Skip to content
Alvo is pre-v0.1: the image runs from its edge tag, and no NuGet package or release is published yet.Pre-v0.1: no release yet.Roadmap and status

Management API

Every route of the Management API, read from a running host's route table.

The Management API manages the project itself: the descriptor, its revisions, policy simulation, expression checks and, where the deployment has a membership store, the people who sign in. Every route below sits under /management, the default of AlvoManagementOptions.RoutePrefix (Alvo:Management:RoutePrefix). This page is read from the route table of a real host booted over the vehicle-registry example, and each summary is the XML documentation of the port member the route calls.

The management surface is deliberately not in the OpenAPI document: it is excluded from the published Data API contract, and a document of its own is a follow-on. That is a deviation from the docs-site design, which planned one OpenAPI-rendered page for both APIs.

Each route requires a management access level (admin, developer or viewer) granted by the descriptor’s access block. For coding agents explains the levels; the per-route level is not listed here.

MethodRouteMemberSummary
PUT/management/ai/connectionSetAiConnectionAsyncWrites the instance’s AI connection, replacing whatever was there.
GET/management/infoGetInfoAsyncDescribes this deployment: the build, the mode, the data provider and the startup mode.
GET/management/projectsListProjectsAsyncLists the projects this instance serves.
GET/management/projects/{project}/capabilitiesGetCapabilitiesAsyncWhat this build honours, warns about and refuses for this project.
POST/management/projects/{project}/cel/checkCheckExpressionAsyncAnswers what applying would say about one expression — by running the validator apply runs on the descriptor with the candidate spliced in, never a second opinion.
GET/management/projects/{project}/cel/functionsGetCelFunctionsAsyncEvery CEL function a descriptor may call on this instance — the built-ins and the host’s registrations — one entry per overload, with parameters, result, nullability and the profiles each compiles in.
GET/management/projects/{project}/descriptorGetDescriptorAsyncThe project’s current descriptor, exactly as it was applied, with the revision an apply must echo in If-Match. This is the export — no re-serialisation happens.
PUT/management/projects/{project}/descriptorApplyDescriptorAsyncApplies a descriptor — the one write path to a project’s configuration.
POST/management/projects/{project}/policy/simulateSimulatePolicyAsyncAnswers what a named caller may do to an entity — by calling the same IPolicyEngine production calls, never a copy of it.
GET/management/projects/{project}/revisionsListRevisionsAsyncThe project’s append-only configuration history, oldest revision first.
GET/management/projects/{project}/revisions/{revision:int}GetRevisionAsyncOne historical revision — the export of a past state.
POST/management/projects/{project}/revisions/{revision:int}/rollbackRollbackAsyncRestores a past revision by appending the reverse migration as a new revision. History is never rewritten.
GET/management/projects/{project}/schemaGetSchemaAsyncThe resolved schema — what the Data API actually serves for this project.
MethodRouteMemberSummary
GET/management/projects/{project}/usersListAsyncOne page of the people on this project.
POST/management/projects/{project}/usersCreateAsyncCreates a person who can sign in.
POST/management/projects/{project}/users/{user:guid}/credential-resetIssueCredentialTokenAsyncMints a single-use token with which a person sets their own password.
PUT/management/projects/{project}/users/{user:guid}/disabledSetDisabledAsyncBars a person from signing in, or lets them back.
DELETE/management/projects/{project}/users/{user:guid}/lockoutClearLockoutAsyncEnds a temporary lockout from failed sign-ins now, and forgets the failed attempts.
PUT/management/projects/{project}/users/{user:guid}/rolesSetRolesAsyncReplaces a person’s role membership.
PUT/management/projects/{project}/users/{user:guid}/tenantSetTenantAsyncGrants, changes or removes the one tenant a person acts in.