CAIN-42 CAIN Studio

API reference

Trust Fabric API

79 operations under /fabric/agent-keys, /fabric/anomalies, /fabric/approvals, /fabric/baseline, /fabric/catalog, /fabric/decision-signing-key…

Last reviewed 2026-10-02

Base URL https://cainstudio.online. Every call carries your key in the X-API-Key header; a free key comes from sign-up, and agent keys from the console. A key only ever sees its own tenant. A call the platform cannot decide is refused, never allowed: timeouts, outages and unknown verdicts do not become ALLOW.

MethodPathWhat it does
GET/fabric/agent-keysList this account's agent keys (secrets are never shown again)
POST/fabric/agent-keysCreate an agent key (a separate principal for one agent)
POST/fabric/agent-keys/{agent_key_id}/fast-pathLet one agent's already-allowed calls to these tools skip the per-call consensus round
DELETE/fabric/agent-keys/{agent_key_id}/fast-pathRemove an agent's fast-path grant immediately
POST/fabric/agent-keys/{agent_key_id}/revokeRevoke one agent key immediately
GET/fabric/anomaliesDeviations from this principal's own baseline
GET/fabric/approvalsActions held for human review
GET/fabric/approvals/{approval_id}One held action
POST/fabric/approvals/{approval_id}/approveLet one held action proceed
POST/fabric/approvals/{approval_id}/denyRefuse one held action
GET/fabric/baselineWhat normal looks like for this tenant or agent
GET/fabric/catalogCatalog grouped by Trust Fabric domain (what the homepage renders)
GET/fabric/decision-signing-keyPublic key that signs every recorded decision
GET/fabric/decisionsList this tenant's recent Fabric decisions
POST/fabric/decisionsAsk the control plane to decide on a proposed action
GET/fabric/decisions/streamLive feed of this tenant's decisions (Server-Sent Events)
GET/fabric/decisions/{decision_id}Retrieve one recorded decision (Evidence)
GET/fabric/decisions/{decision_id}/explainWhy this decision came out the way it did, and which run it belongs to
GET/fabric/decisions/{decision_id}/integrityCheck whether a recorded decision has been altered since it was written
GET/fabric/decisions/{decision_id}/signatureTamper-evidence for one decision record
GET/fabric/decisions/{decision_id}/signed-recordExport one decision row exactly as stored and signed; verify offline with verify_decision_record.py --key https://mcpgate.online/fabric/decision-signing-key
GET/fabric/egress/rulesThis tenant's action-tool allowlist (destinations)
POST/fabric/egress/rulesAdd a destination allow rule (enables egress enforcement)
DELETE/fabric/egress/rulesRemove a destination allow rule
GET/fabric/evidence-accessWho has read this tenant's evidence
POST/fabric/identity/agent-tokensMint a short-lived agent delegation token
POST/fabric/identity/agent-tokens/verifyVerify an agent delegation token
GET/fabric/identity/principalsList this tenant's principals
POST/fabric/identity/principalsRegister a principal
GET/fabric/identity/principals/{principal_id}Fetch one principal
POST/fabric/identity/principals/{principal_id}/revokeRevoke a principal
POST/fabric/identity/principals/{principal_id}/verifyVerify an Ed25519 signature against a registered principal
POST/fabric/identity/sessionsExchange an API key for a short-lived browser session
GET/fabric/identity/sessions/currentInspect the session token in use
GET/fabric/identity/whoamiResolve the calling key to its Fabric principal
GET/fabric/kill-switchWhether this tenant's agents are halted
POST/fabric/kill-switchHalt every subsequent action for this tenant
DELETE/fabric/kill-switchRelease the halt and allow actions again
GET/fabric/policyThe live policy: version, modules, and how it is addressed
POST/fabric/policy/dryrunWhat would happen to my recent traffic under different enforcement
POST/fabric/policy/evaluateAsk the live policy engine about a hypothetical call
GET/fabric/proofThe latest proof run: every claim, executed
GET/fabric/proof/historyEvery proof run, hash-chained
POST/fabric/proof/runExecute every check and publish the result
GET/fabric/servicesEvery live service, with its Trust Fabric domain
GET/fabric/settingsThis tenant's enforcement mode
POST/fabric/settingsSwitch this tenant between shadow and enforce
GET/fabric/simulateReplay recorded decisions under proposed settings
GET/fabric/statusWhich Fabric stages are live and enforcing right now
GET/fabric/teamThis workspace's members, invites and your role
POST/fabric/team/acceptJoin a workspace with an invite (signed-in CAIN account)
GET/fabric/team/invite-infoWhat an invite link is for (no sign-in needed)
POST/fabric/team/invitesInvite someone by email
DELETE/fabric/team/invites/{invite_id}Withdraw an invite
PUT/fabric/team/members/{member_id}Change a member's role
DELETE/fabric/team/members/{member_id}Remove a member (or leave, for yourself)
GET/fabric/team/membershipsWorkspaces your CAIN account belongs to
PUT/fabric/team/nameName this workspace
POST/fabric/team/sessionOpen a workspace as a member (returns a short-lived member token)
GET/fabric/tool-rulesThis tenant's tool rules, in evaluation order
POST/fabric/tool-rulesAdd a tool rule
PUT/fabric/tool-rules-defaultWhat happens when no tool rule matches
GET/fabric/tool-rules-historyEvery change to this tenant's tool rules
POST/fabric/tool-rules/testWhich rule would decide this call? (no evidence, no quota)
PUT/fabric/tool-rules/{rule_id}Change a tool rule (its version increments)
DELETE/fabric/tool-rules/{rule_id}Retire a tool rule (kept in history, never deleted)
GET/fabric/toolargs/schemasRegistered tool schemas for argument validation
PUT/fabric/toolargs/schemasRegister or replace a tool schema (operator-admin)
GET/fabric/toolsEvery tool this tenant's agents called, and which rule governs it
GET/fabric/trajectoriesRecent agent runs for this tenant
GET/fabric/trajectories/{chain_id}Reconstruct one agent run, in order
POST/fabric/trajectories/{chain_id}/analyseGrade this run's path and attribute its failure
GET/fabric/trust-scoreHeuristic trust score, with its arithmetic shown
GET/fabric/tryWhat the no-signup demo can show you
POST/fabric/trySee CAIN decide on a real action -- no account needed
GET/fabric/webhooksWhere this tenant gets notified
POST/fabric/webhooksGet notified when an action is held, blocked or halted
GET/fabric/webhooks/deliveriesWhat was sent, and what failed
DELETE/fabric/webhooks/{endpoint_id}Stop notifying this endpoint

Products built on these calls

← all areas

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem