Confluye
Endpoints

Settings

Workspace preferences, members, and related admin HTTP APIs.

v1 settings currently expose preferences only. Members and the current workspace use /api/v1/workspace-members and /api/v1/workspaces. Session routes cover Git repository and Agent Runtime rollout. See Workspace settings.

Preferences

MethodPathAuth
GET, PATCH/api/v1/settings/preferencesBearer API key (any scope)
GET, PATCH/api/settings/preferencesSession

v1 401: { "error": "Valid bearer API key is required" }. Success: { preference }.

PATCH JSON (all optional): theme (system | light | dark), autoConnectOnDrop, canvasErrorNotifications, canvasViewport { x, y, zoom }, snapToGrid (off | small | large), showCanvasControls, allowTelemetry, chatAiProvider (openai | anthropic | google | local:claude-code | local:codex), chatAiModel, liveTransports, workflowFolders, workflowFolderAssignments, chatFolders, chatFolderAssignments.

agentRuntimeRollout is ignored here. Use PATCH /api/settings/agent-rollout (Admin/Owner) with { surface, mode } (surface: agentNode | copilot | home; mode: legacy | shadow | v2 or null).

Workspace and members

MethodPathNotes
GET/api/v1/workspaces{ workspace } for the key's workspace; 404 if missing
GET/api/v1/workspace-members{ members[] }; workspace key required
POST/api/v1/workspace-members{ email, role }; workspace key and Admin/Owner; 201 { member }

Invite role must be admin, member, or viewer. Empty email: 400. Non-admin invite on v1: 403 "Admin or Owner workspace role is required to invite members."

tRPC workspaceShell.workspaceMembers.invite does not enforce Admin/Owner — only membership.

Session-only settings

MethodPathRole
GET/api/settings/repositoryMember
PATCH, DELETE/api/settings/repositoryAdmin/Owner
GET, PATCH/api/settings/agent-rolloutGET member; PATCH Admin/Owner

Repository PATCH: { owner, repo, defaultBranch?, pathPrefix?, credentialId?, policy? } → { repository, repositoryAccess }. DELETE → { deleted: true\|false }.

Browser connection invitations

The existing Centris-named invitation API also serves connections configured for other websites. Generated links open /integrations/browser/connect/{id}. Reissue older owner-login invitations to use the new guest flow.

POST /api/v1/integrations/centris/connect-requests accepts { "connectionId": "..." } and returns { requestId, connectUrl, expiresAt } with status 201. It requires a workspace API key with write authority and a new, disconnected connection owned by that key's creator. The private URL can be delivered by an external Telegram bot. Its recipient can redeem it once, within 15 minutes, without signing into Confluye. Redemption creates a separate 15-minute, HttpOnly session limited to this login screen. Save and allow access ends browser control and enables agent reading; workflow blocks still require their own owner-issued grants. During the human login, navigation may follow public HTTPS authentication and MFA domains. Private network destinations remain blocked. Saving verifies the configured account page in a new browser and retains only the configured domains' cookies and storage; agent sessions keep the site domain allowlist. The cookie can retrieve only the completion receipt until its original expiry, allowing a lost response or reload to recover confirmation. Cancellation blocks controls before cleanup and can be retried through the same page. Expiration is evaluated using database time. Treat the URL as a credential: send it only to the intended account holder. It cannot open an previously opened account or authorize the rest of Confluye. Create a new connection to request a replacement login after a session expires. A central bot key cannot choose arbitrary target users, and automatic Telegram identity linking is not included.

GET /api/v1/integrations/centris/connect-requests/{id} requires restricted-read authority for the same key owner/workspace. It returns pending, connected, expired, or cancelled, and includes connectionId only after redemption and successful session verification. Polling does not redeem the invitation. Completion remains connected while a workflow uses the account or the account needs reauthentication; revocation changes it to cancelled. Missing or inaccessible requests return 404; provider/storage failures return 503. Both successful responses disable caching.

This is an invitation API for the browser pilot, not an inbound Telegram webhook or a browser automation API. See workspace settings.

Next steps