Information
- OpenAPI version:
3.1.0
The ResponseHub JSON API.
Authentication. Every endpoint except POST /api/v1/auth and
GET /api/docs requires a Bearer token:
Authorization: Bearer rh_<secret>
Tokens are created in Settings → API tokens. The secret is shown once at creation and stored only as a SHA-256 digest — it cannot be recovered, only rolled. Browser session cookies are not accepted.
Account scope. A token belongs to exactly one account and can only ever read or write that account’s data. There is no cross-account addressing and no way to create an account through the API.
Scopes. Binary: every token may read (GET); a token additionally needs
write for any other verb. A token can never exceed its user’s role — a
viewer’s token is read-only regardless of scope, and admin-only endpoints
still require the admin role.
Identifiers. Records are addressed by opaque prefixed IDs
(qu_…, kbi_…, cust_…), never raw database IDs. A record outside your
account returns 404, not 403.
Pagination. List endpoints return 20 per page and a pagination block.
Pass ?page=N.
Rate limits. Per token: 600 reads/min, 120 writes/min; asking a question
10/min; creating or answering questionnaires and RFPs 3/min each. Exceeding
a limit returns 429 with X-RateLimit-* and Retry-After headers.
AI calls. Asking a question is asynchronous (202 Accepted, then poll).
The per-item AI actions (generate_answer, rewrite_answer,
ai_enhance_answer) are synchronous — they block until the model
responds and return 200 with the updated record.
Errors. Every error uses the same envelope, on every endpoint —
including POST /api/v1/auth and rate-limit (429) responses:
{"error": {"code": "not_found", "message": "…", "details": ["…"]}}
An API token secret, e.g. rh_1f3c…
Security scheme type: http