/api/healthSee handlerJSON ok, service name, and uptime seconds.
Smohix Technologies HQ · developer system
API documentation
Catalog derived from app/api route handlers in this repository. Base URL: https://smohix.run
Developer platform → · Manage API keys →
Smohix HQ exposes same-origin HTTP APIs for health checks, alert/vulnerability ingest, console operations (session), connector proxies, and compliance assessor exports. This is not the Smohix AI product API at https://ai.smohix.run.
Base URL: https://smohix.run
GET /api/health (public) or authenticate /api/reasoning/* / /api/robot/* with Authorization: Bearer smohix_sk_….Grouped catalog of routes implemented in this repository. Auth expectations are taken from handlers — do not assume API keys work on session-only console routes.
Liveness for load balancers; no auth.
/api/healthSee handlerJSON ok, service name, and uptime seconds.
/api/healthSee handlerSame as GET without body.
/api/incidents/{id}/exportSession cookieDownload incident as Markdown (authenticated Supabase user).
/api/incidents/{id}/evidenceSession cookieDownload incident evidence pack JSON (timeline, dry-run, audit-linked events).
/api/incidents/{id}/reviewSession cookieDownload post-incident review Markdown (narrative, timeline, execution evidence, audit snapshot).
/api/incidents/{id}/rca/runSession cookieGenerate and persist an incident RCA hypothesis with confidence and evidence references.
/api/incidents/{id}/rca/latestSession cookieFetch latest persisted RCA run for an incident.
/api/services/{id}/sloSession cookieFetch service SLO profile plus latest error budget windows (7d/30d).
/api/overview/error-budget-summarySession cookieFetch SLO error budget overview across services (critical/warning burn and average used budget).
/api/integrations/alertsBearer ingest tokenCreate or dedupe incident from monitoring (Bearer alert ingest token). Paid-gated per deployment; validates token server-side. Supports normalized Smohix payload, Datadog, Prometheus/Grafana Alertmanager, PagerDuty, and New Relic payloads (vendor-specific dedupe keys). Optional HMAC signature check via SMOHIX_ALERT_WEBHOOK_SIGNING_SECRET.
/api/integrations/vulnerabilitiesBearer ingest tokenUpsert Qualys/Tenable finding; auto-open incident for high/critical (Bearer ingest token). Same token as alert ingest. Optional X-Smohix-Vuln-Source header. Supports Qualys (QID/HOST), Tenable (plugin/asset), or generic finding_id payloads.
/api/health/dbNonePostgres readiness via database health RPC (requires migration #15).
/api/connectors/statusSession cookie when Supabase auth is enabledProbe configured reasoning/automation connector URLs.
/api/integrations/connectionsSession cookieList org-scoped first-party integration connection records.
/api/integrations/connectionsSession cookie (owner/admin/operator)Create an org-scoped integration connection placeholder for Slack, PagerDuty, Jira, ServiceNow, GitHub, Datadog, or Prometheus.
/api/integrations/deploy-eventsSession cookieIngest an authenticated deploy/change event for incident and Copilot correlation.
/api/integrations/slack/approvalsSlack request signature (X-Slack-Signature)Receive signed Slack action payloads and decide pending approvals.
/api/approvals/policy-suggestions/promoteSession cookie (or session mode fallback)Promote a decision-intelligence policy suggestion into policy review and log audit evidence.
/api/deployment/profileSession cookieActive organization deployment tier, data region, and boundary (FedRAMP-oriented).
/api/deployment/retentionSession cookieEffective org retention policy for audit_log and closed incidents (tier defaults + overrides).
/api/governance/compliance/summarySession cookieSOC 2 / ISO 27001 control coverage from audit_log and accepted policies (30d window).
/api/governance/compliance/programSession cookieCompliance program dashboard — weighted readiness, SOC 2 / ISO gaps, attestation and vendor rollups.
/api/governance/compliance/gap-remediationsSession cookieGap-to-runbook remediation queue from live assessment exceptions plus org tracking rows.
/api/governance/compliance/risk-heatmapSession cookieCompliance risk heatmap — framework concentration, vendor tier matrix, and top hotspots from live org data.
/api/governance/compliance/executive-summarySession cookieBoard-ready GRC executive summary — program readiness, frameworks, hotspots, and leadership actions (JSON, Markdown, HTML, CSV).
