Request Access

API Reference

Base URL: https://api.strattumx.com/v1. All requests require a bearer token in the Authorization header. Responses are JSON.

Context Query

The primary endpoint. Submits a context query to a connector with policy evaluation. Returns filtered data and an audit event ID.

POST /context/query

Request body

JSON
{
  "connector": "prod-postgres",        // required: connector ID
  "table": "orders",                  // required: target table or object
  "filters": {                         // optional: field equality filters
    "status": "pending"
  },
  "fields": ["order_id", "amount", "customer_id"],  // optional: field subset
  "limit": 100,                       // optional: max rows (default 100, max 1000)
  "offset": 0                          // optional: pagination offset
}

Response

JSON: 200 OK
{
  "audit_event_id": "evt_9c2a14b",
  "connector": "prod-postgres",
  "policy_rule": "reporting-agent-v1:allow:0",
  "resolution": "ALLOWED",
  "rows": [...],
  "row_count": 43,
  "has_more": false
}

Connectors

GET /connectors

List all registered connectors. Returns connector IDs, types, and connection status.

POST /connectors/:id/test

Test connectivity for a registered connector. Returns a status object and latency measurement. Credentials are retrieved from the vault and are not returned in the response.

JSON: 200 OK (test response)
{
  "connector_id": "prod-postgres",
  "status": "OK",
  "latency_ms": 38,
  "schema_version": "2026-05-15T09:12:00Z"
}

Policies

POST /policies

Deploy a new policy or update a policy to a new version. The request body is the full policy document in YAML or JSON. The previous version is retained in history.

JSON: 201 Created
{
  "policy_id": "reporting-agent-v1",
  "version": 2,
  "status": "ACTIVE",
  "deployed_at": "2026-07-01T11:24:17Z"
}

Audit Log

GET /audit/events

Query the audit event log. Supports filtering by agent, connector, resolution, and date range. Returns events in reverse-chronological order by default.

Query parameters

Parameter Type Description
agent string Filter to events from a specific agent key ID
connector string Filter to events for a specific connector ID
resolution string ALLOWED, DENIED, or FILTERED
from ISO 8601 Start of time window (inclusive)
to ISO 8601 End of time window (exclusive)
limit integer Max events returned (default 100, max 1000)

Error responses

Status Code Description
400 INVALID_REQUEST Request body is missing a required field or fails schema validation
401 UNAUTHORIZED Missing or invalid bearer token
403 POLICY_DENIED Policy evaluation resolved to DENIED for this agent and scope
404 CONNECTOR_NOT_FOUND Connector ID does not exist or is not accessible to this account
502 CONNECTOR_ERROR Connector reached the data source but the source returned an error. Includes source error details in connector_error field.
504 CONNECTOR_TIMEOUT Data source did not respond within the connector timeout window (30s default)