REST API reference
Generated from the OpenAPI 3.1 document the API publishes, which is built from the schemas the API validates every request with. Every section has its own page; this one lists every operation.
curl https://api.loopback.so/v1/openapi.json- Base URL
https://api.loopback.so- Version
1.0.0- Operations
241
Sections40
- agency
- analytics
- approvals
- audit
- auth
- billing
- brand
- channels
- claims
- connectors-admin
- domains
- email-webhooks
- error-groups
- files
- github
- health
- ingest
- invitations
- jobs
- mcp
- me
- members
- onboarding
- openapi
- orgs
- patterns
- privacy
- public
- referrals
- releases
- repositories
- runner
- sentry-webhook
- sourcemaps
- sso
- stripe-webhooks
- tickets
- tokens
- widget
- workspaces
agency
11 operations- GET
/v1/agency/clients/{id}One client: its card, service levels, report settings and consent. - GET
/v1/agency/overviewOne card per client: open tickets, approvals, escalations, medians, releases. - GET
/v1/agency/partnerThe agency partner profile, certification and referred customers. - PUT
/v1/agency/partnerCreates or changes the public partner profile; certification is decided by staff. - GET
/v1/agency/queueApprovals and escalations of every client in one queue, with the SLA timers. - GET
/v1/agency/reportsMonthly client reports, newest month first (clients see their own). - POST
/v1/agency/reportsGenerates the report of a client for a month (idempotent per month). - GET
/v1/agency/reports/{id}One monthly client report. - POST
/v1/agency/reports/{id}/sendEmails the report with the agency brand to its recipients. - GET
/v1/agency/resaleResale prices, workspace costs and margins of every client. - GET
/v1/agency/white-labelWhite-label readiness of every client: brand, sender, domains.
analytics
2 operationsapprovals
1 operationaudit
7 operations- GET
/v1/auditThe organization’s audit log, newest first, with filters (owners and admins). - GET
/v1/audit/exportExports the entries matching the filters as CSV or JSON Lines (Enterprise). - GET
/v1/audit/streamThe SIEM stream of the audit log and its delivery state. - PUT
/v1/audit/streamCreates or changes the SIEM stream (Enterprise); the signing secret is shown once. - DELETE
/v1/audit/streamRemoves the SIEM stream and its signing secret. - POST
/v1/audit/stream/rotate-secretReplaces the signing secret of the SIEM stream; the new one is shown once. - POST
/v1/audit/stream/testSends a signed test batch to the SIEM endpoint.
auth
12 operations- GET
/v1/auth/github/callbackGitHub OAuth callback: signs in or links, then redirects to the dashboard. - GET
/v1/auth/github/startStarts the GitHub sign-in (or links GitHub to the signed-in user): redirects to GitHub. - POST
/v1/auth/loginOpens a session with email and password. - POST
/v1/auth/logoutCloses the current session; without one it still succeeds and clears the cookie. - POST
/v1/auth/magic-linkEmails a one-time sign-in link (same answer whether or not the address exists). - POST
/v1/auth/magic-link/verifyConsumes a sign-in link and opens a session. - GET
/v1/auth/meCurrent user, organization, plan, accessible workspaces and session expiry. - POST
/v1/auth/password-resetEmails a password reset link (same answer whether or not the address exists). - POST
/v1/auth/password-reset/confirmSets a new password, closes every other session and opens a new one. - POST
/v1/auth/signupCreates the organization and its owner, then opens a session. - POST
/v1/auth/verify-emailConfirms the email address of the account; signs in only when nobody is signed in (409 when signed in as someone else). - POST
/v1/auth/verify-email/resendSends the verification email again.