/api/governance/compliance/calendarSession cookieGRC compliance calendar — attestations, vendor reviews, bundles, audit season checkpoints (JSON or CSV).
/api/governance/compliance/benchmarkingSession cookieControl benchmarking — org readiness percentiles vs industry reference cohorts (JSON or CSV).
/api/governance/compliance/policy-driftSession cookiePolicy drift — accepted automation guardrails vs live assessment gaps (JSON or CSV).
/api/governance/compliance/control-graphSession cookieControl dependency graph — crosswalk, thematic, shared audit, and shared policy edges (JSON or CSV).
/api/governance/compliance/regulatory-impactSession cookieRegulatory change impact — scenario readiness deltas vs live baseline (JSON or CSV).
/api/governance/compliance/evidence-lineageSession cookieEvidence lineage — audit and policy sources through bundles to assessor workbook (JSON or CSV).
/api/governance/compliance/testing-evidence-linkerSession cookieControl testing evidence linker — dry-run outputs mapped to controls and evidence bundles (JSON or CSV).
/api/governance/compliance/testing-evidence-linkerSession cookieRecord test-to-bundle links in audit log for assessor export trail.
/api/governance/compliance/testing-schedulesSession cookieControl testing schedules — recurring evidence windows from attestations, checkpoints, and freshness (JSON or CSV).
/api/governance/compliance/scope-boundarySession cookieScope boundary mapper — in-scope systems, data flows, and framework control mappings (JSON or CSV).
/api/governance/compliance/kpi-trendsSession cookieCompliance KPI trends — weekly remediation velocity, attestation closure, framework readiness (JSON or CSV).
/api/governance/compliance/posture-scoreSession cookieUnified compliance posture score — blended readiness, attestations, vendors, gaps, risk (JSON or CSV).
/api/governance/compliance/control-ownershipSession cookieGRC control ownership matrix — RACI per control linked to scope and attestations (JSON or CSV).
/api/governance/compliance/exception-registerSession cookieCompliance exception register — assessment gaps, policy drift, compensating remediations (JSON or CSV).
/api/governance/compliance/evidence-requestsSession cookieAssessor evidence request workflow — open document requests with due dates and control linkage (JSON or CSV).
/api/governance/compliance/evidence-request-slaSession cookieEvidence request SLA dashboard — overdue queue, at-risk window, fulfillment metrics (JSON or CSV).
/api/governance/compliance/evidence-request-slaSession cookieDeliver auditor evidence request SLA digest (email + optional webhook).
/api/governance/compliance/evidence-request-sla/scheduledBearer cron secretCron SLA digest delivery (Bearer SMOHIX_EVIDENCE_REQUEST_SLA_CRON_SECRET).
/api/governance/compliance/obligation-icsSession cookieCompliance obligation ICS — iCalendar feed of attestations, vendors, bundles, checkpoints (text/calendar).
/api/governance/compliance/mapping-digestSession cookiePreview regulatory mapping change digest vs last org snapshot.
/api/governance/compliance/mapping-digestSession cookieRun mapping change digest — webhook/email when catalog or crosswalk changes.
/api/governance/compliance/mapping-digest/scheduledBearer cron secretCron mapping digest (Bearer SMOHIX_MAPPING_DIGEST_CRON_SECRET).
/api/governance/compliance/inherited-control-gapsSession cookieInherited control coverage gaps — vendors missing evidence on tier-inherited controls (JSON or CSV).
/api/governance/compliance/control-health-scorecardSession cookieLeadership control health scorecard — posture, vendor inherited controls, and gap closure (JSON or CSV).
/api/governance/compliance/obligation-heatmapSession cookieRegulatory obligation heatmap — open obligations by framework, vendor tier, and testing schedule (JSON or CSV).
/api/governance/compliance/obligation-crossoverSession cookieMulti-framework obligation crossover — shared due windows and crosswalk-linked evidence reuse clusters (JSON or CSV).
/api/governance/compliance/obligation-consolidationSession cookieObligation consolidation playbook — six-step workflows per crossover cluster with tracked play status (JSON or CSV).
/api/governance/compliance/obligation-forecastSession cookieBoard obligation forecast — weekly forward-looking obligation density and committee milestones (JSON or CSV).
