Kanva API (v1)

Download OpenAPI specification:

Kanva customer API. Select one current application session or a tenant-bound API key for workspace resources. Account privacy, recovery, and erasure receipts use separate purpose-bound cookies. Customer bearer tokens and credentials in URLs are rejected. Browser mutations require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF from /api/v1/auth/bootstrap or the current purpose context. Cookie names shown are installation defaults. Never combine an application cookie with X-API-Key. Execution, artifact delivery, local email, and privacy availability depend on qualified deployment adapters; documented contracts do not imply those adapters are enabled.

AccountAuthentication

Anonymous HTTPS bootstrap establishes protected br

Anonymous HTTPS bootstrap establishes protected browser/antiforgery cookies and returns csrfToken, configured provider names, reviewed legal document URLs/versions, availability flags, localAccountsEnabled, and registrationEnabled. Missing reviewed notices or mail delivery keep registration unavailable.

Responses

Response samples

Content type
application/json
{
  • "csrfToken": "string",
  • "providers": [
    ],
  • "privacyNoticeVersion": "string",
  • "termsVersion": "string",
  • "privacyNoticeUrl": "http://example.com",
  • "termsUrl": "http://example.com",
  • "privacyNoticeAvailable": true,
  • "termsAvailable": true,
  • "localAccountsEnabled": true,
  • "registrationEnabled": true
}

Returns the application user's current identity an

Returns the application user's current identity and memberships, noncredential sessionId/sessionVersion, and refreshed csrfToken. A privacy or recovery cookie cannot access this endpoint.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
application/json
{
  • "sessionId": "f6567dd8-e069-418e-8893-7d22fcf12459",
  • "sessionVersion": 0,
  • "csrfToken": "string",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "displayName": "string",
  • "status": "unknown",
  • "purpose": "unknown",
  • "authenticatedAt": "2019-08-24T14:15:22Z",
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

Returns only the explicitly requested purpose cont

Returns only the explicitly requested purpose context and refreshed csrfToken. The purpose query must match the eligible cookie; restricted contexts do not expose application workspace data.

Authorizations:
KanvaApplicationKanvaPrivacyKanvaRecoveryKanvaServiceStatus
query Parameters
purpose
string (SessionPurpose)
Enum: "unknown" "application" "accountPrivacy" "accountRecovery" "serviceStatus"

Responses

Response samples

Content type
application/json
{
  • "sessionId": "f6567dd8-e069-418e-8893-7d22fcf12459",
  • "sessionVersion": 0,
  • "csrfToken": "string",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "displayName": "string",
  • "status": "unknown",
  • "purpose": "unknown",
  • "authenticatedAt": "2019-08-24T14:15:22Z",
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Returns generic accepted=true without revealing account existence. Registration requires the exact displayed current privacyNoticeVersion and a configured reviewed notice and qualified mail delivery. Email proof remains unverified until challenge completion.

Authorizations:
KanvaAntiforgery
Request Body schema:
email
string or null
privacyNoticeVersion
string or null

Responses

Request samples

Content type
{
  • "email": "string",
  • "privacyNoticeVersion": "string"
}

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Returns generic accepted=true without revealing account existence. Registration requires the exact displayed current privacyNoticeVersion and a configured reviewed notice and qualified mail delivery. Email proof remains unverified until challenge completion.

Authorizations:
KanvaAntiforgery
Request Body schema:
email
string or null
privacyNoticeVersion
string or null

Responses

Request samples

Content type
{
  • "email": "string",
  • "privacyNoticeVersion": "string"
}

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

On success the HTTP response binds the eligible purpose cookie and returns authenticated=true and purpose. No customer access token is returned. Reauthentication refreshes the existing eligible purpose, without elevating a restricted session.

Authorizations:
KanvaAntiforgery
Request Body schema:
challengeId
string <uuid>
secret
string or null
password
string or null

Responses

Request samples

Content type
{
  • "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c",
  • "secret": "string",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "authenticated": true,
  • "purpose": "unknown"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

On success the HTTP response binds the eligible purpose cookie and returns authenticated=true and purpose. No customer access token is returned. Reauthentication refreshes the existing eligible purpose, without elevating a restricted session.

Authorizations:
KanvaAntiforgery
Request Body schema:
email
string or null
password
string or null

Responses

Request samples

Content type
{
  • "email": "string",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "authenticated": true,
  • "purpose": "unknown"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Uses a bounded one-use email challenge and a generic accepted response. Reset completion revokes prior sessions; it does not sign the caller in.

Authorizations:
KanvaAntiforgery
Request Body schema:
email
string or null
privacyNoticeVersion
string or null

Responses

Request samples

Content type
{
  • "email": "string",
  • "privacyNoticeVersion": "string"
}

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Uses a bounded one-use email challenge and a generic accepted response. Reset completion revokes prior sessions; it does not sign the caller in.

Authorizations:
KanvaAntiforgery
Request Body schema:
challengeId
string <uuid>
secret
string or null
password
string or null

Responses

Request samples

Content type
{
  • "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c",
  • "secret": "string",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

On success the HTTP response binds the eligible purpose cookie and returns authenticated=true and purpose. No customer access token is returned. Reauthentication refreshes the existing eligible purpose, without elevating a restricted session.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery) (KanvaRecoveryKanvaAntiforgery) (KanvaServiceStatusKanvaAntiforgery)
Request Body schema:
password
string or null
purpose
string (SessionPurpose)
Enum: "unknown" "application" "accountPrivacy" "accountRecovery" "serviceStatus"

Responses

Request samples

Content type
{
  • "password": "string",
  • "purpose": "unknown"
}

Response samples

Content type
application/json
{
  • "authenticated": true,
  • "purpose": "unknown"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Local credential operations require the exact eligible current session purpose and revoke obsolete authentication proofs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery) (KanvaRecoveryKanvaAntiforgery)
Request Body schema:
currentPassword
string or null
newPassword
string or null

Responses

Request samples

Content type
{
  • "currentPassword": "string",
  • "newPassword": "string"
}

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Revokes only the current session of the requested purpose (application by default). Logout is a protected mutation; it cannot be triggered by a GET or another purpose cookie.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery) (KanvaRecoveryKanvaAntiforgery) (KanvaServiceStatusKanvaAntiforgery)
query Parameters
purpose
string (SessionPurpose)
Enum: "unknown" "application" "accountPrivacy" "accountRecovery" "serviceStatus"

Responses

Response samples

Content type
application/json
{
  • "accepted": true
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Consumes a one-use short-lived authorizationId created by the matching SignalR authentication flow and the same protected browser. It binds an HttpOnly purpose cookie. The authorization ID is not a reusable credential.

Authorizations:
KanvaAntiforgery
Request Body schema:
authorizationId
string <uuid>

Responses

Request samples

Content type
{
  • "authorizationId": "fd01ce3c-0799-43be-b4cd-b95dd107d4d8"
}

Response samples

Content type
application/json
{
  • "authenticated": true,
  • "purpose": "unknown"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Submit the same-origin form with csrfToken in its body and the exact current privacyNoticeVersion displayed before navigation. Returns a redirect to configured Google, an exact Microsoft tenant issuer, or the installation's exact enterprise OIDC provider. Reauthenticate=true additionally requires the existing requested purpose session. Provider callback handling is protocol middleware, not a customer bearer-token endpoint.

path Parameters
provider
required
string
Request Body schema: application/x-www-form-urlencoded
CsrfToken
string
ReturnUrl
string
Reauthenticate
boolean
Purpose
string (SessionPurpose)
Enum: "unknown" "application" "accountPrivacy" "accountRecovery" "serviceStatus"
PrivacyNoticeVersion
string

Responses

AccountErasureReceipt

Receipt-cookie access is limited to the bound eras

Receipt-cookie access is limited to the bound erasure request and its receipt expiry. It grants no login, recovery, workspace, or operator authority.

Authorizations:
KanvaErasureReceipt

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Receipt-cookie access is limited to the bound erasure request and its receipt expiry. It grants no login, recovery, workspace, or operator authority.

