Skip to content

Workspaces

78 endpoints. Every path below is served by workspace-backend behind the gateway at https://api.trilocore.ai.

GET /api/v1/workspaces

List Workspaces

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_archived boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces

Create Workspace

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
name string yes —
slug string yes —
curl -X POST https://api.trilocore.ai/api/v1/workspaces \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "…", "slug": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/onboarding

My Onboarding

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/onboarding \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/summary

Tenant Summary

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/summary \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}

Archive Workspace

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}

Get Workspace

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}

Update Workspace

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
description one of no —
name one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"description": "…", "name": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/access-reviews

List Access Reviews

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/access-reviews \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/access-reviews

Create Access Review

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
note one of no —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/access-reviews \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"note": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/activity

List Activity

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
event string no maxLength 100 —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/activity \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/activity/verify

Verify Activity Chain

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/activity/verify \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/attestations

List Attestations

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
audit_share_id string no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/attestations \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/attestations

Issue Attestation

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
audit_share_id string yes maxLength 64, minLength 1
issuer_team_id one of no —
issuer_team_name one of no —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/attestations \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"audit_share_id": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/attestations/{uuid}

Get Attestation

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/attestations/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/attestations/{uuid}/retention

Set Attestation Retention

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
legal_hold one of no —
retention_class one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/attestations/{uuid}/retention \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"legal_hold": false, "retention_class": "standard"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/attestations/{uuid}/verify

Verify Attestation

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/attestations/{uuid}/verify \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/audits

List Reports

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_archived boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
project_id string no — —
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits

Create Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
audit_id one of no —
classification string no one of internal, confidential, restricted
contract_share_id one of no —
summary one of no —
title string yes maxLength 200, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/audits/{uuid}

Get Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/audits/{uuid}

Update Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
audit_id one of no —
classification one of no —
contract_share_id one of no —
summary one of no —
title one of no —
version integer yes —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"version": 0}'

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/acknowledge

Acknowledge Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/acknowledge \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/archive

Archive Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/archive \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/audits/{uuid}/comments

List Report Comments

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/comments \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/comments

Create Report Comment

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
body string yes maxLength 4000, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/comments \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"body": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/audits/{uuid}/documents

List Audit Documents

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/documents \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/documents

Create Audit Document

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
body string no —
kind string yes one of overview, threat_model, invariants, custom
title string yes minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/documents \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind": "overview", "title": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid}

Delete Audit Document

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid}

Get Audit Document

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid}

Update Audit Document

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
body one of no —
position one of no —
title one of no —
version one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/documents/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"body": "…", "position": 0, "title": "…"}'

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/findings

Add Finding

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
classification string no one of internal, confidential, restricted
cwe one of no —
description one of no —
due_date one of no —
file_path one of no —
function_name one of no —
impact one of no —
likelihood one of no —
line_end one of no —
line_start one of no —
poc one of no —
recommendation one of no —
references one of no —
retest_status one of no —
selector one of no —
severity string yes one of info, low, medium, high, critical
title string yes maxLength 200, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/findings \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title": "…", "severity": "info"}'

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/audits/{uuid}/findings/{uuid}

Update Finding

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
classification one of no —
cwe one of no —
description one of no —
due_date one of no —
file_path one of no —
function_name one of no —
impact one of no —
likelihood one of no —
line_end one of no —
line_start one of no —
poc one of no —
recommendation one of no —
references one of no —
retest_status one of no —
selector one of no —
severity one of no —
title one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/findings/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"classification": "internal", "cwe": "…", "description": "…"}'

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/findings/{uuid}/status

Set Finding Status

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
status string yes one of open, acknowledged, resolved, wont_fix
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/findings/{uuid}/status \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"status": "open"}'

▶ Run this example in the sandbox

PUT /api/v1/workspaces/{uuid}/audits/{uuid}/project

Set Report Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend

Request body

Field Type Required Constraints
project_id one of no —
curl -X PUT https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/project \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"project_id": "…"}'

POST /api/v1/workspaces/{uuid}/audits/{uuid}/resolve

Resolve Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/resolve \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/audits/{uuid}/scope

Get Audit Scope

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/scope \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PUT /api/v1/workspaces/{uuid}/audits/{uuid}/scope

Set Audit Scope

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
abi_hash one of no —
architecture_snapshot_id one of no —
chain_id one of no —
commit_sha one of no —
compiler one of no —
compiler_version one of no —
contract_address one of no —
creation_bytecode_hash one of no —
optimizer_enabled one of no —
optimizer_runs one of no —
repository one of no —
runtime_bytecode_hash one of no —
source_hash one of no —
curl -X PUT https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/scope \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"abi_hash": "…", "architecture_snapshot_id": "…", "chain_id": 0}'

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/audits/{uuid}/scope/freeze

Freeze Audit Scope

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/scope/freeze \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

POST /api/v1/workspaces/{uuid}/audits/{uuid}/share

Share Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/audits/{uuid}/share \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/contracts

List Contracts

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_archived boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
project_id string no — —
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/contracts

Create Contract

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
address string yes —
chain_id integer yes —
classification string no one of internal, confidential, restricted
description one of no —
links array no maxItems 20
name string yes maxLength 200, minLength 1
selectors array no maxItems 500
tags array no maxItems 20
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"chain_id": 0, "address": "…", "name": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/contracts/{uuid}

Get Contract

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/contracts/{uuid}

Update Contract

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
classification one of no —
description one of no —
links one of no —
name one of no —
selectors one of no —
tags one of no —
version integer yes —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"version": 0}'

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/contracts/{uuid}/archive

Archive Contract

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid}/archive \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/contracts/{uuid}/comments

