Skip to content

API basics

Every endpoint is described in the API reference.

  • Machines: mutual TLS over TLS 1.3, with a certificate from the cell’s client CA.
  • People: the session token from a passkey sign-in, in Authorization: Bearer <token>.
  • Browser requests must carry an allowed Origin. The API sets no cookies.

GET /v1/meta needs no authentication; it reports the role (cell or platform), the tenant, the region, the version and the passkey domain.

Errors are RFC 9457 application/problem+json:

{"status": 409, "code": "not_decidable", "title": "Conflict", "detail": "...", "type": "https://reindeer.invalid/problems/not_decidable"}

code is the stable member. 429 and 503 answers carry Retry-After.

Session creation, exports and deletions accept an Idempotency-Key (up to 255 characters, kept for seven days):

  • A repeat with the same key returns the stored answer with Idempotency-Replayed: true.
  • 409 idempotency_in_flight while the first request runs.
  • 422 idempotency_mismatch with a different body.

The change feed takes an opaque cursor (or head), limit and wait, and returns next_cursor. Journals and audit events page with after or before and limit.

Limit Value
Request rate 50 per second per identity, burst 100
Default time budget 30 seconds
Change feed 90 seconds
Dry run 5 minutes
Approval decision 6 minutes
Deletion request 10 minutes
Batch upload 1 hour
Export part 6 hours

A request that runs out of its budget before its change is stored answers 503 timeout; a stored change is always answered.