API Reference & Configuration

View source on GitHub (opens in new tab)

Every API endpoint the platform exposes, plus deploy-time configuration variables, Lambda environment variables, and SSM parameters.

← Back to README

API Endpoints

Workflow Management

MethodEndpointDescription
GET/healthHealth check
POST/api/workflowsCreate workflow
GET/api/workflows/{id}Get workflow
PUT/api/workflows/{id}Update workflow
DELETE/api/workflows/{id}Delete workflow
POST/api/workflows/{id}/validateValidate workflow
POST/api/workflows/importImport workflow JSON
GET/api/workflows/{id}/exportExport workflow JSON

Deployment

MethodEndpointDescription
POST/api/deployStart deployment (returns 202 with deployment_id and execution_arn)
GET/api/deploy/{deployment_id}Get deployment status from DynamoDB
POST/api/test-runtimeTest a deployed agent with a prompt (supports session_id for conversation context)
DELETE/api/runtime/{id}Delete runtime + gateway + Cognito + Lambda (full cleanup)
POST/api/generate-toolAI Tool Generator -- generate Lambda code from natural language via Claude Sonnet
POST/api/generate-cfn-templateGenerate downloadable CloudFormation stack (template YAML + deploy scripts + code artifacts)

Flows

MethodEndpointDescription
POST/api/flowsCreate flow
GET/api/flowsList caller's flows
GET/api/flows/{flow_id}Get flow
PUT/api/flows/{flow_id}Update flow
DELETE/api/flows/{flow_id}Delete flow

Observability

MethodEndpointDescription
GET/api/observability/platform-defaultsReturns {enabled, endpoint, sample_rate} so the UI can render the Observability node read-only when platform OTEL is configured. Never returns the secret ARN.
POST/api/observability/credentialsStores OTLP auth credentials in Secrets Manager and returns the secret ARN.

Versioning & Slots

MethodEndpointDescription
GET/api/runtimes/{name}/versionsList a runtime's version history (newest first)
GET/api/runtimes/{name}/slotsGet the production / staging slot pointers
POST/api/runtimes/{name}/rollbackPromote the previous production version back into production

Evaluation, Cost & Observability (runtime-scoped)

MethodEndpointDescription
GET/api/runtimes/{name}/evaluation-configRegistered Online Evaluation config (evaluator IDs + sampling rate)
GET/api/runtimes/{name}/evaluations?hours=Per-evaluator score time-series from CloudWatch Logs Insights
GET/api/runtimes/{name}/dashboard-urlDeep link to the auto-generated CloudWatch dashboard
GET/api/runtimes/{name}/cost?from=&to=Token + estimated-cost rollup by model for the window

Triggers (runtime-scoped)

MethodEndpointDescription
POST/api/runtimes/{name}/triggersRegister a cron / eventbridge / s3 / webhook trigger (target ARN derived server-side; created as registered)
GET/api/runtimes/{name}/triggersList the runtime's triggers
DELETE/api/runtimes/{name}/triggers/{id}Delete a trigger

Agent Registry

MethodEndpointDescription
POST/api/registryPublish an agent blueprint (enters pending review)
GET/api/registry?q=&tag=&scope=all|mine|public|pendingSearch/list visible entries (admins can list pending)
GET/api/registry/{slug}Get one entry (visibility/approval-checked, 404 if not visible)
POST/api/registry/{slug}/cloneClone an approved/own entry's canvas to the caller
PUT/api/registry/{slug}Update metadata (owner only; non-admin edit resets to pending)
DELETE/api/registry/{slug}Delete (owner or registry-admin)
POST/api/registry/{slug}/approveAdmin only — approve a pending entry (403 otherwise)
POST/api/registry/{slug}/rejectAdmin only — reject with optional reason (403 otherwise)

AWS Agent Registry federation (opt-in)

Federates deployed agents into the AWS Agent Registry — a GA AWS service in its own right (it is no longer part of bedrock-agentcore). Requires the backend to run boto3 >= 1.43.66, the first release carrying the agent-registry service models, and the agent-registry:* IAM actions.

MethodEndpointDescription
GET/api/registry/aws-configFederation status: {enabled, registry_id, available, sdk_supported}
POST/api/registry/aws-configAdmin only — enable federation with a registry_id (reachability validated before persisting)
GET/api/registry/aws-search?q=Discovery search across the registry (SearchDiscoverableRegistryRecords)

sdk_supported: false means this deployment's boto3 predates the GA API, so no agent-registry client can be built — a redeploy, not a configuration change. POST returns 400 naming the SDK in that case rather than blaming the registry_id.

LiteLLM as the catalog backend (opt-in)

Makes a LiteLLM proxy the authoritative catalog in place of the internal DynamoDB one. Additive: the default backend is dynamodb and nothing above changes until an admin activates this. See Registry & RBAC.

MethodEndpointDescription
GET/api/registry/litellm-configActive backend + config: {provider, configured, base_url, api_key_ref, verified, capabilities} — never the key itself
POST/api/registry/litellm-configAdmin only — save {base_url, api_key, activate}; the key is minted into agentcore-registry/ and dropped
DELETE/api/registry/litellm-configAdmin only — revert to the platform catalog (DynamoDB entries were never touched)
GET/api/registry/litellm-serversThe MCP servers LiteLLM serves, with enablement. Returns {configured: false, servers: []} when LiteLLM is not configured — not an error

activate: false saves and probes the config without switching the catalog over, so reachability can be tested first. verified: false means the control plane could not probe the proxy — normal for a VPC-private LiteLLM, since the control plane has no VPC egress, and not an error.

