---
title: REST API reference
group: Reference
order: 4
summary: Escanor REST endpoints grouped by area, with links to the OpenAPI schemas for exact request and response fields.
updated: 2026-10-07
---
Base address: `https://api.escanor.in/api/v1`. Paths below are relative to it (a few, such as `/integrations/...` sign-in callbacks, live at the root). Send `Authorization: Bearer <session access token>` on authenticated dashboard requests. MCP keys and log-ingest tokens have separate endpoints and do not grant general REST access. See [API and keys](/docs/api-and-keys) for how to get one.

> **Tip** The service publishes an interactive reference with request and response schemas and a "try it" console at [api.escanor.in/docs](https://api.escanor.in/docs), and the raw OpenAPI document at [api.escanor.in/openapi.json](https://api.escanor.in/openapi.json). This page lists the endpoints; use those for exact fields.

> **Note** Admin, internal and machine-agent endpoints are deliberately not listed. Endpoints can be added or changed; the OpenAPI document is always current.

## Sign-in and sessions

22 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/auth/google/callback` | Google OAuth callback (legacy path). |
| `GET` | `/auth/google/login` | Start Google login (legacy shape: returns `auth_url` instead of `authorization_url`). |
| `POST` | `/auth/handoff` | A link that opens the website already signed in as the caller, for the phone app's "manage billing on the web". |
| `DELETE` | `/auth/integrations/{provider_id}` | Disconnect an integration. |
| `POST` | `/auth/integrations/{provider_id}/connect` | Connect a provider with a pasted token or credential set. |
| `GET` | `/auth/integrations/{provider_id}/status` | Connection status for one provider, plus everything needed to connect it. |
| `GET` | `/auth/integrations/{provider}/authorize` | Start OAuth flow for integration connection (GitHub, Vercel, etc.). |
| `POST` | `/auth/integrations/{provider}/exchange` | Exchange OAuth code for integration connection. |
| `POST` | `/auth/logout` | Logout and invalidate current session. |
| `GET` | `/auth/me` | Get current authenticated user info. |
| `GET` | `/auth/oauth/{provider}/authorize` | Start OAuth login (Google, GitHub). |
| `GET` | `/auth/oauth/{provider}/callback` | Second landing pad for connect callbacks. |
| `POST` | `/auth/oauth/exchange` | Trade a one-time login code for escanor access/refresh tokens. |
| `GET` | `/auth/oauth/github/callback` | GitHub OAuth callback — sign-in, or connecting the GitHub integration. |
| `GET` | `/auth/oauth/google/callback` | Google OAuth callback — sign-in, or connecting Google Cloud. |
| `POST` | `/auth/refresh` | Exchange refresh token for new access token. |
| `GET` | `/auth/session` | Get current user session info. |
| `PATCH` | `/auth/session/context` | Update active organization/workspace context. |
| `PATCH` | `/auth/session/onboarding` | Update user onboarding status. |
| `GET` | `/auth/sessions` | Every place this account is signed in, newest first, with the one making this request marked. |
| `DELETE` | `/auth/sessions/{session_id}` | Sign one place out. Its tokens stop working on their next use. |
| `POST` | `/auth/sessions/revoke-others` | Sign out everywhere except here. |

## Your user

10 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/account/deletion` | Deletion Status |
| `POST` | `/account/deletion` | Request Deletion |
| `POST` | `/account/deletion/cancel` | Cancel Deletion |
| `PATCH` | `/users/me` | Update Profile |
| `GET` | `/users/me/notification-preferences` | Get Preferences |
| `PATCH` | `/users/me/notification-preferences` | Update Preferences |
| `GET` | `/users/me/push-status` | Push Status |
| `POST` | `/users/me/push-test` | Push Test |
| `DELETE` | `/users/me/push-token` | A phone forgets itself (on sign-out), so the next person to use it does not get this person's alerts. Only your own. |
| `POST` | `/users/me/push-token` | Register Push Token |

