Skip to main content

FastGateway API (1.0.0)

Download OpenAPI specification:Download

API for managing Kubernetes Gateway API resources

Auth

Authentication endpoints

Login with username and password

Request Body schema: application/json
required
username
required
string
password
required
string

Responses

Request samples

Content type
application/json
{
  • "username": "string",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "accessToken": "string",
  • "refreshToken": "string",
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "user": {
    }
}

Logout and invalidate token

Authorizations:
bearerAuth

Responses

Refresh access token

Request Body schema: application/json
required
refreshToken
required
string

Responses

Request samples

Content type
application/json
{
  • "refreshToken": "string"
}

Response samples

Content type
application/json
{
  • "accessToken": "string",
  • "refreshToken": "string",
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "user": {
    }
}

Get current user info

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "username": "string",
  • "email": "user@example.com",
  • "role": "owner",
  • "isActive": true,
  • "authProvider": "string",
  • "providerSubject": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "authMethod": "string"
}

List API tokens for current user

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Create new API token

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string
expiresAt
string <date-time>

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "expiresAt": "2019-08-24T14:15:22Z"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "token": "string",
  • "expiresAt": "2019-08-24T14:15:22Z"
}

Revoke API token

Authorizations:
bearerAuth
path Parameters
tokenId
required
string <uuid>

Responses

Change password for current user

Authorizations:
bearerAuth
Request Body schema: application/json
required
currentPassword
required
string

The user's current password

newPassword
required
string >= 8 characters

The new password (minimum 8 characters)

Responses

Request samples

Content type
application/json
{
  • "currentPassword": "string",
  • "newPassword": "stringst"
}

Response samples

Content type
application/json
{
  • "message": "Password changed successfully"
}

Get API token capabilities

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "enabled": true,
  • "maxTokens": 0,
  • "currentCount": 0
}

Users

User management

List all users (Owner only)

Authorizations:
bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
role
string
Enum: "owner" "user"

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create new user (Owner only)

Authorizations:
bearerAuth
Request Body schema: application/json
required
username
required
string
email
required
string <email>
password
required
string
role
required
string
Enum: "owner" "user"

Responses

Request samples

Content type
application/json
{
  • "username": "string",
  • "email": "user@example.com",
  • "password": "string",
  • "role": "owner"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "username": "string",
  • "email": "user@example.com",
  • "role": "owner",
  • "isActive": true,
  • "authProvider": "string",
  • "providerSubject": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get user by ID

Authorizations:
bearerAuth
path Parameters
userId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "username": "string",
  • "email": "user@example.com",
  • "role": "owner",
  • "isActive": true,
  • "authProvider": "string",
  • "providerSubject": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update user

Authorizations:
bearerAuth
path Parameters
userId
required
string <uuid>
Request Body schema: application/json
required
email
string <email>
password
string
isActive
boolean

Responses

Request samples

Content type
application/json
{
  • "email": "user@example.com",
  • "password": "string",
  • "isActive": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "username": "string",
  • "email": "user@example.com",
  • "role": "owner",
  • "isActive": true,
  • "authProvider": "string",
  • "providerSubject": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete user

Authorizations:
bearerAuth
path Parameters
userId
required
string <uuid>

Responses

Projects

Project (Kubernetes cluster) management

List projects

Authorizations:
bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create new project (Owner only)

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string
description
string
connectionType
string
Enum: "in_cluster" "kubeconfig" "api_token"

Kubernetes connection type. The wire values use underscores (e.g. in_cluster, api_token), not hyphens.

kubeconfig
string

Kubeconfig content (for connectionType=kubeconfig)

k8sApiUrl
string

Kubernetes API URL (for connectionType=api_token)

k8sToken
string

Kubernetes bearer token (for connectionType=api_token)

tlsVerification
string
Enum: "system_ca" "custom_ca" "skip"

TLS verification mode for the K8s API (connectionType=api_token only). Defaults to skip when omitted.

k8sCaCert
string

Custom CA certificate PEM (required when tlsVerification=custom_ca)

object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "connectionType": "in_cluster",
  • "kubeconfig": "string",
  • "k8sApiUrl": "string",
  • "k8sToken": "string",
  • "tlsVerification": "system_ca",
  • "k8sCaCert": "string",
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "connectionType": "in_cluster",
  • "k8sApiUrl": "string",
  • "k8sTlsSkipVerify": true,
  • "isConnected": true,
  • "lastConnectedAt": "2019-08-24T14:15:22Z",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "domainCount": 0,
  • "routeCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "approvalEnabled": true,
  • "selfApprovalAllowed": true,
  • "metricsEndpointUrl": "string",
  • "metricsAuthType": "none",
  • "metricsUsername": "string",
  • "metricsTlsSkipVerify": true,
  • "metricsCaCert": "string"
}

Get project by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "connectionType": "in_cluster",
  • "k8sApiUrl": "string",
  • "k8sTlsSkipVerify": true,
  • "isConnected": true,
  • "lastConnectedAt": "2019-08-24T14:15:22Z",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "domainCount": 0,
  • "routeCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "approvalEnabled": true,
  • "selfApprovalAllowed": true,
  • "metricsEndpointUrl": "string",
  • "metricsAuthType": "none",
  • "metricsUsername": "string",
  • "metricsTlsSkipVerify": true,
  • "metricsCaCert": "string"
}

Update project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
string
description
string
kubeconfig
string

Kubeconfig content (for connectionType=kubeconfig)

k8sApiUrl
string

Kubernetes API URL (for connectionType=api_token)

k8sToken
string

Kubernetes bearer token (for connectionType=api_token)

tlsVerification
string
Enum: "system_ca" "custom_ca" "skip"

TLS verification mode for the K8s API (connectionType=api_token only)

k8sCaCert
string

Custom CA certificate PEM (required when tlsVerification=custom_ca)

object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

approvalEnabled
boolean

Whether route changes in this project require approval

selfApprovalAllowed
boolean

Whether the author of a change may also approve it

metricsEndpointUrl
string

Prometheus/VictoriaMetrics-compatible metrics endpoint URL

metricsAuthType
string
Enum: "none" "bearer" "basic"

Authentication method for the metrics endpoint

metricsUsername
string

Username for basic auth against the metrics endpoint

metricsPassword
string

Password for basic auth against the metrics endpoint. Write-only; encrypted at rest and never returned.

metricsToken
string

Bearer token for the metrics endpoint. Write-only; encrypted at rest and never returned.

metricsTlsSkipVerify
boolean

Whether TLS verification of the metrics endpoint is skipped

metricsCaCert
string

Custom CA certificate PEM for the metrics endpoint

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "kubeconfig": "string",
  • "k8sApiUrl": "string",
  • "k8sToken": "string",
  • "tlsVerification": "system_ca",
  • "k8sCaCert": "string",
  • "labels": {
    },
  • "approvalEnabled": true,
  • "selfApprovalAllowed": true,
  • "metricsEndpointUrl": "string",
  • "metricsAuthType": "none",
  • "metricsUsername": "string",
  • "metricsPassword": "string",
  • "metricsToken": "string",
  • "metricsTlsSkipVerify": true,
  • "metricsCaCert": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "connectionType": "in_cluster",
  • "k8sApiUrl": "string",
  • "k8sTlsSkipVerify": true,
  • "isConnected": true,
  • "lastConnectedAt": "2019-08-24T14:15:22Z",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "domainCount": 0,
  • "routeCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "approvalEnabled": true,
  • "selfApprovalAllowed": true,
  • "metricsEndpointUrl": "string",
  • "metricsAuthType": "none",
  • "metricsUsername": "string",
  • "metricsTlsSkipVerify": true,
  • "metricsCaCert": "string"
}

Delete project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Test Kubernetes connection

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "message": "string",
  • "kubernetesVersion": "string"
}

Get project capabilities

Returns available features for the project based on Kubernetes cluster configuration

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "rateLimitAvailable": true
}

Get detected Envoy Gateway / Gateway API versions for project

Returns the cached (or freshly-detected, if the cache is cold or expired) version-compatibility info for the project's cluster.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "status": "supported",
  • "envoyGateway": {
    },
  • "gatewayAPI": {
    },
  • "supportedPairs": [
    ],
  • "checkedAt": "2019-08-24T14:15:22Z",
  • "cacheExpiresAt": "2019-08-24T14:15:22Z"
}

Invalidate cached version info and re-detect

Drops the cached version info for the project, then immediately re-detects and re-caches it.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "status": "supported",
  • "envoyGateway": {
    },
  • "gatewayAPI": {
    },
  • "supportedPairs": [
    ],
  • "checkedAt": "2019-08-24T14:15:22Z",
  • "cacheExpiresAt": "2019-08-24T14:15:22Z"
}

Get current user permissions for project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "canManageDomainTemplates": true,
  • "canManageDomains": true,
  • "canManageTeams": true,
  • "canCreateRoutes": true,
  • "canApproveRoutes": true,
  • "canViewAudit": true,
  • "permissions": [
    ],
  • "isOwner": true,
  • "isProjectAdmin": true
}

List project admins

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add admin to project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
userId
required
string <uuid>

Responses

Request samples

Content type
application/json
{
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b"
}

Remove admin from project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
userId
required
string <uuid>

Responses

List project members

Returns all users who have access to the project (admins, team members, etc.)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
search
string

Free-text search term to filter members

Responses

Response samples

Content type
application/json
[
  • {
    }
]

List current user's teams in project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Teams

Global team management

List teams the current user belongs to

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
[
  • {
    }
]

List all global teams

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Create global team (Owner only)

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string
description
string

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "memberCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get team by ID

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "memberCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update team

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>
Request Body schema: application/json
required
name
string
description
string

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "description": "string",
  • "memberCount": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete team

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>

Responses

List team members

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add member to team

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>
Request Body schema: application/json
required
userId
required
string <uuid>

Responses

Request samples

Content type
application/json
{
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b"
}

Remove member from team

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>
userId
required
string <uuid>

Responses

List projects a team is assigned to

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add member to team by email (Owner only)

If user exists, adds directly. If not, creates a pending invite.

