The contract is the documentation
The live OpenAPI document is the source of truth for routes, schemas, parameters, and examples:operationIds, tags, and schemas are maintained there first.
The Endpoints section of this tab is generated directly from that document: every operation gets a page at /api-reference/{area}/{operation} with its parameters, request and response schemas, code samples, and a playground. Because the pages come from the contract, they stay in step with the API.
Start here
CLI
sumcli covers this whole surface and handles token exchange for you. Start here unless you need raw HTTP.Authentication
Get a bearer token: device login for people, M2M credentials for automation.
Conventions
Errors, streaming, pagination, and rate limits.
Resources
Per-area guidance: conversations, projects and files, reports, workflows, tables, connections.
What’s available
The Resources in this tab cover each area’s operations plus the semantics the contract can’t express: which writes are full replaces, which calls send real email, and where the app and the API disagree on naming. Start there rather than with the raw endpoint list.
Not everything the product does has an API yet. API coverage is the honest list of what’s missing.
Custom verification tests
Administrative clients can manage declarative custom tests, which extend artifact verification, through the stable public surface:
Scopes are
tenant, project, and artifact. Tenant scope derives the organization from the
authenticated principal and rejects scope_id; project and artifact require one. An op=remove
overlay suppresses a test ref from the resolved set and requires confirm=true. Detaching an
attachment removes the overlay row itself; these are intentionally different operations. Tenant-wide
writes are available only to organizations approved for verification-policy administration.
Use sumcli verification-tests for offline YAML/JSON validation and operator cross-org workflows;
the trusted target-org transport detail is not part of the public OpenAPI contract.
Building an agent rather than an app? The MCP Server wraps this API in curated tools with the safety rails already in place: a deliberately narrower, non-destructive subset.