Core endpoints
Base URL: https://api.callvault.dev. This is a curated summary for day-one integration — not a substitute for the operator OpenAPI document.
| Method | Path | Auth | Summary |
|---|---|---|---|
| GET | /health | Public | Liveness and dependency checks for load balancers. |
| POST | /v1/broker/token | Control key (bk_*) | Mint short-lived broker JWT for an agent_app_id. |
| POST | /v1/tools/execute | Broker JWT | Hero route — run a registered tool against a connected_account_id. |
| POST | /v1/tools/invocations/:id/continue | Broker JWT | Resume after operator approval for high-risk invocations. |
| POST | /v1/connections/oauth/start | Auth0 + tenant header | Begin OAuth connect; returns authorize_url for the operator. |
| GET | /v1/connections | Auth0 + tenant header | List connection handles for the tenant. |
| GET | /v1/ops/openapi.json | Auth0 + tenant header | Full OpenAPI document (production-safe; not public /openapi.json). |
Rate limits
Tool execute and token mint routes are rate limited per tenant/IP. Expect 429 rate_limited when exceeding configured thresholds.
Vault fail-closed
If encryption vault is unavailable, execute returns 503 vault_unavailable without calling upstream SaaS APIs.