> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Editions and availability

> How the API reference marks which endpoints exist on OneCLI Cloud, the Community self-hosted edition, and the Enterprise self-hosted edition, and what an unavailable endpoint answers.

OneCLI ships in three editions. Every endpoint page in this reference opens with an **Availability** line that names the editions it exists on, and endpoints that are not available everywhere carry a pill in the sidebar.

| Edition | What it is | Availability label |
| - | - | - |
| **Cloud** | The hosted platform at `api.onecli.sh`. | Cloud |
| **Community (self-hosted)** | The free, open source image you run yourself. | Community (self-hosted) |
| **Enterprise (self-hosted)** | A self-hosted deployment with `ENTERPRISE_ENABLED=true`, covered by the OneCLI Enterprise License. | Enterprise (self-hosted) |

See [Self-hosted OneCLI](/docs/self-hosting/overview) for how the editions compare as products.

## Reading the availability line

<Info>**Availability:** Cloud · Community (self-hosted) · Enterprise (self-hosted)</Info>

The endpoint exists on every edition. Most of the API looks like this: workspaces, agents, grants, secrets, apps, connections, conversations, schedules, memories, skills, channels, organization-level credentials and policy, and invitations are all free on every edition.

<Info>**Availability:** Cloud · Enterprise (self-hosted). Not available on the Community edition.</Info>

The endpoint is part of the Enterprise feature set: the organization directory (members, groups, role mappings), workspace sharing, verified domains, SSO, SCIM, app availability, provisioning, and resource browsing for scoped grants. The sidebar shows an **Enterprise** pill next to it.

On a Community deployment the endpoint answers `403` with the envelope error type `enterprise_license_required`:

```json theme={null}
{
  "error": {
    "message": "Single sign-on, verified domains & SCIM requires a OneCLI Enterprise license.",
    "type": "enterprise_license_required"
  }
}
```

The whole surface is dark, reads included, so a client can probe one endpoint to learn the deployment's posture. The unauthenticated `GET /instance` endpoint reports the same fact as `entitled: true | false` without needing a probe.

<Info>**Availability:** Cloud only.</Info>

The endpoint exists only on the hosted platform. Self-hosted deployments answer `404`. No endpoint in this reference carries this label today; it is reserved for hosted-platform surfaces such as billing.

## Cloud plans

On Cloud every Enterprise endpoint is present, but some features are additionally gated by the organization's plan. Where that applies the endpoint's description says so (for example "On Cloud this needs the Scale plan or above"). A plan refusal is a `403` with the ordinary `authentication_error` type and a message naming the plan.

Two policy features are plan-gated on Cloud but free on every self-hosted edition: deny-by-default (`PATCH /org/policy/default` with `action: block`, Team plan) and rate limits on allow rules (Pro plan). Manual approvals on grants and rules are available on every plan and every edition.

## Roles

Organization-level endpoints (`/org/…`) require the **admin** or **owner** role wherever roles are enforced, which is Cloud and Enterprise. The Community edition runs a flat team: every active member passes the role check, so an organization endpoint that an admin could call on Cloud can be called by any member there.

## Surfaces not in this reference

A few HTTP surfaces exist on the API server but are not part of the public API and are left out of this reference: the runner, channel-adapter, and SSH-terminator daemons' own endpoints (authenticated by their own token families), the Slack inbound webhooks and OAuth callbacks, the CLI's device-login flow, the install and migration script endpoints, and Cloud's billing, webhook intake, and hosted-ops plumbing. They may change without notice.

The server also keeps a set of **compatibility aliases** alive for CLIs that predate a rename. They are not documented as endpoints of their own because each one is the same handler as a documented endpoint: `/v1/projects*` and the `X-Project-Id` header (the workspace rename, see the [overview](/docs/api-reference)), `/v1/apps/connections*` and `/v1/org/apps/connections*` (the connection resources before they moved to `/v1/connections` and `/v1/org/connections`), the filter-in-path forms `/v1/apps/connections/{provider}` and `/v1/org/connections/{provider}` (use `?provider=` instead), and `/v1/org/app-config/*` (now `/v1/org/apps/{provider}/config`). Write new integrations against the documented paths.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.