REST — /api/autobot
10 route handlers under /api/autobot · all session-gated.
Public flags are cross-referenced against
PUBLIC_API_PREFIXESinsrc/lib/route-access.ts. Routes without a public prefix require an authenticated session (or, where applicable, a signed federation request). See Auth models.
| Route | Methods | Access | Description |
|---|---|---|---|
/api/autobot/attachments | POST | Session | POST /api/autobot/attachments — hand the assistant a picture. |
/api/autobot/chat | POST | Session | POST /api/autobot/chat — the ORG assistant. |
/api/autobot/confirm | POST | Session | — |
/api/autobot/credential | GET | Session | GET /api/autobot/credential?targetAgentId= |
/api/autobot/provenance | GET | Session | GET /api/autobot/provenance |
/api/autobot/settings | GET POST | Session | Unified session accepts NextAuth JWT or federated rivr_remote_viewer (#105). |
/api/autobot/status | GET | Session | — |
/api/autobot/threads | GET | Session | — |
/api/autobot/threads/[id] | DELETE | Session | — |
/api/autobot/threads/[id]/messages/[messageId]/actions | PATCH | Session | The vault doc summarises each action's outcome, so a confirm or cancel |