BeeraSafe

API reference

Bolt generation and streaming, plus the Rampart REST surface, its methods, parameters, and examples.

Last updated · September 2026

On this page

Every endpoint below requires a valid session cookie and returns JSON. Failures use the { error } shape documented in Errors.

Bolt investigations

POST/api/generate

Submit an investigation. The request is validated, rate-limited, checked against balance, and charged only after a completed stream.

ParameterTypeRequiredDescription
promptstringrequiredTrimmed text between 3 and 12,000 characters.
mode"offensive" | "defensive"requiredSelects the system posture and asset context.
bash
curl -X POST https://your-domain.com/api/generate \
  -H 'Content-Type: application/json' \
  -H 'Cookie: bolt_session=<session-token>' \
  -d '{"mode": "defensive", "prompt": "Triage the supplied alert. Separate facts from inference."}'
Response stream
text
event: status
data: {"state":"warming","inputTokens":42,"balance":900}

event: token
data: {"text":"Assessment: "}

event: done
data: {"outputTokens":180,"tokenCost":222,"remainingTokens":678}

event: error
data: {"message":"The analysis failed."}

The response uses text/event-stream. Read events until the stream closes. Do not parse a partial answer as a completed finding. Wait for done, persist the final text with the case reference, and handle interruption as an incomplete investigation.

Rampart

GET/api/rampart/organizations

List organizations you belong to.

bash
curl https://your-domain.com/api/rampart/organizations \
  -H 'Cookie: bolt_session=<session-token>'
POST/api/rampart/organizations

Create an organization (you become Owner).

ParameterTypeRequiredDescription
namestringrequiredDisplay name for the organization.
bash
curl -X POST https://your-domain.com/api/rampart/organizations \
  -H 'Content-Type: application/json' \
  -H 'Cookie: bolt_session=<session-token>' \
  -d '{"name": "Acme Corp"}'
GET/api/rampart/repositories?org=<slug>

List synced repositories with scores and counts.

ParameterTypeRequiredDescription
orgstringrequiredOrganization slug.
POST/api/rampart/repositories

Import repositories by full name; runs the first scan.

ParameterTypeRequiredDescription
orgstringrequiredOrganization slug.
fullNamesstring[]requiredRepository full names, e.g. acme/api.
POST/api/rampart/scans

Start a scan on an imported repository.

ParameterTypeRequiredDescription
repositoryIdstringrequiredRampart repository ID.
branchstringoptionalBranch to scan; defaults to the default branch.
triggerstringoptionalTrigger label recorded on the scan.
GET/api/rampart/findings?org=<slug>

List findings with severity, status, and category filters.

ParameterTypeRequiredDescription
orgstringrequiredOrganization slug.
severitystringoptionalcritical | high | medium | low.
statusstringoptionalopen | in_progress | ignored | resolved | accepted_risk.
PATCH/api/rampart/findings/:id

Triage a finding: status, assignee, or accept-risk note.

ParameterTypeRequiredDescription
statusstringoptionalTarget lifecycle state.
notestringoptionalTriage or accept-risk note.
POST/api/rampart/fixes

Preview or open a remediation pull request for a finding.

ParameterTypeRequiredDescription
findingIdstringrequiredFinding to remediate.
dryRunbooleanoptionalPreview the diff without opening a PR.
GET/api/rampart/search?org=<slug>&q=<query>

Global search across repositories, findings, packages, and people.

ParameterTypeRequiredDescription
orgstringrequiredOrganization slug.
qstringrequiredAt least 2 characters.
Was this page helpful?