## MCP keys

3 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/tokens` | List MCP tokens. |
| `DELETE` | `/tokens/{token_id}` | Revoke MCP token. |
| `POST` | `/tokens/create` | Generate MCP bearer token. |

## Integrations

39 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/integrations` | List connected integrations for workspace. |
| `DELETE` | `/integrations/{provider_id}` | Disconnect an integration. |
| `GET` | `/integrations/{provider_id}/analytics` | Live resources and health for one connected integration. |
| `GET` | `/integrations/{provider_id}/capabilities` | Get integration capabilities. |
| `POST` | `/integrations/{provider_id}/connect` | Connect a provider with a pasted token or credential set. |
| `POST` | `/integrations/{provider_id}/connect/local-agent` | Connect |
| `GET` | `/integrations/{provider_id}/detail` | Get detailed integration information. |
| `GET` | `/integrations/{provider_id}/local-agent` | Status |
| `GET` | `/integrations/{provider_id}/oauth/authorize` | Start OAuth flow for integration. |
| `POST` | `/integrations/{provider_id}/oauth/exchange` | Exchange OAuth code for integration tokens. |
| `GET` | `/integrations/{provider_id}/oauth/setup` | Get OAuth setup for specific provider. |
| `GET` | `/integrations/{provider_id}/projects` | List integration projects (e.g., GCP projects). |
| `POST` | `/integrations/{provider_id}/projects/select` | Select integration projects. |
| `GET` | `/integrations/{provider_id}/resources/{resource_id}` | One resource of a connected integration, read live from the provider. |
| `POST` | `/integrations/{provider_id}/resources/{resource_id}/actions` | Run one action against a resource -- the buttons on the resource page. |
| `GET` | `/integrations/{provider_id}/runtime` | Runtime |
| `POST` | `/integrations/{provider_id}/runtime/actions` | Runtime Action |
| `GET` | `/integrations/{provider_id}/status` | Connection status for one provider, plus everything needed to connect it. |
| `POST` | `/integrations/{provider_id}/sync` | Sync a specific integration. |
| `GET` | `/integrations/{provider}/callback` | OAuth callback for integration connections. |
| `GET` | `/integrations/{provider}/connect` | Start OAuth flow for an integration. |
| `GET` | `/integrations/available` | List available integrations. |
| `GET` | `/integrations/catalog` | Integration catalog: categories, each with its provider list. |
| `GET` | `/integrations/connected` | Connected integrations for the caller's workspace. |
| `GET` | `/integrations/health` | For each connected tool: can it still be used, and if not, why. Lets the apps say "reconnect GitLab" instead of showing nothing. |
| `GET` | `/integrations/oauth/setup` | Get OAuth setup information for all providers. |
| `GET` | `/integrations/onboarding-status` | What this workspace has connected, and what it can still connect. |
| `GET` | `/integrations/providers` | List all available integration provider IDs. |
| `POST` | `/integrations/sync-all` | Sync all connected integrations. |
| `GET` | `/integrations/vault` | Get integration vault with all connected credentials. |
| `POST` | `/integrations/vault/initialize` | Initialize integration vault (load credentials, sync integrations). |
| `GET` | `/integrations/available` | List all available integrations. |
| `GET` | `/integrations/catalog/{provider_id}` | Get detailed info about a specific provider. |
| `POST` | `/integrations/connect/api-key` | Connect integration using API key or credentials. |
| `POST` | `/integrations/disconnect` | Disconnect an integration. |
| `POST` | `/integrations/sync` | Sync resources from an integration. |
| `GET` | `/integrations/workspace/{workspace_id}` | List all connected integrations for a workspace. |
| `GET` | `/integrations/workspace/{workspace_id}/analytics` | Get analytics for workspace integrations. |
| `GET` | `/integrations/workspace/{workspace_id}/status/{provider_id}` | Get connection status for a specific provider. |

## Projects and resources

40 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/infrastructure/resources` | Infrastructure |
| `GET` | `/infrastructure/resources/{slug}` | Infrastructure One |
| `GET` | `/projects` | List Projects |
| `GET` | `/projects/{project_id}` | Project |
| `GET` | `/projects/{project_id}/analytics` | Analytics |
| `GET` | `/projects/{project_id}/cron` | Cron |
| `GET` | `/projects/{project_id}/cron/executions` | Cron Executions |
| `GET` | `/projects/{project_id}/deployments` | Deployments |
| `DELETE` | `/projects/{project_id}/deployments/{deployment_id}` | Delete Deployment |
| `GET` | `/projects/{project_id}/deployments/{deployment_id}` | Deployment |
| `GET` | `/projects/{project_id}/deployments/{deployment_id}/build-logs` | Build Logs |
| `POST` | `/projects/{project_id}/deployments/{deployment_id}/cancel` | Cancel |
| `GET` | `/projects/{project_id}/deployments/{deployment_id}/functions` | Deployment Functions List |
| `GET` | `/projects/{project_id}/deployments/{deployment_id}/logs` | Deployment Logs |
| `POST` | `/projects/{project_id}/deployments/{deployment_id}/redeploy` | Redeploy |
| `GET` | `/projects/{project_id}/domains` | Domains |
| `POST` | `/projects/{project_id}/domains` | Domain Add |
| `DELETE` | `/projects/{project_id}/domains/{domain}` | Domain Remove |
| `POST` | `/projects/{project_id}/domains/{domain}/verify` | Domain Verify |
| `GET` | `/projects/{project_id}/env` | Env List |
| `POST` | `/projects/{project_id}/env` | Env Create |
| `DELETE` | `/projects/{project_id}/env/{env_id}` | Env Delete |
| `PATCH` | `/projects/{project_id}/env/{env_id}` | Env Update |
| `GET` | `/projects/{project_id}/firewall/events` | Firewall Events |
| `GET` | `/projects/{project_id}/firewall/overview` | Firewall Overview |
| `GET` | `/projects/{project_id}/functions` | Functions |
| `GET` | `/projects/{project_id}/functions/invocations` | Invocations |
| `GET` | `/projects/{project_id}/logs` | Project Logs |
| `GET` | `/projects/{project_id}/observability` | Requests, errors and functions, derived from the runtime logs of the live deployment. |
| `GET` | `/projects/{project_id}/overview` | Overview |
| `GET` | `/projects/{project_id}/settings` | Settings |
| `PATCH` | `/projects/{project_id}/settings` | Update Settings |
| `GET` | `/projects/{project_id}/speed-insights` | Speed Insights |
| `GET` | `/repositories` | Repositories |
| `GET` | `/runtimes` | List Runtimes |
| `GET` | `/runtimes/preferences` | Get Prefs |
| `PUT` | `/runtimes/preferences` | Put Prefs |
| `POST` | `/runtimes/provision` | Provision Runtime |
| `GET` | `/services` | Services |
| `GET` | `/services/{slug}` | Service |

## Deployments, incidents and timeline

16 endpoints.

| Method | Path | What it does |
|---|---|---|
| `POST` | `/actions/k8s/restart` | Restart Pod |
| `POST` | `/actions/rollback` | Rollback |
| `GET` | `/alerts` | Alerts |
| `GET` | `/deployments` | Deployments |
| `GET` | `/deployments/{deployment_id}` | Deployment |
| `POST` | `/deployments/{deployment_id}/approve` | Approve |
| `POST` | `/deployments/{deployment_id}/reject` | Reject |
| `GET` | `/incidents` | Incidents |
| `GET` | `/incidents/{incident_id}` | Incident |
| `POST` | `/incidents/{incident_id}/summary` | Incident Summary |
| `POST` | `/repair/missions` | Create Repair |
| `POST` | `/repair/missions/{mission_id}/approve` | Approve Repair |
| `GET` | `/repair/platform-status` | Repair Platform Status |
| `GET` | `/runbooks` | Runbooks |
| `GET` | `/timeline/activity` | Timeline |
| `GET` | `/timeline/events` | Every recent event as one flat, newest-first list with its own detail, for a filterable, paged activity table. |

## Monitoring and analytics

29 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/analytics/export.csv` | Export |
| `GET` | `/analytics/overview` | Overview |
| `GET` | `/health` | Health check. |
| `GET` | `/monitoring/overview` | Monitoring |
| `GET` | `/observability/analysis` | Analysis View |
| `POST` | `/observability/client` | Client Logs |
| `GET` | `/observability/client-config` | What the browser or app should send, so it never collects what the workspace turned off. |
| `GET` | `/observability/clusters` | Clusters |
| `POST` | `/observability/collect` | Collect Now |
| `DELETE` | `/observability/data` | Purge |
| `GET` | `/observability/export.ndjson` | Export |
| `GET` | `/observability/histogram` | Volume per bucket for exactly what the log explorer is showing, so the chart above the table always agrees with it. |
| `POST` | `/observability/ingest` | Logs from anything that can send them. Authenticated by an ingest token, not a session. |
| `GET` | `/observability/ingest-tokens` | List Tokens |
| `POST` | `/observability/ingest-tokens` | Create Token |
| `DELETE` | `/observability/ingest-tokens/{token_id}` | Delete Token |
| `GET` | `/observability/logs` | Logs |
| `GET` | `/observability/logs/{entry_id}` | One |
| `GET` | `/observability/logs/stream` | Server-sent events: new entries as they are stored. Ends after a few minutes; the client reconnects from the last cursor. |
| `GET` | `/observability/logs/tail` | Tail |
| `GET` | `/observability/overview` | Overview |
| `GET` | `/observability/preferences` | Get Prefs |
| `PUT` | `/observability/preferences` | Put Prefs |
| `GET` | `/observability/sections` | Sections |
| `GET` | `/observability/sections/{section}` | Section Detail |
| `GET` | `/observability/sources` | Sources |
| `GET` | `/observability/sources/{source}` | Source Detail |
| `GET` | `/status/overview` | Status |
| `GET` | `/uptime/config` | Where the website finds Enterprise Uptime (incidents, sources, settings), or that it is not set up. |

## The assistant and AI

39 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/ai-activity` | Everything the assistant did, from every place it acts: its runs and tasks, the chats you had with it, and every tool |
| `POST` | `/ai-activity/command` | Ai Command |
| `POST` | `/ai/autonomous/run` | Autonomous |
| `GET` | `/ai/capabilities` | Capabilities |
| `POST` | `/ai/chat` | Chat |
| `GET` | `/ai/conversations` | Conversations |
| `POST` | `/ai/conversations` | Create Thread |
| `DELETE` | `/ai/conversations/{conversation_id}` | Delete |
| `GET` | `/ai/conversations/{conversation_id}/messages` | Messages |
| `POST` | `/ai/conversations/{conversation_id}/permissions/{request_id}` | Answer |
| `POST` | `/ai/conversations/{conversation_id}/stop` | Stop |
| `POST` | `/ai/conversations/{thread_id}/messages` | Thread Message |
| `GET` | `/ai/employees` | Employees |
| `GET` | `/ai/investigations/{investigation_id}` | Investigation |
| `POST` | `/ai/investigations/{investigation_id}/approve` | Approve Investigation |
| `POST` | `/ai/jarvis/command` | Jarvis Command |
| `POST` | `/ai/jarvis/run` | Jarvis Run |
| `GET` | `/ai/jarvis/runs` | Jarvis Runs |
| `GET` | `/ai/jarvis/runs/{run_id}` | Jarvis Run Detail |
| `POST` | `/ai/jarvis/runs/{run_id}/cancel` | Cancel Jarvis Run |
| `GET` | `/ai/machine` | The assistant's machine: state, what happened on it, and (on request) its recent output. |
| `GET` | `/ai/missions` | List Missions |
| `POST` | `/ai/missions` | Create Mission |
| `GET` | `/ai/missions/{mission_id}` | Get Mission |
| `POST` | `/ai/missions/{mission_id}/cancel` | Cancel Mission |
| `POST` | `/ai/missions/{mission_id}/retry` | Retry Mission |
| `GET` | `/ai/missions/templates` | Mission Templates |
| `GET` | `/ai/models` | Every model, each marked available or not (and why), with the default: the first that can answer. |
| `GET` | `/ai/providers/health` | Providers Health |
| `POST` | `/ai/providers/health/{provider_id}/test` | Provider Test |
| `GET` | `/ai/recommendations` | Ai Recommendations |
| `GET` | `/ai/status` | Where the assistant is. Also what gets it started and keeps it healthy: poll this. |
| `GET` | `/ai/tools` | Ai Tools |
| `GET` | `/ai/usage` | What this workspace's assistant has used. Real numbers from the model gateway when there is one. |
| `POST` | `/ai/voice/resolve` | Voice Resolve |
| `POST` | `/ai/voice/step` | Voice Step |
| `GET` | `/ai/workspace` | Ai Workspace |
| `GET` | `/llm/{path}` | Proxy |
| `POST` | `/llm/{path}` | Proxy |

