API Overview

After Action supports two programmatic interfaces. Both are served from https://afteraction.dev over HTTPS.

| Interface | Endpoint | Use it for | Auth | |---|---|---|---| | GraphQL API | POST /api/graphql | Reading and writing exercises, gaps, reports, scores and deliverables | Signed-in session, or an API key with the graphql scope | | MCP server | POST /api/mcp | Letting an AI agent read exercises, gaps, scores and action items | API key with the mcp scope |

What about REST?

The web app talks to a set of internal REST routes under /api. They exist to serve the portals, change with them, and are not a supported public contract — do not build integrations against them. Use GraphQL or MCP instead.

Scoping

Every request is scoped to one organization: the signed-in user's, or the organization that created the API key. Role-restricted fields and tools return an authorization error rather than another organization's data.

Limits and errors

Rate limits and error formats differ by interface and are documented on each page:

Versioning

There is no URL versioning. Changes that affect callers are announced in the changelog. Current platform health is on the status page.