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>
Request Body schema: application/json
required
email
required
string <email>

Responses

Request samples

Content type
application/json
{
  • "email": "user@example.com"
}

Response samples

Content type
application/json
{
  • "type": "added",
  • "user": {
    },
  • "invite": {
    }
}

List pending invites for team (Owner only)

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Delete a pending invite (Owner only)

Authorizations:
bearerAuth
path Parameters
teamId
required
string <uuid>
inviteId
required
string <uuid>

Responses

Project Teams

Team-project role assignments

List teams assigned to project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Assign team to project with role

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
teamId
required
string <uuid>
presetIds
required
Array of strings <uuid> non-empty [ items <uuid > ]

Responses

Request samples

Content type
application/json
{
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "presetIds": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "presets": [
    ],
  • "effectivePermissions": [
    ],
  • "team": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Get project team role by team ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
teamId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "presets": [
    ],
  • "effectivePermissions": [
    ],
  • "team": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Update team presets in project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
teamId
required
string <uuid>
Request Body schema: application/json
required
presetIds
required
Array of strings <uuid> non-empty [ items <uuid > ]

Responses

Request samples

Content type
application/json
{
  • "presetIds": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "presets": [
    ],
  • "effectivePermissions": [
    ],
  • "team": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Remove team from project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
teamId
required
string <uuid>

Responses

Domain Templates

Domain template management

List domain templates in project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create domain template

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
description
string
controllerName
string
Default: "gateway.envoyproxy.io/gatewayclass-controller"
exposureType
required
string
Enum: "LoadBalancer" "ClusterIP"
tlsMode
required
string
Enum: "tls_only" "no_tls" "both"
httpPort
integer
Default: 80
httpsPort
integer
Default: 443
tlsPolicy
string
Default: "terminate"
Enum: "terminate" "passthrough"
externalTrafficPolicy
string
Enum: "Cluster" "Local"
loadBalancerClass
string
object
object

Annotations applied to the Envoy proxy pods

object (ContainerResourcesConfig)

Container resource requests and limits for the Envoy proxy container

object (ScalingConfig)

Scaling configuration - fixed replica count, or HPA-managed

mergeGateways
boolean

Merge all Gateways using this template into a single Envoy Deployment/Service

object (TelemetryAccessLogConfig)

Access log configuration (spec.telemetry.accessLog)

object (TelemetryTracingConfig)

Tracing configuration (spec.telemetry.tracing)

object (TelemetryMetricsConfig)

Metrics configuration (spec.telemetry.metrics)

object (PodPlacementConfig)
object (PDBConfig)

PodDisruptionBudget configuration - exactly one of minAvailable/maxUnavailable, selected by "kind"

object (DeploymentStrategyConfig)

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "controllerName": "gateway.envoyproxy.io/gatewayclass-controller",
  • "exposureType": "LoadBalancer",
  • "tlsMode": "tls_only",
  • "httpPort": 80,
  • "httpsPort": 443,
  • "tlsPolicy": "terminate",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "mergeGateways": true,
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "controllerName": "string",
  • "exposureType": "LoadBalancer",
  • "tlsMode": "tls_only",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsPolicy": "terminate",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "mergeGateways": true,
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "status": "pending",
  • "statusMessage": "string",
  • "k8sGatewayClassName": "string",
  • "k8sEnvoyProxyName": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get domain template by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "controllerName": "string",
  • "exposureType": "LoadBalancer",
  • "tlsMode": "tls_only",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsPolicy": "terminate",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "mergeGateways": true,
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "status": "pending",
  • "statusMessage": "string",
  • "k8sGatewayClassName": "string",
  • "k8sEnvoyProxyName": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update domain template

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>
Request Body schema: application/json
required
description
string
externalTrafficPolicy
string
Enum: "Cluster" "Local"
loadBalancerClass
string
object
object

Annotations applied to the Envoy proxy pods

object (ContainerResourcesConfig)

Container resource requests and limits for the Envoy proxy container

object (ScalingConfig)

Scaling configuration - fixed replica count, or HPA-managed

object (TelemetryAccessLogConfig)

Access log configuration (spec.telemetry.accessLog)

object (TelemetryTracingConfig)

Tracing configuration (spec.telemetry.tracing)

object (TelemetryMetricsConfig)

Metrics configuration (spec.telemetry.metrics)

object (PodPlacementConfig)
object (PDBConfig)

PodDisruptionBudget configuration - exactly one of minAvailable/maxUnavailable, selected by "kind"

object (DeploymentStrategyConfig)
clearTelemetryAccessLog
boolean

When true, clears the stored telemetryAccessLog config (JSON null is indistinguishable from absent)

clearTelemetryTracing
boolean

When true, clears the stored telemetryTracing config

clearTelemetryMetrics
boolean

When true, clears the stored telemetryMetrics config

clearPodPlacement
boolean

When true, clears the stored podPlacement config

clearPdbConfig
boolean

When true, clears the stored pdbConfig config

clearDeploymentStrategy
boolean

When true, clears the stored deploymentStrategy config

Responses

Request samples

Content type
application/json
{
  • "description": "string",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "clearTelemetryAccessLog": true,
  • "clearTelemetryTracing": true,
  • "clearTelemetryMetrics": true,
  • "clearPodPlacement": true,
  • "clearPdbConfig": true,
  • "clearDeploymentStrategy": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "controllerName": "string",
  • "exposureType": "LoadBalancer",
  • "tlsMode": "tls_only",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsPolicy": "terminate",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "mergeGateways": true,
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "status": "pending",
  • "statusMessage": "string",
  • "k8sGatewayClassName": "string",
  • "k8sEnvoyProxyName": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete domain template

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>

Responses

Get domain template Kubernetes manifests

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "gatewayClassYaml": "string",
  • "envoyProxyYaml": "string"
}

List domains using this template

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Preview domain template creation

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
description
string
controllerName
string
exposureType
required
string
Enum: "LoadBalancer" "ClusterIP"
tlsMode
required
string
Enum: "tls_only" "no_tls" "both"
httpPort
integer
httpsPort
integer
tlsPolicy
string
Enum: "terminate" "passthrough"
externalTrafficPolicy
string
Enum: "Cluster" "Local"
loadBalancerClass
string
object
object
object (ContainerResourcesConfig)

Container resource requests and limits for the Envoy proxy container

object (ScalingConfig)

Scaling configuration - fixed replica count, or HPA-managed

mergeGateways
boolean

Merge all Gateways using this template into a single Envoy Deployment/Service

object (TelemetryAccessLogConfig)

Access log configuration (spec.telemetry.accessLog)

object (TelemetryTracingConfig)

Tracing configuration (spec.telemetry.tracing)

object (TelemetryMetricsConfig)

Metrics configuration (spec.telemetry.metrics)

object (PodPlacementConfig)
object (PDBConfig)

PodDisruptionBudget configuration - exactly one of minAvailable/maxUnavailable, selected by "kind"

object (DeploymentStrategyConfig)
includeAIReview
boolean
changeDescription
string

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "controllerName": "string",
  • "exposureType": "LoadBalancer",
  • "tlsMode": "tls_only",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsPolicy": "terminate",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "mergeGateways": true,
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "includeAIReview": true,
  • "changeDescription": "string"
}

Response samples

Content type
application/json
{
  • "gatewayClassYaml": "string",
  • "envoyProxyYaml": "string",
  • "gatewayYaml": "string",
  • "aiReview": {
    }
}

Preview domain template changes

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainTemplateId
required
string <uuid>
Request Body schema: application/json
required
description
string
externalTrafficPolicy
string
Enum: "Cluster" "Local"
loadBalancerClass
string
object
object
object (ContainerResourcesConfig)

Container resource requests and limits for the Envoy proxy container

object (ScalingConfig)

Scaling configuration - fixed replica count, or HPA-managed

object (TelemetryAccessLogConfig)

Access log configuration (spec.telemetry.accessLog)

object (TelemetryTracingConfig)

Tracing configuration (spec.telemetry.tracing)

object (TelemetryMetricsConfig)

