Docs

HTTP API

The browser calls Cockpit on the same host. It does not call PostgREST from the client. Handlers live under apps/cockpit/app.

Auth

/cockpit/api/* uses the Supabase session cookie. requireUser() rejects a missing session. The middleware returns JSON 401 for these routes instead of redirecting to HTML. Responses are { "ok": true, ... } or { "ok": false, "error": "..." }.

Three routes sit outside that prefix:

MethodPathAuth
POST/api/mcpAuthorization: Bearer with a cbpat_… token or a user JWT. Proxies to the MCP Edge Function
GET/api/mcpUnauthenticated hint for OAuth metadata. Not a JSON-RPC call
GET/.well-known/oauth-protected-resourcePublic resource metadata
POST/api/v1/ingestAuthorization: Bearer with COCKPIT_INGEST_API_KEY. Agent-hook log ingest. Unexpected failures still return HTTP 200 with ok: false
POST/api/gap-actionSession. Files a pending approval for a calendar gap (log-call, generate-brief, not-held, exclude). Does not apply the action

Shell

MethodsPathPurpose
GET/cockpit/api/cockpitHome aggregate
GET/cockpit/api/dashDash tiles
GET/cockpit/api/global-searchName search. Query q
GET/cockpit/api/short-idResolve a short id
GET/cockpit/api/notificationsInbox
PATCH/cockpit/api/notifications/:idMark read or dismissed

Approvals

MethodsPathPurpose
GET/cockpit/api/approvalsPending queue
GET, PATCH/cockpit/api/approvals/:idRead, or set approved / rejected
POST/cockpit/api/approvals/bulkBulk resolve
POST/cockpit/api/approvals/:id/merge-approveApprove a merge card
GET/cockpit/api/approvals/:id/merge-contextMerge context for the card
POST/cockpit/api/approvals/:id/close-approveApprove a close card
POST/cockpit/api/approvals/:id/reject-cancelReject and cancel the linked work
POST/cockpit/api/approvals/:id/backlogSend linked work back to backlog
GET/cockpit/api/approvals/:id/task-contextTasks attached to the card
GET, PATCH/cockpit/api/approval-shapesRead or edit entity shapes and type contracts

Deck helpers, also session-authenticated: POST /cockpit/api/deck/chat, POST /cockpit/api/deck/graph-chat, GET /cockpit/api/deck/context, GET /cockpit/api/deck/ground, POST /cockpit/api/deck/events.

Tasks

MethodsPathPurpose
GET, POST/cockpit/api/tasksList or create
GET, PATCH/cockpit/api/tasks/:idRead or update
POST/cockpit/api/tasks/:id/promoteAsk to move a backlog task up
POST/cockpit/api/tasks/:id/starttodo to doing
POST/cockpit/api/tasks/:id/completeComplete a task that is not close-gated
POST/cockpit/api/tasks/:id/closeClose-gated acknowledgement
POST/cockpit/api/tasks/:id/request-closeOpen the close path
POST/cockpit/api/tasks/:id/stuckMark stuck
POST/cockpit/api/tasks/:id/resumestuck to todo
POST/cockpit/api/tasks/:id/demotetodo to backlog
POST/cockpit/api/tasks/:id/reopenReopen from done
POST/cockpit/api/tasks/:id/cancelCancel
POST/cockpit/api/tasks/:id/approve-reviewAccept a task that is in review
POST/cockpit/api/tasks/:id/archiveArchive
GET, POST/cockpit/api/tasks/:id/merge-gateRead or act on the linked pull-request gate
GET/cockpit/api/tasks/:id/activitiesActivity linked to the task
POST/cockpit/api/tasks/scheduledCreate a scheduled task
POST/cockpit/api/tasks/:id/schedule-enableEnable that schedule
GET/cockpit/api/task-tagsTag catalog

Records

GET list routes: /accounts, /contacts, /sales (deals), /projects, /campaigns, /territories, /pipeline, /activities, /marketing-content.

Search helpers: GET /accounts/search, GET /records/search.

Generic entity drawer:

MethodsPathPurpose
POST/cockpit/api/entities/:tableCreate through the app's entity path
GET, PATCH, DELETE/cockpit/api/entities/:table/:idRead, update, delete
POST/cockpit/api/entities/:table/:id/mergeMerge

POST, PATCH, and DELETE allow accounts, contacts, deals, projects, campaigns, and territories. GET also opens the drawer for campaign members, prospects, marketing content, and ICP profiles.

