AuraOne / Enterprise Intelligence / Developers
The same platform your workflow runs on, over an API.
Every scoped Enterprise Intelligence workflow exposes the same surface the platform uses: workflows, runs, deliveries, human review, connectors, evaluations, and regression control under /api/v1.
Preview. API access is provisioned per engagement under the public API contract — this page documents the contract, not a self-serve signup.
- Base host
- api.auraone.ai (app.auraone.ai serves the same route tree)
- Route shape
- /api/v1/enterprise-intelligence/... — there is no /v1 rewrite
- Credential
- ak_ API keys or session Bearer JWTs, bound to one organization
Public API contract
Exactly what the contract guarantees
The public contract is documented at docs/api/public-api-contract.md and enforced in CI by the SDK route-contract check. The rules below are the contract, verbatim in substance.
- Hosts
- api.auraone.ai is the preferred base URL for machine clients; api-staging.auraone.ai runs the live contract suiteContract §Hosts
- Routes
- Versioned public routes live under /api/v1/*; a request to /v1/* hits the login redirect, not the APIContract §Route shape
- API keys
- Format ak_<8 lowercase hex>_<64 lowercase hex>; send as Authorization: Bearer ak_… or x-api-key; legacy aura_*/aoc_* formats are not acceptedContract §Credentials
- Organization
- Your organization is derived from the key record — never from X-Org-Id or other headers, which middleware scrubs inboundContract §Organization scoping
- CSRF
- A cookieless request carrying Authorization or x-api-key skips session CSRF; cookie-authenticated browser calls still need x-csrf-tokenContract §CSRF
- Key minting
- POST /api/v1/api-keys is the only public mint route and requires an interactive session; requested scopes are bounded by the minter's permissionsContract §Key minting
Route families
The Enterprise Intelligence surface, family by family.
Every route enforces organization binding from the credential, scope enforcement, and audit events on mutating handlers. Access to these families is provisioned with a scoped engagement.
| API family | Covers | Surface |
|---|---|---|
/api/v1/enterprise-intelligence/workflows | Workflow definitions, versions, activations, approval requests, per-workflow evaluations, and release gates | Workflow scoping and versioning |
/api/v1/enterprise-intelligence/runs | Runs plus per-run acceptance, cancel, commercial terms, compensations, delivery, incidents, output, replay, and trace | Run lifecycle and evidence |
/api/v1/enterprise-intelligence/deliveries | Accepted deliveries and per-delivery detail | Delivery receipts |
/api/v1/enterprise-intelligence/batches | Batch ingest, items, acceptance, cancel, and retry | Batch intake |
/api/v1/enterprise-intelligence/human-tasks | Review tasks and completion for cases that pause for qualified review | Human review |
/api/v1/enterprise-intelligence/connectors | Connector registration, authorization, receipts, test, and revocation | Integrated systems |
/api/v1/enterprise-intelligence/tool-bindings | Tool bindings attached to approved workflow versions | Bound actions |
/api/v1/enterprise-intelligence/evaluations | Evaluation records that judge workflow versions and candidates | Evaluation |
/api/v1/enterprise-intelligence/improvement-items | Named failures and improvement targets with owner and status | Model improvement |
/api/v1/enterprise-intelligence/regression-suites | Regression suites, runs, exports, and per-candidate review | Regression control |
/api/v1/enterprise-intelligence/historical-sets | Historical task sets: register, examples, validation, baseline, dataset, acceptance | Evidence data |
/api/v1/enterprise-intelligence/context-sources | Context source registration, ingest, retry, and withdraw | Permissioned context |
/api/v1/enterprise-intelligence/registry | Model, prompt, tool, node-option, and policy registries | Scoped registries |
/api/v1/enterprise-intelligence/operations | Operations metrics, SLOs, and release-gate state | Operations |
/api/v1/enterprise-intelligence/settings | Per-organization EI settings, dashboard, and health | Administration |
SDK clients
Typed clients under the same contract
Preview. The TypeScript and Python SDKs ship Enterprise Intelligence services that target exactly these route families; the route-contract check fails a release if an SDK method targets a missing or excluded route.
- TypeScript
- @auraone/sdk exposes an enterpriseIntelligence service covering workflows, runs, deliveries, and reviewsdks/typescript
- Python
- aura_one exposes an enterprise_intelligence service with the same route coveragesdks/python
- Contract tests
- sdks/contract-tests runs the live contract suite against api-staging.auraone.ai on releaseSDK staging contract
- Access
- Keys are minted inside a scoped engagement through POST /api/v1/api-keys; there is no anonymous tierContract §Key minting