Metrics configuration (spec.telemetry.metrics)

object (PodPlacementConfig)
object (PDBConfig)

PodDisruptionBudget configuration - exactly one of minAvailable/maxUnavailable, selected by "kind"

object (DeploymentStrategyConfig)
clearTelemetryAccessLog
boolean

When true, clears the stored telemetryAccessLog config (JSON null is indistinguishable from absent)

clearTelemetryTracing
boolean

When true, clears the stored telemetryTracing config

clearTelemetryMetrics
boolean

When true, clears the stored telemetryMetrics config

clearPodPlacement
boolean

When true, clears the stored podPlacement config

clearPdbConfig
boolean

When true, clears the stored pdbConfig config

clearDeploymentStrategy
boolean

When true, clears the stored deploymentStrategy config

includeAIReview
boolean
changeDescription
string

Responses

Request samples

Content type
application/json
{
  • "description": "string",
  • "externalTrafficPolicy": "Cluster",
  • "loadBalancerClass": "string",
  • "annotations": {
    },
  • "podAnnotations": {
    },
  • "containerResources": {
    },
  • "scalingConfig": {
    },
  • "telemetryAccessLog": {
    },
  • "telemetryTracing": {
    },
  • "telemetryMetrics": {
    },
  • "podPlacement": {
    },
  • "pdbConfig": {
    },
  • "deploymentStrategy": {
    },
  • "clearTelemetryAccessLog": true,
  • "clearTelemetryTracing": true,
  • "clearTelemetryMetrics": true,
  • "clearPodPlacement": true,
  • "clearPdbConfig": true,
  • "clearDeploymentStrategy": true,
  • "includeAIReview": true,
  • "changeDescription": "string"
}

Response samples

Content type
application/json
{
  • "currentEnvoyProxyYaml": "string",
  • "proposedEnvoyProxyYaml": "string",
  • "aiReview": {
    }
}

Domains

Domain (Gateway) management

List domains in project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create domain (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
hostname
required
string
domainTemplateId
required
string <uuid>
tlsSecretName
string
tlsSecretNamespace
string

Kubernetes namespace containing the TLS secret. Must be managed by the project unless it is the default FastGateway namespace.

namespace
string

Kubernetes namespace to deploy the domain's gateway resources into. Defaults to the default FastGateway namespace; any other value must be registered for this project.

object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "hostname": "string",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "namespace": "string",
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "name": "string",
  • "hostname": "string",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsMode": "tls_only",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "tlsPolicy": "terminate",
  • "namespace": "string",
  • "k8sGatewayName": "string",
  • "k8sGatewayClassName": "string",
  • "status": "pending",
  • "statusMessage": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "routeCount": 0,
  • "labels": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

List TLS secrets available for domain TLS configuration

Lists kubernetes.io/tls Secrets in a namespace, annotated with whether FastGateway manages them, plus the namespaces available for lookup in this project.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
namespace
string

Kubernetes namespace to list TLS secrets from. Defaults to the project's default namespace.

Responses

Response samples

Content type
application/json
{
  • "namespace": "string",
  • "secrets": [
    ],
  • "availableNamespaces": [
    ]
}

List namespaces eligible for domain deployment

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "namespaces": [
    ]
}

Get domain by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "name": "string",
  • "hostname": "string",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsMode": "tls_only",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "tlsPolicy": "terminate",
  • "namespace": "string",
  • "k8sGatewayName": "string",
  • "k8sGatewayClassName": "string",
  • "status": "pending",
  • "statusMessage": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "routeCount": 0,
  • "labels": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update domain (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
name
string
tlsSecretName
string
tlsSecretNamespace
string

Kubernetes namespace containing the TLS secret. Must be managed by the project unless it is the default FastGateway namespace.

object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "name": "string",
  • "hostname": "string",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsMode": "tls_only",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "tlsPolicy": "terminate",
  • "namespace": "string",
  • "k8sGatewayName": "string",
  • "k8sGatewayClassName": "string",
  • "status": "pending",
  • "statusMessage": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "routeCount": 0,
  • "labels": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete domain (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Get domain settings

Returns the domain-level settings configuration. This is a gateway-agnostic API.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "settings": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update domain settings (Admin only)

Updates the domain-level settings. This is a gateway-agnostic API that gets translated to the appropriate gateway-specific resources (e.g., Envoy Gateway ClientTrafficPolicy). Requires Owner or Project Admin role.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
object (ClientConnectionConfig)

Client connection settings

object (ClientIPDetectionConfig)

Client IP detection configuration for extracting client IP from HTTP headers

object (DomainTimeoutConfig)

Domain-level timeout configuration

object (HTTP3Config)

HTTP/3 configuration

object (TLSSettingsConfig)

TLS settings configuration

object (DomainMTLSConfig)

Domain-level mTLS configuration

object (BackendTrafficPolicyConfig)
object (EnvoyExtensionPolicyConfig)

Lua, Wasm, and ext_proc extension configuration stored for a route

Responses

Request samples

Content type
application/json
{
  • "clientConnection": {
    },
  • "clientIPDetection": {
    },
  • "timeout": {
    },
  • "http3": {
    },
  • "tls": {
    },
  • "mtls": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "settings": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "warnings": [
    ]
}

Attach a managed certificate to a domain (Admin only)

Points the domain's Gateway listener at a usage=server managed certificate and re-applies it. Requires Owner, Project Admin, or domain-manage permission (the same access level as domain settings).

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
certificateId
required
string <uuid>

Responses

Request samples

Content type
application/json
{
  • "certificateId": "93038071-4553-48f6-8780-c7262cd9be88"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "name": "string",
  • "hostname": "string",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsMode": "tls_only",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "tlsPolicy": "terminate",
  • "namespace": "string",
  • "k8sGatewayName": "string",
  • "k8sGatewayClassName": "string",
  • "status": "pending",
  • "statusMessage": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "routeCount": 0,
  • "labels": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Detach the managed certificate from a domain (Admin only)

Clears the domain's managed certificate and re-applies its Gateway listener, which reverts to any legacy BYO TLS secret configured on the domain. Requires Owner, Project Admin, or domain-manage permission.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "name": "string",
  • "hostname": "string",
  • "httpPort": 0,
  • "httpsPort": 0,
  • "tlsMode": "tls_only",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "tlsPolicy": "terminate",
  • "namespace": "string",
  • "k8sGatewayName": "string",
  • "k8sGatewayClassName": "string",
  • "status": "pending",
  • "statusMessage": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "routeCount": 0,
  • "labels": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Add CA certificate for domain mTLS

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
caPem
required
string

CA certificate PEM content

name
required
string

Display name for the CA

Responses

Request samples

Content type
application/json
{
  • "caPem": "string",
  • "name": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "settings": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Remove CA certificate from domain mTLS

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
caId
required
string

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "settings": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get domain Kubernetes YAMLs

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "gatewayYaml": "string",
  • "clientTrafficPolicyYaml": "string",
  • "backendTrafficPolicyYaml": "string",
  • "envoyExtensionPolicyYaml": "string"
}

Preview domain settings changes

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
object (ClientConnectionConfig)

Client connection settings

object (DomainTimeoutConfig)

Domain-level timeout configuration

object (HTTP3Config)

HTTP/3 configuration

object (TLSSettingsConfig)

TLS settings configuration

object (ClientIPDetectionConfig)

Client IP detection configuration for extracting client IP from HTTP headers

object (DomainMTLSConfig)

Domain-level mTLS configuration

object (BackendTrafficPolicyConfig)
object (EnvoyExtensionPolicyConfig)

Lua, Wasm, and ext_proc extension configuration stored for a route

description
string
includeAIReview
boolean

When true, triggers AI review of the proposed changes

Responses

Request samples

Content type
application/json
{
  • "clientConnection": {
    },
  • "timeout": {
    },
  • "http3": {
    },
  • "tls": {
    },
  • "clientIPDetection": {
    },
  • "mtls": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "description": "string",
  • "includeAIReview": true
}

Response samples

Content type
application/json
{
  • "currentGatewayYaml": "string",
  • "currentClientTrafficPolicyYaml": "string",
  • "proposedClientTrafficPolicyYaml": "string",
  • "currentBackendTrafficPolicyYaml": "string",
  • "proposedBackendTrafficPolicyYaml": "string",
  • "currentEnvoyExtensionPolicyYaml": "string",
  • "proposedEnvoyExtensionPolicyYaml": "string",
  • "aiReview": {
    }
}

Preview domain creation

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
hostname
required
string
domainTemplateId
required
string <uuid>
tlsSecretName
string
tlsSecretNamespace
string

Kubernetes namespace containing the TLS secret. Must be managed by the project unless it is the default FastGateway namespace.

namespace
string

Kubernetes namespace to deploy the domain's gateway resources into. Defaults to the default FastGateway namespace; any other value must be registered for this project.

object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

description
string
includeAIReview
boolean

When true, triggers AI review of the proposed domain creation

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "hostname": "string",
  • "domainTemplateId": "8f5df8fe-3460-4807-8240-1ccc797bedbb",
  • "tlsSecretName": "string",
  • "tlsSecretNamespace": "string",
  • "namespace": "string",
  • "labels": {
    },
  • "description": "string",
  • "includeAIReview": true
}

