Skip to main content

API reference

The KoraBridge API lets you manage connections, pipelines, runs and schedules from your own code. It is the same API the app uses.

This reference covers the endpoints available to your organization. Platform administration is not part of it.

Base URL​

https://app.kora-bridge.com/api/v1

All endpoints are under this prefix and are served over HTTPS. Request and response bodies are JSON.

Authentication​

The API uses bearer tokens.

  1. Call POST /api/v1/auth/login with your email and password as a JSON body.
  2. Copy the access_token from the response.
  3. Send it on every other request as Authorization: Bearer <token>.
curl -s https://app.kora-bridge.com/api/v1/auth/login \
-H 'Content-Type: application/json' \
-d '{"email": "you@example.com", "password": "..."}'

curl -s https://app.kora-bridge.com/api/v1/pipelines \
-H "Authorization: Bearer $ACCESS_TOKEN"

The login response also includes a refresh_token. Access tokens are short-lived. When one expires, call POST /api/v1/auth/refresh with {"refresh_token": "..."} to get a new pair. Each refresh token can be used once, so always store the new one that comes back.

Keep tokens out of source control and logs. If you automate against the API, create a dedicated user for it and read the password from a secret store or environment variable.

Rate limits​

Sign-in, token refresh, invitation and password-reset endpoints allow only a few attempts per minute. If you exceed that, you get 429 Too Many Requests with a Retry-After header that says how many seconds to wait.

What is covered​

The reference lists the endpoints your organization can use: sign-in and account, connections and connection types, pipelines, runs, schedules, settings, organization members and usage and plan information. Every operation shows its parameters, request body, responses and schema.

Endpoints for operating the KoraBridge platform itself, inbound webhooks and consent callbacks are not part of this reference.

Errors​

StatusMeaning
401The token is missing, invalid or expired. Sign in or refresh it.
403You are signed in but your role does not allow this action.
404The resource does not exist or is not visible to your organization.
422The request body or parameters failed validation. The response says which fields.
429Too many attempts. Wait for the Retry-After period.
Failed responses can echo your input

A 422 response can echo back the values you sent. Do not log failed responses from requests that carry credentials.