# InOrbit API > How to call the InOrbit API: keys and tokens, accounts and teams, REST, server-sent events, the WebSocket, MQTT, webhooks and MCP, errors, limits, usage, and a reference page for every public operation. What InOrbit is and what runs today: https://inorbit.hr/llms.txt. The API's OpenAPI document: https://api.inorbit.hr/openapi.json. ## Guides - [Accounts, teams and keys](https://developers.inorbit.hr/docs/accounts/): Your own account and teams, what each role in a team may do, invitations, and which account a call counts against. - [Installing an agent](https://developers.inorbit.hr/docs/agents/install/): Run the agent in your own network, enroll it with a one-time token, and run checks on what our cloud cannot reach. - [Authentication](https://developers.inorbit.hr/docs/authentication/): API tokens to start with, API keys for production servers, the scopes both hold, and the pattern for an app that acts as a person. - [Changelog](https://developers.inorbit.hr/docs/changelog/): What changed on the API and on these pages, by date. - [Command line](https://developers.inorbit.hr/docs/command-line/): Install iohr, sign in, keep several accounts as profiles, manage tokens and call the API from a terminal or a CI job. - [Decisions](https://developers.inorbit.hr/docs/decisions/): PRDs, ADRs and RFCs in one product, how they link, how a document is decided, and where Atlas comes in. What runs today and what is in development. - [Domains](https://developers.inorbit.hr/docs/domains/): Prove with one DNS TXT record that an account controls a domain, with the steps for each common DNS provider, the API calls, and how the proof is kept true. - [Errors](https://developers.inorbit.hr/docs/errors/): One envelope on every surface, a fixed set of codes, and what to do with each. - [Quickstart](https://developers.inorbit.hr/docs/): From nothing to your first answer in a minute, then what every answer looks like. - [Limits](https://developers.inorbit.hr/docs/limits/): What bounds a call, a stream, a socket, a key and a webhook, and how a refusal looks. - [Monitor an endpoint](https://developers.inorbit.hr/docs/monitors/): Run an endpoint connection's check on a schedule, from our cloud or from your agent, keep the results for 90 days, and get an event when the target goes down and when it recovers. - [Paging, retries and errors](https://developers.inorbit.hr/docs/paging-retries-errors/): How every list pages, how to retry a write safely, the headers every answer carries, and the error envelope with its codes. - [API reference](https://developers.inorbit.hr/docs/reference/): Every route a token may call, with its parameters, its answer and an example in several languages. - [Generate an SDK for your account](https://developers.inorbit.hr/docs/sdk/): A client in Rust, TypeScript, Go, Python, C# or Java with exactly the operations your credentials may call, for one account or several, checked by the compiler and by a CI step when the API's cut moves. - [Status](https://developers.inorbit.hr/docs/status/): Whether InOrbit is up, for people and for programs. The status page, its answer and the API's health endpoints. - [MCP tools](https://developers.inorbit.hr/docs/transports/mcp-tools/): Every tool /mcp offers, what it needs and an example call, generated from the server's own list. - [MCP](https://developers.inorbit.hr/docs/transports/mcp/): The API as tools for an assistant, over the Model Context Protocol. - [MQTT](https://developers.inorbit.hr/docs/transports/mqtt/): MQTT 5 over a secure WebSocket, for events, every stream as a topic, and any call by publishing to it. - [REST](https://developers.inorbit.hr/docs/transports/rest/): A request and an answer, JSON both ways, on every route in the reference. - [Server-sent events](https://developers.inorbit.hr/docs/transports/sse/): A request that answers with a stream of events, on routes ending in /events. - [Webhooks](https://developers.inorbit.hr/docs/transports/webhooks/): The platform calls your HTTPS endpoint when something happens, with a signed event that carries ids, never content. - [WebSocket](https://developers.inorbit.hr/docs/transports/websocket/): One socket that carries any call by name, several at once, with the same JSON as REST. - [Usage and units](https://developers.inorbit.hr/docs/usage/): How a call is counted, what each category costs, the monthly allowance, and what happens when it runs out. ## Tools - [The agent](https://developers.inorbit.hr/docs/tools/agent/): iohr-agent, the data plane in your own network. Install it as an extension, with Helm or as a package, enroll it, declare its checks, and verify the release. - [The iohr command line](https://developers.inorbit.hr/docs/tools/cli/): Install iohr on Linux, macOS or Windows, check what you installed, and find every command. - [Connections](https://developers.inorbit.hr/docs/tools/connections/): Connect an account's incident, chat, code, enterprise and AI tools once, with a key or by signing in, and let products and keys act on them through a person's grant. - [Extensions](https://developers.inorbit.hr/docs/tools/extensions/): Programs that iohr installs from an OCI registry, verifies, pins and runs, without handing them your long-lived credentials. - [Developer