Authorizations:
(KanvaErasureReceiptKanvaAntiforgery)

Responses

AccountErasureReceipts

Receipt-cookie access is limited to the bound eras

Receipt-cookie access is limited to the bound erasure request and its receipt expiry. It grants no login, recovery, workspace, or operator authority.

Authorizations:
KanvaErasureReceipt
path Parameters
requestId
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Receipt-cookie access is limited to the bound erasure request and its receipt expiry. It grants no login, recovery, workspace, or operator authority.

Authorizations:
(KanvaErasureReceiptKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>

Responses

AccountErasureRequests

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
operationKey
string or null

Responses

Request samples

Content type
{
  • "operationKey": "string"
}

Response samples

Content type
No sample

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy
path Parameters
requestId
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
scopeHash
string or null
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "scopeHash": "string",
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
executorId
string <uuid>

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "executorId": "c2906df5-5cb7-4142-a0b8-82249142b757"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
replacementReceiptSessionId
string or null <uuid>
expectedReceiptVersion
integer or null <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "replacementReceiptSessionId": "ebdfca52-d2b4-428a-bb86-7ecd5afd0bfc",
  • "expectedReceiptVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
receiptAuthorizationId
string <uuid>

Responses

Request samples

Content type
{
  • "receiptAuthorizationId": "9f165451-6fee-4665-b0ac-a079698aec66"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaRecoveryKanvaAntiforgery)
path Parameters
requestId
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

AccountPrivacy

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
operationKey
string or null

Responses

Request samples

Content type
{
  • "operationKey": "string"
}

Response samples

Content type
No sample

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy

Responses

Response samples

Content type
No sample

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy

Responses

Response samples

Content type
No sample

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
scopeHash
string or null
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "scopeHash": "string",
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
executorId
string <uuid>

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "executorId": "c2906df5-5cb7-4142-a0b8-82249142b757"
}

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy
query Parameters
cursor
string

Responses

Response samples

Content type
No sample

Application or privacy review context only, except

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
KanvaApplicationKanvaPrivacy
query Parameters
cursor
string

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
replacementReceiptSessionId
string or null <uuid>
expectedReceiptVersion
integer or null <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "replacementReceiptSessionId": "ebdfca52-d2b4-428a-bb86-7ecd5afd0bfc",
  • "expectedReceiptVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaPrivacyKanvaAntiforgery)
Request Body schema:
receiptAuthorizationId
string <uuid>

Responses

Request samples

Content type
{
  • "receiptAuthorizationId": "9f165451-6fee-4665-b0ac-a079698aec66"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaPrivacyKanvaAntiforgery)

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Application or privacy review context only, except the explicitly restricted recovery operation. Privacy review does not grant workspace access. Confirmation requires current recent authentication, reviewed versions, and qualified independent recovery/erasure dependencies.

Authorizations:
(KanvaPrivacyKanvaAntiforgery)

Responses

AccountRecovery

/api/v1/account-recovery/context

Authorizations:
KanvaRecovery

Responses

Response samples

Content type
No sample

/api/v1/me/account-recovery-context

Authorizations:
KanvaRecovery

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaRecoveryKanvaAntiforgery)
Request Body schema:
requestId
string <uuid>
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaRecoveryKanvaAntiforgery)

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaRecoveryKanvaAntiforgery)

Responses

Admin

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
page
integer <int32>
Default: 0

Page number (0-based).

pageSize
integer <int32>
Default: 20

Number of items per page (default 20, max 100).

search
string

Optional search term to filter by email/user ID.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
userId
required
string

User ID (email).

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
userId
required
string

User ID (email).

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
userId
required
string

User ID (email).

Request Body schema:

API key creation request.

name
required
string or null

Human-readable name for the key.

description
string or null

Optional description of the key's purpose.

scopes
Array of strings or null

Permission scopes for this key.

expiresAt
string or null <date-time>

When the key should expire. Null means never expires.

Responses

Request samples

Content type
{
  • "name": "string",
  • "description": "string",
  • "scopes": [
    ],
  • "expiresAt": "2019-08-24T14:15:22Z"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
userId
required
string

User ID (email).

keyId
required
string <uuid>

API key ID.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Retired legacy administrator operation Deprecated

Disabled. This legacy route never grants administrator authority and returns permission_denied (403) after authentication. Use the separately authorized identity-administration contracts for supported operator actions.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
userId
required
string

User ID (email).

keyId
required
string <uuid>

API key ID.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Administration

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
searchBy
string or null
search
string or null
accountState
string or null
restrictionState
string or null
tenantId
string or null <uuid>
cursor
string or null
pageSize
integer <int32>

Responses

Request samples

Content type
{
  • "searchBy": "string",
  • "search": "string",
  • "accountState": "string",
  • "restrictionState": "string",
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "cursor": "string",
  • "pageSize": 0
}

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
kind
string
Default: "workspace"
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
search
string
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
kind
string
Default: "all"
search
string
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
state
string
Default: "active"
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
action
string
targetId
string <uuid>
search
string

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
handler
required
string
Request Body schema:
schemaVersion
integer <int32>
installationId
string <uuid>
tenantId
string or null <uuid>
targetId
string <uuid>
expectedTargetVersion
integer <int64>
operationKey
string or null
reason
string or null
arguments
any

Responses

Request samples

Content type
{
  • "schemaVersion": 0,
  • "installationId": "7a1bf939-4d70-4439-9ced-a3dbbce12bd7",
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "targetId": "cbca1126-180e-4334-9df8-cf82289d378b",
  • "expectedTargetVersion": 0,
  • "operationKey": "string",
  • "reason": "string",
  • "arguments": null
}

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
commandHash
string or null
expectedDecisionVersion
integer <int64>
decision
string or null
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "commandHash": "string",
  • "expectedDecisionVersion": 0,
  • "decision": "string",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
commandHash
string or null
approvalId
string or null <uuid>

Responses

Request samples

Content type
{
  • "commandHash": "string",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6"
}

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
action
string
operationKey
string

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
state
string
Default: "active"
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
tenantId
string <uuid>
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
module
required
string
query Parameters
tenantId
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
installationId
string <uuid>
scopeKind
string or null
targetId
string <uuid>
tenantId
string or null <uuid>
reasonCategory
string or null
safeExplanation
string or null
operationKey
string or null

Responses

Request samples

Content type
{
  • "installationId": "7a1bf939-4d70-4439-9ced-a3dbbce12bd7",
  • "scopeKind": "string",
  • "targetId": "cbca1126-180e-4334-9df8-cf82289d378b",
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "reasonCategory": "string",
  • "safeExplanation": "string",
  • "operationKey": "string"
}

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
tenantId
string <uuid>
state
string
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
proposalId
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
tenantId
string <uuid>
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
requestId
string <uuid>
read
string or null
nodeId
string or null <uuid>
cursor
string or null
correlationId
string <uuid>

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "read": "string",
  • "nodeId": "959356e3-6168-4a92-b4a5-b9d462be6177",
  • "cursor": "string",
  • "correlationId": "48fb4cd3-2ef6-4479-bea1-7c92721b988c"
}

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

ApiKeys

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Human application session only. Create, rotate, and revoke require current recent authentication. Create and rotate require a stable operationKey; an exact retry returns metadata with secretAvailable=false and key=null. The plaintext secret is displayed only once. Rotation atomically revokes the old key, without overlap.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
operationKey
required
string [ 1 .. 128 ] characters
name
required
string [ 1 .. 100 ] characters

Human-readable name for the key.

description
string or null <= 500 characters

Optional description of the key's purpose.

scopes
required
Array of strings

Explicit granular scopes intersected with the current delegated membership authority.

expiresAt
required
string <date-time>

Required expiration, strictly in the future and within the configured maximum (90 days).

Responses

Request samples

Content type
{
  • "operationKey": "string",
  • "name": "string",
  • "description": "string",
  • "scopes": [
    ],
  • "expiresAt": "2019-08-24T14:15:22Z"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Human application session only. Create, rotate, and revoke require current recent authentication. Create and rotate require a stable operationKey; an exact retry returns metadata with secretAvailable=false and key=null. The plaintext secret is displayed only once. Rotation atomically revokes the old key, without overlap.

