One REST API for the whole loop
Drive experiments, game days, remediation and scoring programmatically. Every endpoint is available through a single gateway.
Base URL
All requests go through the API gateway, which routes to the right service and enforces authentication, CORS and rate limits.
https://api.faultmesh.com
Authentication
FaultMesh accepts two credential types. Interactive and service clients use a JWT bearer token; agents and CI use a long-lived API key.
# User / service token (JWT) Authorization: Bearer <token> # Machine-to-machine (agents, CI) X-Api-Key: <key>
Tokens carry your organisation, role and licensed feature claims, so the same call is automatically scoped and gated to your plan.
Authentication
Obtain and manage tokens and API keys.
Experiments
Create and drive a single controlled fault through its lifecycle.
Game Days
Orchestrate multi-step exercises with inter-step validation.
Incidents
Record incidents and turn them into reproducible experiments.
Remediation
Manage auto-healing rules and inspect what ran.
Scoring & SLO
Read resilience scores, error budgets and SLO definitions.
Topology
Read the live service graph and dependencies.
Licensing
Generate and validate licenses and read usage (admin scope).
Conventions
Rate limiting
The gateway applies a default limit of 100 requests per minute, tightened to 20 per minute on authentication routes. Exceeding a limit returns HTTP 429.
Pagination
List endpoints are paginated and return a page of items alongside total count and paging metadata. Log streams use a monotonic cursor (afterId) for reliable polling.
Errors
Responses use standard HTTP status codes. Error bodies follow a consistent shape with a machine-readable code and a human-readable message localised to your Accept-Language.
{
"code": "experiment.blast_radius_exceeded",
"message": "Blast radius above the safety limit."
}