tools](https://developers.inorbit.hr/docs/tools/): The iohr command line, the client libraries, extensions, the agent and connections, where to get each and what state it is in. - [SDKs](https://developers.inorbit.hr/docs/tools/sdks/): The client libraries for Rust, TypeScript, Python, Go, C# and Java, how to add each, and what they do the same in every language. ## API reference - [Get the caller](https://developers.inorbit.hr/docs/reference/identity/get-caller/): Who the gateway verified for this call: the subject, its kind (`client` for a key, `person` for a person), the scopes, and under `org` the account the call counts against. The first call to make with a new key. Needs scope `identity:read`. - [Get the account](https://developers.inorbit.hr/docs/reference/accounts/get-account/): The account the call counts against, with its plan; for a key, also the key's name and when it was last used. Needs scope `account:read`. - [Get what the account may use](https://developers.inorbit.hr/docs/reference/accounts/get-entitlements/): The account's plan and the features and extensions it includes, with the reason: the plan, or every feature for InOrbit's own accounts and platform admins. Members, the account's keys and tokens with `account:read` may read it; anyone else gets not found. Needs scope `account:read`. - [List audit log entries](https://developers.inorbit.hr/docs/reference/accounts/list-audit-events/): The account's audit log: who changed its members, roles, invitations, keys, tokens, name, plan, policy or deletion, and when, with the changed fields before and after. Newest first; with `after`, only newer entries, oldest first, which is how an `audit.event` webhook receiver fetches what it was told about. Needs a token given `account:audit`, and reads its own account. Needs scope `account:audit`. - [Get this month's units](https://developers.inorbit.hr/docs/reference/usage/get-units/): The account's units this month: the plan, the allowance, what was used by category, operation and key, and what remains. A key reads its own account. Needs scope `usage:read`. - [Get units per day](https://developers.inorbit.hr/docs/reference/usage/get-unit-series/): The account's calls, tokens and units per UTC day, split by who made them (a key, or a person on the sites), by category or by operation. The four largest groups are named and the rest are summed as `other`. Thirty days by default, 92 at most. Needs scope `usage:read`. - [List requests](https://developers.inorbit.hr/docs/reference/usage/list-requests/): Every call counted for the account in the last 30 days, newest first: when, which key or person, which operation, how it ended (ok, a client error or a platform error, with its code), how long it took, and its request id. Never what was sent or answered. Filter by status (ok, error, client, platform), a request id or key id, or part of an operation's name. Needs scope `usage:read`. - [Get usage by day](https://developers.inorbit.hr/docs/reference/usage/get-usage/): What the account used, by day, service and metric: the last 30 days unless `from` and `to` say otherwise, at most 366 days. A key reads its own account. Needs scope `usage:read`. - [List unit categories](https://developers.inorbit.hr/docs/reference/usage/list-unit-categories/): The categories and what one call in each costs, in units. Needs scope `usage:read`. - [List domains](https://developers.inorbit.hr/docs/reference/domains/list-domains/): The account's domains (RFC 0030): each with its scope, its status (`pending`, `seen`, `verified` or `unverified`), the TXT record that proves it and when it was last checked. Needs scope `domains:read`. - [Add a domain](https://developers.inorbit.hr/docs/reference/domains/add-domain/): Start proving a domain: `scope` is `domain` (the domain and every name under it) or `subdomain` (one name under a registered domain and what is under it). The answer carries `record_name` and `record_value`, the one TXT record to publish, and `dns_provider`, who serves the domain's DNS. The token works for seven days. Adding a domain the account already has pending answers it unchanged. Needs scope `domains:write`. - [Get a domain](https://developers.inorbit.hr/docs/reference/domains/get-domain/): One domain of the account, with its record and status. Needs scope `domains:read`. - [Remove a domain](https://developers.inorbit.hr/docs/reference/domains/remove-domain/): The domain stops counting for this account at once: single sign-on through it, agents bound to it and checks from our cloud at its names. The TXT record may be deleted afterwards. Needs scope `domains:write`. - [Check a domain's record](https://developers.inorbit.hr/docs/reference/domains/check-domain/): Looks the TXT record up now through several public resolvers in different networks and says what each answered. `status` is `pending` (none sees a record), `wrong_value` (a record with another value), `partial` (one resolver sees ours) or `seen` (two or more agree). Once `seen`, the domain may be confirmed. Needs scope `domains:write`. - [Confirm a domain](https://developers.inorbit.hr/docs/reference/domains/confirm-domain/): Checks once more and, when the record is seen, makes the domain `verified` for this account. A domain is verified for one account