billing
15 operations- GET
/v1/billingPlan, subscription, usage, credits, spend cap, add-ons, invoices and agency billing. - PUT
/v1/billing/addons/badge-removalAdds or removes the badge removal add-on (Managed). - POST
/v1/billing/cancelCancels the subscription at the end of the paid period. - POST
/v1/billing/checkoutStripe Checkout for a plan: 14-day trial with a card on file (first subscription only). - POST
/v1/billing/connect/onboardingAgency: creates the Stripe Connect account if needed and returns its onboarding link. - GET
/v1/billing/creditsFix credit grants with their expiry, and the latest credit movements. - GET
/v1/billing/invoicesInvoices of the organization, newest first. - POST
/v1/billing/open-sourcePuts an organization without a plan on the free Open Source plan (public repositories only); audited. - PUT
/v1/billing/overageTurns paid fixes beyond every credit on or off. - POST
/v1/billing/planSwitches the plan of the current subscription in the app (prorated). - POST
/v1/billing/portalStripe Customer Portal: payment methods, invoices, billing details, cancellation. - PUT
/v1/billing/spend-capSets or removes the monthly spend cap (alert at 80 %, jobs blocked at 100 %). - POST
/v1/billing/topupsStripe Checkout for a pack of fix credits (one-time payment). - PUT
/v1/billing/workspaces/{id}/managedAgency: turns the Managed add-on of a client workspace on or off. - PUT
/v1/billing/workspaces/{id}/resaleAgency: the resale price of a client workspace and collection through Stripe Connect.
brand
11 operations- GET
/v1/brandBrand profiles, their workspaces and what the plan allows (owner, admin). - POST
/v1/brand/profilesCreates a brand profile (owner, admin). - GET
/v1/brand/profiles/{id}One brand profile. - PATCH
/v1/brand/profiles/{id}Changes a brand profile; the color is darkened to WCAG AA when needed. - DELETE
/v1/brand/profiles/{id}Deletes a brand profile; its workspaces fall back to the default. - PUT
/v1/brand/profiles/{id}/logoUploads the logo (PNG, JPEG or WebP, at most 512 KiB). - DELETE
/v1/brand/profiles/{id}/logoRemoves the logo: surfaces show the name as text. - PUT
/v1/brand/profiles/{id}/status-domainSets the custom status domain and returns the DNS records to publish. - DELETE
/v1/brand/profiles/{id}/status-domainRemoves the custom status domain: status pages go back to the default host. - POST
/v1/brand/profiles/{id}/status-domain/verifyChecks the DNS records of the status domain now. - PUT
/v1/brand/workspaces/{id}Chooses the brand profile of a workspace (null: the default).
channels
7 operations- GET
/v1/channels/{workspaceId}Inbox, forwarding, sending address and recent mail of a workspace. - PATCH
/v1/channels/{workspaceId}Turns the inbox on or off and chooses whether list mail opens tickets (owner, admin). - PUT
/v1/channels/{workspaceId}/forwardingRecords the support address the customer forwards to the inbox (owner, admin). - DELETE
/v1/channels/{workspaceId}/forwardingForgets the forwarded support address (owner, admin). - POST
/v1/channels/{workspaceId}/forwarding/testSends a test email to the support address; its return proves the forwarding. - GET
/v1/channels/{workspaceId}/inboundReceived email of the workspace, newest first, with what happened to each. - POST
/v1/channels/{workspaceId}/inbound/{provider}/{emailId}/releaseLets a quarantined email through: it opens (or joins) a ticket (owner, admin).
claims
2 operationsconnectors-admin
10 operations- GET
/v1/connectorsLog connectors of a workspace with status, last activity, events in 24 hours, masked secrets. - POST
/v1/connectorsCreates a connector; the generic endpoint token is in this answer only. - GET
/v1/connectors/{id}One connector. - PATCH
/v1/connectors/{id}Changes name, settings or secrets (only those sent are replaced). - DELETE
/v1/connectors/{id}Deletes a connector and its secrets; stored error events stay until retention. - POST
/v1/connectors/{id}/pauseStops polling and ingestion until it is resumed. - POST
/v1/connectors/{id}/resumeResumes a paused connector; polling restarts at once. - POST
/v1/connectors/{id}/rotate-tokenGeneric endpoint: a new token, in this answer only; the old one stops working. - POST
/v1/connectors/{id}/testTests the connection with the stored settings and records the outcome. - GET
/v1/connectors/setup/cloudwatchThe external id issued for the workspace and the IAM policies of a CloudWatch role.