Deal line items: GET and POST /cockpit/api/deals/:id/line-items, PATCH and DELETE /cockpit/api/deals/:id/line-items/:itemId.

Products: GET and POST /products, GET and PATCH /products/:id.

Campaign products: GET and POST /campaigns/:id/products, DELETE /campaigns/:id/products/:productId.

Project actions under /projects/:id: GET and PATCH the row, GET …/child-counts, and POST convert, delete, merge, owner, and undo-delete.

Cases: GET and POST /cases, GET and PATCH /cases/:id, outcomes on /cases/:id/outcomes.

Workflows, agents, tokens

MethodsPathPurpose
GET, POST/cockpit/api/workflowsList or create templates
GET, PATCH/cockpit/api/workflows/:idRead or edit
POST/cockpit/api/workflows/:id/triggerEnqueue a trigger
POST/cockpit/api/workflows/:id/trigger/dry-runValidate without starting
GET/cockpit/api/workflows/:id/trigger/eventsTrigger event log
GET, POST/cockpit/api/runtimesList or upsert a runtime. ?all=1 includes disabled
PATCH/cockpit/api/runtimes/:idUpdate. Blank secret keeps the stored one
POST/cockpit/api/runtimes/:id/disableDisable
POST/cockpit/api/runtimes/:id/instant-taskInsert a todo for that runtime
GET/cockpit/api/runtimes/:id/sessionsSessions for the runtime
GET/cockpit/api/runtimes/binding-optionsRuntimes you can bind a job to
GET, POST/cockpit/api/ops/jobsRoutines. /cockpit/api/ops/routines is the same handlers
GET/cockpit/api/queueQueue and tick snapshot
POST/cockpit/api/queue/bindSet or clear a job's primary runtime
POST/cockpit/api/queue/heartbeatbootstrap or run_now
GET, POST/cockpit/api/tokensList tokens, or issue one. Plaintext is in the create response only
POST/cockpit/api/tokens/:id/revokeRevoke
POST/cockpit/api/tokens/:id/scopesReplace extra scopes
POST/cockpit/api/tokens/:id/setsReplace permission-set membership
GET, POST, PATCH/cockpit/api/permission-setsList, create, archive
GET, POST/cockpit/api/permission-sets/adminAdmin operations on sets
GET, POST/cockpit/api/usersList members, or invite / change role / deactivate

Calendar, comments, files

MethodsPathPurpose
GET/cockpit/api/calendar/gridCalendar grid
GET/cockpit/api/timelineLegacy timeline payload
POST/cockpit/api/timeline/linkAttach a note to an event
GET, POST/cockpit/api/commentsList or create
GET, PATCH/cockpit/api/comments/:idRead, or ack / applied / dismiss
GET, POST/cockpit/api/filesFile metadata
GET/cockpit/api/files/:id/urlShort-lived download URL
GET, POST/cockpit/api/assetsMarketing asset registry
GET, PATCH/cockpit/api/assets/:idOne asset
POST/cockpit/api/assets/:id/versionsAdd a version
POST/cockpit/api/assets/:id/currentSet the current version

Goals, ICP, health

MethodsPathPurpose
GET, POST/cockpit/api/goals/chartersCharters
GET/cockpit/api/goals/charters/:idOne charter
GET/cockpit/api/goals/metricsMetric catalog
GET/cockpit/api/goals/metrics/queryCompute one metric
GET, POST/cockpit/api/icp-profilesICP profiles
GET/cockpit/api/icp-fit-intentFit and intent grid
GET/cockpit/api/icp-win-rateWin-rate summary
GET/cockpit/api/healthGraph hygiene
GET/cockpit/api/pipeline-healthMeeting-pipeline health fields
GET/cockpit/api/decisions/rank1Quality-classification audit
GET, PATCH/cockpit/api/decisions/graph/:flowKeyDecision-flow graph
POST/cockpit/api/flows/:slug/startStart a registered flow

Integrations under /cockpit/api/integrations connect or revoke a provider and store optional Cursor and log-drain settings. Treat provider secrets as server-side only.

The route list was taken from the route modules' exported methods. Request bodies are not fully specified here.