Management API
Every route of the Management API, read from a running host's route table.
The Management API manages the project itself: the descriptor, its revisions, policy simulation, expression checks and, where the deployment has a membership store, the people who sign in. Every route below sits under /management, the default of AlvoManagementOptions.RoutePrefix (Alvo:Management:RoutePrefix). This page is read from the route table of a real host booted over the vehicle-registry example, and each summary is the XML documentation of the port member the route calls.
The management surface is deliberately not in the OpenAPI document: it is excluded from the published Data API contract, and a document of its own is a follow-on. That is a deviation from the docs-site design, which planned one OpenAPI-rendered page for both APIs.
Each route requires a management access level (admin, developer or viewer) granted by the descriptor’s access block. For coding agents explains the levels; the per-route level is not listed here.
IAlvoManagement
Section titled “IAlvoManagement”| Method | Route | Member | Summary |
|---|---|---|---|
| PUT | /management/ai/connection | SetAiConnectionAsync | Writes the instance’s AI connection, replacing whatever was there. |
| GET | /management/info | GetInfoAsync | Describes this deployment: the build, the mode, the data provider and the startup mode. |
| GET | /management/projects | ListProjectsAsync | Lists the projects this instance serves. |
| GET | /management/projects/{project}/capabilities | GetCapabilitiesAsync | What this build honours, warns about and refuses for this project. |
| POST | /management/projects/{project}/cel/check | CheckExpressionAsync | Answers what applying would say about one expression — by running the validator apply runs on the descriptor with the candidate spliced in, never a second opinion. |
| GET | /management/projects/{project}/cel/functions | GetCelFunctionsAsync | Every CEL function a descriptor may call on this instance — the built-ins and the host’s registrations — one entry per overload, with parameters, result, nullability and the profiles each compiles in. |
| GET | /management/projects/{project}/descriptor | GetDescriptorAsync | The project’s current descriptor, exactly as it was applied, with the revision an apply must echo in If-Match. This is the export — no re-serialisation happens. |
| PUT | /management/projects/{project}/descriptor | ApplyDescriptorAsync | Applies a descriptor — the one write path to a project’s configuration. |
| POST | /management/projects/{project}/policy/simulate | SimulatePolicyAsync | Answers what a named caller may do to an entity — by calling the same IPolicyEngine production calls, never a copy of it. |
| GET | /management/projects/{project}/revisions | ListRevisionsAsync | The project’s append-only configuration history, oldest revision first. |
| GET | /management/projects/{project}/revisions/{revision:int} | GetRevisionAsync | One historical revision — the export of a past state. |
| POST | /management/projects/{project}/revisions/{revision:int}/rollback | RollbackAsync | Restores a past revision by appending the reverse migration as a new revision. History is never rewritten. |
| GET | /management/projects/{project}/schema | GetSchemaAsync | The resolved schema — what the Data API actually serves for this project. |
IAlvoUserAdministration
Section titled “IAlvoUserAdministration”| Method | Route | Member | Summary |
|---|---|---|---|
| GET | /management/projects/{project}/users | ListAsync | One page of the people on this project. |
| POST | /management/projects/{project}/users | CreateAsync | Creates a person who can sign in. |
| POST | /management/projects/{project}/users/{user:guid}/credential-reset | IssueCredentialTokenAsync | Mints a single-use token with which a person sets their own password. |
| PUT | /management/projects/{project}/users/{user:guid}/disabled | SetDisabledAsync | Bars a person from signing in, or lets them back. |
| DELETE | /management/projects/{project}/users/{user:guid}/lockout | ClearLockoutAsync | Ends a temporary lockout from failed sign-ins now, and forgets the failed attempts. |
| PUT | /management/projects/{project}/users/{user:guid}/roles | SetRolesAsync | Replaces a person’s role membership. |
| PUT | /management/projects/{project}/users/{user:guid}/tenant | SetTenantAsync | Grants, changes or removes the one tenant a person acts in. |