Authorizations:
KanvaApplication
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Human application session only. Create, rotate, and revoke require current recent authentication. Create and rotate require a stable operationKey; an exact retry returns metadata with secretAvailable=false and key=null. The plaintext secret is displayed only once. Rotation atomically revokes the old key, without overlap.

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Human application session only. Create, rotate, and revoke require current recent authentication. Create and rotate require a stable operationKey; an exact retry returns metadata with secretAvailable=false and key=null. The plaintext secret is displayed only once. Rotation atomically revokes the old key, without overlap.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": true,
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Human application session only. Create, rotate, and revoke require current recent authentication. Create and rotate require a stable operationKey; an exact retry returns metadata with secretAvailable=false and key=null. The plaintext secret is displayed only once. Rotation atomically revokes the old key, without overlap.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
expectedVersion
integer <int64>
operationKey
required
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Artifacts

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Protected immutable artifact delivery revalidates the current tenant and complete resource graph before opening bytes and during streaming. Descriptors contain an authenticated same-origin content endpoint, never a raw storage URL. Missing or inaccessible artifacts return 404; unavailable or corrupt storage returns 503.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
artifactId
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Protected immutable artifact delivery revalidates the current tenant and complete resource graph before opening bytes and during streaming. Descriptors contain an authenticated same-origin content endpoint, never a raw storage URL. Missing or inaccessible artifacts return 404; unavailable or corrupt storage returns 503.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
artifactId
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Range
string

Optional single byte range.

Responses

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Protected immutable artifact delivery revalidates the current tenant and complete resource graph before opening bytes and during streaming. Descriptors contain an authenticated same-origin content endpoint, never a raw storage URL. Missing or inaccessible artifacts return 404; unavailable or corrupt storage returns 503.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
artifactId
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Range
string

Optional single byte range.

Responses

ArtifactUploads

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Upload sessions bind the original actor and tenant. CSV, TSV, Excel (.xls/.xlsx), and Parquet inputs are limited to 100 MiB, with contiguous 4 MiB chunks except the final remainder. Stable operation keys make create, finalize, and cancel retryable. Finalization returns a real ingestion job; raw storage paths and byte authority are never returned.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
operationKey
string or null
fileName
string or null
format
string or null
expectedBytes
integer <int64>
expectedSha256
string or null
dataSetId
string or null <uuid>
expectedDataSetRevision
integer or null <int64>
name
string or null
orderBy
string or null

Responses

Request samples

Content type
{
  • "operationKey": "string",
  • "fileName": "string",
  • "format": "string",
  • "expectedBytes": 0,
  • "expectedSha256": "string",
  • "dataSetId": "4d7600aa-4d53-4144-aa57-ce0c5b68b1da",
  • "expectedDataSetRevision": 0,
  • "name": "string",
  • "orderBy": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Upload sessions bind the original actor and tenant. CSV, TSV, Excel (.xls/.xlsx), and Parquet inputs are limited to 100 MiB, with contiguous 4 MiB chunks except the final remainder. Stable operation keys make create, finalize, and cancel retryable. Finalization returns a real ingestion job; raw storage paths and byte authority are never returned.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Upload sessions bind the original actor and tenant. CSV, TSV, Excel (.xls/.xlsx), and Parquet inputs are limited to 100 MiB, with contiguous 4 MiB chunks except the final remainder. Stable operation keys make create, finalize, and cancel retryable. Finalization returns a real ingestion job; raw storage paths and byte authority are never returned.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
operationKey
string or null
expectedSessionVersion
integer <int64>

Responses

Request samples

Content type
{
  • "operationKey": "string",
  • "expectedSessionVersion": 0
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Upload sessions bind the original actor and tenant. CSV, TSV, Excel (.xls/.xlsx), and Parquet inputs are limited to 100 MiB, with contiguous 4 MiB chunks except the final remainder. Stable operation keys make create, finalize, and cancel retryable. Finalization returns a real ingestion job; raw storage paths and byte authority are never returned.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
operationKey
string or null

Responses

Request samples

Content type
{
  • "operationKey": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Upload sessions bind the original actor and tenant. CSV, TSV, Excel (.xls/.xlsx), and Parquet inputs are limited to 100 MiB, with contiguous 4 MiB chunks except the final remainder. Stable operation keys make create, finalize, and cancel retryable. Finalization returns a real ingestion job; raw storage paths and byte authority are never returned.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Upload-Offset
required
integer <int64>

Contiguous acknowledged byte offset. An exact chunk retry is idempotent.

Upload-Chunk-Sha256
required
string

Lowercase SHA-256 of exactly this chunk.

Content-Length
required
integer <int64>

Exact chunk byte count, at most 4194304. Chunked or encoded request bodies are rejected.

Request Body schema: application/octet-stream
required
string <binary>

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Checkpoints

List all checkpoints for a project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Create a new checkpoint from the current trained model. Note: Checkpoint creation is an async operation. Use the SignalR hub for real-time notifications.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Checkpoint request.

projectId
string or null <uuid>
checkpointId
string or null <uuid>
label
required
string or null
description
string or null
setAsDefault
boolean

Responses

Request samples

Content type
{
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "checkpointId": "16673a5e-107b-463f-be42-5cfae1eaa8fe",
  • "label": "string",
  • "description": "string",
  • "setAsDefault": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Get a specific checkpoint by ID with full details including training metrics, input features, and configuration.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

checkpointId
required
string <uuid>

Checkpoint ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Update a checkpoint's label and description.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

checkpointId
required
string <uuid>

Checkpoint ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Checkpoint request.

projectId
string or null <uuid>
checkpointId
string or null <uuid>
label
required
string or null
description
string or null
setAsDefault
boolean

Responses

Request samples

Content type
{
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "checkpointId": "16673a5e-107b-463f-be42-5cfae1eaa8fe",
  • "label": "string",
  • "description": "string",
  • "setAsDefault": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Delete a checkpoint.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

checkpointId
required
string <uuid>

Checkpoint ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

CodeSnippets

Generate a code snippet for making predictions with a project.

Returns code in the specified language showing how to call the prediction API. The code includes project-specific input schema with example values.

Use format=notebook to download a Jupyter notebook instead of raw code.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

query Parameters
lang
string
Default: "python"

Programming language: python, curl, csharp (default: python).

mode
string
Default: "sync"

Snippet mode: sync, async, plain, flask (default: sync).

format
string
Default: "code"

Output format: code, notebook (default: code).

webhookUrl
string

Webhook URL for async mode notifications.

checkpointId
string <uuid>

Saved model checkpoint ID to use for predictions.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

List available code snippet templates.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

ConnectorCommands

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
configurationRevision
integer <int64>
expectedVersion
integer <int64>
objectType
string or null
requestId
string <uuid>
viewInstanceId
string <uuid>
workspaceGeneration
integer <int64>
object (ConnectorReadSelection)
resultContractVersion
integer or null <int32>
object (ConnectorDiscoverySelection)

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "configurationRevision": 0,
  • "expectedVersion": 0,
  • "objectType": "string",
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "viewInstanceId": "13f15bd5-f205-442e-b658-b3fe72263545",
  • "workspaceGeneration": 0,
  • "selection": {
    },
  • "resultContractVersion": 0,
  • "discoverySelection": {
    }
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
configurationRevision
integer <int64>
expectedVersion
integer <int64>
objectType
string or null
requestId
string <uuid>
viewInstanceId
string <uuid>
workspaceGeneration
integer <int64>
object (ConnectorReadSelection)
resultContractVersion
integer or null <int32>
object (ConnectorDiscoverySelection)

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "configurationRevision": 0,
  • "expectedVersion": 0,
  • "objectType": "string",
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "viewInstanceId": "13f15bd5-f205-442e-b658-b3fe72263545",
  • "workspaceGeneration": 0,
  • "selection": {
    },
  • "resultContractVersion": 0,
  • "discoverySelection": {
    }
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
configurationRevision
integer <int64>
expectedVersion
integer <int64>
objectType
string or null
requestId
string <uuid>
viewInstanceId
string <uuid>
workspaceGeneration
integer <int64>
object (ConnectorReadSelection)
resultContractVersion
integer or null <int32>
object (ConnectorDiscoverySelection)

