13. API#
Workspace API keys (Settings, admin-only) are for service integrations — they see the whole workspace (optionally restricted to groups at creation). Personal agent tokens (§9) are for humans' agents. Main endpoints: /v1/answer, /v1/query, /v1/documents, /v1/concepts/{id}, /v1/bundles, /v1/mcp (JSON-RPC), /v1/memories, POST /v1/concepts (author a concept directly — requires kb:author), GET /v1/bundles/{name}/export (OKF export, ?format=zip for a zip; §7). Private working memory (§9a) has REST twins of its MCP tools: POST /v1/context (remember; needs a member token + kb:remember), POST /v1/context/retrieve (blended rehydrate; member token), and POST /v1/context/{id}/promote (promote to team review; member token + kb:remember). All authenticated via Authorization: Bearer.
Standing knowledge agents (§10) don't have a Bearer-token API today — they're managed from the dashboard (Workforce → Standing agents) only.