OpenAPI Specification
openapi: 3.1.0
info:
title: Archal Auth Runtime API
summary: Public API for Archal CLI, session, trace, result, and runtime clone integrations.
description: Archal provisions service-shaped clones of third-party services so AI agents can be tested before they touch production. This spec covers Archal-owned control-plane endpoints and the runtime proxy shape agents use to call clone APIs.
version: 0.3.0
servers:
- url: https://archal.ai
description: Archal web and CLI API
- url: https://api.archal.ai
description: Hosted runtime proxy
security:
- archalToken: []
tags:
- name: Runtime
description: Direct calls into a running clone.
paths:
/runtime/{sessionId}/{cloneId}/api/{path}:
parameters:
- $ref: '#/components/parameters/SessionId'
- name: cloneId
in: path
required: true
schema:
type: string
examples:
- github
- slack
- stripe
- name: path
in: path
required: true
schema:
type: string
get:
operationId: proxyCloneGet
summary: Proxy a GET request to a running clone
tags:
- Runtime
security:
- routeAuthorization: []
parameters:
- $ref: '#/components/parameters/RouteAuthorization'
responses:
'200':
description: Clone-specific response.
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
post:
operationId: proxyClonePost
summary: Proxy a POST request to a running clone
tags:
- Runtime
security:
- routeAuthorization: []
parameters:
- $ref: '#/components/parameters/RouteAuthorization'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/JsonObject'
responses:
'200':
description: Clone-specific response.
'201':
description: Clone-specific resource created.
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
components:
responses:
Forbidden:
description: Authenticated user cannot access the requested resource.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Unauthorized:
description: Missing, invalid, or expired Archal token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
NotFound:
description: Requested resource was not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
parameters:
SessionId:
name: sessionId
in: path
required: true
schema:
type: string
examples:
- env_12345
RouteAuthorization:
name: x-route-authorization
in: header
description: Archal bearer token for the outer route hop. Keep the standard Authorization header for the service-shaped token the clone should see.
schema:
type: string
examples:
- Bearer archal_example
schemas:
JsonObject:
type: object
additionalProperties: true
ErrorResponse:
type: object
properties:
error:
type: string
code:
type: string
message:
type: string
detail:
type: string
additionalProperties: true
securitySchemes:
archalToken:
type: http
scheme: bearer
bearerFormat: Archal API token
routeAuthorization:
type: apiKey
in: header
name: x-route-authorization