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "configurationRevision": 0,
  • "expectedVersion": 0,
  • "objectType": "string",
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "viewInstanceId": "13f15bd5-f205-442e-b658-b3fe72263545",
  • "workspaceGeneration": 0,
  • "selection": {
    },
  • "resultContractVersion": 0,
  • "discoverySelection": {
    }
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
expectedVersion
integer <int64>
configurationRevision
integer <int64>
expectedActiveConfigurationRevision
integer or null <int64>
testJobId
string <uuid>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "expectedVersion": 0,
  • "configurationRevision": 0,
  • "expectedActiveConfigurationRevision": 0,
  • "testJobId": "3b94dbfa-2362-4ebb-b399-dfc216a3eec9"
}

/api/v1/connector-operations/{id}

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
query Parameters
tenantId
string <uuid>

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
jobId
string <uuid>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "jobId": "9d222c6d-893e-4e79-8201-3c9ca16a0f39"
}

/api/v1/connector-operations/{id}/result

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
query Parameters
tenantId
string <uuid>

Responses

/api/v1/customer-workspaces

Authorizations:
KanvaApplicationKanvaApiKey

Responses

/api/v1/connector-bindings

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
tenantId
string <uuid>
providerId
string
dataSourceId
string <uuid>
pageCursor
string

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
expectedVersion
integer <int64>
bindingId
string <uuid>
bindingRevision
integer <int64>
object (ConnectorConfiguration)
object (ConnectorCredentialChange)

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "expectedVersion": 0,
  • "bindingId": "5fecb7b6-229e-4247-b81d-92842fd7d9b7",
  • "bindingRevision": 0,
  • "configuration": {
    },
  • "credentialChange": { }
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
revision
required
integer <int64>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
configurationRevision
integer <int64>
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "configurationRevision": 0,
  • "expectedVersion": 0
}

/api/v1/connector-authorizations/{id}

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
query Parameters
tenantId
string <uuid>

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
authorizationId
string <uuid>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "authorizationId": "fd01ce3c-0799-43be-b4cd-b95dd107d4d8"
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSourceId
string <uuid>
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "expectedVersion": 0
}

ConnectorDefinitions

/api/v1/connector-definitions

Authorizations:
KanvaApplicationKanvaApiKey

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

ConnectorOAuth

/api/v1/connector-oauth/{provider}/callback

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
provider
required
string

Responses

Data

Fetch data from a dataset, project, or prediction scenario.

Triggers an asynchronous data fetch operation from the specified object. Supports different data stages (Raw, Transformed, etc.) and pagination. The result will be available through the jobs endpoint once the operation completes.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
objectType
required
string

Type of object: "dataset", "project", or "scenario".

id
required
string <uuid>

ID of the dataset or project.

query Parameters
key
string

Optional key for data retrieval.

page
integer <int32>
Default: 1

Page number (1-based).

pageSize
integer <int32>
Default: 100

Number of rows per page.

previewFactor
integer <int32>
Default: 0

Preview factor for sampling (0 = no sampling).

fillMissingDates
boolean
Default: true

Whether to fill missing dates in time series data.

dataStage
string
Default: "Raw"

Data stage to retrieve (Raw, Transformed, etc.).

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Datasets

List all datasets accessible to the authenticated user.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
tenantId
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Create a new dataset from a data source.

This operation is asynchronous. The returned job ID can be used to poll for status.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Dataset creation request.

dataSourceId
required
string <uuid>

ID of the data source to create the dataset from.

name
required
string or null

Name of the dataset.

query
string or null

SQL query or data specification.

orderBy
string or null

Column to order the data by (important for time series).

accessType
string or null

Access type: "private" (user only), "domain" (organization), or "public".

Responses

Request samples

Content type
{
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "name": "string",
  • "query": "string",
  • "orderBy": "string",
  • "accessType": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Get a specific dataset by ID.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

query Parameters
tenantId
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Update dataset properties.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Update request.

name
required
string or null

Updated name of the dataset.

description
string or null

Updated description.

query
string or null

Updated SQL query.

orderBy
string or null

Updated ordering column.

reloadData
boolean

Whether to reload data after update.

accessType
string or null

Access type.

Responses

Request samples

Content type
{
  • "name": "string",
  • "description": "string",
  • "query": "string",
  • "orderBy": "string",
  • "reloadData": true,
  • "accessType": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Delete a dataset.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "archiveState": "string"
}

Create a dataset from a URL.

This operation is asynchronous. The data will be fetched from the URL and analyzed.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

URL dataset creation request.

name
required
string or null

Name of the dataset.

url
required
string or null

URL to fetch the data from.

orderBy
string or null

Column to order the data by.

Responses

Request samples

Content type
{
  • "name": "string",
  • "url": "string",
  • "orderBy": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Legacy upload endpoint. Use authenticated artifact upload sessions. Deprecated

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Retired whole-file upload. Returns 400 upload_session_required. Create an artifact upload session, transfer bounded HTTP chunks, then finalize it. Customer FilePath and inline file contents are never accepted as worker input.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Update feature settings for a dataset column.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

featureName
required
string

Name of the feature (column) to update.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Feature settings update request.

required
object (FeatureSettings)
reanalyze
boolean

Whether to re-analyze data after the update.

Responses

Request samples

Content type
{
  • "settings": {
    },
  • "reanalyze": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Trigger data analysis for a dataset.

This operation is asynchronous. Use the jobs endpoint to poll for status.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Load training data for a dataset.

Triggers loading of the dataset's data into the training agent's cache. This is typically called before training or analysis operations. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Dataset ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Optional load parameters.

orderBy
string or null

Ordering column for the data.

query
string or null

SQL query filter.

reloadData
boolean

Force reload of data even if already cached.

Responses

Request samples

Content type
{
  • "orderBy": "string",
  • "query": "string",
  • "reloadData": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

DataSetSnapshots

/api/v1/datasets/{id}/versions

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
query Parameters
tenantId
string <uuid>
offset
integer <int32>
Default: 0

Responses

/api/v1/datasets/{id}/versions/{versionId}/rows

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
versionId
required
string <uuid>
query Parameters
tenantId
string <uuid>
offset
integer <int32>
Default: 0
count
integer <int32>
Default: 100

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSetId
string <uuid>
expectedDataSetRevision
integer <int64>
expectedCurrentVersionId
string or null <uuid>
expectedSettingsRevisionId
string <uuid>
sourceVersion
integer <int64>
sourceConfigurationRevision
integer <int64>
objectType
string or null
object (ConnectorReadSelection)
resultContractVersion
integer or null <int32>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSetId": "4d7600aa-4d53-4144-aa57-ce0c5b68b1da",
  • "expectedDataSetRevision": 0,
  • "expectedCurrentVersionId": "57e1ea5e-deb0-4a0e-859d-a71871070c67",
  • "expectedSettingsRevisionId": "3956b84e-1752-49d3-8d81-bef825e23f00",
  • "sourceVersion": 0,
  • "sourceConfigurationRevision": 0,
  • "objectType": "string",
  • "selection": {
    },
  • "resultContractVersion": 0
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
Request Body schema:
tenantId
string <uuid>
name
string or null
dataSourceId
string <uuid>
sourceVersion
integer <int64>
sourceConfigurationRevision
integer <int64>
objectType
string or null
object (ConnectorReadSelection)
visibility
string or null
requestId
string or null <uuid>
resultContractVersion
integer or null <int32>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "name": "string",
  • "dataSourceId": "2b37f84c-d876-441e-9b27-0c3482a7c574",
  • "sourceVersion": 0,
  • "sourceConfigurationRevision": 0,
  • "objectType": "string",
  • "selection": {
    },
  • "visibility": "string",
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "resultContractVersion": 0
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSetId
string <uuid>
requestId
string <uuid>
viewInstanceId
string <uuid>
workspaceGeneration
integer <int64>
expectedDataSetRevision
integer <int64>
expectedCurrentVersionId
string or null <uuid>
expectedSettingsRevisionId
string <uuid>
expectedSourceConfigurationRevision
integer <int64>
expectedSourceVersion
integer <int64>
publishOnCompletion
boolean