/api/governance/compliance/obligation-whatifSession cookieBoard obligation what-if — stress-test forecast density with week shifts or framework descope (JSON or CSV).
/api/governance/compliance/committee-capacity-budgetSession cookieCommittee obligation capacity budget — weekly owner-hours vs forecast peaks with shortfall flags (JSON or CSV).
/api/governance/compliance/obligation-load-balancingSession cookieObligation owner load balancing — peak-week RACI load slices and rebalance suggestions (JSON or CSV).
/api/governance/compliance/peak-week-staffing-digestSession cookiePeak-week staffing digest — capacity shortfall + load imbalance coincidence preview (JSON or CSV).
/api/governance/compliance/peak-week-staffing-digestSession cookie (owner/admin)Deliver peak-week staffing digest (email, Slack, optional webhook).
/api/governance/compliance/peak-week-staffing-digest/scheduledBearer cron secretCron peak-week staffing digest (Bearer SMOHIX_PEAK_WEEK_STAFFING_DIGEST_CRON_SECRET).
/api/governance/compliance/staffing-actionsSession cookieObligation staffing action tracker — proposed and tracked load-balance and capacity relief actions (JSON, CSV, or HTML completion report).
/api/governance/compliance/staffing-action-remindersSession cookieStaffing action overdue reminders — open actions past peak week preview (JSON or CSV).
/api/governance/compliance/staffing-action-remindersSession cookie (owner/admin)Send staffing action overdue reminders (email and Slack).
/api/governance/compliance/staffing-action-reminders/scheduledBearer cron secretCron staffing overdue reminders (Bearer SMOHIX_STAFFING_OVERDUE_REMINDER_CRON_SECRET).
/api/governance/compliance/staffing-completion-rollupSession cookieStaffing completion rollup — tracked vs open vs completed archive (JSON, CSV, or printable HTML).
/api/governance/compliance/staffing-completion-rollupSession cookie (owner/admin)Email weekly staffing completion rollup to owners and admins.
/api/governance/compliance/staffing-completion-rollup/scheduledBearer cron secretCron staffing completion rollup (Bearer SMOHIX_STAFFING_COMPLETION_ROLLUP_CRON_SECRET).
/api/governance/compliance/staffing-sla-breach-digestSession cookieStaffing SLA breach digest — open actions past committee completion SLA after peak week (JSON or CSV).
/api/governance/compliance/staffing-sla-breach-digestSession cookie (owner/admin)Deliver staffing SLA breach digest (email and Slack).
/api/governance/compliance/staffing-sla-breach-digest/scheduledBearer cron secretCron staffing SLA breach digest (Bearer SMOHIX_STAFFING_SLA_BREACH_DIGEST_CRON_SECRET).
/api/governance/compliance/cross-staffing-committee-escalationSession cookieCross-staffing committee escalation — SLA breaches still open after completion rollup email (JSON or CSV).
/api/governance/compliance/cross-staffing-committee-escalationSession cookie (owner/admin)Deliver cross-staffing committee escalation (email and Slack).
/api/governance/compliance/cross-staffing-committee-escalation/scheduledBearer cron secretCron cross-staffing committee escalation (Bearer SMOHIX_CROSS_STAFFING_COMMITTEE_ESCALATION_CRON_SECRET).
/api/governance/compliance/staffing-digest-auto-chain/scheduledBearer cron secretCron staffing digest auto-chain — rollup, SLA digest, escalation in one run (Bearer SMOHIX_STAFFING_DIGEST_AUTO_CHAIN_CRON_SECRET).
/api/governance/compliance/committee-digestSession cookieQuarterly obligation committee digest — forecast, crossover, and SLA rollup preview (JSON or CSV).
/api/governance/compliance/committee-digestSession cookie (owner/admin)Deliver quarterly obligation committee digest (email + optional webhook).
/api/governance/compliance/committee-digest/scheduledBearer cron secretCron quarterly digest delivery (Bearer SMOHIX_OBLIGATION_COMMITTEE_DIGEST_CRON_SECRET).
/api/governance/compliance/obligation-rollupSession cookieObligation executive rollup — printable HTML (print to PDF), JSON, or CSV for board packets.
/api/governance/compliance/obligation-density-alertsSession cookieObligation density alerting — forecast breach preview against org thresholds (JSON or CSV).
