| GET |
/health |
Anonymous |
Deployment liveness only. |
| GET |
/gateway/v1/config |
Anonymous |
Publish the non-secret Cognito issuer, client id, and enrollment mode. |
| WS |
/gateway/v1/hosts/connect?hostId=…&installationId=… |
Machine account bearer |
Keep one authenticated outbound connection from a Clankie machine. |
| POST |
/gateway/v1/push/registrations |
Encrypted device proof verified by its machine, plus the app’s delivery key |
Register or move versioned APNs delivery when push is configured. |
| POST |
/gateway/v1/push/registrations/clear |
App delivery key; first allocation also requires an encrypted device proof |
Revoke delivery, including when the former machine is offline. |
| POST |
/h/{hostId}/v1/activity/viewer |
Fleet-signed Activity media permit with current audience authorization |
Read the scoped hosted Activity stream while its live audience remains authorized. |
| GET |
/v1/composer/transcription/status (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Read composer transcription availability and included recording allowance. |
| POST |
/v1/composer/transcription/begin (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Begin a bounded, device-scoped composer recording. |
| POST |
/v1/composer/transcription/chunk (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Append a bounded recording chunk at an exact byte offset. |
| POST |
/v1/composer/transcription/commit (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Request one transcription for an editable draft; sending stays explicit. |
| POST |
/v1/composer/transcription/cancel (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Discard that recording and prevent late draft delivery. |
| POST |
/v1/composer/transcription/receipt (inside encrypted exchange) |
Active ordinary paired device bearer with chat access; encrypted exchange only |
Recover the same draft receipt without repeating provider dispatch. |
| GET |
/v1/devices/self/diagnostics-default (inside encrypted exchange) |
Operator or paired device bearer |
Read the account's diagnostics default the device inherits; no other settings. |
| GET |
/v1/captain/readiness (inside encrypted exchange) |
Operator or paired device bearer |
Say whether Clankie can answer and, if not, the secret-free setup reason. |
| POST |
/v1/hosted/operator (inside encrypted exchange) |
Encrypted live device bearer with account-paired operator authority |
Run a bounded operator request on the hosted body; device revocation and inner route validation remain authoritative. |
| POST |
/h/{hostId}/v1/discord/ingress |
Fleet-signed scoped permit and P-256 encrypted request and response |
A trusted Discord connection delivers a sealed addressed turn |
| GET |
/v1/model-keys (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Read the supported model catalog, Clankie model selection and stored-key status, never keys. |
| POST |
/v1/model-keys/set (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Store or replace a provider API key in the body credential broker. |
| POST |
/v1/model-keys/validate (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Check a stored provider key with a bounded provider request; return only a success or error code. |
| POST |
/v1/model-keys/select (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Choose Clankie’s model for its next turn using the shared CLI config. |
| POST |
/v1/model-keys/remove (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Remove a stored provider API key without exposing it. |
| GET |
/v1/model-keys/subscriptions (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Name the providers signed in through an account (OAuth or subscription), without token details. |
| GET |
/v1/model-keys/subscriptions/methods (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
List sign-in methods allowed by the body's provider policy. |
| POST |
/v1/model-keys/subscriptions/start (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Start a provider sign-in for this device and its chosen catalog model. |
| POST |
/v1/model-keys/subscriptions/status (inside encrypted exchange) |
Encrypted initiating device bearer with terminalControl (Take Control) |
Read this device's transient browser URL/code or sign-in outcome. |
| POST |
/v1/model-keys/subscriptions/cancel (inside encrypted exchange) |
Encrypted initiating device bearer with terminalControl (Take Control) |
Cancel a pending sign-in before its credential write is admitted. |
| GET |
/v1/model-keys/options (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Name the providers that can serve a turn now and the running model's reasoning effort, without credentials. |
| POST |
/v1/model-keys/effort (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Set or clear the running model's reasoning effort using the shared CLI config. |
| GET |
/v1/accounts (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Read the body-owned GitHub, Linear and Google catalog with account, grants and recovery status, never tokens. |
| POST |
/v1/accounts/github/start (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Start a GitHub device flow on the body; return the user code and verification URL. |
| POST |
/v1/accounts/github/poll (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Poll a pending GitHub device flow; the body stores the token in its credential broker. |
| POST |
/v1/accounts/linear/start (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Start a Linear OAuth PKCE flow; the verifier stays on the body. |
| POST |
/v1/accounts/linear/complete (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Hand the Linear authorization code to the body, which exchanges it with its verifier. |
| POST |
/v1/accounts/linear/app (inside encrypted exchange) |
Encrypted device bearer with terminal-control access |
Verify and connect a workspace-owned Linear app; client credentials stay on the host. |
| POST |
/v1/accounts/disconnect (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Disable local account access and attempt provider revocation; Google disconnect disables all three Google connections and reports pending revocation if needed. |
| POST |
