API Reference

Resource-oriented REST, JSON, versioned at /v1. Read Conventions first — every other page here assumes it.

Group Covers
Conventions Base URL, auth header, pagination, idempotency, error shape, ID format.
Auth Signup, login, MFA, sessions, password and email lifecycle, invitations, and app tokens (embedded, and hosted + PKCE).
Users Account lifecycle.
Profiles Global and per-app identity data.
Settings Global and per-app configuration.
Applications The app catalog.
Entitlements Grant, toggle, revoke access to an app — the on/off switch.
Roles & Permissions Assign/remove roles; resolve effective permissions.
Organizations Team/seat management.
Tenancy Where a Tenant’s data lives, and the (support-only) process to change it.
Billing The Application owner’s own Substratal subscription: plan, usage, Stripe Checkout and Portal.
Audit Query the audit log.
Webhooks Subscribe to access-change events, including the required access.revoked.
API Keys Service-to-service credentials — how billing or an app’s own backend authenticates.

These pages specify the target contract for an API that does not yet exist. If you’re implementing against this, these are the shapes to build toward — check the repository’s actual code for what’s already real before assuming a page here is live.

Calling this from an AI agent rather than writing HTTP calls by hand? See MCP Server — a tool-call interface generated from openapi.yaml, not a separate contract from the one on this page.


Table of contents


Back to top

Substratal Apps Platform API — living specification. This site is the system of record; see git history for how it has changed over time.

This site uses Just the Docs, a documentation theme for Jekyll.