domains
6 operations- GET
/v1/domainsEmail domains of a workspace's brand: its own profile and, for agencies, the default. - POST
/v1/domainsRegisters a sending or receiving domain with the email provider (owner, admin). - GET
/v1/domains/{brandProfileId}/{purpose}A domain and its records; refreshes the status from the provider when it is stale. - DELETE
/v1/domains/{brandProfileId}/{purpose}Removes the domain from the provider and from the brand profile (owner, admin). - PATCH
/v1/domains/{brandProfileId}/{purpose}/senderChanges the From address or name on a sending domain (owner, admin). - POST
/v1/domains/{brandProfileId}/{purpose}/verifyAsks the provider to check the DNS records now (owner, admin).
email-webhooks
1 operationerror-groups
6 operations- GET
/v1/error-groupsError groups by last seen with users, trend, release, status, trigger and ticket; the proactive summary of one workspace. - GET
/v1/error-groups/{id}One error group: sample events (masked), symbolicated stack, releases, environments. - POST
/v1/error-groups/{id}/ignoreIgnores the error in every release: kept and counted, never ticketed. - POST
/v1/error-groups/{id}/resolveMarks a group resolved, optionally in a release: a reappearance after it is a regression. - POST
/v1/error-groups/{id}/ticketOpens a proactive ticket now, or joins the open ticket that already reports the problem. - POST
/v1/error-groups/{id}/unignorePuts an ignored or resolved group back to watching (an ignored error: in every release).
files
1 operationgithub
9 operations- GET
/v1/githubThe GitHub App for this organization: status, installations, the user’s link. - POST
/v1/github/installInstall URL of the App with a single-use state bound to the organization. - POST
/v1/github/installationsLinks an installation after GitHub’s setup redirect, checked with the user’s GitHub account. - DELETE
/v1/github/installations/{id}Unlinks an installation and disconnects its repositories (the App stays on GitHub). - GET
/v1/github/installations/{id}/repositoriesRepositories the installation can reach, with their connection in the organization. - POST
/v1/github/installations/{id}/syncReads the installation from GitHub again (account, permissions, suspension). - GET
/v1/github/oss/{workspaceId}Open source settings of a workspace. - PATCH
/v1/github/oss/{workspaceId}Changes the open source settings of a workspace; audited. - POST
/v1/webhooks/githubGitHub App webhook: X-Hub-Signature-256 over the raw body, deduplicated by delivery.
health
2 operationsingest
1 operationinvitations
5 operations- GET
/v1/invitationsInvitations of the organization, newest first (owner, admin). - POST
/v1/invitationsInvites a person by email (owner, admin); the link is valid 7 days. - DELETE
/v1/invitations/{id}Revokes a pending invitation (owner, admin). - POST
/v1/invitations/acceptJoins the organization (creating the account if needed) and opens a session. - POST
/v1/invitations/previewShows who invited whom, before accepting (the emailed token is the credential).
jobs
9 operations- GET
/v1/jobs/{id}Job payload (ticket, logs, repository, workspace, limits); starts the job. - GET
/v1/jobs/{id}/agent-credentialThe Codex login (auth.json) the agent needs, locked to this job until it ends. - PUT
/v1/jobs/{id}/agent-credentialStores the refreshed Codex login and releases the lock. - POST
/v1/jobs/{id}/eventsAppends events to the job log (masked again before storing). - POST
/v1/jobs/{id}/git-tokenShort-lived installation token for the job repository (push: fix jobs only). - POST
/v1/jobs/{id}/heartbeatKeeps the job lease alive and reports a cancellation. - POST
/v1/jobs/{id}/pull-requestOpens or finds the PR of the verified loopback/ branch with the App token. - POST
/v1/jobs/{id}/resultFinal result of the job (idempotent); may chain the next job (`next_job_id`). - POST
/v1/jobs/{id}/tokenA fresh job token (and agent MCP token) for a running job, before the current expires.