/api/governance/compliance/obligation-density-alertsSession cookie (owner/admin)Send obligation density Slack and email alerts for active breaches.
/api/governance/compliance/obligation-density-alerts/scheduledBearer cron secretCron obligation density alerts (Bearer SMOHIX_OBLIGATION_DENSITY_ALERT_CRON_SECRET).
/api/governance/compliance/obligation-density-trend-historySession cookieObligation density trend history — trailing-quarter weekly density and alert deliveries (JSON or CSV).
/api/governance/compliance/committee-meeting-packSession cookieCommittee meeting pack ZIP — printable HTML summary, scorecard, posture, exceptions, and open gaps.
/api/governance/compliance/attestation-renewalSession cookieAttestation renewal calendar — renewal waves by due window with framework rollup (JSON or CSV).
/api/governance/compliance/attestation-renewalSession cookieEmail control owners for current renewal waves (org admins).
/api/governance/compliance/attestation-renewal/scheduledBearer cron secretCron owner renewal nudges (Bearer SMOHIX_ATTESTATION_RENEWAL_CRON_SECRET).
/api/governance/legal-holdsSession cookieActive legal holds on incidents and count of audit rows flagged (org-scoped).
/api/governance/compliance/bundlesSession cookieList persisted assessor evidence bundles for the active organization.
/api/governance/compliance/bundlesSession cookie (owner/admin)Create tamper-evident evidence bundle; optional webhook delivery to org URL.
/api/governance/compliance/bundles/scheduledBearer cron secretCron entrypoint to generate bundle (Bearer SMOHIX_BUNDLE_CRON_SECRET, body: orgId, window).
/api/governance/compliance/bundles/{id}Session cookieFetch persisted evidence bundle metadata and manifest verification for the active org.
/api/governance/compliance/bundles/{id}/downloadSession cookieDownload evidence bundle ZIP archive by bundle id.
/api/governance/compliance/crosswalkSession cookieSOC 2 / ISO 27001 crosswalk — mapping matrix with optional periodDays and format=csv|json; evidence overlay per control.
/api/governance/compliance/workbookSession cookieUnified assessor workbook ZIP — evidence pack, crosswalk, framework assessments, README, and tamper-evident manifest.
/api/governance/compliance/digestSession cookie (owner/admin)Compliance program digest — readiness deltas vs prior snapshot, overdue attestations; optional HTTPS webhook delivery.
/api/governance/compliance/digest/scheduledBearer SMOHIX_DIGEST_CRON_SECRETCron digest delivery — Bearer SMOHIX_DIGEST_CRON_SECRET; body { orgId, periodDays? }.
/api/governance/compliance/sla-remindersSession cookiePreview SLA reminder candidates (due soon, overdue, regressed) and org settings.
/api/governance/compliance/sla-remindersSession cookie (owner/admin)Send compliance SLA reminders via Slack and optional Resend email (owner/admin).
/api/governance/compliance/sla-reminders/scheduledBearer SMOHIX_SLA_CRON_SECRETCron SLA reminders — Bearer SMOHIX_SLA_CRON_SECRET; body { orgId }.
/api/governance/compliance/fedramp-poamSession cookieFedRAMP POA&M export — NIST 800-53 rows from continuous assessment gaps; periodDays and format=csv|json.
/api/governance/compliance/evidence-freshnessSession cookieEvidence freshness dashboard — per-control last evidence timestamps, stale queue; format=csv|json.
/api/governance/compliance/baseline-comparisonSession cookieMulti-framework baseline comparison — live readiness and prior-period deltas for all framework packs; format=csv|json.
/api/governance/compliance/assessor-tokensSession cookieList org assessor API tokens and allowed export resource paths.
/api/governance/compliance/assessor-tokensSession cookie (owner/admin)Create org assessor API token (smohix_ca_*); returns plaintext key once.
/api/governance/compliance/assessor-tokens/{id}Session cookie (owner/admin)Revoke assessor API token.
/api/governance/compliance/assessor/{id}Bearer assessor tokenAssessor read-only export — evidence-export, workbook, crosswalk, obligation-ics, baseline-comparison, risk-heatmap, executive-summary, framework reports; Bearer smohix_ca_* token.
/api/governance/compliance/exportSession cookieCompliance evidence pack — audit events + accepted policies with control tags (CSV or JSON).
