OSPRIDocs
Developers

OSPRI Platform API

The shared service that checks access and records usage.

The platform manages invitations, app grants, workspace authorization and usage. Product APIs do the scientific work.

Download the OpenAPI contract. The reference includes administrative and service operations as well as user-facing operations. A documented route is not an authorization grant.

For product developers, the core sequence is:

  1. Verify the user's app-specific token.
  2. Ask the platform whether that actor can perform this operation in the selected workspace.
  3. Apply the product's own record-ownership check.
  4. Execute the versioned operation.
  5. Record the result and durable usage event with its actor, app, workspace and run/operation ID.

Backend policy and usage credentials stay on the server. They are not end-user API keys and must never be placed in a browser, add-in or sample notebook. A usage credential is not a budget-spending permission.

Read the shared release contract before adding another app.