The API

The HTTP API behind the portal: what it is, how to call it, and what a token can reach.

What it is

Everything the portal does goes through the Zero Human OS API, and so can you: start a task from a deploy script, read what is blocked from a dashboard, answer a gate from another system. Its address is:

https://api.zerohuman.com/v1

Every route starts with /v1. There is no other version.

Your first call

Create a token under Settings → API tokens in the portal (Authentication), give it the blockers:read scope, and ask what needs attention:

curl -H "Authorization: Bearer $ZEROHUMAN_TOKEN" https://api.zerohuman.com/v1/blockers

A token acts for the enterprise it was created in, and only reaches what its scopes allow.

What a token can reach

Nearly all of it: tasks, runs, executions, gates, blockers, teams, members, roles, memory, spend, tools, webhooks and the rest, each behind its own scope (Endpoints lists every route). A few things are the portal's alone, because they belong to a person signed in, not to a credential:

  • managing API tokens (no token can create, change or revoke tokens, whatever its scopes);
  • signing in and out, the enterprises a person belongs to, and the people in an enterprise;
  • connected apps and the consent screen.

Without a token

Two routes need no token at all:

  • GET /v1/health answers whether the API is up, and which version it runs.
  • The webhooks, which start a task or answer a gate, authenticate with your enterprise's webhook secret instead.

Also here

  • Authentication: tokens and scopes.
  • Conventions: errors, pagination, and which calls are safe to retry.
  • Endpoints: every route, by resource, with the scope it needs.
  • Tasks over the API: create, change and start a task from code.
  • Webhooks: start a run, or answer a gate, from another system.
  • Agents that speak MCP can use the same API through your enterprise's MCP server.