API reference
The KoraBridge API lets you manage connections, pipelines, runs and schedules from your own code. It is the same API the app uses.
This reference covers the endpoints available to your organization. Platform administration is not part of it.
Base URL
https://app.kora-bridge.com/api/v1
All endpoints are under this prefix and are served over HTTPS. Request and response bodies are JSON.
Authentication
The API uses bearer tokens.
- Call
POST /api/v1/auth/loginwith youremailandpasswordas a JSON body. - Copy the
access_tokenfrom the response. - Send it on every other request as
Authorization: Bearer <token>.
curl -s https://app.kora-bridge.com/api/v1/auth/login \
-H 'Content-Type: application/json' \
-d '{"email": "you@example.com", "password": "..."}'
curl -s https://app.kora-bridge.com/api/v1/pipelines \
-H "Authorization: Bearer $ACCESS_TOKEN"
The login response also includes a refresh_token. Access tokens are short-lived. When one expires, call POST /api/v1/auth/refresh with {"refresh_token": "..."} to get a new pair. Each refresh token can be used once, so always store the new one that comes back.
Keep tokens out of source control and logs. If you automate against the API, create a dedicated user for it and read the password from a secret store or environment variable.
Rate limits
Sign-in, token refresh, invitation and password-reset endpoints allow only a few attempts per minute. If you exceed that, you get 429 Too Many Requests with a Retry-After header that says how many seconds to wait.
What is covered
The reference lists the endpoints your organization can use: sign-in and account, connections and connection types, pipelines, runs, schedules, settings, organization members and usage and plan information. Every operation shows its parameters, request body, responses and schema.
Endpoints for operating the KoraBridge platform itself, inbound webhooks and consent callbacks are not part of this reference.
Errors
| Status | Meaning |
|---|---|
| 401 | The token is missing, invalid or expired. Sign in or refresh it. |
| 403 | You are signed in but your role does not allow this action. |
| 404 | The resource does not exist or is not visible to your organization. |
| 422 | The request body or parameters failed validation. The response says which fields. |
| 429 | Too many attempts. Wait for the Retry-After period. |
A 422 response can echo back the values you sent. Do not log failed responses from requests that carry credentials.