## Automations

14 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/autopilot` | Overview |
| `POST` | `/autopilot/pause` | The kill switch: nothing new starts, nothing is answered, every run stops now. |
| `PUT` | `/autopilot/policy` | Set Policy |
| `POST` | `/autopilot/resume` | Resume |
| `GET` | `/autopilot/runs` | Runs |
| `POST` | `/autopilot/runs` | Start |
| `GET` | `/autopilot/runs/{run_id}` | Run Detail |
| `POST` | `/autopilot/runs/{run_id}/approve` | Approve |
| `POST` | `/autopilot/runs/{run_id}/deny` | Deny |
| `POST` | `/autopilot/runs/{run_id}/stop` | Stop |
| `POST` | `/autopilot/triggers` | Add Trigger |
| `DELETE` | `/autopilot/triggers/{trigger_id}` | Remove Trigger |
| `PATCH` | `/autopilot/triggers/{trigger_id}` | Edit Trigger |
| `POST` | `/autopilot/triggers/{trigger_id}/run` | Run Trigger Now |

## Workspaces and teams

23 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/audit-logs` | Audit Logs |
| `GET` | `/connections` | List all user connections (OAuth integrations, not MCP tokens). |
| `GET` | `/inbox` | Inbox |
| `GET` | `/organizations` | List user's organizations (workspace mapped as org for compatibility). |
| `GET` | `/organizations/{organization_id}/workspaces` | List workspaces in an organization. |
| `GET` | `/search` | Search |
| `GET` | `/team` | Team |
| `POST` | `/team/notify` | Team Notify |
| `GET` | `/workspace/ai-context/connectors` | Context Connectors |
| `POST` | `/workspace/ai-context/connectors` | Create Connector |
| `DELETE` | `/workspace/ai-context/connectors/{connector_id}` | Disconnect Connector |
| `PATCH` | `/workspace/ai-context/connectors/{connector_id}` | Update Connector |
| `DELETE` | `/workspace/ai-context/connectors/{connector_id}/context` | Delete Context |
| `POST` | `/workspace/ai-context/imports` | Import Context |
| `POST` | `/workspace/ai-context/imports/preview` | Preview Import |
| `GET` | `/workspace/ai-context/providers` | Context Providers |
| `GET` | `/workspace/graph` | Graph |
| `GET` | `/workspace/graph/nodes/{node_id}/neighborhood` | Graph Neighborhood |
| `GET` | `/workspace/projects` | Every project, site, service and pipeline from every connected platform, in one list. |
| `GET` | `/workspace/settings` | Workspace Settings |
| `PATCH` | `/workspace/settings` | Rename the workspace or change its defaults. Owners and admins only; every change is audited. |
| `GET` | `/workspace/sources` | Workspace Sources |
| `PUT` | `/workspaces/{workspace_id}/runtime-preferences` | Put Workspace Prefs |

