Developers
One catalogue, every client
Everything the dashboard does is 43 operations in one catalogue, served to the REST API, the hosted MCP server, the CLI and any agent that reads openapi.json.
Entry points
Pick the surface that fits the program
In sixty seconds
From a key to the first answer
An admin creates a key under Settings, API keys. Put it in SKILLHOOK_CLOUD_API_KEY; the examples read it from there.
Every operation is POST /api/v1/tools/{name} with a JSON body. GET /api/v1/tools lists them with the scope each needs and whether this key has it.
Authentication
One key, one scope
Send the key as Authorization: Bearer shc_…, never in a URL. Each scope acts as a role of the organisation; what the role may not do, the key may not do either.
| Scope | Acts as | Allows |
|---|---|---|
| fleet:read | viewer | The overview, stats, alerts, machines, skills, jobs, deliveries, hosted URLs (not the URLs themselves), commands, settings, members, problem reports. |
| fleet:run | member | Also skill sources, job files, live output and the hosted URLs; run and test skills, answer agents, replay, cancel, dismiss alerts. |
| fleet:admin | admin | Also the audit log and notification channels; save and delete skills, hosted URLs on and off, rename and disconnect machines, settings, configuration changes, restarts, updates, secrets. |
Errors
Problem details, every time
Errors are RFC 9457 problem details (application/problem+json). type links to the entry for the code in the reference; request_id is what to quote to support.
A failure on our side that a retry may fix, such as the database out of reach, is 503 unavailable with Retry-After, never a 401 or 404. A body that does not validate is 400 invalid_request with what was wrong; an unknown tool is 404 unknown_tool; a scope the key lacks is 403 forbidden.
Rate limits
Enough for a busy agent
Autonomous agents
Four rules the catalogue is built around
They are what agents.md and the hosted server's instructions say; a well-behaved agent needs nothing else.
Read the reference, or let the plugin read it for you
Every operation, every route, every error code; or one login and the agent has them all.