Transports

DocsTransports

REST

A request and an answer, JSON both ways, on every route in the reference.

Shape

Every route is https://api.inorbit.hr plus the path in the reference. A GET or DELETE takes its parameters from the path and the query string; a POST, PUT or PATCH takes a JSON body with Content-Type: application/json.

curl https://api.inorbit.hr/v1/me \
  -H "Authorization: Bearer $TOKEN" \
  -H "Accept: application/json"

Rules the gateway enforces

  • A body that is not JSON is 415 unsupported_media_type; one that does not parse is 400 bad_request with a field detail named body; one over 2 MiB is 413 payload_too_large.
  • Input is strict: an unknown field, an unknown query key, a singular field given twice, or a value that does not convert is 400 bad_request with a field detail naming it.
  • A known path with a verb it does not serve is 405 method_not_allowed.
  • A list field in the query string repeats the key: ?scopes=a&scopes=b. A nested field is dotted: ?filter.kind=x.
  • An answer is at most 4 MiB.

Retries

Retry on 503 unavailable, 504 timeout and 429 rate_limited, and on nothing else. A 429 carries Retry-After in seconds. A POST is not idempotent unless the reference says so; do not retry one blindly.

The document

GET https://api.inorbit.hr/openapi.json is the public REST surface as OpenAPI 3.1 (the routes an API key may call, and the health endpoints), without a token. The Reference on this site is built from it and shows only the operations a key may call; the document itself marks them with x-tbd-public: true.