Skip to content

API endpoints ​

Every operation of the HTTP API, grouped by area, as declared in api/openapi.yaml. "Access" is the minimum role of a signed-in user and the minimum scope of an API key; "session only" operations do not accept API keys. Load the OpenAPI file into any OpenAPI viewer or client generator for request and response schemas.

config

Configuration as code (YAML export, import and the GitOps directory).

EndpointWhat it doesAccess
POST /api/v1/exportExport reports, queries, connections and channels as YAMLrole editor, scope read
POST /api/v1/importPlan or apply YAML documentsrole admin, scope admin
POST /api/v1/gitops/detachLet the UI change a resource the configuration directory managesrole admin, scope admin
POST /api/v1/gitops/attachGive a detached resource back to the configuration directoryrole admin, scope admin

ai

The AI assistant (proposals only; nothing runs by itself).

EndpointWhat it doesAccess
GET /api/v1/ai/statusWhether the AI assistant is availablerole viewer, scope read
POST /api/v1/ai/generateAsk the AI assistant for a query or a schedulerole editor, scope run

health

Liveness and readiness probes. Public, never contain secrets.

EndpointWhat it doesAccess
GET /health/liveLiveness probepublic
GET /health/readyReadiness probepublic

setup

First-run wizard. Available until the first user exists.

EndpointWhat it doesAccess
GET /api/v1/setup/statusWhether the setup wizard must runpublic
POST /api/v1/setupCreate the first admin and sign inpublic

auth

Sign in and sign out.

EndpointWhat it doesAccess
POST /api/v1/auth/loginSign in with email and passwordpublic
POST /api/v1/auth/login/second-factorFinish signing in with a TOTP code or a recovery codepublic
POST /api/v1/auth/login/second-factor/passkeyStart the passkey step of a sign-inpublic
POST /api/v1/auth/passkey/optionsStart signing in with a passkey, without a passwordpublic
POST /api/v1/auth/passkeyFinish signing in with a passkeypublic
GET /api/v1/auth/oidc/loginLeave for the identity provider (OIDC)public
GET /api/v1/auth/oidc/callbackCome back from the identity providerpublic
POST /api/v1/auth/password-resetEmail a link to choose a new passwordpublic
POST /api/v1/auth/password-reset/confirmChoose a new password with an emailed linkpublic
POST /api/v1/auth/logoutSign out of the current sessionrole viewer, scope read, session only

me

The signed-in user's profile, password, sessions and two-factor authentication.

EndpointWhat it doesAccess
GET /api/v1/meThe signed-in userrole viewer, scope read
PATCH /api/v1/meUpdate name and preferencesrole viewer, scope write, session only
POST /api/v1/me/passwordChange the passwordrole viewer, scope write, session only
GET /api/v1/me/sessionsActive sessions of the callerrole viewer, scope read, session only
POST /api/v1/me/sessions/{sessionId}/revokeSign out one sessionrole viewer, scope write, session only
POST /api/v1/me/sessions/revoke-allSign out everywhere, including this sessionrole viewer, scope write, session only
POST /api/v1/me/2fa/totp/setupStart enrolling an authenticator approle viewer, scope write, session only
POST /api/v1/me/2fa/totp/confirmActivate the authenticator app with a first coderole viewer, scope write, session only
POST /api/v1/me/2fa/totp/disableTurn off two-factor authenticationrole viewer, scope write, session only
POST /api/v1/me/2fa/recovery-codesReplace the recovery codesrole viewer, scope write, session only
GET /api/v1/me/passkeysThe caller's passkeysrole viewer, scope read, session only
POST /api/v1/me/passkeysFinish adding a passkeyrole viewer, scope write, session only
POST /api/v1/me/passkeys/optionsStart adding a passkeyrole viewer, scope write, session only
PATCH /api/v1/me/passkeys/{passkeyId}Rename a passkeyrole viewer, scope write, session only
POST /api/v1/me/passkeys/{passkeyId}/removeRemove a passkeyrole viewer, scope write, session only

users

Workspace members and their roles.

