Conventions
Conventions
What every Keystone endpoint has in common: one envelope, one error shape, UUID ids, and a surface per audience.
Keystone's HTTP API is one FastAPI service (the Statement of Record, "SOR") plus a separate auth service (Heimdal). The two publish OpenAPI 3.1 documents, and this site is generated from them. A few conventions hold across every endpoint; the pages in this group describe them so the reference can stay terse.
In one paragraph
Requests are JSON over HTTPS. Every successful response is wrapped in a SuccessResponse envelope with a request_id, success: true, and the payload under data; every error is an ErrorResponse with the same request_id, success: false, and an error object with a code and message. Identifiers are UUIDs. Paths are versioned at /api/v1/. Endpoints are organized into surfaces by who calls them and what credential they carry; see Surfaces.
Where to look
| Question | Page |
|---|---|
| Which endpoints can my site or app call? | Public API and Edits API |
| What does the console use? | Console API |
| How does an assistant edit a business? | MCP server and How a session works |
| What does a response look like? | Envelopes |
| What does a failure look like? | Errors |