See Self-hosted OneCLI for how the editions compare as products.
Reading the availability line
Availability: Cloud · Community (self-hosted) · Enterprise (self-hosted)
Availability: Cloud · Enterprise (self-hosted). Not available on the Community edition.
403 with the envelope error type enterprise_license_required:
GET /instance endpoint reports the same fact as entitled: true | false without needing a probe.
Availability: Cloud only.
404. No endpoint in this reference carries this label today; it is reserved for hosted-platform surfaces such as billing.
Cloud plans
On Cloud every Enterprise endpoint is present, but some features are additionally gated by the organization’s plan. Where that applies the endpoint’s description says so (for example “On Cloud this needs the Scale plan or above”). A plan refusal is a403 with the ordinary authentication_error type and a message naming the plan.
Two policy features are plan-gated on Cloud but free on every self-hosted edition: deny-by-default (PATCH /org/policy/default with action: block, Team plan) and rate limits on allow rules (Pro plan). Manual approvals on grants and rules are available on every plan and every edition.
Roles
Organization-level endpoints (/org/…) require the admin or owner role wherever roles are enforced, which is Cloud and Enterprise. The Community edition runs a flat team: every active member passes the role check, so an organization endpoint that an admin could call on Cloud can be called by any member there.
Surfaces not in this reference
A few HTTP surfaces exist on the API server but are not part of the public API and are left out of this reference: the runner, channel-adapter, and SSH-terminator daemons’ own endpoints (authenticated by their own token families), the Slack inbound webhooks and OAuth callbacks, the CLI’s device-login flow, the install and migration script endpoints, and Cloud’s billing, webhook intake, and hosted-ops plumbing. They may change without notice. The server also keeps a set of compatibility aliases alive for CLIs that predate a rename. They are not documented as endpoints of their own because each one is the same handler as a documented endpoint:/v1/projects* and the X-Project-Id header (the workspace rename, see the overview), /v1/apps/connections* and /v1/org/apps/connections* (the connection resources before they moved to /v1/connections and /v1/org/connections), the filter-in-path forms /v1/apps/connections/{provider} and /v1/org/connections/{provider} (use ?provider= instead), and /v1/org/app-config/* (now /v1/org/apps/{provider}/config). Write new integrations against the documented paths.