Skip to content
This page is a stub. It records what belongs here and is not written yet. Contributions are welcome.

API reference

Depot is the server an organisation runs, and its REST API is the one an operator, a script or an agent calls. Everything a console does, it does through these routes.

This section is generated. On every build the site reads the OpenAPI document Depot serves at /openapi/v1.json, which Depot builds from its own route table. What is documented is therefore what is mounted, and a route that is renamed in the product is renamed here on the next release.

ReferenceWhat it covers
Depot REST APIEndpoints, alerts, scripts, profiles, tickets, documents, projects and billing
Agent gRPC APIThe contract between an Agent and its Depot
AuthenticationHow to get a credential for each of them

The Agent does not use the REST API. It talks to its Depot over gRPC with mutual TLS, and that contract is generated from the protocol buffers.

Every operation carries a row of badges. They come from the route table, not from a person’s judgement about what the route is for.

BadgeWhat it means
A permission such as alert:ackThe caller needs this permission. No badge and no public marker means the route is behind a session alone
A face such as tenant faceWhich interface the route is mounted on: tenant, MSP, shared or public
A mode such as mspWhich licensed modes have this route. A Depot in a mode that is not listed does not serve it
IdempotentSending the same request twice has the same effect as sending it once
WebSocket or Server sent eventsThe response is a stream. The sample shows the handshake
Token in the pathThe URL itself is the credential. Treat the whole URL as a secret
Not fully resolvedPart of the route could not be read from the source. The operation says which part

An MSP console reaches one client’s data by prefixing the path. Where that applies, the operation says so under its badges.

The reference tracks the released version of Depot, which is named on the service overview page. There is no API version negotiation beyond the /api/v1/ prefix in the paths.

Anchors are stable. Every operation heading has an id equal to its operation id, such as depot.alerts.acknowledge, so a deep link keeps working when the heading is reworded.

Everything here is also available in a form a program can read:

  • The OpenAPI document itself, served by a running Depot at /openapi/v1.json.
  • A plain Markdown twin of every page on this site, at the page URL plus index.md.
  • The page manifest at /api/pages.json.

This page is an outline. It still needs:

  • A worked first request, end to end.
  • Rate limit and pagination conventions in one place, rather than per operation.
  • The error catalogue: which problem types a caller should handle.
  • A short note on which routes an AI agent should never call unattended.

Content is licensed CC BY 4.0. Code samples are MIT. Outpost and the Outpost mark are trademarks of Outpost Business Solutions, PBC and are not covered by either licence.