Every story of the key's organization whatever its status (draft to published), with the current version's title and summary. Filter with status (comma-separated). Keyset pagination: pass next_cursor back as cursor. Scope stories:read. Cache-Control: private, no-store.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
The current version's structured body and every recorded approval decision, newest first. Only decisions recorded by the approval credential are listed (ADR 0038). Scope stories:read.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
The approval queue: stories waiting for a decision
GET/v1/approvalsscope approvals:read
Stories in review_required, newest change first. Decisions are made by people in the Armage workspace (email and Slack approvals are planned), never by an API key: nothing publishes unapproved. Scope approvals:read.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
Published stories as JSON Feed 1.1 (for a CMS to pull)
GET/v1/feed.jsonscope feed:read
The 50 most recent published stories with plain-text and minimal escaped HTML bodies. Scope feed:read. For importers that cannot send headers, the key may be given as ?key= - only a key whose sole scope is feed:read.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
Every endpoint, enabled or not, newest first; never its signing secret (only secret_hint, its last four characters). Endpoints are added, tested, disabled and re-enabled by an owner or admin in the Armage workspace. Scope webhooks:read.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
One row per event per endpoint: status (pending while retries remain, delivered, failed), attempts, the last HTTP status and a short error. Payloads are not kept. Filter with endpoint_id; keyset pagination as /v1/stories. Scope webhooks:read.
No key, a malformed, expired or revoked key, or a key for the other environment (missing_api_key, invalid_api_key, wrong_environment). WWW-Authenticate: Bearer.
A story was sent for review: it is now in the approval queue. Sent to every enabled endpoint subscribed to story.submitted, signed per Standard Webhooks.