Response samples

Content type
application/json
{
  • "proposedGatewayYaml": "string",
  • "aiReview": {
    }
}

Project Namespaces

Project namespace whitelist management

List whitelisted namespaces for project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add namespace to project whitelist

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
namespace
required
string
capabilities
required
Array of strings (NamespaceCapability) non-empty
Items Enum: "deploy_gateway" "backend_service" "tls_secret"

Responses

Request samples

Content type
application/json
{
  • "namespace": "string",
  • "capabilities": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "namespace": "string",
  • "capabilities": [
    ],
  • "referenceGrantCreated": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get project namespace by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
namespaceId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "namespace": "string",
  • "capabilities": [
    ],
  • "referenceGrantCreated": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update capabilities for a project namespace

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
namespaceId
required
string <uuid>
Request Body schema: application/json
required
capabilities
required
Array of strings (NamespaceCapability) non-empty
Items Enum: "deploy_gateway" "backend_service" "tls_secret"

Responses

Request samples

Content type
application/json
{
  • "capabilities": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "namespace": "string",
  • "capabilities": [
    ],
  • "referenceGrantCreated": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Remove namespace from project whitelist

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
namespaceId
required
string <uuid>

Responses

Ensure ReferenceGrant exists for namespace

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
namespaceId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "namespace": "string",
  • "capabilities": [
    ],
  • "referenceGrantCreated": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Routes

Route (HTTPRoute/GRPCRoute) management

Import routes from an OpenAPI spec

Parses an uploaded OpenAPI 3.0/3.1 spec and returns a list of candidate routes (not yet created) for the caller to review and submit individually via createRoute. The request body is capped at 5MB.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
spec
required
string

Raw OpenAPI 3.0/3.1 spec content (JSON or YAML)

required
object (DefaultBackend)

Backend applied to every route parsed from the spec. Exactly one of (service+namespace) or address must be provided.

Responses

Request samples

Content type
application/json
{
  • "spec": "string",
  • "defaultBackend": {
    }
}

Response samples

Content type
application/json
{
  • "routes": [
    ],
  • "warnings": [
    ],
  • "renames": [
    ],
  • "specInfo": {
    }
}

List routes for domain

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
teamId
string <uuid>

Filter by team

status
string
Enum: "pending_create" "pending_update" "pending_delete" "approved" "pending_deploy" "active" "rejected"

Filter by a single status value (unlike listProjectRoutes, this does not accept a comma-separated list)

search
string

Free-text search term

searchField
string
Enum: "all" "name" "path" "owner"

Field to restrict the search term to (defaults to searching all fields)

labels
string

Label filter expression (e.g. "key=value,key2=value2") matched against the route's labels

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create route (submits for approval)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
description
string
protocol
string
Default: "http"
Enum: "http" "grpc"
teamId
required
string <uuid>
required
object (RouteConfig)
securityMode
string (SecurityMode)
Enum: "general" "client"

Security configuration mode. 'general' configures security directly on the route. 'client' uses client attachments.

object (SecurityPolicyInput)
object (BackendTrafficPolicyInput)
object (EnvoyExtensionPolicyInput)

Envoy extension policy input for Lua, Wasm, and ext_proc extensions

object (WafPolicyConfig)

WAF (Web Application Firewall) configuration using coraza-proxy-wasm

changeDescription
string

Optional description of the changes for approval

object (AIReviewResult)
object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "config": {
    },
  • "securityMode": "general",
  • "securityPolicy": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "wafPolicy": {
    },
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "warnings": [
    ]
}

Get route by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "securityPolicy": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "wafPolicy": {
    }
}

Update route (submits for approval)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
Request Body schema: application/json
required
description
string
object (RouteConfig)
object (SecurityPolicyInput)
object (BackendTrafficPolicyInput)
object (EnvoyExtensionPolicyInput)

Envoy extension policy input for Lua, Wasm, and ext_proc extensions

object (WafPolicyConfig)

WAF (Web Application Firewall) configuration using coraza-proxy-wasm

changeDescription
string

Optional description of the changes for approval

object (AIReviewResult)
object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "description": "string",
  • "config": {
    },
  • "securityPolicy": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "wafPolicy": {
    },
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    },
  • "warnings": [
    ]
}

Delete route (submits for approval)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    }
}

Get route as Kubernetes YAML (HTTPRoute only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Get all Kubernetes YAMLs for route (HTTPRoute, SecurityPolicy, BackendTrafficPolicy)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "httpRouteYaml": "string",
  • "securityPolicyYaml": "string",
  • "backendTrafficPolicyYaml": "string",
  • "envoyExtensionPolicyYaml": "string",
  • "backendYaml": "string",
  • "httpRouteFilterYaml": "string",
  • "configMapYaml": "string",
  • "apiKeyClientResources": [
    ]
}

Preview route creation (generate YAML without creating)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
description
string
protocol
string
Default: "http"
Enum: "http" "grpc"
teamId
required
string <uuid>
required
object (RouteConfig)
securityMode
string (SecurityMode)
Enum: "general" "client"

Security configuration mode. 'general' configures security directly on the route. 'client' uses client attachments.

object (SecurityPolicyInput)
object (BackendTrafficPolicyInput)
object (EnvoyExtensionPolicyInput)

Envoy extension policy input for Lua, Wasm, and ext_proc extensions

object (WafPolicyConfig)

WAF (Web Application Firewall) configuration using coraza-proxy-wasm

changeDescription
string

Optional description of the changes for approval

object (AIReviewResult)
object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "config": {
    },
  • "securityMode": "general",
  • "securityPolicy": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "wafPolicy": {
    },
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "proposedYaml": "string",
  • "proposedSecurityPolicyYaml": "string",
  • "proposedBackendTrafficPolicyYaml": "string",
  • "proposedBackendYaml": "string",
  • "proposedEnvoyExtensionPolicyYaml": "string",
  • "proposedHttpRouteFilterYaml": "string",
  • "proposedConfigMapYaml": "string"
}

Check whether a route matcher conflicts with existing routes in the domain

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
required
object (RouteMatch)
excludeRouteId
string <uuid>

Route ID to exclude from conflict checking (e.g., when checking conflicts while editing an existing route)

Responses

Request samples

Content type
application/json
{
  • "match": {
    },
  • "excludeRouteId": "660dfe75-b242-456c-b1e6-54da5bec2537"
}

Response samples

Content type
application/json
{
  • "conflicts": [
    ]
}

Preview route update (compare current vs proposed YAML)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
Request Body schema: application/json
required
description
string
object (RouteConfig)
object (SecurityPolicyInput)
object (BackendTrafficPolicyInput)
object (EnvoyExtensionPolicyInput)

Envoy extension policy input for Lua, Wasm, and ext_proc extensions

object (WafPolicyConfig)

WAF (Web Application Firewall) configuration using coraza-proxy-wasm

changeDescription
string

Optional description of the changes for approval

object (AIReviewResult)
object (Labels)

Arbitrary key/value labels (Kubernetes-style) attached to a resource.

Responses

Request samples

Content type
application/json
{
  • "description": "string",
  • "config": {
    },
  • "securityPolicy": {
    },
  • "backendTrafficPolicy": {
    },
  • "extensionPolicy": {
    },
  • "wafPolicy": {
    },
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "labels": {
    }
}

Response samples

Content type
application/json
{
  • "currentYaml": "string",
  • "proposedYaml": "string",
  • "currentSecurityPolicyYaml": "string",
  • "proposedSecurityPolicyYaml": "string",
  • "currentBackendTrafficPolicyYaml": "string",
  • "proposedBackendTrafficPolicyYaml": "string",
  • "currentBackendYaml": "string",
  • "proposedBackendYaml": "string",
  • "currentEnvoyExtensionPolicyYaml": "string",
  • "proposedEnvoyExtensionPolicyYaml": "string",
  • "currentHttpRouteFilterYaml": "string",
  • "proposedHttpRouteFilterYaml": "string",
  • "currentConfigMapYaml": "string",
  • "proposedConfigMapYaml": "string"
}

Preview route deletion (show what will be deleted)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "currentYaml": "string",
  • "currentSecurityPolicyYaml": "string",
  • "currentBackendTrafficPolicyYaml": "string",
  • "currentBackendYaml": "string",
  • "currentEnvoyExtensionPolicyYaml": "string",
  • "currentHttpRouteFilterYaml": "string",
  • "currentConfigMapYaml": "string"
}

Deploy approved route to Kubernetes

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    }
}

List route version history

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "total": 0,
  • "page": 0,
  • "limit": 0
}

Get specific route version

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
version
required
integer

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "routeId": "fef0741a-9185-417e-be48-b4fe23a36919",
  • "version": 0,
  • "configSnapshot": { },
  • "routeDescription": "string",
  • "protocol": "http",
  • "securityMode": "general",
  • "changeDescription": "string",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "deployedBy": "fcab9d2b-0287-4cf1-ac53-a503d873370d",
  • "deployer": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Rollback route to a previous version

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
version
required
integer

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "domainId": "8a0b02c3-fdd8-452e-bc6e-ef07a335ec7e",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "team": {
    },
  • "name": "string",
  • "description": "string",
  • "protocol": "http",
  • "status": "pending_create",
  • "config": {
    },
  • "securityMode": "general",
  • "pendingApproval": {
    },
  • "clientCount": 0,
  • "securityStatus": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z",
  • "labels": {
    }
}

List routes across all domains in a project

Lists routes in a project, optionally filtered by backend service and namespace. When backend_service and backend_namespace are both set, only routes whose config.backends[] (and optionally config.mirrors[] when include_mirrors=true) contain a Kubernetes backend with that service+namespace are returned. Useful for answering "where is this service used?".