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSetId": "4d7600aa-4d53-4144-aa57-ce0c5b68b1da",
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "viewInstanceId": "13f15bd5-f205-442e-b658-b3fe72263545",
  • "workspaceGeneration": 0,
  • "expectedDataSetRevision": 0,
  • "expectedCurrentVersionId": "57e1ea5e-deb0-4a0e-859d-a71871070c67",
  • "expectedSettingsRevisionId": "3956b84e-1752-49d3-8d81-bef825e23f00",
  • "expectedSourceConfigurationRevision": 0,
  • "expectedSourceVersion": 0,
  • "publishOnCompletion": true
}

/api/v1/datasets/{id}/refreshes/{candidateId}

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>
candidateId
required
string <uuid>
query Parameters
tenantId
string <uuid>

Responses

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
candidateId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSetId
string <uuid>
candidateId
string <uuid>
expectedCandidateRevision
integer <int64>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSetId": "4d7600aa-4d53-4144-aa57-ce0c5b68b1da",
  • "candidateId": "10f4deb6-fd4e-4907-a47e-355caf6e449d",
  • "expectedCandidateRevision": 0
}

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
candidateId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
dataSetId
string <uuid>
candidateId
string <uuid>
expectedDataSetRevision
integer <int64>
expectedCurrentVersionId
string or null <uuid>
expectedSettingsRevisionId
string <uuid>
expectedSourceConfigurationRevision
integer <int64>
expectedCandidateRevision
integer <int64>
preparedViewReceiptId
string <uuid>
reviewedDiffSha256
string or null
confirmEmptyReplacement
boolean

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "dataSetId": "4d7600aa-4d53-4144-aa57-ce0c5b68b1da",
  • "candidateId": "10f4deb6-fd4e-4907-a47e-355caf6e449d",
  • "expectedDataSetRevision": 0,
  • "expectedCurrentVersionId": "57e1ea5e-deb0-4a0e-859d-a71871070c67",
  • "expectedSettingsRevisionId": "3956b84e-1752-49d3-8d81-bef825e23f00",
  • "expectedSourceConfigurationRevision": 0,
  • "expectedCandidateRevision": 0,
  • "preparedViewReceiptId": "de1a3121-cddb-488e-a418-87862d0f4f40",
  • "reviewedDiffSha256": "string",
  • "confirmEmptyReplacement": true
}

DataSources

List all data sources accessible to the authenticated user.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
tenantId
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Create a new data source.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Data source creation request.

object (CreateConnectorSourceRequest)
name
required
string or null

Name of the data source.

type
required
integer <int32> (DataSourceType)
Enum: 0 1 2 3 4 5 6
accessType
string or null

Access type: "private" (user only), "domain" (organization), or "public".

object (DataSourceConnectionApiRequest)

Connection configuration for a data source.

Responses

Request samples

Content type
{
  • "connector": {
    },
  • "name": "string",
  • "type": 0,
  • "accessType": "string",
  • "connection": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Get a specific data source by ID.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Data source ID.

query Parameters
tenantId
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Update an existing data source.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Data source ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Update request.

name
required
string or null

Updated name of the data source.

object (DataSourceConnectionApiRequest)

Connection configuration for a data source.

Responses

Request samples

Content type
{
  • "name": "string",
  • "connection": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Delete a data source.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Data source ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "archiveState": "string"
}

EnforcementDelivery

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey

Responses

FileUpload

Workspace resources require the explicit X-Kanva-T Deprecated

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Retired whole-file upload. Returns 400 upload_session_required. Create an artifact upload session, transfer bounded HTTP chunks, then finalize it. Customer FilePath and inline file contents are never accepted as worker input.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Health

Gets the health status of the API.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Gets a simple liveness check response.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Gets readiness status (includes dependency checks).

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

IdentityAdministration

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
executorId
string <uuid>
action
string or null
targetId
string <uuid>
scopeHash
string or null
expectedExecutorVersion
integer <int64>

Responses

Request samples

Content type
{
  • "executorId": "c2906df5-5cb7-4142-a0b8-82249142b757",
  • "action": "string",
  • "targetId": "cbca1126-180e-4334-9df8-cf82289d378b",
  • "scopeHash": "string",
  • "expectedExecutorVersion": 0
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
outgoingUserId
string <uuid>
successorUserId
string <uuid>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "outgoingUserId": "8c036c4a-9b9f-4c3c-bae7-1789723aefd1",
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
previewId
string <uuid>
approvalId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "previewId": "aa80f39b-ade0-40b6-909f-f6684cf78d20",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
proofId
string <uuid>
approvalId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "proofId": "ba01f738-2fa4-454f-ab7c-391c8898b8df",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
allowWorkspaceOwnerDeletion
boolean

Responses

Request samples

Content type
{
  • "allowWorkspaceOwnerDeletion": true
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
allowWorkspaceOwnerDeletion
boolean
expectedVersion
integer <int64>
scopeHash
string or null
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "allowWorkspaceOwnerDeletion": true,
  • "expectedVersion": 0,
  • "scopeHash": "string",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
successorUserId
string <uuid>

Responses

Request samples

Content type
{
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
successorUserId
string <uuid>
expectedInstallationVersion
integer <int64>
approvalId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7",
  • "expectedInstallationVersion": 0,
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Jobs

Get the status of a specific job.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Job ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Request samples

curl -X GET "https://kanva.human-driven.ai/api/v1/jobs/${JOB_ID}" \
  -H "X-API-Key: ${API_KEY}" \
  -H "X-Kanva-TenantId: ${TENANT_ID}"

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Cancel a pending or running job (DELETE alias).

This is an alias for POST /jobs/{id}/cancel, provided for REST convention compliance.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Job ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Get all jobs for a specific project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

query Parameters
status
string

Optional filter by job status (Pending, InProgress, Completed, Failed).

limit
integer <int32>
Default: 10

Maximum number of jobs to return (default 10, max 100).

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Get the latest job for a project by command type.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
projectId
required
string <uuid>

Project ID.

query Parameters
command
string

Job command type (e.g., TrainModel, TrainBaselineModel).

activeOnly
boolean
Default: false

Return only Pending, SentToAgent or InProgress jobs.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

List all jobs with optional filtering.

Returns jobs across all projects for the authenticated user. Use query parameters to filter by status or command type.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
projectId
string <uuid>

Optional filter by project ID.

status
string

Optional filter by job status (Pending, Running, Completed, Failed, Cancelled).

command
string
limit
integer <int32>
Default: 20

Maximum number of jobs to return (default 20, max 100).

offset
integer <int32>
Default: 0

Number of jobs to skip for pagination (default 0).

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Cancel a pending or running job.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Job ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Lookup

Get lookup data for the application.

