AuraOne / Enterprise Intelligence / Developers

The same platform your workflow runs on, over an API.

Every scoped Enterprise Intelligence workflow exposes the same surface the platform uses: workflows, runs, deliveries, human review, connectors, evaluations, and regression control under /api/v1.

Preview. API access is provisioned per engagement under the public API contract — this page documents the contract, not a self-serve signup.

Base host
api.auraone.ai (app.auraone.ai serves the same route tree)
Route shape
/api/v1/enterprise-intelligence/... — there is no /v1 rewrite
Credential
ak_ API keys or session Bearer JWTs, bound to one organization

Public API contract

Exactly what the contract guarantees

The public contract is documented at docs/api/public-api-contract.md and enforced in CI by the SDK route-contract check. The rules below are the contract, verbatim in substance.

Public contract — canonical
Hosts
api.auraone.ai is the preferred base URL for machine clients; api-staging.auraone.ai runs the live contract suiteContract §Hosts
Routes
Versioned public routes live under /api/v1/*; a request to /v1/* hits the login redirect, not the APIContract §Route shape
API keys
Format ak_<8 lowercase hex>_<64 lowercase hex>; send as Authorization: Bearer ak_… or x-api-key; legacy aura_*/aoc_* formats are not acceptedContract §Credentials
Organization
Your organization is derived from the key record — never from X-Org-Id or other headers, which middleware scrubs inboundContract §Organization scoping
CSRF
A cookieless request carrying Authorization or x-api-key skips session CSRF; cookie-authenticated browser calls still need x-csrf-tokenContract §CSRF
Key minting
POST /api/v1/api-keys is the only public mint route and requires an interactive session; requested scopes are bounded by the minter's permissionsContract §Key minting

Route families

The Enterprise Intelligence surface, family by family.

Every route enforces organization binding from the credential, scope enforcement, and audit events on mutating handlers. Access to these families is provisioned with a scoped engagement.

Enterprise Intelligence route families under /api/v1/enterprise-intelligence
API familyCoversSurface
/api/v1/enterprise-intelligence/workflowsWorkflow definitions, versions, activations, approval requests, per-workflow evaluations, and release gatesWorkflow scoping and versioning
/api/v1/enterprise-intelligence/runsRuns plus per-run acceptance, cancel, commercial terms, compensations, delivery, incidents, output, replay, and traceRun lifecycle and evidence
/api/v1/enterprise-intelligence/deliveriesAccepted deliveries and per-delivery detailDelivery receipts
/api/v1/enterprise-intelligence/batchesBatch ingest, items, acceptance, cancel, and retryBatch intake
/api/v1/enterprise-intelligence/human-tasksReview tasks and completion for cases that pause for qualified reviewHuman review
/api/v1/enterprise-intelligence/connectorsConnector registration, authorization, receipts, test, and revocationIntegrated systems
/api/v1/enterprise-intelligence/tool-bindingsTool bindings attached to approved workflow versionsBound actions
/api/v1/enterprise-intelligence/evaluationsEvaluation records that judge workflow versions and candidatesEvaluation
/api/v1/enterprise-intelligence/improvement-itemsNamed failures and improvement targets with owner and statusModel improvement
/api/v1/enterprise-intelligence/regression-suitesRegression suites, runs, exports, and per-candidate reviewRegression control
/api/v1/enterprise-intelligence/historical-setsHistorical task sets: register, examples, validation, baseline, dataset, acceptanceEvidence data
/api/v1/enterprise-intelligence/context-sourcesContext source registration, ingest, retry, and withdrawPermissioned context
/api/v1/enterprise-intelligence/registryModel, prompt, tool, node-option, and policy registriesScoped registries
/api/v1/enterprise-intelligence/operationsOperations metrics, SLOs, and release-gate stateOperations
/api/v1/enterprise-intelligence/settingsPer-organization EI settings, dashboard, and healthAdministration

SDK clients

Typed clients under the same contract

Preview. The TypeScript and Python SDKs ship Enterprise Intelligence services that target exactly these route families; the route-contract check fails a release if an SDK method targets a missing or excluded route.

Preview
TypeScript
@auraone/sdk exposes an enterpriseIntelligence service covering workflows, runs, deliveries, and reviewsdks/typescript
Python
aura_one exposes an enterprise_intelligence service with the same route coveragesdks/python
Contract tests
sdks/contract-tests runs the live contract suite against api-staging.auraone.ai on releaseSDK staging contract
Access
Keys are minted inside a scoped engagement through POST /api/v1/api-keys; there is no anonymous tierContract §Key minting