mcp
1 operationme
1 operationmembers
3 operationsonboarding
15 operations- GET
/v1/onboardingThe onboarding wizard: steps, agent, demo, next steps. - POST
/v1/onboarding/agentStep 3: the execution of the answer, its credentials, the updated pull request. - POST
/v1/onboarding/completeEnds the wizard. - GET
/v1/onboarding/demoThe live view of the demo: email, status page, diagnosis, draft, pull request. - POST
/v1/onboarding/demoStarts the demo ticket (once per organization, at Loopback’s expense, cost cap). - POST
/v1/onboarding/demo/consentConsent to clone the repository in the Managed sandbox for the demo; granted starts it. - POST
/v1/onboarding/demo/retryRuns a demo that stopped without a diagnosis again, within its cost cap. - POST
/v1/onboarding/demo/workspaceWithout the consent: a test ticket through the workspace’s own runner or agent. - GET
/v1/onboarding/execution/{workspaceId}Execution settings of a workspace with the files the onboarding pull request writes. - PUT
/v1/onboarding/execution/{workspaceId}Changes mode, agent, authentication and credentials of a workspace (rule 6). - DELETE
/v1/onboarding/execution/{workspaceId}/credentials/{credentialId}Deletes a stored agent credential that no workspace uses (audited). - GET
/v1/onboarding/metricsStaff: signup → first diagnosis shown, demos by case, demo costs. - POST
/v1/onboarding/repositoryStep 1: the connected repository; opens the onboarding pull request. - POST
/v1/onboarding/steps/{step}Completes, skips (logs) or reopens a step. - POST
/v1/onboarding/workspaceThe workspace the wizard sets up (created with POST /v1/workspaces).
openapi
1 operationorgs
2 operationspatterns
6 operationsprivacy
4 operations- POST
/v1/privacy/closureCloses the organization: subscriptions end, sessions and tokens stop, its data is deleted within 30 days (owners). - POST
/v1/privacy/erasuresErases one end user by email or widget user id across tickets, subscriptions, identities, error events and reports (owners, admins). - POST
/v1/privacy/exportsExports the organization’s data: an archive is built and a download link is emailed to you (owners). - DELETE
/v1/privacy/tickets/{id}Deletes a ticket with its messages, files, subscribers, jobs and status page (owners, admins).
public
4 operations- GET
/v1/public/brandBrand of a verified white-label host (null for any other host). - POST
/v1/public/oss-sponsorship-requestsAsks for sponsored Managed credits for a public repository (reviewed by hand). - GET
/v1/public/partnersCertified partner agencies listed in the public directory, by name. - GET
/v1/public/statsPublic counters for the landing page: resolved tickets, releases, median resolution.
referrals
1 operationreleases
5 operations- GET
/v1/releasesRelease history with CI status, newest first, plus the open batched proposals. - GET
/v1/releases/{id}A release with its tickets, approvals, CI runs and pipeline log. - POST
/v1/releases/{id}/approveApproves a batched release proposal at the given SHA: tag, release and CI follow. - POST
/v1/releases/{id}/retryResumes a release that stopped after the merge: tag, GitHub Release, CI, notice. - POST
/v1/releases/{id}/versionSets the version of a release that waits for one (manual strategy).