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
backend_service
string

Match routes whose backends contain a Kubernetes backend with this service name. Must be paired with backend_namespace.

backend_namespace
string

Match routes whose backends contain a Kubernetes backend in this namespace. Must be paired with backend_service.

include_mirrors
boolean
Default: false

When true, also match against config.mirrors[].

status
string

Comma-separated list of statuses (pending_create, pending_update, pending_delete, approved, pending_deploy, active, rejected).

team_id
string <uuid>
domain_id
string <uuid>
page
integer >= 1
Default: 1
limit
integer <= 200
Default: 50

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Clients

Global client management (API consumers)

List clients

Owner sees all clients. Others see clients belonging to their teams.

Authorizations:
bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
teamId
string <uuid>

Filter by team

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create client (Owner or team member)

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string
description
string
teamId
required
string <uuid>
contactName
string
contactEmail
string
clientIdHeaderName
string

Header name for client ID routing (default "x-client-id")

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "contactName": "string",
  • "contactEmail": "string",
  • "clientIdHeaderName": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get client by ID

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
name
string
description
string
contactName
string
contactEmail
string
clientIdHeaderName
string

Header name for client ID routing (default "x-client-id")

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "clientIdHeaderName": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Client Attachments

Client-route attachment management

List routes attached to a client

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Attach client to a route (client team initiates)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
routeId
required
string <uuid>
projectId
required
string <uuid>
enableIpAllowlist
boolean
Default: false

Require client IP to be in allowlist

enableApiKey
boolean
Default: false

Require client to provide valid API key

enableJwt
boolean
Default: false

Require client to provide valid JWT token

enableBasicAuth
boolean
Default: false
enableMtls
boolean
Default: false
enableHeaderAuth
boolean
Default: false

Require client to satisfy header-based authorization rules

object (RateLimitConfig)

Rate limit configuration for controlling request volume

object (ExtAuthConfig)

Responses

Request samples

Content type
application/json
{
  • "routeId": "fef0741a-9185-417e-be48-b4fe23a36919",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "enableIpAllowlist": false,
  • "enableApiKey": false,
  • "enableJwt": false,
  • "enableBasicAuth": false,
  • "enableMtls": false,
  • "enableHeaderAuth": false,
  • "rateLimitConfig": {
    },
  • "extAuth": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "routeId": "fef0741a-9185-417e-be48-b4fe23a36919",
  • "enableIpAllowlist": true,
  • "enableApiKey": true,
  • "enableJwt": true,
  • "enableBasicAuth": true,
  • "enableMtls": true,
  • "enableHeaderAuth": true,
  • "rateLimitConfig": {
    },
  • "extAuth": {
    },
  • "status": "pending_attach",
  • "client": {
    },
  • "route": {
    },
  • "creator": {
    },
  • "pendingApproval": {
    },
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

List clients attached to a route

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Attach client to a route (route team initiates)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
Request Body schema: application/json
required
clientId
required
string <uuid>
enableIpAllowlist
boolean
Default: false

Require client IP to be in allowlist

enableApiKey
boolean
Default: false

Require client to provide valid API key

enableJwt
boolean
Default: false

Require client to provide valid JWT token

enableBasicAuth
boolean
Default: false
enableMtls
boolean
Default: false
enableHeaderAuth
boolean
Default: false

Require client to satisfy header-based authorization rules

object (RateLimitConfig)

Rate limit configuration for controlling request volume

object (ExtAuthConfig)

Responses

Request samples

Content type
application/json
{
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "enableIpAllowlist": false,
  • "enableApiKey": false,
  • "enableJwt": false,
  • "enableBasicAuth": false,
  • "enableMtls": false,
  • "enableHeaderAuth": false,
  • "rateLimitConfig": {
    },
  • "extAuth": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "routeId": "fef0741a-9185-417e-be48-b4fe23a36919",
  • "enableIpAllowlist": true,
  • "enableApiKey": true,
  • "enableJwt": true,
  • "enableBasicAuth": true,
  • "enableMtls": true,
  • "enableHeaderAuth": true,
  • "rateLimitConfig": {
    },
  • "extAuth": {
    },
  • "status": "pending_attach",
  • "client": {
    },
  • "route": {
    },
  • "creator": {
    },
  • "pendingApproval": {
    },
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Request detachment of a client from a route

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
attachmentId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "routeId": "fef0741a-9185-417e-be48-b4fe23a36919",
  • "enableIpAllowlist": true,
  • "enableApiKey": true,
  • "enableJwt": true,
  • "enableBasicAuth": true,
  • "enableMtls": true,
  • "enableHeaderAuth": true,
  • "rateLimitConfig": {
    },
  • "extAuth": {
    },
  • "status": "pending_attach",
  • "client": {
    },
  • "route": {
    },
  • "creator": {
    },
  • "pendingApproval": {
    },
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get effective IP allowlist for a route

Returns the merged IP allowlist from all active client attachments with IP allowlisting enabled.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Client Approvals

Stage-based approval workflow for client attachments

List client attachment approvals for a project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
status
string
Default: "pending"
Enum: "pending" "approved" "rejected"

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Get client attachment approval by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Approve a stage of client attachment approval

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>
stageId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Reject a stage of client attachment approval

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>
stageId
required
string <uuid>
Request Body schema: application/json
required
comment
required
string non-empty

Responses

Request samples

Content type
application/json
{
  • "comment": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Approvals

Approval workflow

List pending approvals

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
status
string
Enum: "pending" "approved" "rejected" "cancelled"
entityType
string
Enum: "route" "client_attachment"

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Get approval request by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Get YAML diff for approval request

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "action": "create",
  • "currentYaml": "string",
  • "proposedYaml": "string",
  • "currentSecurityPolicyYaml": "string",
  • "proposedSecurityPolicyYaml": "string",
  • "currentBackendTrafficPolicyYaml": "string",
  • "proposedBackendTrafficPolicyYaml": "string",
  • "currentBackendYaml": "string",
  • "proposedBackendYaml": "string",
  • "currentEnvoyExtensionPolicyYaml": "string",
  • "proposedEnvoyExtensionPolicyYaml": "string",
  • "changeDescription": "string",
  • "aiReview": {
    }
}

Approve a stage of an approval request

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>
stageId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Reject a stage of an approval request

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>
stageId
required
string <uuid>
Request Body schema: application/json
required
comment
required
string non-empty

Responses

Request samples

Content type
application/json
{
  • "comment": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

List comments on an approval

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "total": 0
}

Add comment to an approval

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>
Request Body schema: application/json
required
body
required
string <= 10000 characters

Responses

Request samples

Content type
application/json
{
  • "body": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "body": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "user": {
    }
}

Trigger AI review for an approval

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "summary": "string",
  • "risks": [
    ],
  • "securityNotes": [
    ],
  • "suggestions": [
    ],
  • "configHighlights": [
    ]
}

Cancel an approval request

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
approvalId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "entityId": "156e622c-6cdf-4c27-9bc9-2f2db69919f5",
  • "action": "create",
  • "configSnapshot": { },
  • "previousConfig": { },
  • "submittedBy": "a641a425-2470-49a5-92c2-5825c2833a34",
  • "submitter": {
    },
  • "status": "pending",
  • "stages": [
    ],
  • "entityName": "string",
  • "domainName": "string",
  • "changeDescription": "string",
  • "aiReview": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Kubernetes

Kubernetes resource discovery

List Kubernetes namespaces

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

List Kubernetes GatewayClasses

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • "string"
]

List services in namespace

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
namespace
required
string

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Metrics

Route and domain observability metrics (Prometheus-backed)

Test connectivity to the project's configured Prometheus endpoint

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "ok": true,
  • "prometheusVersion": "string",
  • "error": "string"
}

Get request-rate, error-rate, and latency panels for a domain, plus top-5 route tables

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
query Parameters
range
string
Default: "1h"
Enum: "15m" "1h" "6h" "24h" "7d"

Lookback window for the query

Responses

Response samples

Content type
application/json
{
  • "timeRange": {
    },
  • "totalRequests": 0,
  • "errorRatePercent": 0,
  • "rps": {
    },
  • "latency": {
    },
  • "topRoutesByRps": [
    ],
  • "topRoutesByErrorRate": [
    ]
}

Get request-rate, error-rate, and latency panels for a single route

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
routeId
required
string <uuid>
query Parameters
range
string
Default: "1h"
Enum: "15m" "1h" "6h" "24h" "7d"

Lookback window for the query

Responses

Response samples

Content type
application/json
{
  • "timeRange": {
    },
  • "totalRequests": 0,
  • "errorRatePercent": 0,
  • "rps": {
    },
  • "latency": {
    }
}

System Settings

Global system settings (owner only)

Get system settings (Owner only)

Returns the raw DB-stored values alongside the effective values (DB override if set, else env var/config default).

