Docs / Reference

Broker API reference

The PastKeys broker HTTP API: perform and authorize operations, poll approvals, call published endpoints, and read usage.

Agents talk to the broker over HTTP with Authorization: Bearer <token>, where the token is a workload-identity JWT or an agent token.

Endpoints

Method and pathPurpose
POST /v1/actionsPerform an operation
POST /v1/authorizeDry-run a policy decision (no rate-limit cost)
GET /v1/actions/{id}Poll an operation waiting for approval
POST /e/{id}Call a published endpoint (endpoint key)
GET /e/{id}/actions/{req}Poll an approval-gated endpoint call
GET /v1/providersList providers and actions
GET /v1/usageUsage against the plan
GET /v1/custody/pubkeyThe broker's public key and algorithm
GET /healthzLiveness

Perform an operation

POST /v1/actions
{"provider": "cloudflare", "resource": "example.com", "action": "DNS_READ",
 "parameters": {"type": "A"}}

Success returns 200:

{"success": true, "operation": "DNS_READ", "resource": "example.com",
 "data": {...}, "request_id": "8a41d0c2"}

Status codes

CodeMeaning
200Performed; result in the body
202approval_required, pending or executing; poll the given path
400Malformed request or unknown provider
401Missing, invalid, expired or replayed identity token
403Denied; reason says why
429Plan quota reached
500The credential could not be obtained
502, 504The provider failed or timed out

Deny reasons

lockdown, guardrail_deny, explicit_deny, unknown_agent, no_matching_rule, action_not_allowed, constraint_violation, rate_limited. Allowed calls carry policy_match, break_glass, approved or endpoint in the audit log.