Keystone Developers
Open Keystone
Guides

Conventions

Surfaces

The eight groups of endpoints, by audience and credential, and how they map onto the two services.

The raw OpenAPI documents list several hundred paths with little structure beyond tags. This site assigns every operation to a surface by its path prefix. A surface has one audience and one credential, so once you know which surface you are on you know what every request carries.

SOR surfaces

SurfacePrefixAudienceCredential
Public API/api/v1/publicA business's website or headless front endX-API-Key (the site's key)
Edits API/api/v1/editsAssistants and tools making reviewed changesConsole bearer token, or MCP bearer token with X-Internal-Api-Key
Console API/api/v1/admin, /api/v1/businesses, /api/v1/aiThe Keystone consoleConsole bearer token
Agent API/api/v1/agentKeystone's own agentsX-Internal-Api-Key
Internal API/api/v1/internalOther Keystone servicesX-Internal-Api-Key
Webhooks and callbacks/api/v1/webhooks, /api/v1/ads/webhook, /api/v1/voiceGitHub, Entri, Meta, the voice providerThe provider's signature
System/health, /api/health, /api/v1/sitesProbes and the sites registryNone

Heimdal

SurfacePrefixAudienceCredential
Auth service/api/v1/auth, /users, /roles, /permissions, /oauth, /consumer, /internalConsole, websites, MCP clients, servicesCredentials on sign-in; bearer tokens after; X-Internal-Api-Key for internal

Groups

Inside a surface, operations are grouped by the resource they manage: the spec's resource tag where FastAPI emitted one (contacts, website_mod, ads_campaigns), otherwise the first path segment after the prefix. Group pages carry every operation in full; surface pages list them one per line.

Why the console surface is so large

The Console API holds everything go.keystone.app does, for every area of the product. Most of it is per-business and scoped by the caller's memberships. Platform-staff endpoints (accounts, platform admins, promos, pricing) sit alongside and refuse non-staff callers.