API reference
Portal: resources, groups, tags and dashboards
Every resource of an organization in one list, resource groups and tags, each resource's activity and access, your favourite services and recent resources, and dashboards.
What Cloud's portal is built on. Resources are addressed by kind and reference: project (a Serverless App Service, by its id), database and bucket (by resource id), domain (by hostname), repository (by resource id) and agent (by device id). Favourites, recent resources and dashboards are per person; people only, not keys.
GET /v1/orgs/:orgId/portal/resources
Every resource of the org you may read, of every kind (Serverless App Services, databases, buckets, domains, repositories, agents), with its resource group and tags. q keeps those with every word in their name, details, id or tags; kind, group (a resource group id, or none) and tag (key or key=value) filter; limit caps the list (default 500). total and counts (by kind) are of every resource you may read, before filters.
Auth: user access token or platform agent key
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
| Query parameter | Type | Required | Default | Notes |
|---|---|---|---|---|
q | string | No | up to 200 characters | |
kind | "project" | "database" | "bucket" | "domain" | "repository" | "agent" | No | ||
group | string | No | up to 64 characters | |
tag | string | No | up to 330 characters | |
limit | integer | No | 500 | 1–500; coerced from a string |
Response 200
{
resources: {
kind: "project" | "repository" | "agent" | "database" | "bucket" | "domain"
id: string
name: string
detail?: string
location?: string
region?: string
projectId?: string
groupId?: string
tags: {
key: string
value: string
}[]
status?: string
createdAt?: number
updatedAt?: number
}[]
total: number
counts: {
project?: number
repository?: number
agent?: number
database?: number
bucket?: number
domain?: number
}
}GET /v1/orgs/:orgId/portal/resources/:kind/:ref
One resource with its resource group and tags.
Auth: user access token or platform agent key · Scopes: projects:read (for a Serverless App Service (project)), resources:read (for a database or bucket), domains:read (for a domain), git:read (for a repository), agents:read (for an agent)
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:kind | What the resource is: project (a Serverless App Service), database, bucket, domain, repository or agent. |
:ref | The resource: its id (prj_…, res_…, dev_…), or a domain's hostname. |
Response 200
{
resource: {
kind: "project" | "repository" | "agent" | "database" | "bucket" | "domain"
id: string
name: string
detail?: string
location?: string
region?: string
projectId?: string
groupId?: string
tags: {
key: string
value: string
}[]
status?: string
createdAt?: number
updatedAt?: number
}
}Errors
| Status | Message |
|---|---|
404 | Unknown kind of resource. |
404 | Resource not found. |
PUT /v1/orgs/:orgId/portal/resources/:kind/:ref
Sets a resource's resource group (groupId, or null for none) and its tags (tags: up to 20 { key, value }, keys unique; replaces them all). Needs the right to change that resource.
Auth: user access token or platform agent key · Scopes: projects:read (for a Serverless App Service (project)), resources:read (for a database or bucket), domains:read (for a domain), git:read (for a repository), agents:read (for an agent), projects:write (for a Serverless App Service (project)), resources:write (for a database or bucket), domains:write (for a domain), git:write (for a repository)
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:kind | What the resource is: project (a Serverless App Service), database, bucket, domain, repository or agent. |
:ref | The resource: its id (prj_…, res_…, dev_…), or a domain's hostname. |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
groupId | string | No | up to 64 characters; can be null |
tags | object[] | No | up to 20 items |
tags[].key | string | Yes | up to 64 characters |
tags[].value | string | Yes | up to 256 characters |
Response 200
{
groupId: null | string
tags: {
key: string
value: string
}[]
}Errors
| Status | Message |
|---|---|
400 | Agents have no tags or groups. |
400 | Resource group not found. |
400 | Tag keys use letters, numbers, spaces and _ . : / = + - @, up to 64 characters, each once. |
404 | Unknown kind of resource. |
404 | Resource not found. |
GET /v1/orgs/:orgId/portal/resources/:kind/:ref/activity
What happened to a resource, newest first: its entries in the org's audit log, filtered like the log (action, actor) and paged (cursor, limit). Readable by those who may read the resource.