EndpointWhat it doesAccess
GET /api/v1/usersMembers of the workspacerole viewer, scope read
POST /api/v1/usersAdd a user with a temporary passwordrole admin, scope admin
GET /api/v1/users/{userId}One member of the workspacerole viewer, scope read
PATCH /api/v1/users/{userId}Change name, role or enabled staterole admin, scope admin
POST /api/v1/users/{userId}/reset-passwordGive the user a new temporary passwordrole admin, scope admin
POST /api/v1/users/{userId}/2fa/disableTurn off another user's two-factor authenticationrole admin, scope admin

api-keys

Keys for automation. Managed by admins.

EndpointWhat it doesAccess
GET /api/v1/api-keysAPI keys of the workspacerole admin, scope admin
POST /api/v1/api-keysCreate an API keyrole admin, scope admin
POST /api/v1/api-keys/{apiKeyId}/revokeRevoke an API keyrole admin, scope admin

settings

Workspace settings.

EndpointWhat it doesAccess
GET /api/v1/settingsWorkspace settingsrole viewer, scope read
PATCH /api/v1/settingsChange workspace settingsrole admin, scope admin
GET /api/v1/settings/oidcSingle sign-on (OIDC) settingsrole admin, scope admin
PUT /api/v1/settings/oidcChange the single sign-on (OIDC) settingsrole admin, scope admin
POST /api/v1/settings/oidc/testRead the provider's discovery documentrole admin, scope admin
GET /api/v1/settings/alertsSystem alert channels and the outbound heartbeatrole admin, scope admin
PUT /api/v1/settings/alertsReplace the system alert and heartbeat settingsrole admin, scope admin
GET /api/v1/settings/aiThe AI assistant's provider and its settingsrole admin, scope admin
PUT /api/v1/settings/aiChoose the AI provider, or turn the assistant offrole admin, scope admin
POST /api/v1/settings/ai/testCheck AI settings before saving themrole admin, scope admin

security-events

Audit trail of security-relevant actions, for admins.

EndpointWhat it doesAccess
GET /api/v1/security-eventsSecurity events, newest firstrole admin, scope admin

system

The instance itself (storage, backups, version), for admins.

EndpointWhat it doesAccess
GET /api/v1/system/aboutVersion of this instance and the latest releaserole viewer, scope read
GET /api/v1/system/storageArtifact storage, retention and scheduled backupsrole admin, scope admin

plugins

Installed plugins with their configuration schemas, capabilities and translations.

EndpointWhat it doesAccess
GET /api/v1/pluginsInstalled pluginsrole viewer, scope read

connections

User databases. Rowbird only reads from them.

EndpointWhat it doesAccess
GET /api/v1/connectionsConnections of the workspace, by namerole viewer, scope read
POST /api/v1/connectionsAdd a connectionrole admin, scope admin
POST /api/v1/connections/testTest configuration that is not savedrole admin, scope admin
GET /api/v1/connections/{connectionId}One connectionrole viewer, scope read
PATCH /api/v1/connections/{connectionId}Change a connectionrole admin, scope admin
DELETE /api/v1/connections/{connectionId}Delete a connection that nothing usesrole admin, scope admin
POST /api/v1/connections/{connectionId}/testTest a saved connectionrole admin, scope admin
GET /api/v1/connections/{connectionId}/schemaCached schema of the databaserole viewer, scope read
POST /api/v1/connections/{connectionId}/schema/refreshIntrospect the schema againrole editor, scope write

queries

Named, versioned SQL bound to a connection, and its preview.

EndpointWhat it doesAccess
GET /api/v1/queriesQueries of the workspace, most recently changed firstrole viewer, scope read
POST /api/v1/queriesCreate a query and its first versionrole editor, scope write
POST /api/v1/queries/previewRun SQL read-only with a row cap and a short timeoutrole editor, scope run
GET /api/v1/queries/{queryId}One query with its current versionrole viewer, scope read
PATCH /api/v1/queries/{queryId}Change a queryrole editor, scope write
DELETE /api/v1/queries/{queryId}Delete a query that no report usesrole editor, scope write
GET /api/v1/queries/{queryId}/versionsVersions of a query, newest firstrole viewer, scope read
GET /api/v1/queries/{queryId}/versions/{number}One version with its SQLrole viewer, scope read
POST /api/v1/queries/{queryId}/restoreMake a copy of an old version the current onerole editor, scope write

channels

Destinations with their settings (email, chats, webhooks, buckets) and health.

