API reference

Every public endpoint under /v1, with its purpose and the credential it accepts. Bodies are validated with the same schemas the console uses; a validation failure returns 400 invalid_body with the field errors.

Written from the code · updated 26 Sep 2026 · Something wrong or missing? Tell us

Authentication

Authorization: Bearer cak_… for backend and agent keys, or the console session cookie. “editor+” means the org role must be editor or owner. Machine-to-machine calls should always use a key.

Endpoints

MethodPathPurposeAuth
POST/v1/mandatesRegister a mandate (authority, subject, limits, expiry)backend API key or session (editor+)
POST/v1/operationsPropose an action; 202 + decision. Idempotency-Key honouredagent or backend key, or session (editor+)
GET/v1/operations/{id}Operation state, decision reasons, approval, evidence countany key or session
POST/v1/operations/{id}/decisionApprove / reject with the exact approval digestsession only
POST/v1/observationsObservation mode: report an action the agent took itself; 201 + would-be decision, read-only verificationagent or backend key, or session (editor+)
GET/v1/observationsObservations + summary (?project_id, days, flagged=1)any key or session
GET/v1/observations/{id}One observation with its verification state and noteany key or session
GET/v1/projectsList projectsany key or session
POST/v1/projectsCreate a project (templates added automatically)session only
POST/v1/projects/{id}/agent-buildsRegister an agent build: version, endpoint_url, auth_header?, response_path?, set_defaultbackend API key or session (editor+)
POST/v1/projects/{id}/agent-builds/probeProbe an endpoint with a sample request; nothing storedbackend API key or session (editor+)
POST/v1/projects/{id}/connections/sandboxCreate a simulated-Stripe world + connectionbackend API key or session (editor+)
POST/v1/projects/{id}/pause · /unpauseKill-switch: stop new writes / re-queue held operationssession only
GETPUT/v1/projects/{id}/end-user-capsPer-end-user rate and spend capsbackend API key or session (editor+)
POST/v1/projects/{id}/connections/stripeConnect Stripe: restricted key + webhook secret, permissions probed read-onlybackend API key or session (editor+)
POST/v1/projects/{id}/connections/{connection_id}/rotateRotate the key (same Stripe account) and optionally the webhook secretbackend API key or session (editor+)
POST/v1/projects/{id}/connections/{connection_id}/defaultMake it the project’s default Guard connectionbackend API key or session (editor+)
DELETE/v1/projects/{id}/connections/{connection_id}Remove (credentials deleted; refused while in use)backend API key or session (editor+)
GETPUTDELETE/v1/projects/{id}/access-serviceClient access service URL + signing secret (secret never returned)backend API key or session (editor+)
POST/v1/projects/{id}/access-service/testOne signed read for a customer id; shows the state or the exact errorbackend API key or session (editor+)
POST/v1/test-runsStart a suite (repeats 1–5); counts against the planbackend API key or session (editor+)
GET/v1/test-runs/{id}Run status, verdict, counts, cost, per-scenario attemptsany key or session
GET/v1/test-runs/{id}/export?format=json|csv|pdfany key or session
GET/v1/test-runs/compare?base=&head= — version comparisonany key or session
POST/v1/test-runs/{id}/incidentsOpen an incident from a failed runsession only
GETPOST/v1/schedulesScheduled suites (cron)backend API key or session (editor+)
PATCHDELETE/v1/schedules/{id} · POST …/runEdit, delete, run nowbackend API key or session (editor+)
GETPUT/v1/guardrailsRail configuration per projectbackend API key or session (editor+)
GET/v1/guardrails/hitsRecent hits (keyset paginated)any key or session
GETPOST/v1/alert-channelsSlack / email / webhook alerts per projectbackend API key or session (editor+)
DELETE/v1/alert-channels/{id} · POST …/testRemove, send a test alertbackend API key or session (editor+)
GETPOST/v1/incidentsList / create incidentsany key or session
POST/v1/incidents/{id}/transition · /notesOPEN → ASSIGNED → RESOLVED / ACCEPTED_RISK; journalsession only
POST/v1/architect/drafts · /acceptDraft scenarios from a description; accept the approved onesbackend API key or session (editor+)
POST/v1/redteam/suiteGenerate hostile inputs and run thembackend API key or session (editor+)
GET/v1/compliance/export?from&to&project_id&format=json|pdf — tamper-evident reportany key or session
POST/v1/compliance/emailEmail the compliance PDFsession only
GETPOST/v1/api-keysList / create keys (backend | agent, per project or org)session only (owner)
GETPUT/v1/ai-settings · POST …/testAI mode (off / byok / managed), model, key, spend cap; real metered test callsession only
GETPUT/v1/planPlan and usage (PUT only when billing is not configured; otherwise 409 use_billing)session only (owner)
GET/v1/billingBilling state: subscribed, status (active / past_due / canceled), renewal, grace endany key or session
POST/v1/billing/checkoutStart a Stripe Checkout for { plan: test | guard }; returns the URLsession only (owner)
POST/v1/billing/portalOpen the Stripe Customer Portal (cards, invoices, plan change, cancel)session only (owner)
POST/v1/access-requestsAsk COLVO to unlock a capabilitysession only
POST/v1/webhooks/stripe/{connectionId}Signature-verified Stripe intakestripe-signature

Pagination

List endpoints that can grow use keyset pagination: ?limit= (max 200) and ?cursor= from the previous response’s next_cursor. Order is newest first and stable while new rows arrive.

Rate limits

Public forms are limited per IP (429 rate_limited). API keys are not rate limited during the pilot beyond plan quotas; abusive traffic is paused per organisation and the owner is told why.

API reference · Docs · COLVO