Skip to main content
OneCLI ships in three editions. Every endpoint page in this reference opens with an Availability line that names the editions it exists on, and endpoints that are not available everywhere carry a pill in the sidebar. See Self-hosted OneCLI for how the editions compare as products.

Reading the availability line

Availability: Cloud · Community (self-hosted) · Enterprise (self-hosted)
The endpoint exists on every edition. Most of the API looks like this: workspaces, agents, grants, secrets, apps, connections, conversations, schedules, memories, skills, channels, organization-level credentials and policy, and invitations are all free on every edition.
Availability: Cloud · Enterprise (self-hosted). Not available on the Community edition.
The endpoint is part of the Enterprise feature set: the organization directory (members, groups, role mappings), workspace sharing, verified domains, SSO, SCIM, app availability, provisioning, and resource browsing for scoped grants. The sidebar shows an Enterprise pill next to it. On a Community deployment the endpoint answers 403 with the envelope error type enterprise_license_required:
The whole surface is dark, reads included, so a client can probe one endpoint to learn the deployment’s posture. The unauthenticated GET /instance endpoint reports the same fact as entitled: true | false without needing a probe.
Availability: Cloud only.
The endpoint exists only on the hosted platform. Self-hosted deployments answer 404. No endpoint in this reference carries this label today; it is reserved for hosted-platform surfaces such as billing.

Cloud plans

On Cloud every Enterprise endpoint is present, but some features are additionally gated by the organization’s plan. Where that applies the endpoint’s description says so (for example “On Cloud this needs the Scale plan or above”). A plan refusal is a 403 with the ordinary authentication_error type and a message naming the plan. Two policy features are plan-gated on Cloud but free on every self-hosted edition: deny-by-default (PATCH /org/policy/default with action: block, Team plan) and rate limits on allow rules (Pro plan). Manual approvals on grants and rules are available on every plan and every edition.

Roles

Organization-level endpoints (/org/…) require the admin or owner role wherever roles are enforced, which is Cloud and Enterprise. The Community edition runs a flat team: every active member passes the role check, so an organization endpoint that an admin could call on Cloud can be called by any member there.

Surfaces not in this reference

A few HTTP surfaces exist on the API server but are not part of the public API and are left out of this reference: the runner, channel-adapter, and SSH-terminator daemons’ own endpoints (authenticated by their own token families), the Slack inbound webhooks and OAuth callbacks, the CLI’s device-login flow, the install and migration script endpoints, and Cloud’s billing, webhook intake, and hosted-ops plumbing. They may change without notice. The server also keeps a set of compatibility aliases alive for CLIs that predate a rename. They are not documented as endpoints of their own because each one is the same handler as a documented endpoint: /v1/projects* and the X-Project-Id header (the workspace rename, see the overview), /v1/apps/connections* and /v1/org/apps/connections* (the connection resources before they moved to /v1/connections and /v1/org/connections), the filter-in-path forms /v1/apps/connections/{provider} and /v1/org/connections/{provider} (use ?provider= instead), and /v1/org/app-config/* (now /v1/org/apps/{provider}/config). Write new integrations against the documented paths.