API basics
Every endpoint is described in the API reference.
Authentication
Section titled “Authentication”- Machines: mutual TLS over TLS 1.3, with a certificate from the cell’s client CA.
- People: the session token from a passkey sign-in, in
Authorization: Bearer <token>. - Browser requests must carry an allowed
Origin. The API sets no cookies.
GET /v1/meta needs no authentication; it reports the role (cell or platform), the tenant, the region, the version and the passkey domain.
Errors
Section titled “Errors”Errors are RFC 9457 application/problem+json:
{"status": 409, "code": "not_decidable", "title": "Conflict", "detail": "...", "type": "https://reindeer.invalid/problems/not_decidable"}code is the stable member. 429 and 503 answers carry Retry-After.
Safe retries
Section titled “Safe retries”Session creation, exports and deletions accept an Idempotency-Key (up to 255 characters, kept for seven days):
- A repeat with the same key returns the stored answer with
Idempotency-Replayed: true. 409 idempotency_in_flightwhile the first request runs.422 idempotency_mismatchwith a different body.
Cursors and paging
Section titled “Cursors and paging”The change feed takes an opaque cursor (or head), limit and wait, and returns next_cursor. Journals and audit events page with after or before and limit.
Limits and time budgets
Section titled “Limits and time budgets”| Limit | Value |
|---|---|
| Request rate | 50 per second per identity, burst 100 |
| Default time budget | 30 seconds |
| Change feed | 90 seconds |
| Dry run | 5 minutes |
| Approval decision | 6 minutes |
| Deletion request | 10 minutes |
| Batch upload | 1 hour |
| Export part | 6 hours |
A request that runs out of its budget before its change is stored answers 503 timeout; a stored change is always answered.