API reference
App API
The API the Prodgator web app uses. Use the v1 public API for scripts and integrations.
The Prodgator web app talks to . These routes exist to serve the app. They take a signed-in user's WorkOS access token, and they change when the app changes.
For scripts, dashboards and CI jobs, use the Public REST API (v1) with an API key. It is versioned and documented in OpenAPI.
Authentication
Authorization: Bearer <WorkOS access token>Prodgator's authorizer reads the organization, role, permissions and plan from the token. Each route then checks the role and plan it needs.
Main route groups
| Routes | Used for |
|---|---|
| , | The Pipelines list and run summaries |
| , , | Run controls (GitHub Actions; re-run one job also on GitLab) |
| Dashboard metrics and DORA metrics | |
| , | Deployments |
| , , | Approvals and rollback |
| , | Gates and deployment environments |
| , , | Release policies, where they apply, and approver groups |
| , , | Security findings |
| Policies, checks, evaluation, enforcement and break-glass | |
| , /, | Notifications |
| , , | Provider and tool connections |
| , | Notification delivery |
| /, | API keys |
| Checkout and the billing portal | |
| Linked provider accounts | |
| , | Custom adapters and processing rules |
Errors
Most routes answer errors as:
{ "error": "Message", "code": "SOME_CODE" }| Status | Meaning |
|---|---|
| Bad request | |
| Missing or invalid token | |
| The plan does not include the feature or a limit was reached | |
| The role is not high enough | |
| Not found | |
| The item changed state, for example a deployment that is no longer pending | |
| Server error |
Live updates
The app also keeps a WebSocket connection to for live updates of runs, deployments, notifications, security alerts and compliance checks. It is not a public interface.