at a time: another account holding it loses it and receives `domain.transferred`. Needs scope `domains:write`. - [List webhook endpoints](https://developers.inorbit.hr/docs/reference/webhooks/list-webhook-endpoints/): The account's webhook endpoints, with their status and the last day's deliveries. Needs scope `webhooks:read`. - [Create a webhook endpoint](https://developers.inorbit.hr/docs/reference/webhooks/create-webhook-endpoint/): A public HTTPS address and the event types it wants, at least one. The answer carries the signing secret, shown this once. Needs scope `webhooks:write`. - [Get a webhook endpoint](https://developers.inorbit.hr/docs/reference/webhooks/get-webhook-endpoint/): One endpoint by id. Needs scope `webhooks:read`. - [Update a webhook endpoint](https://developers.inorbit.hr/docs/reference/webhooks/update-webhook-endpoint/): Change the address, the description or the event types, or enable and disable it. A field left out stays as it is. Needs scope `webhooks:write`. - [Delete a webhook endpoint](https://developers.inorbit.hr/docs/reference/webhooks/delete-webhook-endpoint/): Deletes the endpoint and its delivery history. Deliveries still waiting are dropped. Needs scope `webhooks:write`. - [Rotate the signing secret](https://developers.inorbit.hr/docs/reference/webhooks/rotate-webhook-secret/): A new signing secret, shown this once. The old one keeps signing alongside it for a day, so you can switch without missing a delivery. Needs scope `webhooks:write`. - [Send a test event](https://developers.inorbit.hr/docs/reference/webhooks/send-test-event/): Delivers a `webhook.test` event to the endpoint now, signed like any other. Needs scope `webhooks:write`. - [List deliveries](https://developers.inorbit.hr/docs/reference/webhooks/list-webhook-deliveries/): Every delivery to one endpoint, newest first: attempts, status code, time taken and the next retry. Needs scope `webhooks:read`. - [Retry a delivery](https://developers.inorbit.hr/docs/reference/webhooks/retry-webhook-delivery/): Sends a failed delivery again now, with the same event id. Needs scope `webhooks:write`. - [Recover an endpoint](https://developers.inorbit.hr/docs/reference/webhooks/recover-webhook-endpoint/): Sends again what the endpoint missed since a time: every delivery that failed for good, and every event of its types that was never sent to it (while it was turned off), oldest first, 10,000 a call. `truncated` says to call again with the same `since`. Needs scope `webhooks:write`. - [Get delivery stats](https://developers.inorbit.hr/docs/reference/webhooks/get-webhook-stats/): How your webhook deliveries went, for every endpoint or one: succeeded and failed per hour or day, your server's answer time (p50 and p95), the failures grouped by error and HTTP status, and counts per event type. Needs scope `webhooks:read`. - [List test inboxes](https://developers.inorbit.hr/docs/reference/inboxes/list-webhook-inboxes/): The account's test inbox, when it has one: its id, its address and when it expires. Needs scope `webhooks:read`. - [Create a test inbox](https://developers.inorbit.hr/docs/reference/inboxes/create-webhook-inbox/): An address on the API that keeps the last 50 requests posted to it for 24 hours, for trying webhooks without a server. One per account: if there is one, this answers it. Needs scope `webhooks:write`. - [List inbox requests](https://developers.inorbit.hr/docs/reference/inboxes/list-inbox-requests/): What the test inbox received, newest first: the webhook headers, the body, and whether the signature matched the secret of the endpoint that points at it. Needs scope `webhooks:read`. - [Delete a test inbox](https://developers.inorbit.hr/docs/reference/inboxes/delete-webhook-inbox/): Deletes the inbox and everything it received. Posts to its address then answer 404. Needs scope `webhooks:write`. - [List event types](https://developers.inorbit.hr/docs/reference/events/list-event-types/): The event catalogue: every type you can receive, with the JSON Schema of its `data`. Needs scope `events:read`. - [Stream events](https://developers.inorbit.hr/docs/reference/events/stream-events/): Your account's events as they happen, as server-sent events. The same events a webhook receives, carrying ids and never content. Needs scope `events:read`. - [Get events per day](https://developers.inorbit.hr/docs/reference/events/get-event-stats/): How many events of each type your account published per UTC day, over the last 7 or 30 days. Needs scope `events:read`. - [List notifications](https://developers.inorbit.hr/docs/reference/events/list-notifications/): The account's notable events, newest first: units near the allowance, a health alert, a webhook endpoint turned off, a member who joined or left, a revoked key or token, a domain that lost its proof, a revoked agent, a deleted connection. Each says whether you have read it, and `unread` counts the rest (at most 99). Needs scope `events:read`. - [List agents](https://developers.inorbit.hr/docs/reference/agents/list-agents/): The account's agents, newest first: each one's environment, the verified domains it is bound to, whether it is online, offline or revoked, the version it reported and when it was last heard from. Paged with `page_size` (0 means 