MSP HTTP API Overview
The published OpenAPI document is generated from the MSP backend's maintained
Springdoc product contract. It excludes operator-only Advanced APIs and Admin
management APIs.
Base URL
Use the same origin as the MSP Console. Customer deployments normally expose the API through:
<environment-origin>/msp-api
The downloadable contract uses a same-origin server URL and therefore works with an IP address, HTTP test environment, or customer domain without editing a hard-coded host.
Authentication
Management requests use a short-lived Bearer token. A Human user may obtain and
store that token through sstudio login; do not paste API keys or tokens into
Agent prompts, source files, or support logs.
export SSTUDIO_PLATFORM__API_ENDPOINT="https://your-host.example"
export SSTUDIO_PLATFORM__API_KEY="your-api-key"
sstudio login \
--api-key "$SSTUDIO_PLATFORM__API_KEY" \
--base-url "$SSTUDIO_PLATFORM__API_ENDPOINT"
For direct HTTP integrations, use the documented API-key login operation and
keep the resulting Bearer token in a secret manager. Ordinary resource
operations require Authorization: Bearer <token> and remain subject to the
current user's role and resource grants.
Response envelope
Most JSON responses use:
{
"code": 200,
"message": "ok",
"errorCode": null,
"details": null,
"data": {}
}
A non-2xx HTTP status or a non-success business code is a failure. File and raw text downloads may return their documented media type instead of the envelope.
Reference and contract
Publishing an endpoint does not authorize an Agent to call it. Agents must
continue to obey the msp-operations capability manifest, including its raw
transport and credential-management restrictions.