/api/governance/compliance/type-iiSession cookieSOC 2 Type II continuous monitoring report — control trends, exceptions, evidence bundle and legal-hold counts.
/api/governance/compliance/iso-assessmentSession cookieISO 27001 Annex A continuous assessment — domain readiness, control trends, and gap analysis.
/api/governance/compliance/pci-dssSession cookiePCI DSS v4 control pack — requirement readiness, trends, and gap analysis from shared audit evidence.
/api/governance/compliance/hipaaSession cookieHIPAA Security Rule safeguards — readiness, trends, gap analysis, and BAA vendor control inheritance.
/api/governance/compliance/nist-csfSession cookieNIST CSF 2.0 alignment — function maturity tiers, control trends, and gap analysis from shared audit evidence.
/api/governance/compliance/cis-v8Session cookieCIS Controls v8 safeguard pack — Implementation Group readiness, control trends, and gap analysis.
/api/governance/compliance/cmmc-l2Session cookieCMMC 2.0 Level 2 overlay — 800-171 practice readiness, SPRS-style score, and gap analysis.
/api/governance/compliance/gdpr-art32Session cookieGDPR Article 32 technical measures — domain readiness, DPA bands, and gap analysis.
/api/governance/compliance/attestationsSession cookieControl attestation board — owners, due dates, status, linked audit evidence counts per SOC 2 / ISO control.
/api/governance/third-party/vendorsSession cookieThird-party risk register — vendors with inherited controls, attestation status, and reused audit evidence counts.
/api/governance/third-party/vendorsSession cookie (owner/admin)Add vendor; inherit SOC 2 / ISO controls from risk tier and category (owner/admin).
/api/governance/policy-blocks/summarySession cookieReturn policy-block analytics summary for current user (window=7d|30d, includes prior-window delta and reason distribution).
/api/automations/dry-runSession cookieRun playbook dry-run; may persist and append audit when configured.
/api/automations/executeSession cookieRecord guarded execution after successful dry-run with approval note and rollback plan.
/api/automations/remediateSession cookieRun guarded remediation with dry-run freshness and accepted policy checks.
/api/automations/policiesSession cookieList versioned automation policy-as-code documents for the active workspace.
/api/automations/policiesSession cookie (owner/admin/operator)Create a draft or active policy-as-code version for a playbook.
/api/attack-paths/simulateSession cookieSimulate ranked attack paths from vuln entry points through dependency graph to production targets. Optional query: targetServiceId, maxDepth.
/api/services/dependency-graphSession cookieFetch service dependency graph (nodes and directed edges).
/api/copilot/chatSession cookie when OPENAI_API_KEY and Supabase auth are set; otherwise IP rate limitStreaming or JSON chat completion (OpenAI → reasoning URL → guided offline).
/api/copilot/threadsSession cookieList conversation threads.
/api/copilot/threadsSession cookieCreate thread.
/api/copilot/threads/{id}/messagesSession cookieList messages in a thread.
/api/copilot/threads/{id}/messagesSession cookieAppend user message and run assistant turn.
/api/user/api-keysSession cookieList API keys (metadata).
/api/user/api-keysSession cookieCreate API key (returns plaintext once).
/api/user/api-keys/{id}Session cookieRevoke key.
/api/user/alert-ingest-tokensSession cookieList alert ingest tokens.
/api/user/alert-ingest-tokensSession cookieCreate ingest token (returns secret once).
/api/user/alert-ingest-tokens/{id}Session cookieRevoke ingest token.
/api/user/exportSession cookieDownload JSON export of user incidents and profile metadata.
/api/user/notification-preferencesSession cookieRead notification preference flags.
/api/user/notification-preferencesSession cookieUpdate notification preference flags on profile.
/api/user/account/delete-requestSession cookieSubmit account deletion request for manual review.
Forward to REACT_APP_SH_BACKEND_API and REACT_APP_ROBOT_BACKEND when set.
/api/reasoning/*Session cookie or Smohix API key (Bearer smohix_sk_… / X-Smohix-Api-Key)Proxy to reasoning backend.
/api/robot/*Session cookie or Smohix API key (Bearer smohix_sk_… / X-Smohix-Api-Key)Proxy to automation robot backend.
/api/audit/exportSession cookieDownload all audit_log rows for the signed-in user as CSV (optional window=24h|7d|30d|all).