EndpointWhat it doesAccess
GET /api/v1/channelsChannels of the workspace, by name, with their healthrole viewer, scope read
POST /api/v1/channelsCreate a channelrole admin, scope admin
POST /api/v1/channels/testTest unsaved channel settingsrole admin, scope admin
GET /api/v1/channels/{channelId}One channelrole viewer, scope read
PATCH /api/v1/channels/{channelId}Change a channelrole admin, scope admin
DELETE /api/v1/channels/{channelId}Delete a channel that no delivery usesrole admin, scope admin
POST /api/v1/channels/{channelId}/testSend a test message through a saved channelrole editor, scope run
POST /api/v1/channels/{channelId}/retry-failedSend a channel's failed delivery attempts againrole editor, scope run

Shared links to run files, with expiry, revocation and a download log.

EndpointWhat it doesAccess
GET /api/v1/linksShared links, newest firstrole viewer, scope read
GET /api/v1/links/{linkId}One link with its latest downloadsrole viewer, scope read
POST /api/v1/links/{linkId}/revokeRevoke a link at oncerole editor, scope write

reports

Queries on a schedule, with a condition, and their schedules.

EndpointWhat it doesAccess
GET /api/v1/reportsReports of the workspace, by title, with their last runrole viewer, scope read
POST /api/v1/reportsCreate a report and schedule its first runrole editor, scope write
GET /api/v1/reports/{reportId}One reportrole viewer, scope read
PATCH /api/v1/reports/{reportId}Change a reportrole editor, scope write
DELETE /api/v1/reports/{reportId}Delete a report and its runsrole editor, scope write
POST /api/v1/reports/{reportId}/pauseStop scheduling a reportrole editor, scope write
POST /api/v1/reports/{reportId}/resumeSchedule a paused report again from nowrole editor, scope write
POST /api/v1/reports/{reportId}/runQueue a manual runrole editor, scope run
POST /api/v1/schedules/previewNext occurrences and description of a schedulerole viewer, scope read
GET /api/v1/reports/{reportId}/deliveriesA report's deliveries, in orderrole viewer, scope read
POST /api/v1/reports/{reportId}/deliveriesAdd a delivery to a reportrole editor, scope write
PUT /api/v1/reports/{reportId}/deliveries/{deliveryId}Replace a delivery's settingsrole editor, scope write
DELETE /api/v1/reports/{reportId}/deliveries/{deliveryId}Remove a deliveryrole editor, scope write
POST /api/v1/deliveries/previewRender a delivery's message without sending itrole editor, scope run
POST /api/v1/reports/{reportId}/test-deliveryRun the report now and deliver it only to the callerrole editor, scope run

runs

Executions of reports, scheduled or manual.

EndpointWhat it doesAccess
GET /api/v1/runsRuns, newest firstrole viewer, scope read
GET /api/v1/runs/{runId}One run with its steps, parameters, condition and result samplerole viewer, scope read
POST /api/v1/runs/{runId}/cancelCancel a pending or running runrole editor, scope run
POST /api/v1/runs/{runId}/attempts/{attemptId}/retrySend a failed delivery attempt againrole editor, scope run
GET /api/v1/runs/{runId}/resultThe run's result as a filerole viewer, scope read

notifications

In-app notifications of the signed-in user, and the real-time event stream.

EndpointWhat it doesAccess
GET /api/v1/notificationsThe signed-in user's notifications, newest firstrole viewer, scope read
POST /api/v1/notifications/read-allMark every notification of the signed-in user as readrole viewer, scope read
POST /api/v1/notifications/{notificationId}/readMark one notification as readrole viewer, scope read
GET /api/v1/dashboardHome page summary and what the health banner showsrole viewer, scope read
GET /api/v1/eventsReal-time events as Server-Sent Eventsrole viewer, scope read

Released under the Apache License 2.0.