50, at most 200) and `next_page_token`. Needs scope `agents:read`. - [Get an agent](https://developers.inorbit.hr/docs/reference/agents/get-agent/): One agent by id. Needs scope `agents:read`. - [Delete an agent](https://developers.inorbit.hr/docs/reference/agents/delete-agent/): Revokes the agent if it is not already, then takes it off the list. Needs scope `agents:write`. - [Create an agent enrollment](https://developers.inorbit.hr/docs/reference/agents/create-agent-enrollment/): A one-time token (`ioe_…`) that enrolls one agent for an environment and the account's verified domains, within the hour. The token is in this answer only; the platform keeps its hash. Every domain must be verified for the account. Needs scope `agents:write`. - [Revoke an agent](https://developers.inorbit.hr/docs/reference/agents/revoke-agent/): Cuts the agent off: its session closes within seconds and its identity is deleted, so it cannot connect again. It stays in the list as revoked. Needs scope `agents:write`. - [Run a check through an agent](https://developers.inorbit.hr/docs/reference/agents/run-agent-check/): Sends one check to an online agent and waits up to 30 seconds for its result: `ok`, `failed` or `refused` by the agent's local policy, with the latency, the HTTP status and an error class, never a body. A named host must be inside the agent's verified domains; a private address or an internal name goes to the agent, whose policy decides. `auth` is a reference the agent resolves in your secret store (`vault:`, `k8s:`, `env:`, `file:`), never a secret. Needs scope `agents:write`. - [List spaces](https://developers.inorbit.hr/docs/reference/decisions/list-spaces/): The account's spaces, newest first: one per system, each with its documents' counts by status and when it last changed. `query` matches the name. Paged with `page_size` and `next_page_token`. Needs scope `decisions:read`. - [Create a space](https://developers.inorbit.hr/docs/reference/decisions/create-space/): A new space in your account or a team you are a member of. Numbers run per kind across all the account's spaces. Needs scope `decisions:write`. - [Get a space](https://developers.inorbit.hr/docs/reference/decisions/get-space/): One space: its name, description, slug and counts. A space you cannot see answers 404, the same as one that does not exist. Needs scope `decisions:read`. - [Update a space](https://developers.inorbit.hr/docs/reference/decisions/update-space/): Rename a space or change its description. Owners and admins of the account only. Needs scope `decisions:write`. - [Delete a space](https://developers.inorbit.hr/docs/reference/decisions/delete-space/): Delete a space with every document, version, comment, review and diagram in it. Owners and admins only; it cannot be undone, so export it first. Needs scope `decisions:write`. - [Get a space's settings](https://developers.inorbit.hr/docs/reference/decisions/get-space-settings/): The redaction rules the checks apply to its public documents (domains, words, patterns) and how many approvals a decision needs. Needs scope `decisions:read`. - [Update a space's settings](https://developers.inorbit.hr/docs/reference/decisions/update-space-settings/): Replace the redaction rules and the approvals a decision needs. Owners and admins only. Needs scope `decisions:write`. - [List documents](https://developers.inorbit.hr/docs/reference/decisions/list-documents/): The space's RFCs, studies, PRDs and ADRs, newest change first, each with its number, title, status and the checks' findings on its current version. Filter by `status` and `types` (`rfc`, `study`, `prd`, `adr`); `query` matches number, title and summary. Needs scope `decisions:read`. - [Create a document](https://developers.inorbit.hr/docs/reference/decisions/create-document/): A new RFC, study, PRD (product intent) or ADR (one decision record) from a template, with the next free number of its kind in the account. Sub-RFCs name their parent and get the next part number under it. Needs scope `decisions:write`. - [Get a document](https://developers.inorbit.hr/docs/reference/decisions/get-document/): A document's text at its current version, or at `version`, with its front matter, findings, mentions and backlinks. Needs scope `decisions:read`. - [List versions](https://developers.inorbit.hr/docs/reference/decisions/list-versions/): Every version of a document, newest first: who saved it, when, the message and the lines added and removed. Needs scope `decisions:read`. - [Save a version](https://developers.inorbit.hr/docs/reference/decisions/save-document/): Save new text as the next version with a message. Send the version you started from: if someone saved after it, the answer is 409 and nothing is overwritten. The checks run on every save and their findings come back. Needs scope `decisions:write`. - [Set a document's status](https://developers.inorbit.hr/docs/reference/decisions/set-document-status/): Mark a document open, decided or superseded. Decided needs the space's approvals on the current version; superseded names the document that replaces it. Needs scope `decisions:write`. - [Set who reads a document](https://developers.inorbit.hr/docs/reference/decisions/set-document-access/): One of `public`, `preview`, `partner`, `team` or `internal`; the space's owners and admins only. Public needs the redaction check to find nothing in the current version, else 412 names each finding's rule and line. Preview and partner are for InOrbit's own spaces. Needs scope `decisions:write`. - [Append a status-log line](https://developers.inorbit.hr/docs/reference/decisions/append-status-line/): Add one dated line at the end of a document's `## Status log` without sending its text: a new version on top of the current one, so a save in between is kept. Without `base_version` it never conflicts. One line of 1 to 2000 characters; the date `YYYY-MM-DD`, today (UTC) when empty. On a public document the line must pass the redaction check, else 412 names the rule and line. Needs scope `decisions:write`. - [Set a document's stage](https://developers.inorbit.hr/docs/reference/decisions/set-document-stage/): Where the work stands: `proposed`, `building`, `in_review`, `partly_live`, `live` or `abandoned`. The reason is appended to the status log in the same new version. `partly_live` and `live` need merged pull requests recorded on the document, and are refused until those are. Needs scope `decisions:write`. - [Set where a document is kept](https://developers.inorbit.hr/docs/reference/decisions/set-document-source/): `product` (edited here; an import from a repository leaves it alone) or `repository` (a file is the source and the import updates it). The space's owners and admins move a document to the product; back to the repository is for InOrbit's admins. Needs scope `decisions:write`. - [Mark a document outward-facing](https://developers.inorbit.hr/docs/reference/decisions/set-document-outward/): Whether the document's scope faces outward: a public page, a price, a repository's visibility, a public access level, a message to customers. Such a document is accepted only with the owner's own approval. Writers mark it; only the owner clears it. Needs scope `decisions:write`. - [List the timeline](https://developers.inorbit.hr/docs/reference/decisions/list-timeline/): The status log lines of a space's documents, newest first, or of one document with `document_id`, between `from` and `to`. Needs scope `decisions:read`. - [List comments](https://developers.inorbit.hr/docs/reference/decisions/list-comments/): A document's comment threads, each anchored to a section, with replies. `status` is `open` or `resolved`. Needs scope `decisions:read`. - [Add a comment](https://developers.inorbit.hr/docs/reference/decisions/add-comment/): A comment on a section of the current version, or a reply to a thread. Needs scope `decisions:write`. - [Resolve a comment](https://developers.inorbit.hr/docs/reference/decisions/resolve-comment/): Resolve or reopen a thread. Needs scope `decisions:write`. - [List reviews](https://developers.inorbit.hr/docs/reference/decisions/list-reviews/): A document's review requests and decisions, each tied to the version it was made on. Needs scope `decisions:read`. - [Request a review](https://developers.inorbit.hr/docs/reference/decisions/request-review/): Ask named members to review the current version. Needs scope `decisions:write`. - [Submit a review](https://developers.inorbit.hr/docs/reference/decisions/submit-review/): Approve the current version or ask for changes, as one of the requested reviewers. Needs scope `decisions:write`. - [List your review queue](https://developers.inorbit.hr/docs/reference/decisions/list-review-queue/): Reviews waiting for you across the account's spaces, or the ones you asked of others with `status=asked`. Needs scope `decisions:read`. - [What waits on you](https://developers.inorbit.hr/docs/reference/decisions/get-waiting/): Everything waiting on you across the account's spaces, oldest first: reviews asked of you, documents you are to decide, and open questions asked of you (or of the owners and admins, when you are one), each with what settling it unblocks. Needs scope `decisions:read`. - [List a space's questions](https://developers.inorbit.hr/docs/reference/decisions/list-questions/): The questions asked in a space, newest first, with their answers. Needs scope `decisions:read`. - [Ask a person](https://developers.inorbit.hr/docs/reference/decisions/ask-question/): Ask a person to settle something in a space, with what the answer unblocks. It waits on their list until a person answers it. Needs scope `decisions:write`. - [Answer a question](https://developers.inorbit.hr/docs/reference/decisions/answer-question/): Answer an open question: the person asked, or an owner or an admin of the account. A person only, never an assistant. Needs scope `decisions:write`. - [Search diagrams](https://developers.inorbit.hr/docs/reference/decisions/search-diagrams/): Diagrams across the account's spaces, newest change first, with the documents that embed each counted; or, with `space_id` and `document_id`, the diagrams one document embeds in its order. Needs scope `decisions:read`. - [List diagrams](https://developers.inorbit.hr/docs/reference/decisions/list-diagrams/): The space's architecture diagrams, newest change first. Needs scope `decisions:read`. - [Create a diagram](https://developers.inorbit.hr/docs/reference/decisions/create-diagram/): A new, empty diagram in the space. Needs scope `decisions:write`. - [Get a diagram](https://developers.inorbit.hr/docs/reference/decisions/get-diagram/): A diagram's model (elements, links, boundaries) at its current version or at `version`. Needs scope `decisions:read`. - [Rename a diagram](https://developers.inorbit.hr/docs/reference/decisions/update-diagram/): Change a diagram's name. Needs scope `decisions:write`. - [Delete a diagram](https://developers.inorbit.hr/docs/reference/decisions/delete-diagram/): Delete a diagram and its versions. Owners and admins only. Needs scope `decisions:write`. - [List a diagram's versions](https://developers.inorbit.hr/docs/reference/decisions/list-diagram-versions/): Who saved each version of a diagram, when and why, newest first. Draw one with Get a diagram's `version` and `svg`. Needs scope `decisions:read`. - [Save a diagram](https://developers.inorbit.hr/docs/reference/decisions/save-diagram/): Save the model as the next version; a stale base version is 409, as for documents. Needs scope `decisions:write`. - [Export a space](https://developers.inorbit.hr/docs/reference/decisions/export-space/): Every document as Markdown in the RFC format and every diagram as JSON, a page at a time; follow `next_page_token` to the end. Needs scope `decisions:read`. - [List public documents](https://developers.inorbit.hr/docs/reference/decisions/list-public-documents/): Documents you may read without belonging to their space: with no token, the public ones; signed in, also what your role allows. Last changed first. Needs scope `decisions:read`. - [Get a public document](https://developers.inorbit.hr/docs/reference/decisions/get-public-document/): One document by its space, kind and number, with no token when it is public. Anything you may not read is 404. Needs scope `decisions:read`. - [Get a public diagram](https://developers.inorbit.hr/docs/reference/decisions/get-public-diagram/): A diagram that a document you may read embeds, with no token when that document is public. Needs scope `decisions:read`. - [List corrections](https://developers.inorbit.hr/docs/reference/corrections/list-corrections/): An account's corrections, newest first. Needs scope `decisions:read`. - [Record a correction](https://developers.inorbit.hr/docs/reference/corrections/record-correction/): Record a correction of an AI agent: when a person corrected it, or when the agent noticed on its own that it drifted from the plan. A rule already adopted makes it a recurrence of the earlier correction. Needs scope `decisions:write`. - [An agent's rules](https://developers.inorbit.hr/docs/reference/corrections/get-correction-rules/): The briefing an agent reads when a session starts: the adopted rules for that agent first, then every agent's, each with how often it was broken again, and the newest open corrections. Needs scope `decisions:read`. - [Update a correction](https://developers.inorbit.hr/docs/reference/corrections/update-correction/): Change a correction's status or its rule's wording. An assistant may adopt a rule or mark it recurred; only a person verifies. Needs scope `decisions:write`. - [Delete a correction](https://developers.inorbit.hr/docs/reference/corrections/delete-correction/): An owner or an admin of the account, a person, never an assistant. Needs scope `decisions:write`. - [List connection kinds](https://developers.inorbit.hr/docs/reference/connections/list-connection-kinds/): What a connection can be (RFC 0018): each kind's authentication, configuration fields and actions, with every action's class (`read`, `write_reversible`, `write_irreversible`), its typed parameters and their JSON Schema. Needs scope `connections:read`. - [List connectors](https://developers.inorbit.hr/docs/reference/connections/list-connectors/): The connector catalogue (RFC 0044): every app a connection can be made from, with its category, auth modes and the fields each asks for (secret ones are sealed and never answered), its settings, its actions with their class and parameters, the hosts it may call, and whether it is `available`, `coming_soon` or `needs_app` (it signs in and this platform has no OAuth app for it yet). `kind` is `connector`, or `client` for an AI assistant that uses InOrbit over MCP (its `setup` says how); `ai` marks an AI model provider (bring your own key). Needs scope `connections:read`. - [Get a connector](https://developers.inorbit.hr/docs/reference/connections/get-connector/): One connector of the catalogue, by its id (`incident-io`, `pagerduty`, `datadog`, `grafana`, `discord`, ...). Needs scope `connections:read`. - [List connections](https://developers.inorbit.hr/docs/reference/connections/list-connections/): The account's connections, newest first: kind, executor (`cloud` or an agent), configuration, what kind of credential it holds (never the credential), status, last test and live grants. Needs scope `connections:read`. - [Create a connection](https://developers.inorbit.hr/docs/reference/connections/create-connection/): Add a connection. An `endpoint` on our cloud takes its key in `secret`, sealed in the vault and never answered; on an agent it takes `secret_ref` (`vault:`, `k8s:`, `env:` or `file:`), which we never resolve. A `webhook-in` answers its signing secret once, in `webhook_secret`, and its `receive_url`. Our cloud