API reference
Trust Fabric API
79 operations under /fabric/agent-keys, /fabric/anomalies, /fabric/approvals, /fabric/baseline, /fabric/catalog, /fabric/decision-signing-key…
Last reviewed 2026-10-02
Base URL https://cainstudio.online. Every call carries your key in the X-API-Key header; a free key comes from sign-up, and agent keys from the console. A key only ever sees its own tenant. A call the platform cannot decide is refused, never allowed: timeouts, outages and unknown verdicts do not become ALLOW.
| Method | Path | What it does |
|---|---|---|
| GET | /fabric/agent-keys | List this account's agent keys (secrets are never shown again) |
| POST | /fabric/agent-keys | Create an agent key (a separate principal for one agent) |
| POST | /fabric/agent-keys/{agent_key_id}/fast-path | Let one agent's already-allowed calls to these tools skip the per-call consensus round |
| DELETE | /fabric/agent-keys/{agent_key_id}/fast-path | Remove an agent's fast-path grant immediately |
| POST | /fabric/agent-keys/{agent_key_id}/revoke | Revoke one agent key immediately |
| GET | /fabric/anomalies | Deviations from this principal's own baseline |
| GET | /fabric/approvals | Actions held for human review |
| GET | /fabric/approvals/{approval_id} | One held action |
| POST | /fabric/approvals/{approval_id}/approve | Let one held action proceed |
| POST | /fabric/approvals/{approval_id}/deny | Refuse one held action |
| GET | /fabric/baseline | What normal looks like for this tenant or agent |
| GET | /fabric/catalog | Catalog grouped by Trust Fabric domain (what the homepage renders) |
| GET | /fabric/decision-signing-key | Public key that signs every recorded decision |
| GET | /fabric/decisions | List this tenant's recent Fabric decisions |
| POST | /fabric/decisions | Ask the control plane to decide on a proposed action |
| GET | /fabric/decisions/stream | Live feed of this tenant's decisions (Server-Sent Events) |
| GET | /fabric/decisions/{decision_id} | Retrieve one recorded decision (Evidence) |
| GET | /fabric/decisions/{decision_id}/explain | Why this decision came out the way it did, and which run it belongs to |
| GET | /fabric/decisions/{decision_id}/integrity | Check whether a recorded decision has been altered since it was written |
| GET | /fabric/decisions/{decision_id}/signature | Tamper-evidence for one decision record |
| GET | /fabric/decisions/{decision_id}/signed-record | Export one decision row exactly as stored and signed; verify offline with verify_decision_record.py --key https://mcpgate.online/fabric/decision-signing-key |
| GET | /fabric/egress/rules | This tenant's action-tool allowlist (destinations) |
| POST | /fabric/egress/rules | Add a destination allow rule (enables egress enforcement) |
| DELETE | /fabric/egress/rules | Remove a destination allow rule |
| GET | /fabric/evidence-access | Who has read this tenant's evidence |
| POST | /fabric/identity/agent-tokens | Mint a short-lived agent delegation token |
| POST | /fabric/identity/agent-tokens/verify | Verify an agent delegation token |
| GET | /fabric/identity/principals | List this tenant's principals |
| POST | /fabric/identity/principals | Register a principal |
| GET | /fabric/identity/principals/{principal_id} | Fetch one principal |
| POST | /fabric/identity/principals/{principal_id}/revoke | Revoke a principal |
| POST | /fabric/identity/principals/{principal_id}/verify | Verify an Ed25519 signature against a registered principal |
| POST | /fabric/identity/sessions | Exchange an API key for a short-lived browser session |
| GET | /fabric/identity/sessions/current | Inspect the session token in use |
| GET | /fabric/identity/whoami | Resolve the calling key to its Fabric principal |
| GET | /fabric/kill-switch | Whether this tenant's agents are halted |
| POST | /fabric/kill-switch | Halt every subsequent action for this tenant |
| DELETE | /fabric/kill-switch | Release the halt and allow actions again |
| GET | /fabric/policy | The live policy: version, modules, and how it is addressed |
| POST | /fabric/policy/dryrun | What would happen to my recent traffic under different enforcement |
| POST | /fabric/policy/evaluate | Ask the live policy engine about a hypothetical call |
| GET | /fabric/proof | The latest proof run: every claim, executed |
| GET | /fabric/proof/history | Every proof run, hash-chained |
| POST | /fabric/proof/run | Execute every check and publish the result |
| GET | /fabric/services | Every live service, with its Trust Fabric domain |
| GET | /fabric/settings | This tenant's enforcement mode |
| POST | /fabric/settings | Switch this tenant between shadow and enforce |
| GET | /fabric/simulate | Replay recorded decisions under proposed settings |
| GET | /fabric/status | Which Fabric stages are live and enforcing right now |
| GET | /fabric/team | This workspace's members, invites and your role |
| POST | /fabric/team/accept | Join a workspace with an invite (signed-in CAIN account) |
| GET | /fabric/team/invite-info | What an invite link is for (no sign-in needed) |
| POST | /fabric/team/invites | Invite someone by email |
| DELETE | /fabric/team/invites/{invite_id} | Withdraw an invite |
| PUT | /fabric/team/members/{member_id} | Change a member's role |
| DELETE | /fabric/team/members/{member_id} | Remove a member (or leave, for yourself) |
| GET | /fabric/team/memberships | Workspaces your CAIN account belongs to |
| PUT | /fabric/team/name | Name this workspace |
| POST | /fabric/team/session | Open a workspace as a member (returns a short-lived member token) |
| GET | /fabric/tool-rules | This tenant's tool rules, in evaluation order |
| POST | /fabric/tool-rules | Add a tool rule |
| PUT | /fabric/tool-rules-default | What happens when no tool rule matches |
| GET | /fabric/tool-rules-history | Every change to this tenant's tool rules |
| POST | /fabric/tool-rules/test | Which rule would decide this call? (no evidence, no quota) |
| PUT | /fabric/tool-rules/{rule_id} | Change a tool rule (its version increments) |
| DELETE | /fabric/tool-rules/{rule_id} | Retire a tool rule (kept in history, never deleted) |
| GET | /fabric/toolargs/schemas | Registered tool schemas for argument validation |
| PUT | /fabric/toolargs/schemas | Register or replace a tool schema (operator-admin) |
| GET | /fabric/tools | Every tool this tenant's agents called, and which rule governs it |
| GET | /fabric/trajectories | Recent agent runs for this tenant |
| GET | /fabric/trajectories/{chain_id} | Reconstruct one agent run, in order |
| POST | /fabric/trajectories/{chain_id}/analyse | Grade this run's path and attribute its failure |
| GET | /fabric/trust-score | Heuristic trust score, with its arithmetic shown |
| GET | /fabric/try | What the no-signup demo can show you |
| POST | /fabric/try | See CAIN decide on a real action -- no account needed |
| GET | /fabric/webhooks | Where this tenant gets notified |
| POST | /fabric/webhooks | Get notified when an action is held, blocked or halted |
| GET | /fabric/webhooks/deliveries | What was sent, and what failed |
| DELETE | /fabric/webhooks/{endpoint_id} | Stop notifying this endpoint |
Products built on these calls
- CAIN Observability — A live window into what every agent is doing and why each action was allowed or stopped.
- CAIN Trajectory — Spots when an agent's chain of actions drifts somewhere it should not go, even in small steps.
- CAIN Identity — Gives every agent and person a verifiable identity, so CAIN always knows who is acting.
- CAIN Proof — Turns every decision into a signed receipt anyone can check.
- Decision signing key — The public key that lets anyone check a CAIN decision was really signed by CAIN.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem