openapi.yaml. This page covers behavior that the reference does not show well.
Every /v1 endpoint requires Authorization: Bearer <token> when server.auth.tokens is set. /health needs no token.
Run a flow
200 with the run result, even when a node failed. Check ok.
nodes is the trace: status (done, error or skipped), timing and result for each node, including decision probabilities.
Idempotency
Send anIdempotency-Key header to make retries safe. A retry with the same key and input returns the first successful result with Idempotent-Replayed: true and does not run the flow again. See enterprise integration for the limits.
Server-sent events
SendAccept: text/event-stream to receive events as they happen. Each event name matches its type: node:start, node:done, node:error, node:skipped, provider:call. The last event is result, which holds the run result. If the server is busy, the stream ends with a result event that carries an error, because the HTTP status is already sent. Closing the connection cancels the run.