Kontyra REST API Specification
The unified programmatic core of Kontyra. Every resource — from sandboxes and events to billing and neural inference — is orchestrated through this high-performance REST interface.
1. Overview & Gateway Ingress
All requests to Kontyra services route through api.kontyra.name.ng/v1. The gateway validates authentication tokens, checks organization access, rate-limits abuse, and distributes requests to dedicated backend microservices.
Zero-trust cryptographic verification with sub-millisecond edge routing
Receives HTTPS requests with Bearer JWT, X-Api-Key, or X-Kontyra-Key headers.
Verifies allowed origins (*.kontyra.name.ng or registered domains) and checks IP burst limits.
Validates RS256 signatures against JWKS; unpacks user ID, tier, and active organization roles.
Routes payload directly to isolated microservice (DevOS containers, Firestore, Kora GPU nodes).
2. Authentication & Headers
Authenticate your requests by including one of the supported authentication headers:
Standard RFC 6750 Bearer token header. Use for user session JWTs or programmatic service tokens.
Dedicated machine-to-machine API key generated in the Kontyra Console.
Optional header to switch execution context into an organization workspace.
3. Standard Response Envelope & Errors
All gateway responses return JSON formatted with standard metadata:
{
"success": true,
"data": {
"id": "proj_8291ac",
"name": "edge-analytics",
"status": "ready"
},
"timestamp": "2026-10-03T04:20:00.000Z"
}{
"success": false,
"error": {
"code": "INSUFFICIENT_PERMISSIONS",
"message": "Only organization Admins or Owners may deploy this workspace.",
"doc_url": "https://docs.kontyra.name.ng/console#rbac"
},
"timestamp": "2026-10-03T04:20:00.000Z"
}4. Rate Limits & Edge Throttling
Gateway rate limits protect platform stability. Every response includes real-time telemetry headers:
5. DevOS Projects & Runtimes
Manage DevOS sandboxes, deployment diffs, and live edge subdomains:
curl -X POST https://api.kontyra.name.ng/v1/projects/proj_8291ac/deploy \
-H "Authorization: Bearer test-kontyra-key" \
-H "Content-Type: application/json" \
-d '{
"environment": "production",
"trigger": "api"
}'6. VUX Events & Ticket Verification
Query conferences, issue tickets, and validate attendees at event doors:
curl -X POST https://api.kontyra.name.ng/v1/events/evt_hackathon_2026/check-in \
-H "Authorization: Bearer test-kontyra-key" \
-H "Content-Type: application/json" \
-d '{
"ticketCode": "TKT-A8F2B1C9",
"scannedBy": "gate_scanner_01"
}'7. Organizations & Member Management
Programmatically query organization rosters, invite members, and fetch security audit trails:
curl -X GET "https://api.kontyra.name.ng/v1/orgs/org_98f12a/audit-logs?limit=25" \
-H "Authorization: Bearer test-kontyra-key"8. S3 Storage & Pre-signed Uploads
Upload large files directly to S3-compatible cloud storage using secure pre-signed URLs without routing data through the application server:
curl -X POST https://api.kontyra.name.ng/v1/storage/upload \
-H "Authorization: Bearer test-kontyra-key" \
-H "Content-Type: application/json" \
-d '{
"filename": "bundle-release-v2.zip",
"contentType": "application/zip",
"sizeBytes": 1420580
}'9. Neural AI Chat Completions
Directly invoke the KORA transformer engine using standard OpenAI-compatible completions payloads:
curl -X POST https://api.kontyra.name.ng/v1/chat/completions \
-H "Authorization: Bearer test-kontyra-key" \
-H "Content-Type: application/json" \
-d '{
"model": "kora-v2",
"messages": [
{ "role": "user", "content": "How do I configure devos.json for Next.js 16?" }
]
}'