Backend Route Inventory
The public contract is exposed only by backend/engine. Internal services keep the same path shape so the engine can proxy without changing Manager, mobile, SDK, ADK, web, or external API clients.
Engine Public Routes
GET /api/v1/healthGET /api/v1/readyPOST /api/v1/auth/tokenPOST /api/v1/auth/registerGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realmsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realms/:id/membersGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realms/:id/agentsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realms/:id/servicesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realms/:id/identities/servicesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/realms/:id/themeGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/users/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/auth/keysGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/auth/is-authenticatedGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/auth/introspectGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/internal/webhooks/inboundGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/storesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/searchGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/productGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/cartsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/carts/clearGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/ordersGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/catalog/orders/completeGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/statusGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/capabilitiesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/flowsPOST /api/v1/runtime/flows/draftGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/flows/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/flows/:id/activateGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/flows/:id/previewGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/flows/:id/executePOST /api/v1/runtime/flows/:id/publish|archive|rollback|test|promoteGET /api/v1/runtime/flows/:id/versions|fixtures|triggersPOST /api/v1/runtime/flows/:id/fixtures|triggersPOST /api/v1/runtime/flows/:id/triggers/:trigger_id/fireDELETE /api/v1/runtime/flows/:id/triggers/:trigger_idPOST /api/v1/runtime/mcp/tool-proposals/generateGET /api/v1/runtime/mcp/tool-proposalsPOST /api/v1/runtime/mcp/tool-proposals/:proposal_id/reviewGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/promptsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/prompts/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/prompts/:id/activateGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/agents/:agent_id/configGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/agents/:agent_id/mcp-serversGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/agents/:agent_id/mcp-servers/:mcp_server_idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/agents/:agent_id/flows/:flow_id/selectGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/sessionsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/sessions/:session_idPOST /api/v1/runtime/sessions/:session_id/completePOST /api/v1/runtime/sessions/:session_id/cancelPOST /api/v1/runtime/sessions/:session_id/resetGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/sessions/:session_id/messagesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/users/:user_id/contextGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/sessions/:session_id/contextGET|PUT /api/v1/runtime/sessions/:session_id/stateDELETE /api/v1/runtime/sessions/:session_id/state/:keyPOST /api/v1/runtime/sessions/:session_id/summarizeGET|POST /api/v1/runtime/knowledgePOST /api/v1/runtime/knowledge/searchDELETE /api/v1/runtime/knowledge/:knowledge_idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/routing/rulesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/routing/rules/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/routing/previewGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/routing/reloadGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/routing/trace/:trace_idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/ai/chatGET /api/v1/runtime/flow-routing-profilesGET|PUT /api/v1/runtime/flows/:id/routing-profileGET|PUT /api/v1/runtime/flow-routing-policyPOST /api/v1/runtime/flow-routing-previewPOST /api/v1/runtime/executeGET|POST /api/v1/runtime/executionsGET /api/v1/runtime/executions/:idPOST /api/v1/runtime/executions/:id/cancelPOST /api/v1/runtime/executions/:id/retryPOST /api/v1/runtime/executions/:id/resumeGET /api/v1/runtime/executions/:id/eventsGET /api/v1/runtime/executions/:id/actionsPOST /api/v1/runtime/executions/:id/approvals/:approval_id/approvePOST /api/v1/runtime/executions/:id/approvals/:approval_id/denyGET|POST /api/v1/runtime/evaluationsGET /api/v1/runtime/routing-recommendationsPOST /api/v1/runtime/routing-recommendations/generateGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/ai/usageGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/ai/usage/statsGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/providersGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/providers/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/providers/:id/toggleGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/providers/templatesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/providers/templates/:typeGET /api/v1/runtime/configuration/schemaGET /api/v1/runtime/configuration/exportPOST /api/v1/runtime/configuration/deploy(dry_run=trueplans,falseapplies)POST /api/v1/governance/flow-routing-evaluations
Provider create/update payloads use the authenticated JWT realm_id and the shared provider contract: name, description, type, write-only api_key, base_url, supports_text, supports_image, text_model, image_model, price fields, currency, is_default, is_active, and optional settings. At least one capability must be enabled and each enabled capability requires its matching model.
Automatic Flow classification uses only the authenticated realm's active, text-capable default provider. Agent-level provider assignments apply after Flow selection. If that default is unavailable, routing-disabled, or denied by data-egress policy, the resolver uses deterministic local fallback instead of another provider.
