FlowRelay FlowRelay Docs Shopify Flow
All docs pages

START

USE CASES

SET UP

OPERATE

RECOVER

AGENT ACCESS

REFERENCE

Markdown

Agent Operations API Reference

Plain Markdown for agents, CLIs, MCP clients, and readers who want a copyable text version.

# Agent Operations API Reference

Canonical: https://docs.flowrelay.app/reference/api/
Markdown: https://docs.flowrelay.app/reference/api.md

The Agent Operations API is the canonical machine-access contract for FlowRelay. The API, CLI, and MCP are access surfaces over this one contract; they do not grant separate authority. Use it for scoped reads and action previews.

## Start with the manifest
Use the manifest before authenticated calls, and reread it before reusing cached capability URLs or operation names. It identifies the live edition (Shopify Flow), capability URLs, safety boundaries, the OpenAPI location, the docs index, the CLI reference, the MCP reference, and current public docs pointers.

- Route: GET /agent/v1/manifest; Use it for: Edition identity, capability metadata, docs URLs, and safety boundaries.
- Route: GET /agent/v1/plan-usage; Use it for: Exact usage meters, remaining capacity, enforcement state, and retry guidance before loops or high-volume work.
- Route: https://docs.flowrelay.app/llms.txt; Use it for: Canonical human and Markdown docs discovery.
- Route: https://docs.flowrelay.app/reference/openapi/agent-operations.openapi.json; Use it for: Exact request and response contract discovery.
- Route: https://docs.flowrelay.app/setup/trigger-variants-and-event-mapping/; Use it for: Product meaning for triggerVariant, resourceIdPath, relatedResourceIdPath, and mapping fields.
- Route: https://docs.flowrelay.app/agent-access/agent-mission-playbooks/; Use it for: Translate an operator mission into context reads, allowed actions, and escalation boundaries.
- Route: https://docs.flowrelay.app/agent-access/setup-with-an-agent/; Use it for: Guide a new endpoint setup through inventory, one endpoint, one synthetic handoff proof, plan fit, and monitoring cadence.
- Route: https://docs.flowrelay.app/agent-access/endpoint-swap-plan/; Use it for: Guide an existing sender or receiver lane migration through inventory, one safe pilot, operator approval, rollback, and cutover planning.
- Route: https://docs.flowrelay.app/agent-access/support-and-expansion-requests/; Use it for: Choose the right lane for support issues, future-edition expansion demand, and missing FlowRelay feature requests.
- Route: https://docs.flowrelay.app/agent-access/availability-and-refusals/; Use it for: Explain whether an action is available, blocked, human-only, or outside the current edition.

## Get set up
Start with public discovery, then add a merchant-authorized Agent Access bearer token for operational reads and approved action previews.

### Read the public manifest
Confirms Shopify Flow edition identity, docs URLs, capability metadata, and safety boundaries.

```sh
curl https://api.flowrelay.app/agent/v1/manifest
```

### Inspect the OpenAPI contract
Use this for exact request and response shapes before calling authenticated routes.

```sh
curl https://docs.flowrelay.app/reference/openapi/agent-operations.openapi.json
```

### Read mapping semantics
Use this before creating or editing an endpoint through API, CLI, or MCP.

```sh
https://docs.flowrelay.app/setup/trigger-variants-and-event-mapping/
```

### Read mission playbooks
Use this to map the operator's goal to context reads, safe actions, and escalation.

```sh
https://docs.flowrelay.app/agent-access/agent-mission-playbooks/
```

### Read availability guidance
Use this before assuming a listed capability can be executed.

```sh
https://docs.flowrelay.app/agent-access/availability-and-refusals/
```

### Read plan usage
Check usage meters before broad reads, polling, or repeated action previews.

```sh
curl -H "Authorization: Bearer $FLOWRELAY_AGENT_TOKEN" https://api.flowrelay.app/agent/v1/plan-usage
```

### Read scoped event history
Requires a merchant-authorized Agent Access grant token.

```sh
curl -H "Authorization: Bearer $FLOWRELAY_AGENT_TOKEN" "https://api.flowrelay.app/agent/v1/events?limit=25"
```

## Authentication model
Authenticated Agent Operations use merchant-authorized grant tokens supplied at request time. Public examples must never include real bearer tokens, grant tokens, session values, authentication headers, Shopify tokens, or private endpoint material; use placeholder environment variables such as $FLOWRELAY_AGENT_TOKEN.

- Signal: scope; How to use it: Confirms whether the grant permits the read, preview, or execution.
- Signal: actor; How to use it: Preserves human or authorized-agent attribution.
- Signal: refusal; How to use it: Explains why an action is outside authority or unsafe.

## Reads
Read routes return safe facts (setup, event history, receipts, diagnostics, plan usage, and grant status) without exposing raw private material unless the grant explicitly authorizes that surface.

- Read area: Setup and endpoints; Purpose: Explain how the sender, event type, authentication mode, and Shopify Flow trigger are configured.
- Read area: Events and receipts; Purpose: Find what FlowRelay accepted, where the handoff stopped, and what recovery options exist. Delivered means FlowRelay handed the trigger to Shopify Flow. It does not mean downstream Shopify Flow branches, app calls, fulfillment changes, emails, or later systems completed.
- Read area: Diagnostics and plan state; Purpose: Prepare redacted support collaboration and understand usage safeguards.

## Action previews
Side-effecting operations use preview, confirmation, idempotency, metering, audit, and refusal semantics. Use the action previews reference before replay, diagnostics share, endpoint edit, rotation, delete, or test execution.

## Request lanes
Use the structured request lanes when the agent needs human support, wants to record future-edition demand, or finds a missing FlowRelay capability. These routes record product-state signals so the team has context; they do not create a commitment, priority, or timeline. Responses acknowledge receipt, not delivery of a feature.

- Route: POST /agent/v1/support-request-intents; Use it for: Previewing or submitting an active help or recovery request with consent, redaction, and safe support context.
- Route: POST /agent/v1/expansion-requests; Use it for: Recording non-binding demand for future platform, native-edition, trigger-lane, multi-store, or event-reliability expansion.
- Route: POST /agent/v1/feature-requests; Use it for: Recording non-binding requests for missing FlowRelay capabilities inside the current product surface, not support tickets, expansion requests, or generic wishlists.

## Errors and schemas
Use support codes and generated schemas for exact fields. The prose docs explain product meaning; the generated OpenAPI contract explains exact request and response shape. Endpoint create and edit work should pair the OpenAPI schema with the trigger variants and event mapping reference.

## Mission and availability
When an agent receives a goal rather than a specific route, use the mission playbooks before tool use. When a route exists but may be blocked by scope, usage, target state, safety, or product boundary, use the availability and refusals guide before retrying.

## Example Surface
- `curl https://api.flowrelay.app/agent/v1/manifest`
- `curl -H "Authorization: Bearer $FLOWRELAY_AGENT_TOKEN" https://api.flowrelay.app/agent/v1/plan-usage`
- `curl -H "Authorization: Bearer $FLOWRELAY_AGENT_TOKEN" https://api.flowrelay.app/agent/v1/events?limit=25`
- `POST /agent/v1/endpoints`
- `POST /agent/v1/events/{eventId}/replay-intents`
- `POST /agent/v1/feature-requests`

## Safety Boundary
Do not share endpoint secrets, authentication headers, HMAC values, tokens, raw event bodies, customer records, Shopify sessions, store passwords, or database URLs in public examples.