/api/audit/slack-events/exportSession cookieDownload Slack delivery audit rows as CSV (optional window=24h|7d|30d|all).
Public contact intake and platform-admin lead review on smohix.run.
/api/contactNone (public form)Submit a contact or pilot enquiry (validated, rate-limited, stored via service role). Returns referenceId (ZEN-XXXXXX). Honeypot, consent, and minimum submit duration enforced. No PII in logs.
/api/admin/leadsSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSList contact leads with pagination and filters (platform admin email allowlist).
/api/admin/leadsSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSUpdate lead status, internal notes, or assignment.
/api/admin/leads/{id}Session cookie + SMOHIX_PLATFORM_ADMIN_EMAILSLead detail with append-only activity history.
/api/admin/leads/{id}Session cookie + SMOHIX_PLATFORM_ADMIN_EMAILSUpdate lead pipeline fields (stage, owner, follow-up, priority).
/api/admin/leads/{id}/convert-pilotSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSCreate pilot project from lead (admin action only).
/api/admin/leads/{id}/emailSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSPrepare or send follow-up email template (Resend if configured).
/api/admin/leads/exportSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSCSV export of filtered leads (formula-safe).
/api/admin/dashboardSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSRevOps dashboard metrics from live lead/pilot data.
/api/admin/pilotsSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSList pilot projects.
/api/admin/pilotsSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSCreate pilot from lead ID.
/api/admin/pilots/{id}Session cookie + SMOHIX_PLATFORM_ADMIN_EMAILSPilot detail with activity history.
/api/admin/pilots/{id}Session cookie + SMOHIX_PLATFORM_ADMIN_EMAILSUpdate pilot fields and status.
/api/admin/pilots/{id}/proposalSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSDeterministic pilot proposal (JSON, HTML, or Markdown).
/api/admin/pilots/{id}/calendarSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSDownload .ics for discovery, kickoff, or review dates.
/api/admin/pilots/exportSession cookie + SMOHIX_PLATFORM_ADMIN_EMAILSCSV export of pilot projects.
/api/billing/checkoutSession cookieRedirect signed-in user to PayPal approval URL for tier (pro|team|top_up).
/api/billing/checkoutSession cookieCreate PayPal subscription or top-up order; returns approvalUrl.
/api/webhooks/paypalPayPal webhook signaturePayPal billing webhook (subscriptions, top-ups, cancellations).
/api/webhooks/lemonsqueezyWebhook signature (Lemon)Lemon Squeezy subscription webhook (legacy).
Error bodies are typically JSON with an error field and optional message. Exact shapes vary by route.
Sensitive routes enforce in-memory limits (Upstash when configured). Proxy routes typically allow 120 requests per 60 seconds per user+IP. Alert and vulnerability ingest apply similar per-IP limits. Responses may include retry_after / Retry-After when limited.
Inbound HTTP endpoints include alert and vulnerability ingest (Bearer ingest tokens, optional HMAC), billing provider webhooks (signature-verified), and Slack approval callbacks. There is no general-purpose “subscribe to events” developer webhook API in this repository. Org compliance modules may deliver HTTPS digests when configured in the console.
Create and revoke keys in Settings → API keys. Keys use the smohix_sk_ prefix. They authenticate /api/reasoning/* and /api/robot/*. Keys do not currently support fine-grained scopes. The plaintext secret is returned once at creation. Legacy prefixes remain accepted for compatibility where implemented.
HQ routes are served under /api/… without a public /v1 path segment today. Treat the catalog as the source of truth; a full versioned public API may be introduced later without inventing endpoints here.
Partial YAML for local tooling only — not a complete published OpenAPI specification.
openapi: 3.0.3
info:
title: Smohix API
version: "0.1.0"
description: Abbreviated sketch for tooling — not a full published OpenAPI document.
servers:
- url: https://smohix.run
paths:
/api/health:
get:
summary: Liveness and uptime
/api/integrations/alerts:
post:
summary: Alert ingest (Bearer ingest token)
/api/reasoning/{path}:
get:
summary: Reasoning proxy (session or smohix_sk_ API key)
/api/robot/{path}:
get:
summary: Robot proxy (session or smohix_sk_ API key)
/api/user/api-keys:
get:
summary: List API keys (session)
post:
summary: Create API key (session)