How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Kardinal Management API

The Management API from Kardinal — 5 operation(s) for management.

Kardinal Management API is one of 8 APIs that Kardinal publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Management. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, and authentication docs.

This API exposes 5 operations across 5 paths, and defines 20 schemas. It is described by OpenAPI 3.2.0, at version 2.55.0.

Requests are made against a single base URL, /api/v2.

5 operations 5 paths 20 schemas 3 GET1 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.55.0
Base URL
https://app.kardinal.ai/api/v2
Authentication
HTTP Bearer, HTTP Bearer, HTTP Bearer, HTTP Bearer, HTTP Bearer
Resource Areas
1

Authentication & Security 5

Kardinal Management API declares 5 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (otp_token). It accepts HTTP bearer tokens (JWT) (gdpr_token). It accepts HTTP bearer tokens (JWT) (access_token). It accepts HTTP bearer tokens (JWT) (refresh_token). It accepts HTTP bearer tokens (JWT) (password_token). By default, every request must be authenticated.

Paths & Operations 5

Across 5 paths, the API surfaces 5 operations — 3 GET, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Management 5
POST
/login/refresh
Refresh the access token
postLoginRefresh body → 200400401403500
PUT
/agencies/{agencyId}/plans/{planId}/running
Stop or restart the optimization of a plan
putPlanRunning 3 params body → 200400401403404500
GET
/agencies/{agencyId}/plans/{planId}/state
Fetch the latest state of a plan
fetchLastPlanState 2 params → 200401403404500
GET
/agencies/{agencyId}/plans/{planId}/states
Fetch the latest states of a plan
fetchLastNPlanStates 3 params → 200401403500
GET
/agencies/{agencyId}/plans/{planId}/status
Retrieve a plan status
getPlanStatus 2 params → 200401403404500

Schemas 20

The contract defines 20 schemas that model the data the API accepts and returns. The most detailed are PlanStatus (5 properties), EnvelopedPlanStatus (4 properties), EnvelopedTimedPlanState (3 properties), Error (3 properties). Each schema is shown below with its type and property counts.

PlanStatus
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
5 properties
GDPRToken
string
A JSON Web Token with scope 'gdpr', to be used to approve a GDPR policy, valid for 1 hour.
AgencyId
The agency id.
ErrorProperties
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
PlanId
The plan id.
PlanState
string
The corresponding plan's state. - waiting: The plan was received and is awaiting processing. - processing: The plan is being processed. - preOptimizing: The pl…
AccessToken
string
A JSON Web Token with scope 'access', to be used to access protected data, valid for 1 hour.
EnvelopedTimedPlanStates
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
3 properties
EnvelopedErrors
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
1 property
RegexPrefixedIdValidation
string
An id beginning with a prefix and an underscore.
PlanVersion
integer
The plan version.
EnvelopedLoginRefreshOutput
object
An object containing the new access token.
2 properties
DateTime
string
A full calendar date time, expressed in the ISO8601 date format: YYYY-MM-DDThh:mm:ssZ.
EnvelopedPlanStatus
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
4 properties
PlanStatusVersion
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
2 properties
RegexIdValidation
string
At least one character among those allowed: unaccented alpha-numeric characters, "-", ".", "", "~", ":", "@", "!", "$", ",".
EnvelopedLoginGDPROutput
object
An object containing a 'gdpr' JSON Web Token, returned by a successful login of a user which needs to approve a GDPR policy.
2 properties
Error
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
3 properties 2 required
EnvelopedTimedPlanState
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
3 properties
TimedPlanState
object
[TOVALIDATE] Description pending review by a Kardinal engineer.
3 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

kardinal-management-api-openapi.yml Raw ↑

Other APIs Kardinal publishes across the network.

Kardinal Authenticate API
Kardinal Core API
Kardinal Order API
Kardinal Plan API
Kardinal Resource API
Kardinal Simple Plan API
Kardinal Solution API
Where this information came from

This is an independent, third-party profile of Kardinal Management API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.