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "baseUrl": "string",
  • "jwtExpiry": "string",
  • "refreshTokenExpiry": "string",
  • "logLevel": "debug",
  • "effective": {
    }
}

Update system settings (Owner only)

All fields are optional, but any field omitted from the request body is cleared to empty (falling back to its effective default) — this is a full replace, not a partial merge. jwtExpiry/refreshTokenExpiry must parse as Go duration strings (e.g. 24h, 1h30m); logLevel must be one of debug/info/warn/error.

Authorizations:
bearerAuth
Request Body schema: application/json
required
baseUrl
string
jwtExpiry
string

Go duration string (e.g. 24h, 1h30m)

refreshTokenExpiry
string

Go duration string (e.g. 168h, 720h)

logLevel
string
Enum: "debug" "info" "warn" "error"

Responses

Request samples

Content type
application/json
{
  • "baseUrl": "string",
  • "jwtExpiry": "string",
  • "refreshTokenExpiry": "string",
  • "logLevel": "debug"
}

Response samples

Content type
application/json
{
  • "baseUrl": "string",
  • "jwtExpiry": "string",
  • "refreshTokenExpiry": "string",
  • "logLevel": "debug",
  • "effective": {
    }
}

Topology

Read-only project and domain topology views

Get the per-domain topology view

Returns the domain's gateway status, routes, backends, and (in client security mode) attached clients and per-attachment enforcement flags.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "domain": {
    },
  • "gateway": {
    },
  • "routes": [
    ],
  • "backends": [
    ],
  • "clients": [
    ],
  • "attachments": [
    ]
}

Get the project-wide topology view

Aggregates per-domain summary cards, per-client per-domain rollups, and IP-allowlist reachability rows across every domain in the project.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "domains": [
    ],
  • "clients": [
    ],
  • "ips": [
    ]
}

Audit

Audit logs

List audit logs

Requires audit.view permission, Owner, or Project Admin role.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
resourceType
string
Enum: "domain" "domain_template" "route" "team" "user" "project_namespace" "approval"
action
string
Enum: "create" "update" "delete" "approve" "reject" "deploy" "approve_stage" "reject_stage" "cancel_approval"
userId
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Export audit logs as CSV

Exports all matching audit logs as a CSV file. Supports the same filters as the list endpoint but returns all results without pagination. Requires audit.view permission, Owner, or Project Admin role.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
resourceType
string
Enum: "domain" "domain_template" "route" "team" "user" "project_namespace" "approval"
action
string
Enum: "create" "update" "delete" "approve" "reject" "deploy" "approve_stage" "reject_stage" "cancel_approval"
userId
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Delete old audit logs

Permanently deletes audit logs older than the specified number of days. This action cannot be undone. Requires Owner or Project Admin role.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
days
required
integer >= 1

Delete audit logs older than this many days

Responses

Request samples

Content type
application/json
{
  • "days": 90
}

Response samples

Content type
application/json
{
  • "deleted": 0,
  • "message": "Deleted 42 audit logs older than 90 days"
}

Client mTLS

Client mTLS authentication management

Configure mTLS authentication for client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
enabled
boolean
caName
string

CA certificate name

caPem
string

CA certificate PEM content

Array of objects (MTLSSANEntry)
hashes
Array of strings

Responses

Request samples

Content type
application/json
{
  • "enabled": true,
  • "caName": "string",
  • "caPem": "string",
  • "sans": [
    ],
  • "hashes": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Remove mTLS authentication from client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Attach a managed client certificate to a client (team member)

Attaches a managed, usage=client certificate (issued via POST /projects/{projectId}/certificates) to this client's mTLS configuration. Writes only the client row -- the CA Secret and ClientTrafficPolicy it implies materialize at the next domain deploy, exactly like PUT .../mtls. Requires the caller to be a member of the client's team, and the certificate to be usage=client, status=ready, in a project the client's team has access to, and not already attached elsewhere.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
certificateId
required
string <uuid>

A managed, usage=client certificate (see POST /projects/{projectId}/certificates) in a project the client's team has access to.

Responses

Request samples

Content type
application/json
{
  • "certificateId": "93038071-4553-48f6-8780-c7262cd9be88"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Detach the managed certificate from a client (team member)

Clears the client's managed certificate and its derived mTLS fields, reverting the client to no mTLS. A previously-configured BYO mTLS configuration is not restored automatically -- re-add it via PUT .../mtls if wanted.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

List managed certificates this client could attach (team member)

Lists managed client-usage certificates that are ready, in a project the client's team has a role in, and not already attached to any client -- scoping the attach picker to what this client could actually attach, rather than every certificate the caller can see. Responses carry certificate metadata only, never key material.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

AI

AI-powered route generation and chat

Check AI service availability

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "enabled": true,
  • "provider": "anthropic"
}

Chat with AI assistant (SSE stream)

Interactive AI chat with context about routes and domains. Supports conversation history. Returns Server-Sent Events (SSE) stream. Enterprise-only feature.

Authorizations:
bearerAuth
Request Body schema: application/json
required
message
required
string <= 10000 characters

User message to the AI assistant

object (AIChatContext)
Array of objects (AIChatMessage) <= 50 items

Previous conversation messages

Responses

Request samples

Content type
application/json
{
  • "message": "string",
  • "context": {
    },
  • "history": [
    ]
}

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Generate routes using AI (SSE stream)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
mode
required
string
Enum: "natural_language" "manifest_import"
input
required
string

User prompt or YAML manifest

formatHint
string
Enum: "ingress" "istio" "kong"

Source manifest dialect hint, used when mode is manifest_import

Responses

Request samples

Content type
application/json
{
  • "mode": "natural_language",
  • "input": "string",
  • "formatHint": "ingress"
}

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Review route YAML changes using AI

Sends current and/or proposed YAML configurations to AI for structured review. Returns summary, risks, security notes, suggestions, and config highlights. Enterprise-only feature.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
domainId
required
string <uuid>
Request Body schema: application/json
required
action
required
string
Enum: "create" "update" "delete"

Type of route change being reviewed

description
string

Optional human description of the changes

object (AIYamlSet)

Set of YAML strings for different resource types

object (AIYamlSet)

Set of YAML strings for different resource types

Responses

Request samples

Content type
application/json
{
  • "action": "create",
  • "description": "string",
  • "proposedYaml": {
    },
  • "currentYaml": {
    }
}

Response samples

Content type
application/json
{
  • "summary": "string",
  • "risks": [
    ],
  • "securityNotes": [
    ],
  • "suggestions": [
    ],
  • "configHighlights": [
    ]
}

Approval Policies

Approval policy management (admin only)

List approval policies for a project (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Create approval policy (Admin only)

Creates a custom approval policy for a project. Policies define the approval stages required for specific entity types (route, client_attachment) and actions.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
entityType
required
string
Enum: "route" "client_attachment"

Type of entity this policy applies to

action
string

Specific action this policy applies to (optional)

required
Array of objects (PolicyStageInput)

Approval stages to configure

Responses

Request samples

Content type
application/json
{
  • "entityType": "route",
  • "action": "string",
  • "stages": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "action": "string",
  • "stages": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get approval policy by ID (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
policyId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "action": "string",
  • "stages": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update approval policy (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
policyId
required
string <uuid>
Request Body schema: application/json
required
entityType
required
string
Enum: "route" "client_attachment"

Type of entity this policy applies to

action
string

Specific action this policy applies to (optional)

required
Array of objects (PolicyStageInput)

Approval stages to configure

Responses

Request samples

Content type
application/json
{
  • "entityType": "route",
  • "action": "string",
  • "stages": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "entityType": "route",
  • "action": "string",
  • "stages": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete approval policy (Admin only)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
policyId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "message": "string"
}

Client Headers

Client header authorization management

List headers for a client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add header to client (Owner or team member)

Adds a header authorization rule to the client. The header name and values are used to match incoming requests for authorization. Routes with this client attached will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
name
required
string

Header name (e.g., "x-user-id")

values
required
Array of strings

Allowed values for this header

description
string

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "values": [
    ],
  • "description": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "name": "string",
  • "values": [
    ],
  • "description": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Remove header from client (Owner or team member)

Removes a header authorization rule from the client. Routes with this client attached will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
headerId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Client Methods

Client HTTP method authorization management

Set allowed HTTP methods for client (Owner or team member)

Sets the allowed HTTP methods for the client. These methods are used in authorization rules when the client is attached to routes. Valid methods: GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS. Pass an empty array to clear all method restrictions. Routes with this client attached will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
methods
required
Array of strings
Items Enum: "GET" "POST" "PUT" "DELETE" "PATCH" "HEAD" "OPTIONS"

