API reference
The v1 API creates requests, reads decisions and lets your worker claim a sealed intent. Policy, the audit log and the full record of a ceremony live on the dashboard.
Base URL
Section titled “Base URL”https://api.outis.tech/v1
The SDKs default to it, so a client needs only a key.
Conventions
Section titled “Conventions”- Requests and responses are JSON. A body has to be
application/json; a write with another content type is a 415. - Every time is UTC epoch milliseconds and nullable. A null time means not yet.
- An unknown field in a body is a 400.
- Ids are opaque strings. A request id looks like
req-4f2a9c1b8d7e6f50. - Creating takes an
Idempotency-Keyheader. With one, a retry returns the request the first call made; without one, creating twice makes two requests. See Create a request. - Every response wraps its record with
server_now, the server’s clock when it answered.
| Language | Package | Client |
|---|---|---|
| Node | @outis/sdk |
new Outis({ apiKey }) |
| Python | outis |
Outis(api_key=) |
| Go | github.com/outis-auth/outis-go |
outis.New(apiKey) |
Each SDK guards a call (waiting up to 30 minutes, or handing it to a worker you run), creates and reads requests, checks an authorization against the operation you’re about to run, and verifies webhooks (verifyWebhook, verify_webhook and outis.VerifyWebhook). SDKs covers all three. The curl tab on every sample shows the wire format.
Authentication
API keys, scopes and refusals.
Errors
The error body and every status.
Requests
The request object, create and retrieve.
Execution
Sealed intents, claims and reports.
Events and callbacks
The post, its headers, its signature and its retries.