2). Sign in in a browser or with a device code, keep several accounts as profiles, manage API tokens and call the API from a terminal or CI; install it with Homebrew, APT,install.shorinstall.ps1. Command line has the details. - 2026-10-02: the audit log as a webhook. Every entry of an account's audit log (its
members, roles, invitations, keys, tokens, name, plan, policy, deletion) is also sent
as
audit.eventwithaudit_event_id,actionandactor, in order and at least once. Read the entry with a token given the new scopeaccount:audit:GET /v1/accounts/orgs/{org_id}/audit?after=<the last id you saw>answers what came after it, oldest first. - 2026-10-02: a test inbox for webhooks. Press Use a test inbox in the console's
Webhooks section, or call
POST /v1/webhooks/inboxes, and you get an address that keeps what is posted to it for 24 hours. Add it as an endpoint, send a test event, and see the signed request and whether its signature verified, without a server of your own. See Try it without a server. - 2026-10-02, rolling out: webhooks and MQTT. The platform sends signed webhooks to an HTTPS endpoint
you add in the console's Webhooks section or over
/v1/webhooks/endpoints, per the Standard Webhooks specification, retried for about 28 hours, every attempt on record. MQTT 5 is served atwss://api.inorbit.hr/v1/mqtt: the account's events onevents/<type>, every server-sent events route as a topic, and any method called by publishing torpc/<service>/<Method>. Events carry ids, never content;GET /v1/events/typeslists them. New scopes:events:read,webhooks:read,webhooks:write. The bounds are on Limits. - 2026-10-02: the reference fills in what it knows. Signed in,
org_idis the selected token's account and can be picked from your accounts and teams, the usage range is this month, a digest'sidis the latest; every value can still be typed. Create a test token can make the token for a team you own or administer. - 2026-10-02: API tokens. Make a bearer token in the console, or in one click on
these pages, with the scopes and lifetime you choose (7 to 365 days); it is shown
once and sent as
Authorization: Bearer, no exchange needed. The reference's playground and samples carry the token you select in its new token bar. Revoking a token or a key now refuses its tokens within seconds on every route, including the tokens a key already issued. The console page is API tokens and keys, with search, filters and paging, and can propose a token from a plain description. The playground no longer calls through this site as you; use a token. - 2026-10-01: these pages are rebuilt: a quickstart, a page on accounts, teams and
keys, language tabs on the code, and a reference with readable names. Reference pages
moved to short addresses (
/docs/reference/radar/list-digests/was/docs/reference/radar/RadarService.ListDigests/); the old ones redirect. The radar'sinclude_draftsparameter is no longer listed: it is ignored for keys. - 2026-10-01: InOrbit names on the wire. Tokens carry the audience
iohr-api(wastbd-api); the OpenAPI document marks public operations withx-iohr-publicand their scopes withx-iohr-scopes(wasx-tbd-*); schema names and/v1/wsmethod names use the packagesiohr.<service>.v1(wastbd.<service>.v1); the MCP server reports the nameinorbit; error details use the domaininorbit.hr. API key scopes (identity:read, ...) and every REST path are unchanged. - 2026-10-01: a model generation is priced by its tokens, 4 units per 1000 (before, 400 per call whatever its length), and units are the account's one budget: at zero on a plan that blocks, its people on the sites stop as well as its keys. The products' per-person daily limits rose well above any plan and now only bound abuse.
- 2026-10-01: units. Every call made for an account is counted and weighed by its
operation's category (
read1 togenerate400 units); an account gets an allowance of units a month, 100 000 onfree, and when it runs out its keys are refused with429 quota_exceededuntil the 1st. Usage and units has the details; the console's Usage page shows the month.usage:readalso reads the units and the price list, andradar:readopens the radar's published digests to keys. - 2026-10-01: an API key holds the scopes chosen when it is made:
identity:read,account:read,usage:read; a route admits a token only with its scope, and each operation in the reference names it. The singletbd.publicscope is gone: a key made before today no longer reaches any route; make a new one in the console. - 2026-10-01: sign in on this site with the same account as the rest of inorbit.hr; the reference's playground can call as you, or with a token you paste, and the API answers this site's browser calls (GET only).
- 2026-10-01:
GET /openapi.jsonserves the public document only: the routes an API key may call, the health endpoints, and the schemas those use. Before, it served every route the gateway has. With a token,GET /v1/openapi.jsonanswers the document for your plan. - 2026-09-30: these pages open. The OpenAPI document gains
servers(the API's public address), abearersecurity scheme on every operation but the health endpoints, andx-tbd-publicon the routes a key may call;GET /openapi.jsonneeds no token. Token requests are limited per client address instead of one shared bucket.