Base URL

All requests go through the API gateway, which routes to the right service and enforces authentication, CORS and rate limits.

https://api.faultmesh.com

Authentication

FaultMesh accepts two credential types. Interactive and service clients use a JWT bearer token; agents and CI use a long-lived API key.

http
# User / service token (JWT)
Authorization: Bearer <token>

# Machine-to-machine (agents, CI)
X-Api-Key: <key>

Tokens carry your organisation, role and licensed feature claims, so the same call is automatically scoped and gated to your plan.

Authentication

Obtain and manage tokens and API keys.

POST/auth/loginIssue a token pair
POST/auth/refreshRefresh an access token
POST/auth/revokeRevoke a token
GET/auth/meCurrent user & claims
POST/auth/api-keysCreate an API key
DEL/auth/api-keys/{id}Revoke an API key

Experiments

Create and drive a single controlled fault through its lifecycle.

POST/api/experimentsCreate experiment
GET/api/experimentsList (paginated)
GET/api/experiments/{id}Get experiment
POST/api/experiments/{id}/approveApprove
POST/api/experiments/{id}/executeExecute
POST/api/experiments/{id}/abortAbort
GET/api/experiments/{id}/timelineTimeline & events

Game Days

Orchestrate multi-step exercises with inter-step validation.

POST/api/gamedaysCreate game day
GET/api/gamedaysList game days
GET/api/gamedays/{id}Get details
POST/api/gamedays/{id}/startStart orchestration
GET/api/gamedays/{id}/progressStep progress
GET/api/gamedays/{id}/logsLog stream (cursor)

Incidents

Record incidents and turn them into reproducible experiments.

POST/api/incidentsReport incident
GET/api/incidentsList incidents
GET/api/incidents/{id}Get incident
POST/api/incidents/{id}/generate-experimentGenerate experiment

Remediation

Manage auto-healing rules and inspect what ran.

GET/api/remediation/rulesList rules
POST/api/remediation/rulesCreate rule
PUT/api/remediation/rules/{id}Update / toggle rule
GET/api/remediation/auditExecution audit log

Scoring & SLO

Read resilience scores, error budgets and SLO definitions.

GET/api/scoring/{service}Resilience score
GET/api/scoring/{service}/error-budgetError budget & burn rate
GET/api/scoring/{service}/forecastBudget forecast (ML)
GET/api/scoring/sloList SLO definitions
POST/api/scoring/sloCreate SLO definition

Topology

Read the live service graph and dependencies.

GET/api/topologyService graph
GET/api/topology/{service}/dependenciesDependencies & blast radius

Licensing

Generate and validate licenses and read usage (admin scope).

POST/license/generateGenerate license
POST/license/validateValidate license
GET/license/usageUsage & metering

Conventions

Rate limiting

The gateway applies a default limit of 100 requests per minute, tightened to 20 per minute on authentication routes. Exceeding a limit returns HTTP 429.

Pagination

List endpoints are paginated and return a page of items alongside total count and paging metadata. Log streams use a monotonic cursor (afterId) for reliable polling.

Errors

Responses use standard HTTP status codes. Error bodies follow a consistent shape with a machine-readable code and a human-readable message localised to your Accept-Language.

json
{
  "code": "experiment.blast_radius_exceeded",
  "message": "Blast radius above the safety limit."
}