API Overview
After Action supports two programmatic interfaces. Both are served from https://afteraction.dev over HTTPS.
| Interface | Endpoint | Use it for | Auth |
|---|---|---|---|
| GraphQL API | POST /api/graphql | Reading and writing exercises, gaps, reports, scores and deliverables | Signed-in session, or an API key with the graphql scope |
| MCP server | POST /api/mcp | Letting an AI agent read exercises, gaps, scores and action items | API key with the mcp scope |
What about REST?
The web app talks to a set of internal REST routes under /api. They exist to serve the portals, change with them, and are not a supported public contract — do not build integrations against them. Use GraphQL or MCP instead.
Scoping
Every request is scoped to one organization: the signed-in user's, or the organization that created the API key. Role-restricted fields and tools return an authorization error rather than another organization's data.
Limits and errors
Rate limits and error formats differ by interface and are documented on each page:
Versioning
There is no URL versioning. Changes that affect callers are announced in the changelog. Current platform health is on the status page.