List Contract Comments

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid}/comments \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/contracts/{uuid}/comments

Create Contract Comment

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
body string yes maxLength 4000, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid}/comments \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"body": "…"}'

▶ Run this example in the sandbox

PUT /api/v1/workspaces/{uuid}/contracts/{uuid}/project

Set Contract Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend

Request body

Field Type Required Constraints
project_id one of no —
curl -X PUT https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid}/project \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"project_id": "…"}'

POST /api/v1/workspaces/{uuid}/contracts/{uuid}/share

Share Contract

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

This operation takes no request body.

curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/contracts/{uuid}/share \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/docs

List Docs

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_archived boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
project_id string no — —
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/docs \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/docs

Create Doc

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
body string yes —
format string no —
project_id one of no —
title string yes —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/docs \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title": "…", "body": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/docs/{uuid}

Archive Doc

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/docs/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/docs/{uuid}

Get Doc

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/docs/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/docs/{uuid}

Update Doc

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
body one of no —
project_id one of no —
title one of no —
version one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/docs/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"body": "…", "project_id": "…", "title": "…"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/findings/metrics

Workspace Finding Metrics

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/findings/metrics \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/invitations

List Invitations

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_closed boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/invitations \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/invitations

Create Invitation

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
access_expires_in_days one of no —
expires_in_days one of no —
invited_email string yes maxLength 320, minLength 3
invited_user_id one of no —
project_id one of no —
role string yes maxLength 64, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/invitations \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"invited_email": "…", "role": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/invitations/{uuid}

Revoke Invitation

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/invitations/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/members

List Members

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_inactive boolean no — —
include_projects boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/members \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/members

Add Member

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
expires_at one of no —
principal_id string yes maxLength 128, minLength 1
principal_label one of no —
principal_type string yes maxLength 32, minLength 1
role string yes maxLength 64, minLength 1
starts_at one of no —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/members \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"principal_type": "…", "principal_id": "…", "role": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/members/{uuid}

Revoke Member

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/members/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/projects

List Projects

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
include_archived boolean no — —
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/projects \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/projects

Create Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
chain one of no —
ide_workspace_id one of no —
name one of no —
target_address one of no —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/projects \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"chain": "…", "ide_workspace_id": "…", "name": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/projects/{uuid}

Archive Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/projects/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/projects/{uuid}

Get Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/projects/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/projects/{uuid}

Update Project

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
name one of no —
status one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/projects/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "…", "status": "active"}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/reports

List Reports

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
project_id string no — —
source_audit_share_id string no — —
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/reports

Create Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
project_id string yes maxLength 64, minLength 1
source_audit_share_id one of no —
summary one of no —
title string yes maxLength 200, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"project_id": "…", "title": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/reports/{uuid}

Archive Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/reports/{uuid}

Get Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PATCH /api/v1/workspaces/{uuid}/reports/{uuid}

Update Report

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
summary one of no —
title one of no —
version integer yes —
visibility one of no —
curl -X PATCH https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"version": 0}'

▶ Run this example in the sandbox

List Share Links

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid}/share-links \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/reports/{uuid}/share-links

Create Share Link

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
auth_scope one of no —
expires_in_days one of no —
label one of no —
max_views one of no —
mode string no one of anonymous, authenticated, specific
permissions string no maxLength 200
recipients one of no —
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid}/share-links \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"auth_scope": "workspace", "expires_in_days": 1, "label": "…"}'

DELETE /api/v1/workspaces/{uuid}/reports/{uuid}/share-links/{uuid}

Revoke Share Link

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/reports/{uuid}/share-links/{uuid} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

GET /api/v1/workspaces/{uuid}/snapshot

Get Workspace Snapshot

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/snapshot \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

PUT /api/v1/workspaces/{uuid}/snapshot

Save Workspace Snapshot

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend

Request body

Field Type Required Constraints
files object yes —
version integer no —
curl -X PUT https://api.trilocore.ai/api/v1/workspaces/{uuid}/snapshot \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"files": {}}'

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/summary

Workspace Summary

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/summary \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

GET /api/v1/workspaces/{uuid}/teams

List Team Grants

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 200
Upstream workspace-backend
Pagination paged: page_size ≤ 200 (default 50) + page_token; the body is {data, has_more, next_page_token, page_size}

Query parameters

Parameter Type Required Constraints Description
page_size integer no default 50, clamped to 200, minimum 1 Items per page. Default 50; values above 200 are clamped to 200 (never an error). The effective value is echoed as page_size.
page_token string no maxLength 2048 Opaque token from a previous page's next_page_token. Valid for 3 days, only with the same filters and the same caller. Omit it to start from the first page.
curl -X GET https://api.trilocore.ai/api/v1/workspaces/{uuid}/teams \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"

▶ Run this example in the sandbox

POST /api/v1/workspaces/{uuid}/teams

Grant Team

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 201
Upstream workspace-backend

Request body

Field Type Required Constraints
team_id string yes maxLength 64, minLength 1
team_kind string yes one of dev, audit
team_name string yes maxLength 120, minLength 1
curl -X POST https://api.trilocore.ai/api/v1/workspaces/{uuid}/teams \
  -H "Authorization: Bearer $TRILOCORE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"team_id": "…", "team_kind": "dev", "team_name": "…"}'

▶ Run this example in the sandbox

DELETE /api/v1/workspaces/{uuid}/teams/{id}

Revoke Team

Property Value
Authentication Authorization: Bearer (jns_ key or SSO session)
Idempotency-Key not required
Success 204
Upstream workspace-backend
curl -X DELETE https://api.trilocore.ai/api/v1/workspaces/{uuid}/teams/{id} \
  -H "Authorization: Bearer $TRILOCORE_API_KEY"