Skip to main content

REST API, auth and quotas

The canonical public base URL is https://public-api.atlasrepo.com. Browse Swagger UI or download OpenAPI JSON. The public document contains only supported client operations; Admin, internal automation, operator and private Scout operations are excluded.

Authentication​

Public operations declare security: []. Eligible API operations use an API key in the x-api-key header. Account endpoints use the authenticated AtlasRepo web session. Never put an API key in browser code, URLs, logs or a repository.

export ATLASREPO_API_KEY='replace-with-your-key'

curl --fail-with-body \
-H "x-api-key: $ATLASREPO_API_KEY" \
'https://public-api.atlasrepo.com/api/catalog/search?q=workflow&limit=10'

Common methods​

MethodAccessPurpose
GET /api/catalog/topPublicBrowse a public catalog page
GET /api/catalog/searchEligible key or paid sessionSearch the full catalog
POST /api/catalog/solvePublic contractSubmit a task for the documented solution projection
GET /api/pulsePublicRead full Pulse sections
GET /api/coursesPublicList published course outlines
GET /api/courses/{slug}PublicRead a published course outline
GET /api/skillsPublicBrowse published skills

This table is an orientation, not a frozen copy of every request field. Swagger is the source of truth for parameters, responses and authentication.

Request quota​

GET /api/account/mcp-oauth returns account-scoped MCP connections and a quota object:

{
"tier": "…",
"plan": "…",
"unit": "requests",
"limit": 100,
"used": 12,
"remaining": 88,
"windowSeconds": 3600,
"resetAt": "2026-10-01T00:00:00.000Z",
"unlimited": false
}

The values describe a request window, not necessarily a monthly allowance. Unlimited access uses null for limit, remaining and resetAt. A finite inactive window reports used: 0, remaining: limit and resetAt: null. Connections are filtered to the authenticated user. OAuth scopes and expiry keep their documented meanings.