Auth: user access token or platform agent key · Scopes: projects:read (for a Serverless App Service (project)), resources:read (for a database or bucket), domains:read (for a domain), git:read (for a repository), agents:read (for an agent)
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:kind | What the resource is: project (a Serverless App Service), database, bucket, domain, repository or agent. |
:ref | The resource: its id (prj_…, res_…, dev_…), or a domain's hostname. |
| Query parameter | Type | Required | Default | Notes |
|---|---|---|---|---|
cursor | string | No | up to 4,096 characters | |
action | string | No | matches ^[a-z_]{1,32}(\.[a-z_]{1,32})?$ | |
actor | string | No | 1–512 characters | |
limit | integer | No | 50 | 1–100; coerced from a string |
Response 200
{
events: {
eventId: string
orgId: string
action: string
actor: {
type: "user" | "key" | "device" | "system"
id: string
label?: string
}
target: {
type: string
id: string
label?: string
}
metadata?: {
[key: string]: unknown
}
ip?: string
userAgent?: string
createdAt: number
}[]
cursor: null | string
retentionDays?: number
}Errors
| Status | Message |
|---|---|
400 | Invalid cursor |
404 | Unknown kind of resource. |
404 | Resource not found. |
GET /v1/orgs/:orgId/portal/resources/:kind/:ref/access
Who can reach a resource: each member, their role and what that role lets them do with it (manage, change or read), and the groups whose grants widen access to a Serverless App Service or a repository. Roles are changed in Tenant.
Auth: user access token or platform agent key · Scopes: members:read, projects:read (for a Serverless App Service (project)), resources:read (for a database or bucket), domains:read (for a domain), git:read (for a repository), agents:read (for an agent)
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:kind | What the resource is: project (a Serverless App Service), database, bucket, domain, repository or agent. |
:ref | The resource: its id (prj_…, res_…, dev_…), or a domain's hostname. |
Response 200
{
members: {
userId: string
name?: string
email?: string
role: "owner" | "admin" | "developer" | "viewer"
access: string
}[]
groups: {
teamId: string
name: string
access: string
}[]
}Errors
| Status | Message |
|---|---|
404 | Unknown kind of resource. |
404 | Resource not found. |
GET /v1/orgs/:orgId/portal/groups
The org's resource groups.
Auth: user access token or platform agent key · Scope: org:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Response 200
{
groups: {
groupId: string
name: string
description?: string
createdAt?: number
}[]
}POST /v1/orgs/:orgId/portal/groups
Creates a resource group (name, optional description). Needs resources:write.
Auth: user access token or platform agent key · Scope: resources:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | Yes | 1–64 characters; trimmed |
description | string | No | up to 256 characters; trimmed |
Response 201
{
group: {
groupId: string
name: string
description?: string
createdAt?: number
}
}Errors
| Status | Message |
|---|---|
400 | An organization has at most 200 resource groups. |
409 | A resource group with this name exists. |
PATCH /v1/orgs/:orgId/portal/groups/:resourceGroupId
Renames a resource group or changes its description. Needs resources:write.
Auth: user access token or platform agent key · Scope: resources:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:resourceGroupId | Resource group id (rgp_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | No | 1–64 characters; trimmed |
description | string | No | up to 256 characters; trimmed |
Response 200
{
group: {
groupId: string
name: string
description?: string
}
}Errors
| Status | Message |
|---|---|
404 | Resource group not found. |
409 | A resource group with this name exists. |
DELETE /v1/orgs/:orgId/portal/groups/:resourceGroupId
Deletes a resource group; its resources stay, outside any group. Needs resources:write.
Auth: user access token or platform agent key · Scope: resources:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:resourceGroupId | Resource group id (rgp_…). |
Response 200
{
ok: true
}Errors
| Status | Message |
|---|---|
404 | Resource group not found. |
GET /v1/orgs/:orgId/portal/me
Your portal in this org: favourite services in order (null: the defaults), recent resources and the dashboard Dashboard opens. People only.
Auth: user access token or platform agent key · Scope: org:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Response 200
{
favourites: null | string[]
recent: {
kind: "project" | "repository" | "agent" | "database" | "bucket" | "domain"
id: string
name: string
at: number
}[]
dashboardId: null | string
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
PUT /v1/orgs/:orgId/portal/me
Saves your favourite services (favourites: service keys in order, null for the defaults) or the dashboard Dashboard opens (dashboardId).
Auth: user access token or platform agent key · Scope: org:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
favourites | string[] | No | up to 40 items; each up to 40 characters; can be null |
dashboardId | string | No | up to 64 characters; can be null |
Response 200
{
favourites: null | string[]
recent: {
kind: "project" | "repository" | "agent" | "database" | "bucket" | "domain"
id: string
name: string
at: number
}[]
dashboardId: null | string
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
POST /v1/orgs/:orgId/portal/me/recent
Records that you opened a resource (kind, ref), for Recent.
Auth: user access token or platform agent key · Scopes: projects:read (for a Serverless App Service (project)), resources:read (for a database or bucket), domains:read (for a domain), git:read (for a repository), agents:read (for an agent)
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
kind | "project" | "database" | "bucket" | "domain" | "repository" | "agent" | Yes | |
ref | string | Yes | 1–260 characters |
Response 200
{
recent: {
kind: "project" | "repository" | "agent" | "database" | "bucket" | "domain"
id: string
name: string
at: number
}[]
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
404 | Resource not found. |
GET /v1/orgs/:orgId/portal/dashboards
Dashboards you can open: yours and those shared with the organization (without their tiles).
Auth: user access token or platform agent key · Scope: org:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Response 200
{
dashboards: {
tiles?: {
id: string
type: "resource" | "link" | "recent" | "note" | "deployments" | "traffic" | "services"
x: number
y: number
w: number
h: number
config: {
[key: string]: string
}
}[]
dashboardId: string
name: string
ownerId: string
shared: boolean
updatedAt?: number
}[]
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
POST /v1/orgs/:orgId/portal/dashboards
Creates a dashboard (name, optional shared and tiles); yours alone unless shared.
Auth: user access token or platform agent key · Scope: org:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | Yes | 1–80 characters; trimmed |
shared | boolean | No | |
tiles | any JSON[] | No | up to 60 items |
Response 201
{
dashboard: {
tiles?: {
id: string
type: "resource" | "link" | "recent" | "note" | "deployments" | "traffic" | "services"
x: number
y: number
w: number
h: number
config: {
[key: string]: string
}
}[]
dashboardId: string
name: string
ownerId: string
shared: boolean
updatedAt?: number
}
}Errors
| Status | Message |
|---|---|
400 | You have 50 dashboards here already. |
403 | The portal's preferences and dashboards belong to people. |
GET /v1/orgs/:orgId/portal/dashboards/:dashboardId
A dashboard with its tiles.
Auth: user access token or platform agent key
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:dashboardId | Dashboard id: an issue dashboard (dsh_…) or a Cloud portal dashboard (pdb_…). |
Response 200
{
dashboard: {
canChange?: boolean
tiles?: {
id: string
type: "resource" | "link" | "recent" | "note" | "deployments" | "traffic" | "services"
x: number
y: number
w: number
h: number
config: {
[key: string]: string
}
}[]
dashboardId: string
name: string
ownerId: string
shared: boolean
updatedAt?: number
}
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
404 | Dashboard not found. |
PUT /v1/orgs/:orgId/portal/dashboards/:dashboardId
Changes a dashboard: name, shared (owners only) and tiles (replaced; positions are compacted).
Auth: user access token or platform agent key
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:dashboardId | Dashboard id: an issue dashboard (dsh_…) or a Cloud portal dashboard (pdb_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | No | 1–80 characters; trimmed |
shared | boolean | No | |
tiles | any JSON[] | No | up to 60 items |
Response 200
{
dashboard: {
canChange: true
tiles?: {
id: string
type: "resource" | "link" | "recent" | "note" | "deployments" | "traffic" | "services"
x: number
y: number
w: number
h: number
config: {
[key: string]: string
}
}[]
dashboardId: string
name: string
ownerId: string
shared: boolean
updatedAt?: number
}
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
403 | Only its owner changes this dashboard. |
403 | Only its owner shares or unshares a dashboard. |
404 | Dashboard not found. |
DELETE /v1/orgs/:orgId/portal/dashboards/:dashboardId
Deletes a dashboard (its owner, or for a shared one those who manage the organization).
Auth: user access token or platform agent key
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:dashboardId | Dashboard id: an issue dashboard (dsh_…) or a Cloud portal dashboard (pdb_…). |
Response 200
{
ok: true
}Errors
| Status | Message |
|---|---|
403 | The portal's preferences and dashboards belong to people. |
403 | Only its owner deletes this dashboard. |
404 | Dashboard not found. |