calls only hosts inside a verified domain of the account. A connector's id as `kind` (List connectors) takes `auth_mode`, `credentials` (its fields, sealed, never answered) and `config`; its test request runs first, a refused key stores nothing, and `label` names the account at the provider. Needs scope `connections:write`. - [Start signing in to a provider](https://developers.inorbit.hr/docs/reference/connections/start-connect/): Connect an account by signing in at the provider (OAuth 2.0, RFC 0044): makes a single-use sign-in for you, valid ten minutes, with its own state and PKCE verifier, and answers `authorize_url` to open in a browser, `session_id` and `expires_at`. The provider sends you back to the console's `/connections/callback/` page, which completes it. `scopes` adds any of the mode's `optional_scopes`; `config` holds settings needed before signing in; `connection_id` reconnects that connection. A connector whose OAuth app is not set up on this platform is `needs_app` and refused. Needs scope `connections:write`. - [Complete a sign-in](https://developers.inorbit.hr/docs/reference/connections/complete-connect/): Called by the console's callback page as the person who started the sign-in, with the `state` and `code` the provider sent back (or its `error`). Exchanges the code with the PKCE verifier, seals the tokens (never answered), runs the connector's test and answers the connection with its `label`, granted `scopes`, `token_expires_at` and `external_id`. A workspace the account already connected is updated, not connected twice. The state works once. Needs scope `connections:write`. - [Get a sign-in](https://developers.inorbit.hr/docs/reference/connections/get-connect-session/): Where a sign-in stands, for a command line waiting on the browser: `pending`, `completed` (with the connection), `failed` (with why) or `expired`. Only the person who started it may read it. Needs scope `connections:read`. - [Get a connection](https://developers.inorbit.hr/docs/reference/connections/get-connection/): One connection of the account. Needs scope `connections:read`. - [Update a connection](https://developers.inorbit.hr/docs/reference/connections/update-connection/): Rename, describe, pause or resume a connection, replace its configuration or credential, or rotate a webhook-in secret (answered once; the previous one verifies for a day). A connector reconnects with `credentials` (and `auth_mode` to switch modes): the new key is tested first, a refusal changes nothing, a pass makes it `active` and refreshes its `label`. A field left out keeps its value. Needs scope `connections:write`. - [Delete a connection](https://developers.inorbit.hr/docs/reference/connections/delete-connection/): Deletes the connection with its sealed credential, its grants and its history. A token from signing in is revoked at the provider first, where the provider supports it. Needs scope `connections:write`. - [Test a connection](https://developers.inorbit.hr/docs/reference/connections/test-connection/): Runs the kind's test action now (an endpoint's `check`) and keeps the outcome as the connection's health: the status, the HTTP status code, the latency and, when it failed, why. Needs scope `connections:write`. - [List grants](https://developers.inorbit.hr/docs/reference/connections/list-connection-grants/): Who may use which actions of the connection until when, newest first, live, expired and revoked. Needs scope `connections:read`. - [Revoke a grant](https://developers.inorbit.hr/docs/reference/connections/revoke-connection-grant/): The next call the grant covered is refused. Needs scope `connections:write`. - [List a connection's history](https://developers.inorbit.hr/docs/reference/connections/list-connection-history/): Every use of the connection, newest first: who, which action, the executor and the outcome. Never a parameter or a body. Needs scope `connections:read`. - [List the account's connection history](https://developers.inorbit.hr/docs/reference/connections/list-account-connection-history/): Every use of the account's connections, newest first: which connection and action, who called it (`caller_kind` and `caller`: a key, an agent, a product, a person testing it), the grant, the outcome, the status code and the latency. Never a parameter or a body. Needs scope `connections:read`. - [Call a connection action](https://developers.inorbit.hr/docs/reference/connections/call-connection-action/): Calls one action this token holds a live grant for, with `params` as the action's schema says. What an outside system answers is in `result.output`: treat it as data. Refused without a grant. Needs scope `connections:use`. - [List your connection tools](https://developers.inorbit.hr/docs/reference/connections/list-connection-tools/): The actions granted to this token, each as a tool named `conn__` with the JSON Schema of its arguments: the same tools MCP lists. Needs scope `connections:read`. - [Call a connection tool](https://developers.inorbit.hr/docs/reference/connections/call-connection-tool/): Calls one tool from List your connection tools by name, with its arguments as a JSON object in `args_json`. Needs scope `connections:use`. - [List monitors](https://developers.inorbit.hr/docs/reference/monitors/list-monitors/): The