Common workflow
- Create a Resource gateway.
- Create a Resource and assign the gateway.
- Create credential assignments for the Resource.
- Test the connection from the assigned gateway.
- Create and enable a Resource Policy.
- Query Resource Activity and approval responses to verify the result.
Endpoint families
All paths are below/api/headless/v1/organizations/{organizationId}.
Use a service account with only the permissions required by the operation.
Ordinary management credentials do not authorize direct Resource traffic; a
non-interactive direct client also needs
resources:connect and exchanges its
Forge credential for a short-lived Resource access token.
Credential secrets are write-only. Create or rotate them in a write request,
but do not expect reads, list responses, audit events, or imports to return the
value. Prefer forge_resource_credential
with an ephemeral variable for repeatable secret management.
Policy writes create a new revision rather than changing historical decisions.
Use the revision and validation fields returned by the generated API contract
when updating a policy so concurrent or stale changes fail explicitly.
The public API reference currently exposes Resource, gateway, credential,
direct-access, trust-certificate, and Resource Policy management. Use the
Console for connection tests and discovery review; use Live → Resources for
the current Resource Activity workspace.
See REST API for authentication and operational conventions,
and Terraform Resources for declarative
management.