repositories
9 operations- GET
/v1/repositoriesConnected repositories the user can see, by workspace. - POST
/v1/repositoriesConnects a repository of an installation to a workspace (plan limits apply). - GET
/v1/repositories/{id}A connected repository with its onboarding, secret and open source activity. - DELETE
/v1/repositories/{id}Disconnects a repository; its code index cache is deleted. - PUT
/v1/repositories/{id}/agent-keyStores the agent key as the Actions secret LOOPBACK_AGENT_KEY (last 4 kept). - POST
/v1/repositories/{id}/guidelinesReads CONTRIBUTING and CODE_OF_CONDUCT of a public repository again. - POST
/v1/repositories/{id}/labelsCreates the open source labels (loopback, no-loopback) in the repository. - POST
/v1/repositories/{id}/onboarding-prOpens or updates the onboarding pull request "Add Loopback". - POST
/v1/repositories/{id}/refreshReads name, default branch and visibility from GitHub again.
runner
2 operationssentry-webhook
1 operationsourcemaps
4 operations- GET
/v1/sourcemapsSource maps of one release, by bundle URL path (owner, admin, reviewer). - POST
/v1/sourcemapsStores the source maps of a release, used to symbolicate minified stack traces. - DELETE
/v1/sourcemapsRemoves every source map of a release (owner, admin). - GET
/v1/sourcemaps/releasesReleases of a workspace with uploaded source maps (owner, admin, reviewer).
sso
22 operations- GET
/v1/auth/sso/completeOpens the session of a validated SAML sign-in, in the browser that started it. - GET
/v1/auth/sso/connections/{id}The organization and name of a connection, for the app tile confirmation page. - POST
/v1/auth/sso/connections/{id}/startStarts the sign-in of one connection, once confirmed on the app’s own page. - GET
/v1/auth/sso/loginIdentity provider app tile: redirects to the confirmation page, where the sign-in starts with a same-origin request. - GET
/v1/auth/sso/oidc/callbackOIDC callback: exchanges the code, signs in, then redirects to the dashboard. - POST
/v1/auth/sso/recoveryBreak-glass sign-in of an owner while single sign-on is required (password and a single-use recovery code). - POST
/v1/auth/sso/saml/{id}/acsSAML assertion consumer service (HTTP-POST binding): validates the response, then 303 to the completion step. - GET
/v1/auth/sso/saml/{id}/metadataSAML service provider metadata of a connection (entity id, ACS URL). - POST
/v1/auth/sso/startReturns the identity provider URL for the email domain (404 when it has no SSO). - GET
/v1/securitySingle sign-on and approval governance of the organization (owners and admins). - PUT
/v1/security/governanceSets how many approvers a fix or release needs, and which roles approve (owners). - POST
/v1/security/sso/connectionsAdds an OIDC or SAML connection (owners; plans with single sign-on). - PATCH
/v1/security/sso/connections/{id}Changes a connection; a new client secret replaces the stored one (provider settings and domains: owners). - DELETE
/v1/security/sso/connections/{id}Removes a connection and its client secret (owners). - POST
/v1/security/sso/connections/{id}/testChecks the identity provider settings (OIDC discovery, SAML certificate). - POST
/v1/security/sso/connections/{id}/unlinkUnlinks a member from their identity at the provider (owners); the next sign-in links again. - POST
/v1/security/sso/domainsClaims an email domain and returns the TXT record that proves it (owners). - DELETE
/v1/security/sso/domains/{domain}Removes a domain from single sign-on (owners). - POST
/v1/security/sso/domains/{domain}/verifyLooks up the TXT record of a claimed domain (owners). - PUT
/v1/security/sso/enforcementRequires single sign-on for the organization, or stops requiring it (owners). - POST
/v1/security/sso/recovery-codesReplaces the break-glass recovery codes (owners); the old ones stop working. - POST
/v1/security/sso/released-addressesFrees an address of a verified domain from an account of another organization, which is closed (owners).
