Docs / Concepts

Published endpoints

Publish one scoped operation as its own REST endpoint with its own key, so an agent can call a normal API without any provider credential.

An endpoint packages one operation (provider, resource, action, fixed parameters) behind its own URL and key. Hand an agent the URL and key: it calls a plain REST API, and the broker does the rest.

Create one

In Endpoints, choose New endpoint and set:

  • Provider, resource and action, for example cloudflare, example.com, DNS_READ.
  • Fixed parameters: set by you, the caller cannot change them.
  • Caller parameters: the only parameters a caller may send, each with an optional constraint. Anything else is rejected.
  • Require approval, optionally.

The key is shown once. Call it:

curl -X POST https://your-broker.example/e/ep_ab12 \
  -H "Authorization: Bearer pk_ep_..." \
  -H "Content-Type: application/json" -d '{}'

Control

  • Turn off an endpoint to cut access instantly; turn it back on later.
  • Rotate the key to invalidate the old one.
  • Account guardrails and lockdown still apply.

Endpoint keys are long-lived by nature. Prefer them for simple integrations; for agents that can use workload identity, that is the stronger option.