/v1/accounts/google/start (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Start body-owned Google consent for Gmail, Calendar or selected-file Drive access, with state and PKCE. |
| POST |
/v1/accounts/google/complete (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Exchange the one-time Google code and selected Drive file IDs on the body; return identity and grants without tokens. |
| POST |
/v1/accounts/google/check (inside encrypted exchange) |
Encrypted active device bearer with terminalControl (Take Control) |
Refresh and verify the selected Google account's authorized access and return its recovery status. |
| GET |
/h/{hostId}/v1/gateway/challenge |
Host routing identity; no device bearer |
Obtain a one-use challenge for an encrypted device exchange. |
| POST |
/h/{hostId}/v1/gateway/encrypted |
Authenticated device-to-host AES-GCM envelope |
Carry pairing, conversation, control, artifact and terminal traffic without revealing application bytes to the gateway. |
| POST |
/h/{hostId}/v1/gateway/push-authorize |
Gateway-internal one-use encrypted device proof |
Authorize push delivery at the device’s Mac without exposing its bearer. |
| POST |
/v1/pairing/redeem (inside encrypted exchange) |
One-time offer secret inside the authenticated pairing envelope |
Claim an active pairing offer and receive a completion token. |
| POST |
/v1/pairing/complete (inside encrypted exchange) |
One-time completion token |
Accept a subset of the offered grants and activate the device. |
| POST |
/v1/hosted/support (inside encrypted exchange) |
Signed single-use hosted account ticket bound to the exact support command |
Apply an owner support command and return an authenticated encrypted response. |
| GET |
/v1/support/grants (inside encrypted exchange) |
Owner operator or active device bearer with terminal-control access |
Read the body's customer-issued support grants and lifecycle state. |
| POST |
/v1/support/grants (inside encrypted exchange) |
Owner operator or active device bearer with terminal-control access |
Create a referenced read-state or shell support window of at most 72 hours. |
| GET |
/v1/devices/self (inside encrypted exchange) |
Device bearer |
Read the paired device’s own registration and grants. |
| GET |
/v1/devices (inside encrypted exchange) |
Operator or paired device bearer |
List the owner's paired devices for Settings → Devices. |
| POST |
/v1/devices/:id/revoke (inside encrypted exchange) |
Operator, or a paired device holding terminal control |
Revoke one paired device, including the caller itself. |
| POST |
/v1/devices/self/push (inside encrypted exchange) |
Device bearer |
Enable or disable this device’s versioned push reference on its machine. |
| POST |
/v1/devices/self/session/refresh (inside encrypted exchange) |
Device bearer |
Renew the paired device’s short-lived session. |
| POST |
/h/{hostId}/v1/hooks/linear |
Linear’s own HMAC signature over the request body |
Wake the operator thread when the owner comments on a Linear issue. |
| POST |
/v1/devices/wake-key (inside encrypted exchange) |
Encrypted live device bearer; managed bodies only |
Register this device’s public key for waking its hosted body. Self-hosted bodies return 404. |
| POST |
/h/{hostId}/v1/hosted/pair-offer |
Single-use fleet ticket bound to the browser key; managed bodies only |
Return a signed, encrypted pairing offer to the account page’s browser. |
| POST |
/operator/v1/dispatch (inside encrypted exchange) |
Device bearer plus the operation’s grant |
Send a chat, fleet, steer, or terminal-control operation to Clankie’s host. |
| POST |
/operator/v1/tail (inside encrypted exchange) |
Device bearer with chat access |
Read the app conversation as a bounded long-poll stream. |
| POST |
/operator/v1/terminal-tail (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read terminal frames from the host’s supported Herdr integration. |
| POST |
/operator/v1/artifacts/download (inside encrypted exchange) |
Encrypted device bearer plus chat grant |
Download exact bytes of a delivered artifact scoped to its conversation. |
| GET |
/v1/body-leases (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read the active body leases and their ownership on the paired host. |
| GET |
/v1/discord/rooms (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read the Discord rooms and their routing state on the paired host. |
| GET |
/v1/discord/settings (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read the host's Discord settings without credentials. |
| GET |
/v1/discord/directory (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read the Discord guild and channel directory available to the host. |
| GET |
/v1/discord/room-voice (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read the selected Discord room's current voice state. |
| GET |
/v1/discord/voice-transcripts (inside encrypted exchange) |
Device bearer with terminal-observe access |
Read bounded voice transcripts for the selected Discord room. |
| POST |
/v1/discord/room-guidance (inside encrypted exchange) |
Device bearer with steer access |
Update owner guidance for a Discord room through its paired host. |
| POST |
/v1/discord/setup/test-post (inside encrypted exchange) |
Device bearer with terminal-control access |
Send the bounded setup test message through the paired host's Discord body. |
| GET |
/v1/operator/fleet-settings (inside encrypted exchange) |
Encrypted live device bearer with terminalControl (Take Control) |
Read the owner's fleet size, models, work closure and machine setup responsibility. |
| POST |
/v1/operator/fleet-settings (inside encrypted exchange) |
Encrypted live device bearer with terminalControl (Take Control) |
Update fleet settings against the current revision and owner authority. |
| GET |
/v1/operator/projects (inside encrypted exchange) |
Encrypted live device bearer with terminalControl (Take Control) |
Read project settings, including autonomy overrides when explicitly requested. |
| POST |
/v1/operator/projects/update (inside encrypted exchange) |
Encrypted live device bearer with terminalControl (Take Control) |
Update project settings and fleet responsibility overrides with current owner authority. |