Returns metadata needed by clients including:

  • Available projects and datasets
  • Supported model types and baselines
  • Aggregation functions and data types
  • Feature explainer patterns

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

MemberApiKeys

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
membershipId
required
string <uuid>

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
membershipId
required
string <uuid>
keyId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
membershipId
string <uuid>
principalId
string <uuid>
keyId
string <uuid>
expectedMembershipVersion
integer <int64>
expectedPrincipalVersion
integer <int64>
expectedKeyVersion
integer <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "membershipId": "8072cc74-4782-4f2c-827c-699c48ce2092",
  • "principalId": "0a52818d-1e0c-4e64-848e-4d04f9e914e5",
  • "keyId": "468bcefd-6536-4844-8249-aff3ecb2ef7b",
  • "expectedMembershipVersion": 0,
  • "expectedPrincipalVersion": 0,
  • "expectedKeyVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Ownership

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
successorUserId
string <uuid>
effect
string (OwnershipEffect)
Enum: "unknown" "workspaceHandover" "ownerRoleGrant"

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7",
  • "effect": "unknown"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
previewId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "previewId": "aa80f39b-ade0-40b6-909f-f6684cf78d20",
  • "operationKey": "string",
  • "reason": "string"
}

/api/v1/ownership/offers

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

/api/v1/ownership/notices

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
userId
string <uuid>
role
string (TenantRole)
Enum: "unknown" "viewer" "member" "admin" "owner"
status
string (MembershipStatus)
Enum: "unknown" "active" "suspended" "removed"
expectedVersion
integer or null <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "role": "unknown",
  • "status": "unknown",
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

/api/v1/ownership/workspaces/{id}/deletion-capability

Authorizations:
KanvaApplication
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

OwnershipOffers

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
successorUserId
string <uuid>
effect
string (OwnershipEffect)
Enum: "unknown" "workspaceHandover" "ownerRoleGrant"

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7",
  • "effect": "unknown"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
Request Body schema:
previewId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "previewId": "aa80f39b-ade0-40b6-909f-f6684cf78d20",
  • "operationKey": "string",
  • "reason": "string"
}

/api/v1/me/ownership-offers

Authorizations:
KanvaApplication
query Parameters
cursor
string

Responses

Response samples

Content type
No sample

/api/v1/me/ownership-offers/{offerId}

Authorizations:
KanvaApplication
path Parameters
offerId
required
string <uuid>

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
offerId
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
offerId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
offerId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
offerId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
scopeHash
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "scopeHash": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
noticeId
required
string <uuid>

Responses

Response samples

Content type
No sample

Projects

List all projects accessible to the authenticated user.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Create a new ML project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Project creation request.

projectSubtype
string or null
object (SnapshotProjectInputSelection)
object (ReviewedProjectInputSelection)
object (CopyProjectInput)
workspaceGeneration
integer <int64>
datasetId
required
string <uuid>

ID of the dataset to use for this project.

name
required
string or null

Name of the project.

description
string or null

Description of the project.

problemCategory
required
integer <int32> (ProblemCategory)
Enum: 0 1 2 3 4
accessType
string or null

New projects use "private". Share the created project through the resource-sharing API.

Responses

Request samples

Content type
{
  • "projectSubtype": "string",
  • "snapshotInput": {
    },
  • "inputSelection": {
    },
  • "copyInput": {
    },
  • "workspaceGeneration": 0,
  • "datasetId": "6586f21b-ad4d-4d06-a309-712af47184a2",
  • "name": "string",
  • "description": "string",
  • "problemCategory": 0,
  • "accessType": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Get a specific project by ID.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Delete a project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Update project metadata.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Metadata update request.

problemDomain
string or null

Problem domain and business logic description.

problemSolutionReason
string or null

Why we are trying to solve this problem.

businessValue
string or null

Expected business value from the solution.

dataAvailable
string or null

Description of available data.

dataCollection
string or null

How the data was collected.

successDefinition
string or null

How success will be measured.

runtime
string or null

Expected runtime environment.

constraints
string or null

Expected constraints.

Responses

Request samples

Content type
{
  • "problemDomain": "string",
  • "problemSolutionReason": "string",
  • "businessValue": "string",
  • "dataAvailable": "string",
  • "dataCollection": "string",
  • "successDefinition": "string",
  • "runtime": "string",
  • "constraints": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Train a baseline model for the project.

Baseline training establishes a simple reference model to compare against more complex models. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Baseline training request.

trainingProfile
string or null

Training profile to use.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "trainingProfile": "string",
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Train the main model for the project.

This operation is asynchronous. Use the jobs endpoint to poll for status.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Training request.

trainingProfile
string or null

Training profile to use (Fast, Balanced, Thorough).

previewFactor
integer <int32>

Preview factor for visualization (0 = no preview).

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "trainingProfile": "string",
  • "previewFactor": 0,
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Optimize model hyperparameters.

This operation searches for the best hyperparameters for the selected model. Requires that a model has already been trained. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Optimization request.

trainingProfile
string or null

Training profile to use.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "trainingProfile": "string",
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Reset training results for a project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Reset request.

resetBaselineResults
boolean

Whether to reset baseline training results.

resetTrainingResults
boolean

Whether to reset model training results.

Responses

Request samples

Content type
{
  • "resetBaselineResults": true,
  • "resetTrainingResults": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Generate predictions using the trained model.

Requires that a model has been trained for this project. Use sync=true query parameter for synchronous response (waits for prediction result). Default is async mode which returns a job ID for polling.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

query Parameters
sync
boolean
Default: false

If true, wait for prediction result. If false (default), return job ID.

timeout
integer <int32>
Default: 60

Timeout in seconds for sync mode (default: 60, max: 300).

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Prediction request with input values.

required
object or null

Input values for prediction. Key is feature name, value is list of values.

checkpointId
string or null <uuid>

Optional checkpoint ID. If not specified, uses default checkpoint or last trained model.

checkpointLabel
string or null

Optional checkpoint label. Alternative to checkpointId for specifying which model to use. If both checkpointId and checkpointLabel are provided, checkpointId takes precedence.

Responses

Request samples

Content type
{
  • "input": {
    },
  • "checkpointId": "16673a5e-107b-463f-be42-5cfae1eaa8fe",
  • "checkpointLabel": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Find discords (anomalous patterns) in the project's time series data.

Discords are subsequences in the data that are maximally different from all other subsequences. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Discord detection parameters.

chunkSize
integer <int32>

Size of the chunk to analyze for discord detection.

maxDiscords
integer <int32>

Maximum number of discords to return.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "chunkSize": 0,
  • "maxDiscords": 0,
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Find trend outliers in the project's data.

Identifies data points that deviate significantly from the expected trend. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Outlier detection parameters.

outlierThresholdFactor
number <double>

Threshold factor for outlier detection (higher = fewer outliers).

windowSize
integer <int32>

Window size for trend calculation.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "outlierThresholdFactor": 0.1,
  • "windowSize": 0,
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Find samples similar to a specified sample.

Returns samples from the training data that are most similar to the specified sample. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Similar samples request parameters.

sourceSampleIndex
integer <int64>

Index of the source sample to find similar samples for.

object or null

Alternatively, provide the source sample values directly.

samplesCount
integer <int32>

Number of similar samples to return.

Responses

Request samples

Content type
{
  • "sourceSampleIndex": 0,
  • "sourceSample": {
    },
  • "samplesCount": 0
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Request AI-powered interpretation of project data or visualizations.

Generates natural language explanations for model behavior, feature importance, or other visualizations. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Interpretation request.

interpretationType
string (InterpretationTypeApi)
Enum: "FeatureImportanceChart" "ConfusionMatrix" "ProbabilityVsAccuracyChart"

Type of interpretation to request.

imageData
string or null

Optional base64 encoded image data (e.g., chart screenshot) to include in interpretation.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "interpretationType": "FeatureImportanceChart",
  • "imageData": "string",
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

List all prediction scenarios for a project.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": [
    ],
  • "error": {
    }
}

Create a new prediction scenario.

If fileData is not provided, the scenario will be auto-generated based on project configuration.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Scenario creation request.

title
required
string or null

Title of the scenario.

description
string or null

Description of the scenario.

color
string or null

Color for visual identification (hex code).

fileData
string or null

Base64 encoded file data for the scenario source file. If not provided, the scenario will be auto-generated.

fileName
string or null

Original filename if uploading a file.

endDate
string or null <date-time>

End date for auto-generated scenarios.

checkpointLabel
string or null

Optional custom label for the checkpoint when creating a new one (checkpointId is null). If not provided, the scenario title is used.

checkpointId
string or null <uuid>

Reference to an existing checkpoint (saved model) to use for this scenario. If null, a new checkpoint is created from the current model.

object or null

Checkpoints for dependent projects. Key: Dependent project ID, Value: Checkpoint ID from that project. Use null as value to indicate "Save current model" for that dependent project.

