Skip to main content
Everything the console does goes through Duraton’s HTTP API, and so can you. It is plain JSON over HTTP - no SDK required to trigger events, read runs, or control them.

Base URL

DURATON_URL is the Duraton API base: https://run.duraton.dev. All paths below are relative to it.

Authentication

Every request needs an API key, presented as a Bearer token. Issue one in the console under API Keys:
Keys carry a scope. A public (read-only) key can call the GET endpoints; writes (every POST, PATCH, and DELETE, plus the /connect upgrade) need a secret key.

Conventions

  • Request and response bodies are JSON. Send POST and PATCH bodies as a JSON object.
  • Reads return 200; writes return 200, 201, 202, or 204 depending on the route. The full map, and the failure codes, are in errors.
  • Listings are newest-first and bounded. GET /runs, GET /webhook-deliveries, and GET /webhook-source-deliveries use keyset pagination via the X-Next-Cursor header; the other listings take a limit (see limits).

Runs

Control

Events

Approvals

Webhooks

Registry

The runner protocol (POST /register, the invoke call, GET /connect) is documented separately in the protocol reference, and the same operations are available to AI agents as MCP tools.