Core endpoints

Base URL: https://api.callvault.dev. This is a curated summary for day-one integration — not a substitute for the operator OpenAPI document.

MethodPathAuthSummary
GET/healthPublicLiveness and dependency checks for load balancers.
POST/v1/broker/tokenControl key (bk_*)Mint short-lived broker JWT for an agent_app_id.
POST/v1/tools/executeBroker JWTHero route — run a registered tool against a connected_account_id.
POST/v1/tools/invocations/:id/continueBroker JWTResume after operator approval for high-risk invocations.
POST/v1/connections/oauth/startAuth0 + tenant headerBegin OAuth connect; returns authorize_url for the operator.
GET/v1/connectionsAuth0 + tenant headerList connection handles for the tenant.
GET/v1/ops/openapi.jsonAuth0 + tenant headerFull OpenAPI document (production-safe; not public /openapi.json).

Rate limits

Tool execute and token mint routes are rate limited per tenant/IP. Expect 429 rate_limited when exceeding configured thresholds.

Vault fail-closed

If encryption vault is unavailable, execute returns 503 vault_unavailable without calling upstream SaaS APIs.