Responses

Request samples

Content type
{
  • "title": "string",
  • "description": "string",
  • "color": "string",
  • "fileData": "string",
  • "fileName": "string",
  • "endDate": "2019-08-24T14:15:22Z",
  • "checkpointLabel": "string",
  • "checkpointId": "16673a5e-107b-463f-be42-5cfae1eaa8fe",
  • "dependentProjectCheckpoints": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Delete a prediction scenario.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

scenarioId
required
string

Scenario ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": null,
  • "error": {
    }
}

Export model assets for deployment.

Packages the trained model and related assets for use outside of Kanva. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Export configuration.

modelType
string (ModelTypeApi)
Enum: "Baseline" "Trained"

Model type for export.

object (WebhookConfig)

Webhook configuration for async operation callbacks.

Responses

Request samples

Content type
{
  • "modelType": "Baseline",
  • "webhook": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Request protected delivery of an exported model bundle.

Validates the current project graph before checking delivery availability. Returns an authenticated descriptor for the immutable exported artifact. Stored artifact locators and job results are never returned as download URLs.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Returns the latest visible immutable model export descriptor and its authenticated same-origin content endpoint. It never returns a raw storage URL. Download with the same current session or API key and X-Kanva-TenantId; range requests are supported.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "data": null,
  • "success": true,
  • "error": {
    }
}

Optimize classification threshold for a project.

For classification projects, this finds the optimal decision threshold that maximizes the model benefit based on the configured business value metrics. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Update project ML configuration properties.

Updates the project's ML configuration including features, target columns, forecasting settings, and other training-related properties. This may trigger a re-analysis of the data if specified.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Project properties to update.

object or null
convertMissingToZero
boolean
dataSplitRatio
number or null <float>
object or null
object or null
description
string or null
displayGroupingFeatures
Array of strings or null
object or null
forceReload
boolean
object or null
object (ForecastingProjectConfig)
groupingFeatures
Array of strings or null
object or null
object (ModelBenefit)
object or null
name
string or null
occurrenceThreshold
integer or null <int64>
Array of objects or null (PredictionScenario)
projectId
required
string <uuid>
reanalyze
boolean
resampling
string or null
object or null
object or null
object or null
splitIndex
integer or null <int64>
targetFeatures
Array of strings or null
timestepFeature
string or null
object (TrainingDataSettings)
object or null

Responses

Request samples

Content type
{
  • "bookmarkedRows": {
    },
  • "convertMissingToZero": true,
  • "dataSplitRatio": 0.1,
  • "dateExtractions": {
    },
  • "dependentProjectFeatures": {
    },
  • "description": "string",
  • "displayGroupingFeatures": [
    ],
  • "features": {
    },
  • "forceReload": true,
  • "excludedRows": {
    },
  • "forecastingConfig": {
    },
  • "groupingFeatures": [
    ],
  • "lags": {
    },
  • "modelBenefit": {
    },
  • "modelParameters": {
    },
  • "name": "string",
  • "occurrenceThreshold": 0,
  • "predictionScenarios": [
    ],
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "reanalyze": true,
  • "resampling": "string",
  • "resamplingAggregation": {
    },
  • "selectedBaselines": {
    },
  • "selectedModels": {
    },
  • "splitIndex": 0,
  • "targetFeatures": [
    ],
  • "timestepFeature": "string",
  • "trainingDataSettings": {
    },
  • "windows": {
    }
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Load project data from the data source.

Triggers loading of data from the project's associated dataset. This is typically called after making configuration changes that require fresh data. This operation is asynchronous.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires configured execution admission, an enrolled worker, current job authority, and finite capacity. The server pins the admitted resource graph and one worker attempt before dispatch. Unavailable execution dependencies return 503 execution_unavailable before work is submitted.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Switch between saved model configurations.

Switches the project to use a different saved configuration. Configurations represent different ML setups (features, parameters) that can be compared.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>

Project ID.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:

Configuration switch request.

configuration
required
string or null

Configuration identifier to switch to.

Responses

Request samples

Content type
{
  • "configuration": "string"
}

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

ResourceVisibility

Searches active workspace members for an authorized sharing review.

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
projectId
string <uuid>

The project being shared. Supply exactly one project or dataset.

datasetId
string <uuid>

The dataset being shared. Supply exactly one project or dataset.

search
string

Optional literal, case-insensitive display-name substring, trimmed and limited to 128 characters.

page
integer <int32>
Default: 1

One-based page number. Pages beyond the results return an empty items list.

pageSize
integer <int32>
Default: 20

Number of members per page, from 1 to 100; defaults to 20.

membershipIds
Array of strings <uuid> [ items <uuid > ]

Optional 1 to 100 distinct membership UUIDs, supplied as repeated query parameters. Combined with search by intersection; unavailable members are omitted.

header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Response samples

Content type
application/json
{
  • "success": true,
  • "data": {
    },
  • "error": {
    }
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
projectId
string or null <uuid>
datasetId
string or null <uuid>
audience
string or null
Array of objects or null (ReviewedSharingRecipient)
operationKey
string or null
Array of objects or null (ReviewedSharingResource)

Responses

Request samples

Content type
{
  • "projectId": "5a8591dd-4039-49df-9202-96385ba3eff8",
  • "datasetId": "6586f21b-ad4d-4d06-a309-712af47184a2",
  • "audience": "string",
  • "recipients": [
    ],
  • "operationKey": "string",
  • "resources": [
    ]
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
kind
string or null
id
string <uuid>
membershipId
string <uuid>
expectedVersion
integer <int64>
expectedMembershipVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "kind": "string",
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "membershipId": "8072cc74-4782-4f2c-827c-699c48ce2092",
  • "expectedVersion": 0,
  • "expectedMembershipVersion": 0,
  • "operationKey": "string"
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Authorizations:
KanvaApplicationKanvaApiKey
query Parameters
projectId
string <uuid>
datasetId
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Responses

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
visibility
string (ResourceVisibility)
Enum: "unknown" "private" "workspace" "selectedMembers"
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "visibility": "unknown",
  • "expectedVersion": 0
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
visibility
string (ResourceVisibility)
Enum: "unknown" "private" "workspace" "selectedMembers"
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "visibility": "unknown",
  • "expectedVersion": 0
}

Workspace resources require the explicit X-Kanva-T

Workspace resources require the explicit X-Kanva-TenantId header, live membership, and current resource visibility. API-key operations additionally require their explicit granular scope; scope never grants access to a hidden resource.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
id
required
string <uuid>
header Parameters
X-Kanva-TenantId
required
string <uuid>

Explicit workspace selector (UUID), never authority. It must match the current membership and, for API keys, the key's bound tenant. Resource parents and visibility are revalidated in the same command.

Request Body schema:
visibility
string (ResourceVisibility)
Enum: "unknown" "private" "workspace" "selectedMembers"
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "visibility": "unknown",
  • "expectedVersion": 0
}

ServiceStatus

/api/v1/me/service-status

Authorizations:
KanvaApplicationKanvaServiceStatus
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) (KanvaServiceStatusKanvaAntiforgery)
Request Body schema:
caseId
string <uuid>
expectedCaseVersion
integer <int64>
explanation
string or null
operationKey
string or null

Responses

Request samples

Content type
{
  • "caseId": "af51d69f-996a-4891-a745-aadfcdec225a",
  • "expectedCaseVersion": 0,
  • "explanation": "string",
  • "operationKey": "string"
}

Response samples

Content type
No sample

/api/v1/me/enforcement-appeals

Authorizations:
KanvaApplicationKanvaServiceStatus
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

/api/v1/me/enforcement-appeals/{id}

Authorizations:
KanvaApplicationKanvaServiceStatus
path Parameters
id
required
string <uuid>

Responses

Response samples

Content type
No sample

SupportAccess

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
tenantId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
Array of objects or null (SupportResourceSelection)
Array of objects or null (SupportDatasetSelection)
operationKey
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "roots": [
    ],
  • "previews": [
    ],
  • "operationKey": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
tenantId
required
string <uuid>
query Parameters
cursor
string
pageSize
integer <int32>
Default: 25

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Authorizations:
KanvaApplicationKanvaApiKey
path Parameters
tenantId
required
string <uuid>
id
required
string <uuid>

