Skip to main content
These conventions apply across all API endpoints. Individual endpoint pages may document additional behavior, but the patterns below are universal.

Pagination

Most list endpoints support offset-based pagination: Responses include pagination metadata:
Use total and has_more to build page controls or iterate through all results:

Cursor pagination

Some endpoints use cursor-based pagination instead: The response includes next_page_token when more results exist:
Endpoint pages specify which pagination style they use.

Organization header

Include X-Organization-Id to scope requests to an organization’s resources:
When omitted, the API returns the user’s personal resources. See Authentication for the full personal vs org distinction.

Timestamps

All timestamps are ISO 8601 in UTC:
Fields named created_at and updated_at follow this format. updated_at is null when the resource has never been modified after creation.

Content types

Most endpoints accept and return application/json. File upload endpoints (e.g. session file write) accept multipart/form-data.

Idempotency

For POST requests that create resources, you can include an Idempotency-Key header to prevent duplicate creation on retries:
If the same Idempotency-Key is sent within 24 hours, the API returns the original response without creating a duplicate resource. Keys are scoped to the API key that sent them.

Custom methods

Some operations don’t map cleanly to standard HTTP verbs. These use the colon-separated action pattern:
Custom methods always use POST and append :action to the resource path.