API and automation
Everything the console does, it does through the same API available to you. There is no privileged path: the interface is a client of the API, like any other.
A single surface
That principle has a strong practical consequence: if a capability is not in the API, nothing can reach it — not the interface, not a script, not an agent. That eliminates the entire class of problems where an automation can do more than the interface would allow.
No customer receives administrative infrastructure credentials, access to the control database, or an alternative mutation path.
How the API behaves
| Rule | What it means if you integrate |
|---|---|
| Scope from the authenticated session | The organization comes from your session, never from the request body |
| Long operations are asynchronous | Deploying answers with an operation identifier; you follow the progress |
| Creation is protected against repetition | Resending the same request with the same key returns the same response, not a second resource |
| Errors have one shape | A stable code, a message, and a suggested action |
| State has two vocabularies | The precise state and the user-facing state come together, so no client reimplements the mapping |
Following an operation
Deploying, restoring, adjusting resources, and changing the address of an already deployed project create an operation. It has its own state, queryable progress, and can be cancelled while the cancellation window is open.
That is why the interface never sits with a stopped clock: it is following the operation, and shows what has happened so far.
Agent-assisted operation
Zero was built to be operated by agents too — Imaginne, for example. The rule that makes that safe fits in one sentence:
Every agent operation goes through the same governed API, with the same permissions as the person who triggered it.
An agent can analyze a repository, explain what will be deployed, deploy, observe, diagnose, propose a fix, and roll back. What it cannot do is escape the API: there is no parallel surface.
Two additional guarantees:
- A destructive action triggered by an agent requires human confirmation.
- The audit trail separates human authors from agent authors, and the action's origin (interface, script, integration) is recorded separately.
Credentials and access
API access uses the same identity as the console. Long-lived keys for integration are granted by the team that administers the platform — there is no self-service for that today.
Availability
Not every resource described in the contract is exposed in this installation. The list of what exists today is in What exists today, and the console answers by capability rather than letting a screen say "not found" when it is the capability that does not exist.
To get the API contract for your installation's version, talk to the team that administers the platform.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.