Durable background jobs, apply targets, request-changes (send a candidate_ready job back for another pass), and quality-reviews (a human go/no-go on the candidate, distinct from the machine eval gate)
/rework-tasks and /projects/{id}/rework-tasks
Owned, recoverable work auto-created when a refinement job is terminally rejected: list/get/claim/resolve/reassign; project routes enforce workspace visibility and role policy
/releases
Candidates, evaluation, waivers, signoff, reporting, and reconcile operations
/rollback
Shared rollback helpers where an asset family exposes them
/observability/*, /metrics, /events/stream
Traces, experiments, metrics, and SSE
/audit-log
Read-only audit explorer and export
/gateway/* and /llm-pricing
Gateway discovery, guardrails, usage, and pricing overrides
The SDK guide and SDK API reference wrap the same route families above with typed models, error translation, automatic CSRF handling, and polling helpers. The SDK docs should explain the Python abstraction; this page is the raw route inventory.
Project responses include the caller's effective access_role and a sorted permissions list. The membership endpoints return members objects with the member id, user id, role, active status, and audit timestamps:
Route
Purpose
Required project role
GET /projects/{project_id}/members
List active members
any visible member
POST /projects/{project_id}/members
Add or reactivate a member
owner
PATCH /projects/{project_id}/members/{user_id}
Change role or status
owner
DELETE /projects/{project_id}/members/{user_id}
Deactivate a member
owner
Project roles are owner, editor, reviewer, and viewer. These roles are project-level decisions; the caller's bearer-token scope remains a separate global ceiling.