REST — /api/autobot
14 route handlers under /api/autobot · all session-gated.
Public flags are cross-referenced against
PUBLIC_API_PREFIXESinsrc/lib/route-access.ts. Routes without a public prefix require an authenticated session (or, where applicable, a signed federation request). See Auth models.
| Route | Methods | Access | Description |
|---|---|---|---|
/api/autobot/attachments | POST | Session | POST /api/autobot/attachments — hand the assistant a picture. |
/api/autobot/chat | POST | Session | POST /api/autobot/chat — the ORG assistant. |
/api/autobot/codex | GET DELETE | Session | GET /api/autobot/codex?targetAgentId= — the connected ChatGPT account (no token). |
/api/autobot/codex/device | POST | Session | POST /api/autobot/codex/device — start a ChatGPT device sign-in. |
/api/autobot/codex/device/poll | POST | Session | POST /api/autobot/codex/device/poll — advance a waiting ChatGPT sign-in. |
/api/autobot/codex/models | GET | Session | GET /api/autobot/codex/models — the Codex models the signed-in person's |
/api/autobot/confirm | POST | Session | A plan runs every step inside one confirm, so it gets more than the default time. |
/api/autobot/credential | GET | Session | GET /api/autobot/credential?targetAgentId= |
/api/autobot/provenance | GET | Session | GET /api/autobot/provenance |
/api/autobot/settings | GET POST | Session | Unified session accepts NextAuth JWT or federated rivr_remote_viewer (#105). |
/api/autobot/status | GET | Session | — |
/api/autobot/threads | GET | Session | — |
/api/autobot/threads/[id] | DELETE | Session | — |
/api/autobot/threads/[id]/messages/[messageId]/actions | PATCH | Session | The vault doc summarises each action's outcome, so a confirm or cancel |