Allowed HTTP methods for this client

Responses

Request samples

Content type
application/json
{
  • "methods": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "teamId": "a4ede8ba-7c0a-4485-8763-cbd9b282fbec",
  • "name": "string",
  • "description": "string",
  • "contactName": "string",
  • "contactEmail": "string",
  • "ipAddressCount": 0,
  • "headerCount": 0,
  • "attachmentCount": 0,
  • "apiKeyEnabled": true,
  • "apiKeyPrefix": "string",
  • "apiKeyHeaderName": "string",
  • "apiKeyCreatedAt": "2019-08-24T14:15:22Z",
  • "apiKeyCreatedBy": "6c6b69b2-3a82-447c-bb3b-021672b61a37",
  • "clientIdHeaderName": "string",
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5",
  • "jwtCreator": {
    },
  • "mtlsEnabled": true,
  • "mtlsCaName": "string",
  • "mtlsCaSecret": "string",
  • "mtlsCaSecretKey": "string",
  • "mtlsSans": [
    ],
  • "mtlsHashes": [
    ],
  • "mtlsCreatedAt": "2019-08-24T14:15:22Z",
  • "mtlsCreatedBy": "61155729-cc3f-4ef6-afd2-3810176240d0",
  • "mtlsCreator": {
    },
  • "managedCertificateId": "7fd97265-059c-4695-8f7b-acfe4bd852da",
  • "allowedMethods": [
    ],
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "team": {
    },
  • "creator": {
    },
  • "apiKeyCreator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

SSO

Single Sign-On configuration

Get public SSO configuration

Responses

Response samples

Content type
application/json
{
  • "enabled": true,
  • "providerName": "string",
  • "forceSSO": true,
  • "allowedDomains": [
    ]
}

Initiate SSO authorization flow

Redirects user to the OIDC identity provider for authentication

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Handle SSO callback from identity provider

Processes the callback from the OIDC identity provider and redirects to frontend with tokens

query Parameters
code
string

Authorization code from IdP

state
string

CSRF state token

error
string

Error from IdP (if any)

error_description
string

Error description from IdP

Responses

Get SSO configuration (Owner only)

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "enabled": true,
  • "providerName": "string",
  • "issuerUrl": "string",
  • "clientId": "string",
  • "scopes": [
    ],
  • "allowedDomains": [
    ],
  • "allowedEmails": [
    ],
  • "autoRegister": true,
  • "forceSSO": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update SSO configuration (Owner only)

Authorizations:
bearerAuth
Request Body schema: application/json
required
providerName
required
string

Identity provider name (e.g., google, okta)

issuerUrl
required
string

OIDC issuer URL

clientId
required
string

OAuth2 client ID

clientSecret
required
string

OAuth2 client secret

scopes
Array of strings

OAuth2 scopes (default - openid, email, profile)

allowedDomains
Array of strings

Restrict SSO to these email domains

allowedEmails
Array of strings <email> [ items <email > ]

Restrict SSO to these specific email addresses

autoRegister
boolean

Auto-create users on first SSO login

forceSSO
boolean

Force SSO for non-owner users

Responses

Request samples

Content type
application/json
{
  • "providerName": "string",
  • "issuerUrl": "string",
  • "clientId": "string",
  • "clientSecret": "string",
  • "scopes": [
    ],
  • "allowedDomains": [
    ],
  • "allowedEmails": [
    ],
  • "autoRegister": true,
  • "forceSSO": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "enabled": true,
  • "providerName": "string",
  • "issuerUrl": "string",
  • "clientId": "string",
  • "scopes": [
    ],
  • "allowedDomains": [
    ],
  • "allowedEmails": [
    ],
  • "autoRegister": true,
  • "forceSSO": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Disable SSO (Owner only)

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "message": "SSO disabled"
}

DNS Credentials

Platform-global DNS provider credential management (owner only)

List DNS provider credentials (Owner only)

Platform-global. Never includes credential material.

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Create DNS provider credential (Owner only)

Credentials are encrypted at rest and never returned in any response.

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string
providerType
required
string

DNS provider identifier (e.g. cloudflare, route53).

required
object

Provider-specific plaintext credential values (e.g. {"apiToken": "..."}). Encrypted at rest; never returned in any response.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "providerType": "string",
  • "credentials": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "providerType": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get DNS provider credential (Owner only)

Metadata only, never includes credential material.

Authorizations:
bearerAuth
path Parameters
dnsCredentialId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "providerType": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update DNS provider credential (Owner only)

Update the name and/or rotate the credential values. Omitting credentials leaves the existing encrypted values untouched.

Authorizations:
bearerAuth
path Parameters
dnsCredentialId
required
string <uuid>
Request Body schema: application/json
required
name
string
object

Provider-specific plaintext credential values to rotate. Encrypted at rest; never returned in any response.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "credentials": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "providerType": "string",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete DNS provider credential (Owner only)

Authorizations:
bearerAuth
path Parameters
dnsCredentialId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Certificate Issuers

Platform-global certificate issuer and issuer-project grant management (owner only)

List certificate issuers (Owner only)

Platform-global. Never includes key material.

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Create certificate issuer (Owner only)

Body discriminated by type (self_signed_ca or acme). Creates the corresponding cert-manager CRDs in the control cluster.

Authorizations:
bearerAuth
Request Body schema: application/json
required
type
required
string
Enum: "self_signed_ca" "acme"
name
required
string
commonName
string

Required when type is self_signed_ca.

keyAlgorithm
string

Defaults to RSA when type is self_signed_ca.

keySize
integer

Defaults to 4096 when type is self_signed_ca.

durationDays
integer

Defaults to 3650 when type is self_signed_ca.

server
string

ACME server URL. Required when type is acme.

email
string

Required when type is acme.

eabKeyId
string

ACME External Account Binding key ID, if the ACME server requires EAB (e.g. ZeroSSL).

eabHmacKey
string

ACME External Account Binding HMAC key, plaintext in the request only -- stored as a cert-manager Secret, never persisted in this row or returned.

dnsCredentialId
string <uuid>

DNS provider credential used for the ACME DNS-01 solver. Required when type is acme.

Responses

Request samples

Content type
application/json
{
  • "type": "self_signed_ca",
  • "name": "string",
  • "commonName": "string",
  • "keyAlgorithm": "string",
  • "keySize": 0,
  • "durationDays": 0,
  • "server": "string",
  • "email": "string",
  • "eabKeyId": "string",
  • "eabHmacKey": "string",
  • "dnsCredentialId": "e9f8639e-b43a-4064-8d5f-9c5cfadbca10"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "type": "self_signed_ca",
  • "status": "pending",
  • "statusMessage": "string",
  • "config": {
    },
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get certificate issuer (Owner only)

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "type": "self_signed_ca",
  • "status": "pending",
  • "statusMessage": "string",
  • "config": {
    },
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete certificate issuer (Owner only)

Removes the underlying cert-manager CRDs. 409 if referenced by any ManagedCertificate.

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Get certificate issuer readiness (Owner only)

cert-manager readiness of the underlying Issuer (Ready condition + message).

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "status": "pending",
  • "statusMessage": "string"
}

List projects an issuer is granted to (Owner only)

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Grant an issuer to a project (Owner only)

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>
Request Body schema: application/json
required
projectId
required
string <uuid>

Responses

Request samples

Content type
application/json
{
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8"
}

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Revoke an issuer's grant to a project (Owner only)

409 if a certificate in that project still uses the issuer.

Authorizations:
bearerAuth
path Parameters
issuerId
required
string <uuid>
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Managed Certificates

Project-scoped certificate issuance from a granted issuer

List managed certificates across all projects (Owner only)

Owner-only fleet view of managed certificates across ALL projects, enriched with each certificate's resolved issuer name/type, Phase 3a distribution sync state, and referencing domains. Filterable by projectId to narrow to a single project.

Authorizations:
bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
status
string
Enum: "pending" "issuing" "ready" "error"

Filter by certificate status.

usage
string
Enum: "server" "client"

Filter by certificate usage.

issuerId
string <uuid>

Filter by issuer.

projectId
string <uuid>

Filter to a single project.

expiresBefore
string <date-time>

Filter to certificates expiring before this RFC3339 timestamp.

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

List managed certificates in project (requires cert.view)

Each item is enriched with its resolved issuer name/type, Phase 3a distribution sync state, and the domains referencing it.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
status
string
Enum: "pending" "issuing" "ready" "error"

Filter by certificate status.

issuerId
string <uuid>

Filter by issuer.

usage
string
Enum: "server" "client"

Filter by certificate usage.

expiresBefore
string <date-time>

Filter to certificates expiring before this RFC3339 timestamp.

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Create managed certificate (requires cert.create)

Issues a certificate from an issuer granted to this project. Opens an approval when the project has approvals enabled (returns 202 with the pending certificate + approvalId); otherwise issues immediately (201, approvalId null).

