API reference
Bolt generation and streaming, plus the Rampart REST surface, its methods, parameters, and examples.
Last updated · September 2026
On this page
Every endpoint below requires a valid session cookie and returns JSON. Failures use the { error } shape documented in Errors.
Bolt investigations
/api/generateSubmit an investigation. The request is validated, rate-limited, checked against balance, and charged only after a completed stream.
| Parameter | Type | Required | Description |
|---|---|---|---|
| prompt | string | required | Trimmed text between 3 and 12,000 characters. |
| mode | "offensive" | "defensive" | required | Selects the system posture and asset context. |
curl -X POST https://your-domain.com/api/generate \
-H 'Content-Type: application/json' \
-H 'Cookie: bolt_session=<session-token>' \
-d '{"mode": "defensive", "prompt": "Triage the supplied alert. Separate facts from inference."}'event: status
data: {"state":"warming","inputTokens":42,"balance":900}
event: token
data: {"text":"Assessment: "}
event: done
data: {"outputTokens":180,"tokenCost":222,"remainingTokens":678}
event: error
data: {"message":"The analysis failed."}The response uses text/event-stream. Read events until the stream closes. Do not parse a partial answer as a completed finding. Wait for done, persist the final text with the case reference, and handle interruption as an incomplete investigation.
Rampart
/api/rampart/organizationsList organizations you belong to.
curl https://your-domain.com/api/rampart/organizations \ -H 'Cookie: bolt_session=<session-token>'
/api/rampart/organizationsCreate an organization (you become Owner).
| Parameter | Type | Required | Description |
|---|---|---|---|
| name | string | required | Display name for the organization. |
curl -X POST https://your-domain.com/api/rampart/organizations \
-H 'Content-Type: application/json' \
-H 'Cookie: bolt_session=<session-token>' \
-d '{"name": "Acme Corp"}'/api/rampart/repositories?org=<slug>List synced repositories with scores and counts.
| Parameter | Type | Required | Description |
|---|---|---|---|
| org | string | required | Organization slug. |
/api/rampart/repositoriesImport repositories by full name; runs the first scan.
| Parameter | Type | Required | Description |
|---|---|---|---|
| org | string | required | Organization slug. |
| fullNames | string[] | required | Repository full names, e.g. acme/api. |
/api/rampart/scansStart a scan on an imported repository.
| Parameter | Type | Required | Description |
|---|---|---|---|
| repositoryId | string | required | Rampart repository ID. |
| branch | string | optional | Branch to scan; defaults to the default branch. |
| trigger | string | optional | Trigger label recorded on the scan. |
/api/rampart/findings?org=<slug>List findings with severity, status, and category filters.
| Parameter | Type | Required | Description |
|---|---|---|---|
| org | string | required | Organization slug. |
| severity | string | optional | critical | high | medium | low. |
| status | string | optional | open | in_progress | ignored | resolved | accepted_risk. |
/api/rampart/findings/:idTriage a finding: status, assignee, or accept-risk note.
| Parameter | Type | Required | Description |
|---|---|---|---|
| status | string | optional | Target lifecycle state. |
| note | string | optional | Triage or accept-risk note. |
/api/rampart/fixesPreview or open a remediation pull request for a finding.
| Parameter | Type | Required | Description |
|---|---|---|---|
| findingId | string | required | Finding to remediate. |
| dryRun | boolean | optional | Preview the diff without opening a PR. |
/api/rampart/search?org=<slug>&q=<query>Global search across repositories, findings, packages, and people.
| Parameter | Type | Required | Description |
|---|---|---|---|
| org | string | required | Organization slug. |
| q | string | required | At least 2 characters. |

