Admin
18 operations. All areas
- POST /v1/companies
- GET /v1/operator/companies/{id}/plan
- POST /v1/operator/companies/{id}/plan
- GET /v1/company
- GET /v1/me
- POST /v1/company/kill-switch
- POST /v1/users
- GET /v1/users
- POST /v1/agents
- GET /v1/agents
- POST /v1/agents/{id}/revoke
- POST /v1/keys
- GET /v1/keys
- GET /v1/keys/{id}
- POST /v1/keys/{id}/rotate
- POST /v1/owner-invites/claim
- POST /v1/keys/{id}/revoke
- POST /v1/company/fiscal-year
POST/v1/companies
Create a company (tenant) with its owner user and owner API key. Operator bootstrap token required.
- Operation
createCompany - Scope: operator token
- Write: needs Idempotency-Key (or dry_run)
- Request body
namestring, requiredowner_namestring, requiredplan"solo" | "business" | "advanced" | "owned" ADR-0009 plan; sets the API rate limit (Solo 60, Business 300, Advanced 1,200 requests/min; Owned: the operator's setting).starter_chart"general" | "services" | "retail" | "empty" Starter chart of accounts: general small business (default), services/agency, retail/product, or empty (migrations bring their own chart).periodsboolean Create this fiscal year's and the next one's monthly periods (default true; false for a custom calendar)
- Responses
201Created, with the starter chart applied and this fiscal year's and the next one's monthly periods (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
GET/v1/operator/companies/{id}/plan
A company's plan (ADR-0009) and the API rate limit it gives. Operator token only.
- Operation
getCompanyPlan - Scope: operator token
- Read
- Parameters
idpath, string, required
- Responses
200Plan (object)- Errors
400,401,403,404,429,500(Error:error.type,message)
POST/v1/operator/companies/{id}/plan
Set a company's plan (ADR-0009); its keys' and agents' rate limits follow on the next request. Audited in the company's log as the operator. Operator token only.
- Operation
setCompanyPlan - Scope: operator token
- Write: sets a value, no Idempotency-Key needed
- Parameters
idpath, string, required
- Request body
plan"solo" | "business" | "advanced" | "owned", required ADR-0009 plan; sets the API rate limit (Solo 60, Business 300, Advanced 1,200 requests/min; Owned: the operator's setting).reasonstring, required
- Responses
200Plan set (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)
GET/v1/company
The caller's company
- Operation
getCompany - Scope: read
- Read
- Responses
200Company (object)- Errors
400,401,403,429,500(Error:error.type,message)
GET/v1/me
Who the caller is: principal type, name, role, scopes, company
- Operation
getMe - Scope: read
- Read
- Responses
200Caller (object)- Errors
400,401,403,429,500(Error:error.type,message)
POST/v1/company/kill-switch
Suspend or resume ALL agent writes for this company
- Operation
setKillSwitch - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
suspendedboolean, requiredreasonstring, required
- Responses
200Updated (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
POST/v1/users
Create a human user
- Operation
createUser - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
namestring, requiredrole"owner" | "cpa" | "accountant" | "staff", required
- Responses
201Created (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
GET/v1/users
People in this company (names for the audit view)
- Operation
listUsers - Scope: read
- Read
- Responses
200Users (object)- Errors
400,401,403,429,500(Error:error.type,message)
POST/v1/agents
Register an agent with scopes and a posting threshold
- Operation
createAgent - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
namestring, requiredscopesarray of "read" | "propose" | "approve" | "admin", requiredposting_threshold_centsinteger, required Integer cents (100 = $1.00). Never a float.owner_user_idstring
- Responses
201Created (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
GET/v1/agents
Registered agents with scopes, thresholds and revocation
- Operation
listAgents - Scope: read
- Read
- Responses
200Agents (object)- Errors
400,401,403,429,500(Error:error.type,message)
POST/v1/agents/{id}/revoke
Revoke an agent; all its keys stop working on the next request
- Operation
revokeAgent - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Parameters
idpath, string, required
- Request body
reasonstring, required
- Responses
200Revoked (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)
POST/v1/keys
Mint an API key for a user or agent (secret returned once, stored hashed). Keys expire: people's after 365 days, agents' after 30 days by default (at most 90).
- Operation
createKey - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
principal_type"user" | "agent", requireduser_idstringagent_idstringscopesarray of "read" | "propose" | "approve" | "admin", requiredexpires_in_daysinteger Lifetime in days. Default: 365 for a person's key, 30 for an agent's (at most 90).rate_limit_rpminteger | null This key's own rate budget in requests per minute (null: the company plan's limit).
- Responses
201Created (NewApiKey)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
GET/v1/keys
API keys (never secrets): expiry, last use, rate budget, rotation, status. Admins see the company's keys; others their own.
- Operation
listKeys - Scope: read
- Read
- Parameters
include_endedquery, booleanuser_idquery, stringagent_idquery, string
- Responses
200Keys (object)- Errors
400,401,403,429,500(Error:error.type,message)
GET/v1/keys/{id}
One API key (admins: any in the company; others: their own)
- Operation
getKey - Scope: read
- Read
- Parameters
idpath, string, required
- Responses
200Key (object)- Errors
400,401,403,404,429,500(Error:error.type,message)
POST/v1/keys/{id}/rotate
Rotate a live key (the company's admins, or the key's own holder: an agent can rotate the key it calls with). The successor has the same principal and scopes and a fresh lifetime; the old key keeps working for the overlap window (default 24 h, at most 7 days, 0 = at once). The new secret is returned once.
- Operation
rotateKey - Scope: read
- Write: needs Idempotency-Key (or dry_run)
- Parameters
idpath, string, required
- Request body
overlap_secondsintegerexpires_in_daysinteger Lifetime in days. Default: 365 for a person's key, 30 for an agent's (at most 90).rate_limit_rpminteger | null Change the budget (the company's admins only); omitted: unchanged.reasonstring
- Responses
201Rotated (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)
POST/v1/owner-invites/claim
The owner claims a company an accounting firm created: send the invitation (ebi_...) as the Bearer token. Returns the owner's key once; the firm never sees it. Single use; void after 14 days or once the company revokes the firm's access.
- Operation
claimOwnerInvite - Scope: owner invitation
- Write: needs Idempotency-Key (or dry_run)
- Request body
expires_in_daysinteger Lifetime in days. Default: 365 for a person's key, 30 for an agent's (at most 90).
- Responses
201Claimed (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
POST/v1/keys/{id}/revoke
Revoke one API key, effective on the next request
- Operation
revokeKey - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Parameters
idpath, string, required
- Request body
reasonstring, required
- Responses
200Revoked (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)
POST/v1/company/fiscal-year
Set the fiscal year start month (refused while any period is hard-locked). Applies to reports, year-to-date and fiscal-year period locks.
- Operation
setFiscalYear - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
start_monthinteger, requiredreasonstring
- Responses
200Updated (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)