Public endpoints
Routes that need no API key, such as the connector catalog, assets, trigger ingress and the hosted Connect page.
These routes need no API key. The public catalog lists only built-in connectors, not a project's custom tools or connections. Hosted Connect routes require a connect-link token and expose the offered project connectors and that user's accounts within the link's scope, never stored credentials.
| Route | What it does |
|---|---|
GET /health | Health check. |
GET /api/catalog | One page of built-in connectors. |
GET /api/catalog/:connectorId | One built-in connector with tools and trigger events. |
GET /assets/* | Connector logos and project uploads. |
POST /api/triggers/:token | Where providers deliver trigger events. |
/api/connect/:token/* | Backend of the hosted Connect page. |
/api/dashboard/* routes serve the dashboard. They need a signed-in dashboard session and do not
accept an API key. /api/auth/* and /api/waitlist back the website.
Health
GET /health
curl "https://api.dexby.ai/health"{ "data": { "status": "ok" } }Catalog
GET /api/catalog
One page of built-in connectors, most popular first, then by id. Your project's own MCP servers and imported APIs are never listed. Responses are cacheable for 5 minutes.
| Query | Type | Default | What it does |
|---|---|---|---|
query | string | none | Search text, 1 to 200 characters. |
category | string | none | One category, such as communication or developer-tools. |
popular | boolean | none | true: only the most popular, in rank order. |
facets | boolean | false | Adds facets with counts per category and of popular connectors. |
limit | integer | 100 | 1 to 500. |
cursor | string | none | The previous page's nextCursor. |
curl "https://api.dexby.ai/api/catalog?category=developer-tools&limit=1"{
"data": [
{
"id": "github",
"name": "GitHub",
"description": "Repositories, issues, and pull requests.",
"category": "developer-tools",
"popular": true,
"verification": "unverified",
"actions": 41,
"logo": "https://assets.dexby.ai/logos/github"
}
],
"nextCursor": "00003github"
}actions is the connector's tool count. verification is unverified when not set.
GET /api/catalog/:connectorId
One built-in connector. An unknown id answers 404 NOT_FOUND. Cacheable for 5 minutes.
| Path | Where to get it |
|---|---|
:connectorId | Connector id, such as slack. From GET /api/catalog or the connectors page. |
| Field | What it is |
|---|---|
id, name, description, category, logo | As in the list. |
popular | Whether it is among the most popular. |
proxy | Whether POST /v1/tools/proxy accepts it. |
verification | Verification level, unverified when not set. |
authMethods[] | { name, type, description? } for each way to connect. |
tools[] | { id, description, effect, dataClassification }. Unclassified tools are pii. |
triggers[] | { id, name, description }. id is the event for POST /v1/triggers. |
curl "https://api.dexby.ai/api/catalog/slack"Assets
GET /assets/*
Serves /assets/<key>. A deployment with an assets host, such as assets.dexby.ai, serves the
same keys at its root. Use the logo URL from the API rather than building one.
| Key | Content | Cache |
|---|---|---|
logos/<connector-id> | A built-in connector's logo | 1 day |
projects/... | A project upload, content-addressed | 1 year, immutable |
Files are served inert, with a sandboxing Content-Security-Policy and nosniff. A missing file
answers 404.
Trigger ingress
POST /api/triggers/:token
Receives provider events. You do not call it: Dexby registers it with the provider, or you paste
the trigger's url (from POST /v1/triggers) into the provider's settings. The token names the
trigger; the provider's signature or secret proves the sender. Responses have no JSON body.
| Status | When |
|---|---|
200 | Verified. Each event goes to your webhooks as trigger.fired. |
200 with text | A handshake answer, such as Slack's URL verification challenge. |
400, 401, 404 | Verification failed, or no trigger has this token. |
413 | Body over 1,000,000 bytes. |
429 | Over 600 deliveries to this trigger in one minute. |
503 | The trigger's secret could not be read. The provider retries later. |
Hosted Connect page
The page at a connect link's url calls these routes. :token is the token in that URL, from
POST /v1/connect-links. It is the only credential and names the project and user. CORS allows
only Dexby's web app.
| Route | What it does |
|---|---|
GET /api/connect/:token | Link status (active, used, expired), branding, offered connectors, and the user's accounts. |
POST /api/connect/:token/authorize | Starts OAuth. Body: authConfigId, and connectionId or name. Answers { url }. |
POST /api/connect/:token/accounts | Stores a key or field credential. Body: authConfigId, fields, and connectionId or name. Answers 201, or 200 on reconnect. |
GET /api/connect/:token/connections | The user's connections, when self-management is on in Configure → Connect UI. |
PATCH /api/connect/:token/connections/:id | Renames a connection. Body: name. |
DELETE /api/connect/:token/connections/:id | Removes a connection. |
| Status | Code | When |
|---|---|---|
| 400 | VALIDATION_ERROR | Invalid body, or the wrong route for the connector's auth method. |
| 403 | FORBIDDEN | The link does not offer this auth config, or self-management is off. |
| 404 | NOT_FOUND | Invalid token, or the connector or connection is not available. |
| 409 | NAME_TAKEN | The user already has an account with that name. |
| 410 | LINK_USED | The link already connected an account. |
| 410 | LINK_EXPIRED | The link has expired. |
See connect accounts.