> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Resource API

> Automate Resource inventory, gateways, credentials, policies, and activity.

The Resource API uses the same organization-scoped authentication, pagination,
errors, idempotency, and audit logging as the rest of the Forge REST API. Use
the generated **REST API** reference in this documentation for exact request
and response schemas.

## Common workflow

1. Create a Resource gateway.
2. Create a Resource and assign the gateway.
3. Create credential assignments for the Resource.
4. Test the connection from the assigned gateway.
5. Create and enable a Resource Policy.
6. Query Resource Activity and approval responses to verify the result.

## Endpoint families

All paths are below
`/api/headless/v1/organizations/{organizationId}`.

| Purpose | Paths |
| - | - |
| Gateways | `/resource-gateways`, `/resource-gateways/{gatewayId}` |
| Resources | `/resources`, `/resources/{resourceId}` |
| Credentials | `/resources/{resourceId}/credentials`, `/resources/{resourceId}/credentials/{credentialId}` |
| Client trust | `/resources/trust-certificate` |
| Direct access | `/resources/{resourceId}/direct-access` |
| Resource Policies | `/resource-policies`, `/resource-policies/{familyPolicyId}` and revision paths |

Use a service account with only the permissions required by the operation.
Ordinary management credentials do not authorize direct Resource traffic; a
non-interactive direct client also needs `resources:connect` and exchanges its
Forge credential for a short-lived Resource access token.

Credential secrets are write-only. Create or rotate them in a write request,
but do not expect reads, list responses, audit events, or imports to return the
value. Prefer [`forge_resource_credential`](/developer/terraform/forge-resource-credential)
with an ephemeral variable for repeatable secret management.

Policy writes create a new revision rather than changing historical decisions.
Use the revision and validation fields returned by the generated API contract
when updating a policy so concurrent or stale changes fail explicitly.

The public API reference currently exposes Resource, gateway, credential,
direct-access, trust-certificate, and Resource Policy management. Use the
Console for connection tests and discovery review; use **Live → Resources** for
the current Resource Activity workspace.

See [REST API](/developer/api) for authentication and operational conventions,
and [Terraform Resources](/developer/terraform/forge-resource) for declarative
management.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.