API Overview
KubeOpera does not expose a public, directly-callable REST API, and there is no API-token or OAuth2-client-credentials flow for third-party integrations to authenticate against one. This is a deliberate architectural choice, not a gap: every backend service is reached exclusively through the Next.js frontend's own server-side proxy routes, which keeps backend hostnames, ports, and service-to-service credentials out of the browser entirely and avoids CORS by construction. A logged-in user's session cookie is what authorizes a proxy call — there's no separate API key to issue, rotate, or leak.
If you're looking to integrate with KubeOpera programmatically — from a script, an AI agent, or another internal tool — the MCP Server is the real, supported way to do that. It exposes the platform's operational surface (cluster health, apps, deployments, incidents, and more) as a set of typed tools over the Model Context Protocol, authenticated the same way any other backend call is, and is what this documentation's own examples and the platform's AI chat sidebar both use under the hood.
What this section actually documents
The pages under this section describe KubeOpera API's real internal REST surface — the routes the frontend's proxy calls on a user's behalf. They're useful for understanding what operations exist and how they're shaped, and for anyone extending the frontend itself, but they are not a public, externally-callable contract: every route here requires the same session-derived JWT the frontend already holds, validated the same way described in the Security Guide.
Where to look for what
- Application and deployment operations (create, list, scale, roll back an app) — see KubeOpera API.
- CI/CD pipelines and Kaniko builds — also documented on the KubeOpera API page, under its own sections.
- Inbound Git webhooks (a tenant's own repository push triggering a build) — see Build Service.
- Programmatic, agent-facing access — see the MCP Server section, including the full tool reference.
Next Steps
- KubeOpera API service page — the real endpoint reference
- MCP Server Overview — the actual way to integrate programmatically
- Security Guide — how authentication and authorization work across the platform