Because LiteLLM has no write API for MCP server records, entries projected from LiteLLM are read-only: publish, update, delete, approve, reject and clone return 501 naming LiteLLM rather than silently accepting a write that would then diverge. Entries published from a canvas live in the platform sidecar and stay fully mutable — the limit is per entry, not per operation. capabilities (including read_only_sources) on GET /litellm-config is the machine-readable form of that. The pre-deploy governance gate stays fail-closed: if the catalog cannot be read, deploys referencing an integration return 503.

Prompt Library

MethodEndpointDescription
POST/api/promptsCreate a prompt (seeds v1)
GET/api/promptsList visible prompts
GET / PUT / DELETE/api/prompts/{name}Get / update / delete a prompt
POST/api/prompts/{name}/versionsAppend a new version
POST/api/prompts/{name}/promote/{version_id}Pin the default version
GET/api/prompts/{name}/resolve?version=Resolve {version_id, body} (used at codegen)

HITL, Connectors, Workspaces & GitOps

MethodEndpointDescription
GET/api/hitl/pendingCaller's pending human-approval queue
POST/api/hitl/{request_id}/decisionApprove / reject a pending approval
GET/api/connectorsList pre-built SaaS connector definitions
GET/api/connectors/{id}Connector tool + credential schema
POST/api/workflows/{id}/shareShare a workflow (viewer/editor; owner only)
DELETE/api/workflows/{id}/share/{sub}Revoke a share
GET/api/workspacesList workspace-visible workflows with effective role
POST/api/workflows/{id}/git-tokenStore a Git PAT (owner-scoped Secrets Manager)
POST/api/workflows/{id}/git-syncPull a workflow spec from Git (SSRF-guarded)

NL Agent Generation & Code Export

MethodEndpointDescription
POST/api/generate-canvasNL description → validated canvas spec (Bedrock tool-use, clarify → generate)
POST/api/export-pythonDownload a standalone runnable Python agent project (presigned S3 zip)

Configuration

Deploy-time variables consumed by ./scripts/deploy.sh and passed as CDK context parameters to the infrastructure stack:

VariableDefaultDescription
ENVIRONMENT_NAMEdevEnvironment identifier (e.g., dev, staging, prod)
AWS_REGIONus-east-1Target AWS region
PROJECT_NAMEagentcore-workflowProject name used for resource naming and tagging
COGNITO_USERS(carried forward)Comma-separated emails for pre-created Cognito users (e.g., user1@example.com,user2@example.com). Users are created in NO group → no scopes → read-only until you assign a persona (see Registry & RBAC). Each email becomes a custom resource whose deletion deletes the Cognito user, so dropping an email is how you offboard someone. Because an omitted variable is indistinguishable from an intentionally emptied one, leaving it unset on a redeploy carries the already-provisioned users forward rather than deleting them — deploy.sh prints a warning naming them. Pass COGNITO_USERS=none to genuinely remove them all. A re-provisioned user gets a new emailed temporary password and loses their group memberships. This carry-forward lives in scripts/deploy.sh, so bypassing it — running npx cdk deploy or cdk diff directly — plans the deletion again; pass --context cognito_users=a@b.com,... yourself in that case.
OTEL_ENDPOINT(unset)OTLP HTTP endpoint for platform-level observability (e.g. https://cloud.langfuse.com/api/public/otel). When set, every platform Lambda + every deployed agent exports traces here. Per-canvas Observability nodes can still add resource attributes additively but cannot override the endpoint.
OTEL_AUTH_SECRET_ARN(unset)ARN of a Secrets Manager secret holding the precomputed Authorization header value (e.g. Basic <base64>). Created by scripts/bootstrap-otel-secret.sh. Required when OTEL_ENDPOINT is set.
OTEL_SAMPLE_RATE1.0Trace sampling ratio (0.0–1.0).
OTEL_SERVICE_NAME_PREFIX{PROJECT_NAME}Prefix prepended to service.name resource attribute on every span.

Environment Variables (Lambda)

VariableDescription
DEPLOYMENT_TABLE_NAMEDynamoDB table name for deployment state
WORKFLOWS_TABLE_NAMEDynamoDB table name for workflow definitions
STATE_MACHINE_ARNStep Functions state machine ARN for deployment orchestration
APP_AWS_REGIONAWS region for service calls
TOOL_GENERATOR_MODEL_IDClaude model ID for AI Tool Generator (default: us.anthropic.claude-sonnet-5)

SSM Parameters

Application configuration is stored under /agentcore-workflow/{env}/ in SSM Parameter Store:

ParameterDescription
/agentcore-workflow/{env}/cors-originsAllowed CORS origins
/agentcore-workflow/{env}/aws-regionAWS region
/agentcore-workflow/{env}/dynamodb-table-nameWorkflows DynamoDB table name
/agentcore-workflow/{env}/otel/endpointOTLP endpoint (when platform OTEL is configured)
/agentcore-workflow/{env}/otel/auth-secret-arnSecrets Manager ARN for the OTLP auth header
/agentcore-workflow/{env}/otel/sample-rateTrace sampling ratio
/agentcore-workflow/{env}/otel/service-name-prefixservice.name prefix