Docs/API Reference/Emergency Shutdown

Emergency Shutdown API

Activate and monitor emergency shutdowns to halt AI agent operations when critical incidents are detected. Severity-based response from monitoring alerts to full service suspension.

Endpoints

GET/v1/emergency-shutdownGet active shutdown status
POST/v1/emergency-shutdownActivate emergency shutdown
GET/v1/emergency-shutdown/statusOrg status, active shutdowns and history
POST/v1/emergency-shutdown/resolveResolve (lift) an active shutdown

Authentication

All endpoints require API key authentication. Subject to admin-level rate limiting. The organisation is always the one the API key belongs to; an org id in the request body is ignored, and a key can see, activate and resolve shutdowns for its own organisation only.

Critical Operation
At severity 4-5, governance calls (/v1/govern and the protocol adapters) return 503 until the shutdown is resolved: for the whole organisation with scope "org", or only for calls made with the activating API key with scope "key". It takes effect on every server within 5 seconds. Use with caution.

Severity Levels

LevelLabelImpact
5CriticalAll governance calls return 503 — full service halt
4SevereAll governance calls return 503 — full service halt
3MajorGovernance responses include emergency warnings
2ModerateAlert logged, monitoring active
1MinorAlert logged, monitoring active

Get Shutdown Status

GET/v1/emergency-shutdown

Returns all active emergency shutdowns for your organization.

bash
curl "https://tork.network/api/v1/emergency-shutdown" \
  -H "x-tork-api-key: tork_sk_your_api_key"
json
{
  "active_shutdowns": [
    {
      "id": "esd_abc123",
      "severity": 4,
      "severity_label": "Severe",
      "reason": "Detected unredacted PII in production output",
      "scope": "org",
      "status": "activated",
      "activated_at": "2026-02-12T10:00:00Z",
      "activated_by": "key_prefix_abc"
    }
  ]
}

Activate Emergency Shutdown

POST/v1/emergency-shutdown

Activates an emergency shutdown with the specified severity level.

Request Body

ParameterTypeRequiredDescription
severitynumberYesSeverity level 1-5
reasonstringYesDescription of the incident (non-empty)
scopestringNo"org" (default): your organisation. "key": only calls made with this API key. "all" (every organisation on the platform) is refused with 403 for API keys; it is reserved for Tork platform administrators.

Example

bash
curl -X POST "https://tork.network/api/v1/emergency-shutdown" \
  -H "x-tork-api-key: tork_sk_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "severity": 5,
    "reason": "Critical data breach detected — unredacted SSNs in agent output",
    "scope": "org"
  }'
json
{
  "shutdown_id": "tork_sd_1770906600000_9f2c4e1a7b3d5e60",
  "severity": 5,
  "severity_label": "Immediate",
  "status": "activated",
  "scope": "org",
  "activated_at": "2026-02-12T14:30:00Z",
  "message": "Emergency shutdown activated. Governance calls for this organisation return 503 until resolved (every server instance within 5 seconds).",
  "affected_scope": "org",
  "audit_logged": true
}

Error Responses

StatusDescription
400Invalid severity (must be 1-5), empty reason, or invalid scope
401Missing or invalid API key
403scope "all" requested with an API key (PLATFORM_SCOPE_FORBIDDEN)
429Rate limit exceeded
503The shutdown could not be recorded and is NOT in effect (SHUTDOWN_STORE_UNAVAILABLE); retry
500Internal server error