Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Body

application/json

At most 500 events and 262144 UTF-8 bytes, before field filtering.

batchId
string<uuid>
required

Client UUID, retained unchanged across retries of the same request.

Required string length: 36
Pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
events
object[]
required
Required array length: 1 - 500 elements
dropped
integer
default:0

How many events the queue dropped before this batch.

Required range: 0 <= x <= 1000000000

Response

The complete batch committed, or its original success body was replayed. No partial acceptance.

contractVersion
integer
required
batchId
string<uuid>
required
Required string length: 36
recorded
integer
required
Required range: 1 <= x <= 500
rejected
object[]
required