Platform API
The AI operating engine, available as an API
Your assets, brand standards, knowledge and agents — the platform your teams work in, called from the systems you already run. Two headers authenticate a request, and the database enforces what it can reach.
GET /api/v1/agents?limit=2
X-Api-Key: gai_9f3c…
X-Tenant-Id: 3f2a9c1e-7b44-4c0d-9d2f-8a1b…
{
"data": [
{ "agent_name": "Sales Enablement", … },
{ "agent_name": "Brand Reviewer", … }
],
"has_more": false,
"next_cursor": null
}- 556 operations
- 67 objects
- OpenAPI 3.1, generated from the running service
What the key reaches
One API over the whole platform
There is no separate integration product. The endpoints below are the same ones the GenuineAI app calls, under the same permissions and the same license entitlements as the people using it.
Assets and media
Move files in through signed URLs, then read a library that tags, describes, de-duplicates and recognizes the people in your photography on its own.
- /files
- /albums
- /people
- /storage
Brand and creative
Fill templates from your own data, restyle work to the brand kit, and export finished artwork, decks and infographics.
- /designs
- /presentations
- /infographics
- /studio
Knowledge and context
Load the context your answers depend on, import and export it in bulk, and search across everything the workspace holds.
- /knowledge-bases
- /search
- /memories
Agents and conversation
Run your configured agents from inside your own product. Thread events stream over SSE while a reply is still being written.
- /agents
- /threads
- /prompts
Automation
Compile, deploy and start multi-step workflows, hand a task to autopilot, and read back every run and every step.
- /workflows
- /tasks
- /executions
Channels and publishing
Generate and approve website content, sync it two ways with your CMS, publish to social, and run the widgets and phone lines your customers reach.
- /sites
- /social
- /chat-widgets
- /voice-agents
Why it is safe to build on
Built-in guarantees
Each of these is a property of how the service is built rather than a policy someone has to keep following, which is why we can state it plainly.
A workspace cannot read another workspace's rows
Isolation is a row-level security policy in the database, not a WHERE clause somebody remembered to write. Every request opens a transaction that declares its workspace first, and a query that forgets its filter returns nothing rather than someone else's data.
A key can only ever narrow
A key acts as the person who issued it and can never do more than they can. key_permissions narrows it further, an IP allowlist and an expiry bound it, only a digest is stored, and revoking takes effect on the next request.
One error shape, and a closed list of codes
Every failure is application/problem+json carrying a code from a fixed vocabulary — enforced closed, so a code minted by a provider we call never reaches you wearing ours. Branch on it; it is part of the contract.
The reference is generated, not written
The spec is built by walking the running router, and the permission shown on each operation is read out of the middleware that enforces it. The service refuses to start if a route declares no gate at all.
Read the reference →After it is live
Visibility into what the integration did
Audit history, the access log, AI spend and storage are ordinary endpoints, so the reporting your governance asks for is something you can pull rather than request.
- GET /admin/history
- Who changed what, when, and what the row looked like before.
- GET /admin/log
- Every API call made against the workspace, with its outcome.
- GET /usage/*
- AI spend by user, model, module and day — against the plan.
- GET /storage/*
- What is stored, what is holding on to it, and what can be freed.
Limits are applied at the edge and every response names the tiers governing it in a RateLimit-Policy header, so a client can read its own budget instead of guessing at one. See rate limits.
Getting access
API access is switched on per workspace and keys are issued from account settings. A key rejected with license_required means the module is not enabled yet — your account team turns it on. Questions about an integration go to support@genuinehq.com.