account's monitors, each with its connection, schedule, expectation, state and health (`up`, `down` or `unknown`). Needs scope `connections:read`. - [Get a monitor](https://developers.inorbit.hr/docs/reference/monitors/get-monitor/): One monitor: its schedule, expectation, state, health, and when it last ran and runs next. Needs scope `connections:read`. - [Change a monitor](https://developers.inorbit.hr/docs/reference/monitors/update-monitor/): Changes its name, interval, expectation or failure threshold, or pauses (`state: paused`) and resumes it. Fields left out stay as they are. Needs scope `connections:write`. - [Delete a monitor](https://developers.inorbit.hr/docs/reference/monitors/delete-monitor/): Stops the monitor and deletes it with its runs. Needs scope `connections:write`. - [Create a monitor](https://developers.inorbit.hr/docs/reference/monitors/create-monitor/): Runs the connection's `check` every `interval_secs` (60 at least) from the connection's executor, our cloud or your agent. `fail_after` failures in a row (1 to 5, 2 when 0) make it `down`. Needs scope `connections:write`. - [List a monitor's runs](https://developers.inorbit.hr/docs/reference/monitors/list-monitor-runs/): Every run, newest first: when, the outcome, the latency, the status code and the class of error. Never a body. Runs are kept 90 days. Needs scope `connections:read`. - [Get a monitor's summary](https://developers.inorbit.hr/docs/reference/monitors/get-monitor-summary/): Health and since when, uptime over 24 hours, 7 days and 30 days as fractions from 0 to 1, the median and 95th percentile latency, and the last failure. Needs scope `connections:read`. - [Get a monitor's series](https://developers.inorbit.hr/docs/reference/monitors/get-monitor-series/): A range of a monitor's runs in equal buckets, read on the server: runs, passes, failures, uptime and the median, 95th and 99th percentile latency per bucket and over the range, and the failures by class. At most 500 buckets, within the 90 days runs are kept. Needs scope `connections:read`. - [Search extensions](https://developers.inorbit.hr/docs/reference/extensions/list-extensions/): The extensions catalogue (RFC 0073) the account may see, by publisher and name: InOrbit's own, the account's private listings, and public ones. Each listing has its kind, the publisher's description in the publisher's words, and its latest version. Another account's private listing never appears. Needs scope `extensions:read`. - [Get an extension](https://developers.inorbit.hr/docs/reference/extensions/get-extension/): One listing with its latest version: the OCI digest `iohr-ext.lock` pins, the API scopes it may ask for, the Linux capabilities its system service needs, its evidence (none yet until verification runs exist) and the `iohr ext install` command. 404 when the account may not see it. Needs scope `extensions:read`. - [List an extension's versions](https://developers.inorbit.hr/docs/reference/extensions/list-extension-versions/): A listing's versions, newest first, each with its digest, platforms, scopes, privileges, signer and evidence. Needs scope `extensions:read`. - [Get a publisher](https://developers.inorbit.hr/docs/reference/extensions/get-extension-publisher/): A publisher's namespace, name, proved domain and whether it is InOrbit, with how many of its listings the account may see. Needs scope `extensions:read`. - [List recordings](https://developers.inorbit.hr/docs/reference/trails/list-recordings/): The account's trail recordings (RFC 0055), newest first, without their events: each one's site, client, when it started and was kept, how many events it holds and how many were dropped by the client or by the service. Admins only until trails open. Needs scope `trail:read`. - [Upload a recording](https://developers.inorbit.hr/docs/reference/trails/upload-recording/): Keep one recording in the account: the site's host, the client (`extension` or `script`), when it started, the client's drop count and 1 to 5000 events, at most 256 KiB. The service checks every event against the kinds and fields the recorder sends and drops the rest, counted in `rejected`; names and messages are scrubbed again. 500 uploads per account per day; kept 90 days. Needs scope `trail:write`. - [Get a recording](https://developers.inorbit.hr/docs/reference/trails/get-recording/): One recording with its events, each `{k, t, ...fields}`: pages, clicks with a role, a name and a selector, scroll depth, focus and visibility, timings and the Core Web Vitals, long tasks, scrubbed errors, rage and dead clicks. Never anything typed. Needs scope `trail:read`. - [Delete a recording](https://developers.inorbit.hr/docs/reference/trails/delete-recording/): The recording and its events are deleted at once. Needs scope `trail:write`. - [List digests](https://developers.inorbit.hr/docs/reference/radar/list-digests/): Published Radar digests, newest week first. Needs scope `radar:read`. - [Get a digest](https://developers.inorbit.hr/docs/reference/radar/get-digest/): One published digest by id. Needs scope `radar:read`. - [List items](https://developers.inorbit.hr/docs/reference/radar/list-items/): The items Radar has read, newest first: the raw material of a digest. Needs scope `radar:read`.