Transports
REST
A request and an answer, JSON both ways, on every route in the reference.
Shape
Every route is https://api.inorbit.hr plus the path in the reference. A GET or
DELETE takes its parameters from the path and the query string; a POST, PUT or
PATCH takes a JSON body with Content-Type: application/json.
curl https://api.inorbit.hr/v1/me \
-H "Authorization: Bearer $TOKEN" \
-H "Accept: application/json"Rules the gateway enforces
- A body that is not JSON is
415 unsupported_media_type; one that does not parse is400 bad_requestwith afielddetail namedbody; one over 2 MiB is413 payload_too_large. - Input is strict: an unknown field, an unknown query key, a singular field given
twice, or a value that does not convert is
400 bad_requestwith afielddetail naming it. - A known path with a verb it does not serve is
405 method_not_allowed. - A list field in the query string repeats the key:
?scopes=a&scopes=b. A nested field is dotted:?filter.kind=x. - An answer is at most 4 MiB.
Retries
Retry on 503 unavailable, 504 timeout and 429 rate_limited, and on nothing
else. A 429 carries Retry-After in seconds. A POST runs every time it is sent
unless it carries an Idempotency-Key on an operation whose reference lists the
header; then a repeat answers what the first call did
(Paging, retries and errors).
The document
GET https://api.inorbit.hr/openapi.json is the public REST surface as OpenAPI 3.1 (the routes an API key may call, and the health endpoints),
without a token. The Reference on this site is built from it and
shows only the operations a key may call; the document itself marks them with
x-iohr-public: true.