Skip to main content

MSP HTTP API Overview

The published OpenAPI document is generated from the MSP backend's maintained Springdoc product contract. It excludes operator-only Advanced APIs and Admin management APIs.

Base URL​

Use the same origin as the MSP Console. Customer deployments normally expose the API through:

<environment-origin>/msp-api

The downloadable contract uses a same-origin server URL and therefore works with an IP address, HTTP test environment, or customer domain without editing a hard-coded host.

Authentication​

Management requests use a short-lived Bearer token. A Human user may obtain and store that token through sstudio login; do not paste API keys or tokens into Agent prompts, source files, or support logs.

export SSTUDIO_PLATFORM__API_ENDPOINT="https://your-host.example"
export SSTUDIO_PLATFORM__API_KEY="your-api-key"
sstudio login \
--api-key "$SSTUDIO_PLATFORM__API_KEY" \
--base-url "$SSTUDIO_PLATFORM__API_ENDPOINT"

For direct HTTP integrations, use the documented API-key login operation and keep the resulting Bearer token in a secret manager. Ordinary resource operations require Authorization: Bearer <token> and remain subject to the current user's role and resource grants.

Response envelope​

Most JSON responses use:

{
"code": 200,
"message": "ok",
"errorCode": null,
"details": null,
"data": {}
}

A non-2xx HTTP status or a non-success business code is a failure. File and raw text downloads may return their documented media type instead of the envelope.

Reference and contract​

Publishing an endpoint does not authorize an Agent to call it. Agents must continue to obey the msp-operations capability manifest, including its raw transport and credential-management restrictions.