API
Same permission, quote, and evidence rules as the UI. An API key cannot bypass spend approval.
POST /api/v1/quotes
Expiring execution quote
POST /api/v1/approvals
Bind spend to a manifest hash
POST /api/v1/runs
Reserve and start
POST /api/v1/sessions/:id/followups
0.25 RU continuation
POST /api/mcp
Read/draft; run needs approval
POST /api/v1/human-evidence
Holdout import