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
tenantId
required
string <uuid>
id
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedRequestVersion
integer <int64>
nodeIds
Array of strings or null <uuid> [ items <uuid > ]
expiresAt
string <date-time>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedRequestVersion": 0,
  • "nodeIds": [
    ],
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "operationKey": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
tenantId
required
string <uuid>
id
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedRequestVersion
integer <int64>
consentId
string or null <uuid>
expectedConsentVersion
integer or null <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedRequestVersion": 0,
  • "consentId": "e521cf62-a45f-49c5-8372-94853fffeb55",
  • "expectedConsentVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery) KanvaApiKey
path Parameters
tenantId
required
string <uuid>
id
required
string <uuid>
Request Body schema:
requestId
string <uuid>
expectedRequestVersion
integer <int64>
consentId
string or null <uuid>
expectedConsentVersion
integer or null <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "expectedRequestVersion": 0,
  • "consentId": "e521cf62-a45f-49c5-8372-94853fffeb55",
  • "expectedConsentVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

TenantMembers

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
query Parameters
offset
integer <int32>
Default: 0

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

An ordinary successor's Owner promotion creates an ownerRoleGrant offer and returns 202 with state=pending. Membership and resource owners remain unchanged until the exact recipient accepts. Assignment to the designated organization owner completes immediately with notification. Exact retries return the original result.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
userId
string <uuid>
role
string (TenantRole)
Enum: "unknown" "viewer" "member" "admin" "owner"
status
string (MembershipStatus)
Enum: "unknown" "active" "suspended" "removed"
expectedVersion
integer or null <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "role": "unknown",
  • "status": "unknown",
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

An ordinary successor's Owner promotion creates an ownerRoleGrant offer and returns 202 with state=pending. Membership and resource owners remain unchanged until the exact recipient accepts. Assignment to the designated organization owner completes immediately with notification. Exact retries return the original result.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
membershipId
required
string <uuid>
Request Body schema:
tenantId
string <uuid>
userId
string <uuid>
role
string (TenantRole)
Enum: "unknown" "viewer" "member" "admin" "owner"
status
string (MembershipStatus)
Enum: "unknown" "active" "suspended" "removed"
expectedVersion
integer or null <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "userId": "2c4a230c-5085-4924-a3e1-25fb4fc5965b",
  • "role": "unknown",
  • "status": "unknown",
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
membershipId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

WorkspaceProvisioning

/api/v1/me/workspace-provisioning-options

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
workspaceName
string or null
operationKey
string or null
expectedOptionsVersion
string or null
expectedCustomerAccountVersion
integer or null <int64>
expectedCustomerManagementVersion
integer or null <int64>
privacyNoticeVersion
string or null
termsVersion
string or null

Responses

Request samples

Content type
{
  • "workspaceName": "string",
  • "operationKey": "string",
  • "expectedOptionsVersion": "string",
  • "expectedCustomerAccountVersion": 0,
  • "expectedCustomerManagementVersion": 0,
  • "privacyNoticeVersion": "string",
  • "termsVersion": "string"
}

Response samples

Content type
No sample

/api/v1/me/workspace-provisioning/{operationId}

Authorizations:
KanvaApplication
path Parameters
operationId
required
string <uuid>

Responses

Response samples

Content type
No sample

/api/v1/me/customer-management

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
customerAccountId
string <uuid>
successorUserId
string <uuid>
expectedVersion
integer <int64>
expectedManagementVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "customerAccountId": "d8c60791-7301-441c-98e8-5bea9a162d9b",
  • "successorUserId": "9950fe45-56d9-45ab-91a9-8e8fcc8331a7",
  • "expectedVersion": 0,
  • "expectedManagementVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
id
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
expectedManagementVersion
integer <int64>
operationKey
string or null
approvalId
string or null <uuid>
scopeHash
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "expectedManagementVersion": 0,
  • "operationKey": "string",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "scopeHash": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

WorkspaceRetirement

Human application session only. Deletion requires

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Human application session only. Deletion requires

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
Request Body schema:
expectedTenantVersion
integer <int64>
expectedOrganizationPolicyVersion
integer <int64>
workspaceConfirmation
string or null
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "expectedTenantVersion": 0,
  • "expectedOrganizationPolicyVersion": 0,
  • "workspaceConfirmation": "string",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
application/json
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "state": "string",
  • "version": 0,
  • "createdAt": "2019-08-24T14:15:22Z",
  • "frozenAt": "2019-08-24T14:15:22Z",
  • "completedAt": "2019-08-24T14:15:22Z",
  • "recoveryEvidence": "string",
  • "pendingReason": "string",
  • "canCancel": true
}

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
KanvaApplication
path Parameters
tenantId
required
string <uuid>
requestId
required
string <uuid>

Responses

Response samples

Content type
No sample

The route tenantId selects the workspace. Matching

The route tenantId selects the workspace. Matching current membership, role, target, and expected versions are checked by the shared service; route or body identifiers do not grant authority.

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
tenantId
required
string <uuid>
requestId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
operationKey
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
expectedVersion
integer <int64>

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "expectedVersion": 0
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
expectedTenantVersion
integer <int64>
approvalId
string <uuid>
scopeHash
string or null
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "expectedTenantVersion": 0,
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "scopeHash": "string",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
tenantId
string <uuid>
reason
string or null
reviewBy
string <date-time>
operationKey
string or null

Responses

Request samples

Content type
{
  • "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",
  • "reason": "string",
  • "reviewBy": "2019-08-24T14:15:22Z",
  • "operationKey": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
holdId
required
string <uuid>

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
holdId
string <uuid>
expectedVersion
integer <int64>
approvalId
string <uuid>
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "holdId": "05363803-5510-4d71-8d1f-307021f9ad73",
  • "expectedVersion": 0,
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Requires a current installation-operator role and

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
KanvaApplication

Responses

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
customerId
required
string <uuid>
Request Body schema:
action
string or null
offerId
string or null <uuid>

Responses

Request samples

Content type
{
  • "action": "string",
  • "offerId": "42da58f8-9040-4cf5-98ce-bce9965cca0d"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
Request Body schema:
customerAccountId
string <uuid>
offerId
string <uuid>
expectedVersion
integer <int64>
expectedManagementVersion
integer <int64>
approvalId
string <uuid>
scopeHash
string or null
operationKey
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "customerAccountId": "d8c60791-7301-441c-98e8-5bea9a162d9b",
  • "offerId": "42da58f8-9040-4cf5-98ce-bce9965cca0d",
  • "expectedVersion": 0,
  • "expectedManagementVersion": 0,
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "scopeHash": "string",
  • "operationKey": "string",
  • "reason": "string"
}

Response samples

Content type
No sample

Browser requests require HTTPS, an exact configure

Browser requests require HTTPS, an exact configured Origin, protected browser cookies, and X-Kanva-CSRF bound to the current purpose session. Refresh the token after session binding. Never put credentials or antiforgery tokens in URLs.

Requires a current installation-operator role and the operation's approval policy in addition to the application session. Workspace ownership, API keys, and legacy admin flags cannot grant this role.

Human application session only. Deletion requires exact reviewed versions, operationKey, and workspace confirmation. A durable freeze receipt closes workspace admission; cleanup waits for worker stop acknowledgments, active readers, and retention holds. Cancellation is allowed only before that freeze. Operator and commercial actions also require their independently approved scope.

Authorizations:
(KanvaApplicationKanvaAntiforgery)
path Parameters
customerId
required
string <uuid>
Request Body schema:
expectedVersion
integer <int64>
expectedManagementVersion
integer <int64>
operationKey
string or null
approvalId
string or null <uuid>
scopeHash
string or null
reason
string or null

Responses

Request samples

Content type
{
  • "expectedVersion": 0,
  • "expectedManagementVersion": 0,
  • "operationKey": "string",
  • "approvalId": "23bbe807-dea1-4601-b208-07fd1aaad2b6",
  • "scopeHash": "string",
  • "reason": "string"
}

Response samples

Content type
No sample