The API-key-gated Developer API exposes versioned resources under /v1.
Base URL
Use https://api.openfactor.ai.
Send the API key as either Authorization: Bearer <key> or the x-api-key
header. GET /v1/me returns the authenticated key's effective team scope,
capabilities, and action grants.
Capability profile
Capabilities provide coarse read or manage access. A key's value for each family is one of the levels shown below.
| Family | Levels | Endpoint families |
|---|---|---|
workspace | none, read | Configuration, teams, and team members |
projects | none, read, manage | Projects and project membership |
automation | none, read, manage | Schedules, firing history, and workflow generation |
billing | none, read, manage | Usage, credits, plans, invoices, controls, and rewards |
webhooks | none, manage | Custom webhook ingestion |
Read endpoints require the corresponding read level (or manage, where the
family supports it). Mutations require manage plus the exact action grant.
The team or project permission policy is still evaluated last and may deny the
request or require approval.
Action grants
| Family | Actions |
|---|---|
| Projects | project.create, project.update, project.delete, project.member.add, project.member.remove |
| Automation | schedule.create, schedule.trigger, schedule.delete, workflow.generate |
| Billing | billing.native_subscription.update, billing.native_subscription.cancel, billing.native_subscription.resume, billing.usage_alert.update, billing.usage_alert.delete, billing.spend_limit.raise, billing.spend_limit.lower, billing.spend_limit.delete, billing.auto_top_up.raise, billing.auto_top_up.lower |
| Webhooks | webhook.event.ingest |
An action grant narrows what the credential may attempt; it never bypasses the organization's permission policy.
Endpoint families
| Family | Paths | Examples |
|---|---|---|
| Identity | /v1/me | Inspect the current API key |
| Workspace | /v1/config, /v1/teams/* | Read configuration, teams, and members |
| Projects | /v1/teams/:teamId/projects/* | List, create, update, archive, and manage members |
| Billing | /v1/billing/* | Query usage and credits; manage subscriptions, alerts, limits, top-ups |
| Schedules | /v1/schedules/* | List schedules and firings; create, trigger, and delete schedules |
| Workflows | /v1/workflows/* | List templates, build prompts, and generate workflow code |
| Webhooks | /v1/webhooks/custom | Ingest custom webhook events |
The unversioned /, /health, and /version service endpoints are also in
the OpenAPI document.
Billing resources
Billing read access covers charges, contract commitments, metering events, usage queries and summaries, credit balance and ledger, plans and the current subscription, invoices, controls, features, entities, rewards, referral overview, alerts, spend limits, and auto-top-ups.
Only resources documented in the Developer API contract are available to API keys. Product administration and service operations are not Developer API resources.