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
issuerId
required
string <uuid>
usage
required
string
Enum: "server" "client"
dnsNames
Array of strings

Required when usage is server.

subject
string

Required when usage is client.

keyAlgorithm
string

Defaults to RSA.

keySize
integer

Defaults to 2048.

durationDays
integer

Defaults to 90.

keyMode
string
Enum: "managed" "csr"

Defaults to managed (cert-manager generates and holds the leaf private key). Set to csr to have cert-manager only sign a caller-supplied CSR, in which case csr is required and the private key never exists server-side (so export is not applicable to the resulting certificate).

uriSans
Array of strings

URI Subject Alternative Names, applicable to client-usage certificates.

csr
string

Caller-supplied PEM-encoded certificate signing request. Required when keyMode is csr; ignored otherwise.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "issuerId": "d481fa31-74f9-4e8d-98ce-a395773acfa0",
  • "usage": "server",
  • "dnsNames": [
    ],
  • "subject": "string",
  • "keyAlgorithm": "string",
  • "keySize": 0,
  • "durationDays": 0,
  • "keyMode": "managed",
  • "uriSans": [
    ],
  • "csr": "string"
}

Response samples

Content type
application/json
{
  • "certificate": {
    },
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6"
}

List certificate issuers granted to this project (requires cert.view)

Populates a certificate-create form's issuer picker. Never includes key material.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Get managed certificate (requires cert.view)

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "issuerId": "d481fa31-74f9-4e8d-98ce-a395773acfa0",
  • "usage": "server",
  • "dnsNames": [
    ],
  • "status": "pending",
  • "statusMessage": "string",
  • "fingerprint": "string",
  • "notAfter": "2019-08-24T14:15:22Z",
  • "createdAt": "2019-08-24T14:15:22Z",
  • "keyMode": "managed",
  • "subject": "string",
  • "uriSans": [
    ],
  • "exportAvailable": true
}

Delete managed certificate (requires cert.delete)

Removes the leaf Certificate CRD (and its Secret) from the control cluster.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Get managed certificate issuance status (requires cert.view)

Live cert-manager readiness of the underlying Certificate resource (Ready condition + message).

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "status": "pending",
  • "message": "string",
  • "notAfter": "2019-08-24T14:15:22Z"
}

Get managed certificate distribution status (requires cert.view)

Phase 3a distribution state -- how far the certdist controller has gotten pushing this certificate's Secret into the project's tenant cluster. Returns a pending placeholder (not a 404) when the controller has not pushed it yet.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "status": "pending",
  • "lastPushedFingerprint": "string",
  • "message": "string",
  • "lastSyncedAt": "2019-08-24T14:15:22Z"
}

Force a certificate distribution resync (requires cert.edit)

Flips the distribution row back to pending so the certdist controller re-pushes the certificate's Secret on its next tick. NOTIFY is not wired up, so this is a ticker-driven nudge rather than an immediate push.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Request a certificate export (requires cert.edit)

Opens an approval to export a managed-key certificate's private key material. Once approved -- immediately, if the project has approvals disabled -- the requesting user gets a short-lived, single-use grant redeemable via GET .../export/download. Only applicable to managed-key certificates (keyMode: managed): a csr-key-mode certificate's private key never existed server-side (only its CSR was handed to cert-manager), so there is nothing to export and this returns 409.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6"
}

Download the exported certificate + private key bundle (one-time)

Streams the certificate's leaf certificate, private key, and issuer CA chain as a single concatenated application/x-pem-file attachment. This is the ONLY endpoint in the API that ever returns private key material, and only when the calling user holds an approved, unconsumed, unexpired export grant for this certificate (see POST .../export) -- the grant is consumed atomically on this call, so it can be downloaded exactly once.

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
certificateId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Notifications

User notifications

List notifications for current user

Authorizations:
bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 20
unread
string
Value: "true"

Filter to unread notifications only

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "pagination": {
    }
}

Get unread notification count

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "unread": 0
}

Mark notification as read

Authorizations:
bearerAuth
path Parameters
notificationId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "success": true
}

Mark all notifications as read

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "success": true
}

Health

Service health check

Health check

Responses

Response samples

Content type
application/json
{
  • "status": "ok"
}

Docs

API documentation

Get OpenAPI specification

Returns the bundled OpenAPI 3.0.3 specification for the FastGateway API

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Permission Presets

List permission presets for project

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Create permission preset

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
Request Body schema: application/json
required
name
required
string
description
string
permissions
required
Array of strings (Permission)
Items Enum: "route.view" "route.create" "route.edit" "route.delete" "route.deploy" "route.approve" "client.view" "client.create" "client.edit" "client.delete" "client.manage_ip" "client.manage_apikey" "client.manage_jwt" "client.attach" "client.detach" "client.approve" "domain.view" "domain.create" "domain.edit" "domain.delete" "project.settings" "project.teams" "project.approval_policy" "audit.view"

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "permissions": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "permissions": [
    ],
  • "isBuiltin": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get permission preset by ID

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
presetId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "permissions": [
    ],
  • "isBuiltin": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update permission preset

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
presetId
required
string <uuid>
Request Body schema: application/json
required
name
string
description
string
permissions
Array of strings (Permission)
Items Enum: "route.view" "route.create" "route.edit" "route.delete" "route.deploy" "route.approve" "client.view" "client.create" "client.edit" "client.delete" "client.manage_ip" "client.manage_apikey" "client.manage_jwt" "client.attach" "client.detach" "client.approve" "domain.view" "domain.create" "domain.edit" "domain.delete" "project.settings" "project.teams" "project.approval_policy" "audit.view"

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "description": "string",
  • "permissions": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "name": "string",
  • "description": "string",
  • "permissions": [
    ],
  • "isBuiltin": true,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete permission preset

Authorizations:
bearerAuth
path Parameters
projectId
required
string <uuid>
presetId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Client IPs

List IP addresses for a client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Add IP address to client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
cidr
required
string

IP address or CIDR range

description
string

Responses

Request samples

Content type
application/json
{
  • "cidr": "string",
  • "description": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "clientId": "5e505642-9024-474d-9434-e5a44f505cc5",
  • "cidr": "string",
  • "description": "string",
  • "createdBy": "25a02396-1048-48f9-bf93-102d2fb7895e",
  • "creator": {
    },
  • "createdAt": "2019-08-24T14:15:22Z"
}

Remove IP address from client (Owner or team member)

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
ipId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Client API Key

Generate API key for client (Owner or team member)

Generates a new API key for the client. If the client already has an API key, it will be replaced with a new one. The plaintext key is returned only once in the response and cannot be retrieved again.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
optional
headerName
string
Default: "x-api-key"

Header name to send the API key in requests (default "x-api-key")

Responses

Request samples

Content type
application/json
{
  • "headerName": "x-api-key"
}

Response samples

Content type
application/json
{
  • "apiKey": "fg_live_aB3cD4eF5gH6iJ7kL8mN9oP0qR1sT2u",
  • "prefix": "fg_live_aB3c",
  • "headerName": "x-api-key",
  • "createdAt": "2019-08-24T14:15:22Z"
}

Revoke API key for client (Owner or team member)

Revokes the client's API key. Routes with this client attached using API key authentication will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}

Client JWT

Configure JWT authentication for client (Owner or team member)

Configures JWT authentication for the client. Requires a valid issuer URL and JWKS URL. Optionally accepts audience values, required claims, and claim-to-header mappings.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
issuer
required
string

JWT issuer URL

jwksUrl
required
string

URL to fetch JWKS for JWT validation

audiences
Array of strings

Expected JWT audience values

Array of objects (JWTRequiredClaim)

Required JWT claims for authorization

Array of objects (JWTClaimToHeader)

JWT claims to map to HTTP headers

Responses

Request samples

Content type
application/json
{}

Response samples

Content type
application/json
{
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5"
}

Update JWT authentication for client (Owner or team member)

Updates the JWT authentication configuration for the client. The client must already have JWT configured. Routes with this client attached using JWT authentication will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>
Request Body schema: application/json
required
issuer
required
string

JWT issuer URL

jwksUrl
required
string

URL to fetch JWKS for JWT validation

audiences
Array of strings

Expected JWT audience values

Array of objects (JWTRequiredClaim)

Required JWT claims for authorization

Array of objects (JWTClaimToHeader)

JWT claims to map to HTTP headers

Responses

Request samples

Content type
application/json
{}

Response samples

Content type
application/json
{
  • "jwtEnabled": true,
  • "jwtIssuer": "string",
  • "jwtJwksUrl": "string",
  • "jwtAudiences": [
    ],
  • "jwtRequiredClaims": [
    ],
  • "jwtClaimToHeaders": [
    ],
  • "jwtCreatedAt": "2019-08-24T14:15:22Z",
  • "jwtCreatedBy": "5f8b5dae-c6ae-408f-95ea-415c23d264b5"
}

Remove JWT authentication from client (Owner or team member)

Removes JWT authentication from the client. Routes with this client attached using JWT authentication will move to pending_deploy status.

Authorizations:
bearerAuth
path Parameters
clientId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "code": "string",
  • "message": "string"
}