stripe-webhooks
2 operationstickets
24 operations- GET
/v1/ticketsInbox and unified queue: filters, search, cursor pagination. - GET
/v1/tickets/{id}The ticket page: conversation, diagnosis, drafts, fixes with diff, release, audit, jobs. - POST
/v1/tickets/{id}/approveApprova e rilascia: approves the fix at the exact SHA; merge, tag and release follow. - POST
/v1/tickets/{id}/assignAssigns the ticket to a team member who can open its workspace (null unassigns). - POST
/v1/tickets/{id}/back-to-approvalRiporta in approvazione: an escalated ticket whose verified fix was never merged (its release stopped before the merge) goes back to awaiting approval, with its open PR (approver roles). - POST
/v1/tickets/{id}/closeCloses the ticket (a duplicate subscribes its customer to the original). - POST
/v1/tickets/{id}/draftsWrites a reply or an information request of the team (an escalated ticket, a discarded draft): a draft, sent by its own click. - PATCH
/v1/tickets/{id}/drafts/{draftId}Saves edits to a draft and to the proposed public summary. - POST
/v1/tickets/{id}/drafts/{draftId}/discardDiscards a draft. - POST
/v1/tickets/{id}/drafts/{draftId}/sendSends a draft to the customer after the click (white-label guard for agencies). - POST
/v1/tickets/{id}/escalateHands the ticket to a person, with the reason (the team is notified). - GET
/v1/tickets/{id}/fix-attempts/{fixAttemptId}/diffUnified diff of a fix attempt (its pull request on GitHub). - POST
/v1/tickets/{id}/fix-in-managedFix in Managed with a credit: an escalated bug of a BYO workspace is fixed in the Managed sandbox, paid with one fix credit (approver roles). A fix still queued for the workspace runner or agent is replaced; one at work refuses it (409 fix_job_active). - GET
/v1/tickets/{id}/jobs/{jobId}/eventsLog of one job of the ticket, oldest first. - POST
/v1/tickets/{id}/notesAdds an internal note to the conversation (never sent to the customer). - POST
/v1/tickets/{id}/open-prCopilot: opens the pull request of the verified fix branch. - POST
/v1/tickets/{id}/rejectRejects the fix: its PR is closed and the ticket goes to the team. - POST
/v1/tickets/{id}/release/retryResumes the release of a merged fix that stopped: tag, GitHub Release, CI and the notice, with the same approvals and SHA. - POST
/v1/tickets/{id}/reopenReopens the ticket into triage. - POST
/v1/tickets/{id}/request-changesAsks for a new fix attempt with the reviewer’s notes (the old PR is closed). - POST
/v1/tickets/{id}/status-linkRevokes or rotates the public status link of the ticket. - GET
/v1/tickets/{id}/subscribersEnd users told when the fix ships (emails masked). - POST
/v1/tickets/{id}/subscribersAdds an email address to the release notice of the ticket. - DELETE
/v1/tickets/{id}/subscribers/{subscriberId}Removes a subscriber of the ticket.
tokens
3 operationswidget
8 operations- GET
/v1/widget/configConfiguration of the widget for a public key: brand, texts, capture, passive collection. - POST
/v1/widget/eventsPassive error events (host consent required), stored for the proactive mode. - POST
/v1/widget/identifyLinks an end-user hash to an email (host consent required), for proactive notices. - POST
/v1/widget/reportsA report from the widget form: creates a ticket of origin widget. - GET
/v1/workspaces/{id}/widgetWidget settings of a workspace, with its install status and preview (owner, admin). - PATCH
/v1/workspaces/{id}/widgetChanges allowed origins, capture and passive collection of the widget (owner, admin). - POST
/v1/workspaces/{id}/widget/rotate-keyReplaces the public key; the old key stops working (owner, admin). - POST
/v1/workspaces/{id}/widget/test-reportSends a test report through the widget intake: a closed ticket, no tokens spent.
workspaces
5 operations- GET
/v1/workspacesWorkspaces the signed-in user can open, by name (team). - POST
/v1/workspacesCreates a workspace with its mailbox and widget install (owner, admin). - GET
/v1/workspaces/{id}One workspace with its settings (team). - PATCH
/v1/workspaces/{id}Changes the settings of a workspace (owner, admin); every change is audited. - POST
/v1/workspaces/{id}/archiveArchives a workspace: its mailbox stops receiving and its tokens are revoked.