## Plans and billing

8 endpoints.

| Method | Path | What it does |
|---|---|---|
| `POST` | `/billing/cancel` | Cancel |
| `POST` | `/billing/change-plan` | Switch between paid plans. Up is immediate (the difference is charged by Razorpay); down waits for the period to end. |
| `POST` | `/billing/checkout` | Checkout |
| `GET` | `/billing/entitlements` | Entitlements |
| `GET` | `/billing/invoices` | Invoices |
| `GET` | `/billing/plans` | Plans |
| `GET` | `/billing/subscription` | Subscription |
| `POST` | `/billing/verify` | Verify |

## Security and privacy

11 endpoints.

| Method | Path | What it does |
|---|---|---|
| `GET` | `/compliance/consents` | Get Consents |
| `POST` | `/compliance/consents` | Record Consent |
| `GET` | `/compliance/me/export` | Export My Data |
| `GET` | `/compliance/requests` | List Requests |
| `POST` | `/compliance/requests` | Open Request |
| `GET` | `/compliance/requests/{request_id}` | Get Request |
| `GET` | `/security/2fa` | Two Factor Status |
| `POST` | `/security/2fa/backup-codes` | Two Factor Backup Codes |
| `POST` | `/security/2fa/disable` | Two Factor Disable |
| `POST` | `/security/2fa/enable` | Two Factor Enable |
| `POST` | `/security/2fa/setup` | Two Factor Setup |

## Everything else

| Method | Path | What it does |
|---|---|---|
| `GET` | `/` | API info. |
| `GET` | `/.well-known/oauth-authorization-server` | RFC 8414. Plain OAuth clients -- MCP among them -- look here, not at the OIDC path. |
| `GET` | `/.well-known/openid-configuration` | OpenID Connect Discovery 1.0 §4. |
| `GET` | `/oidc/consent/{request_id}` | What the consent screen needs to render: who is asking, and for what. |
| `POST` | `/oidc/consent/{request_id}` | Record the user's decision and return where the browser should go next. |
| `GET` | `/oidc/grants` | Applications this user has connected, for a "connected apps" screen. |
| `DELETE` | `/oidc/grants/{client_id}` | Disconnect an application: forget the consent and kill its tokens. |
| `GET` | `/health` | Health check. |
| `GET` | `/oidc/authorize` | Start an authorization code flow. |
| `POST` | `/oidc/introspect` | RFC 7662. Lets a resource server ask what a token is. |
| `GET` | `/oidc/jwks.json` | Public keys for verifying tokens this provider signed. |
| `GET` | `/oidc/logout` | OpenID Connect RP-Initiated Logout 1.0. |
| `POST` | `/oidc/logout` | OpenID Connect RP-Initiated Logout 1.0. |
| `POST` | `/oidc/register` | RFC 7591 §3.1. |
| `DELETE` | `/oidc/register/{client_id}` | RFC 7592 §2.3 -- deregister, taking the client's live tokens with it. |
| `GET` | `/oidc/register/{client_id}` | RFC 7592 §2.1 -- read the current registration. |
| `PUT` | `/oidc/register/{client_id}` | RFC 7592 §2.2 -- update the descriptive fields and redirect URIs. |
| `POST` | `/oidc/revoke` | RFC 7009. Always answers 200, even for an unknown token. |
| `POST` | `/oidc/token` | Exchange a grant for tokens (RFC 6749 §3.2). |
| `GET` | `/oidc/userinfo` | Claims about the authenticated user (OIDC Core §5.3). |
| `POST` | `/oidc/userinfo` | Claims about the authenticated user (OIDC Core §5.3). |