GET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/serversGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/servers/:idGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/servers/:id/toggleGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/servers/:id/testGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/servers/:id/discoverGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/servers/:id/toolsGET|POST|OPTIONS /api/v1/runtime/mcp/servers/:id/credentialsPOST|OPTIONS /api/v1/runtime/mcp/servers/:id/credentials/:version/rollbackGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/proxyGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/tools/routeGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/tools/executeGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/tools/execute-parallelGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/runtime/mcp/tools/aggregateGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/usagesGET|POST|PUT|PATCH|DELETE|OPTIONS /api/v1/usages/summaryPOST /api/v1/data/eventsPOST /api/v1/data/events/batchGET /api/v1/data/queryGET /api/v1/data/summary
Internal Services
auth-service:/api/v1/health,/api/v1/ready, auth, realm, user, auth-status,/api/v1/auth/verify, and/api/v1/auth/introspectroutes.runtime-service:/api/v1/health,/api/v1/ready, runtime status, flows, prompts, agents, sessions, context, and routing routes.ai-service:/api/v1/health,/api/v1/ready, AI chat, AI usage, and provider routes.mcp-service:/health,/ready,/mcp,/api/v1/health,/api/v1/ready, MCP server management, proxy, routing, execution, parallel execution, and aggregation routes.usage-service:/api/v1/health,/api/v1/ready, usage listing and summary routes.catalog-service:/api/v1/healthand Catalog auth, webhook, store, product, cart, and order routes. The Engine is its default public boundary; an explicitly secured dedicated ingress is optional.enrichment-service:/healthplus internal Enrichment execution, usage, and job routes. Manager calls it over the private service network.data-service: anonymous realm-scoped commerce, search, and conversation event ingestion, OpenSearch query, and aggregation routes.safezone-service: internal tenant policy resolution, installed Safe Zone health checks, request/response inspection, masking/blocking decisions, and decision-only audit metadata.
Health and readiness routes are safe for probes. All domain routes require engine-signed internal headers when INTERNAL_SERVICE_SECRET is configured.
MCP server registration automatically calls tools/list, persists discovered tools in mcp_tools, and uses that registry for route selection when callers do not provide explicit mcp_server_ids. Manual rediscovery remains available through POST /api/v1/runtime/mcp/servers/:id/discover.
Unified MCP Service
The unified mcp-service exposes MCP JSON-RPC over HTTP:
POST /forinitialize,tools/list, andtools/callPOST /mcpfor the same MCP JSON-RPC methodsGET /healthGET /ready
Core tools:
acp_api_request: generic engine/api/v1request tool for complete API coverage.acp_mcp_authenticate: authenticate MCP access through Auth with a Manager API key or legacy realm service identity.acp_auth_register: register a user when enabled.acp_runtime_ai_chat: call runtime AI chat.acp_runtime_execute: synchronously run the versioned durable execution contract.acp_runtime_create_execution: queue a durable execution.acp_runtime_list_executions,acp_runtime_execution_get: inspect execution state and normalized results.acp_runtime_execution_events,acp_runtime_execution_actions: inspect progress or replay normalized actions without side effects.acp_runtime_execution_cancel,acp_runtime_execution_retry,acp_runtime_execution_resume: control durable work.acp_runtime_approval_approve,acp_runtime_approval_deny: decide pending write-tool approvals.acp_runtime_list_flows: list flows available to the authenticated realm.acp_runtime_list_providers: list AI providers.acp_runtime_mcp_execute_tool: execute a routed MCP tool through the engine.acp_usage_summary: read usage summary.acp_configuration_schema,acp_configuration_export: inspect or export portable, secret-free realm configuration.acp_configuration_plan,acp_configuration_apply: validate/diff or transactionally apply reviewed configuration.acp_data_record_event,acp_data_record_events: ingest anonymous events after PII removal and pseudonymization.acp_data_query,acp_data_summary: query realm-scoped anonymous event data and aggregations.
The Merchant Commerce reference contract is catalog_search, catalog_get_product, cart_create, cart_get, cart_add_item, cart_update_item, cart_remove_item, cart_clear, cart_close, checkout_prepare, checkout_get, and checkout_cancel. Legacy Catalog aliases remain available for migration compatibility. Every write requires an idempotency key; checkout is an opaque payment handoff. Procurement and payment-provider tools are intentionally not exposed by ACP's built-in merchant profile.
Catalog MCP tool calls accept a merchant API key through Authorization: Bearer, x-api-key, X-Catalog-API-Key, or the legacy X-MCP-API-Key. Realm-bound Engine tools use an Engine Identities API key:
X-ACP-Realm-IDAuthorization: Bearer <api-key>orx-api-key: <api-key>
The same values can also be provided as realmId and apiKey, or inside auth: { realmId, apiKey }. Legacy accessKey and secretKey arguments and headers remain supported.
Developer, Observability, and Governance Routes
All Go services expose an internal-network GET /metrics endpoint for Prometheus scraping. Metrics contain service, HTTP method, route, and status labels only; realm identifiers and request payloads are excluded.
GET /api/v1/sdk/configGET /api/v1/observability/logsGET /api/v1/observability/traces/:trace_idGET /api/v1/observability/metricsGET|POST /api/v1/observability/alertsGET|POST /api/v1/integrations/clientsPOST /api/v1/integrations/clients/:id/rotate-secretGET /api/v1/governancePOST /api/v1/governance/policiesPOST /api/v1/governance/policies/:id/activatePOST /api/v1/governance/allowlistPOST /api/v1/governance/allowlist/:id/decisionPUT /api/v1/governance/quotasPOST /api/v1/governance/evaluation-datasetsPOST /api/v1/governance/evaluation-runsPOST /api/v1/governance/deployment-profilesPOST /api/v1/governance/support-accessPOST /api/v1/governance/lawful-requestsPOST /api/v1/runtime/webhooksGET /api/v1/runtime/configuration/schemaGET /api/v1/runtime/configuration/exportPOST /api/v1/runtime/configuration/deployGET /api/v1/usages/tools/summaryPOST /api/v1/usages/export