API Reference

API Endpoints

Complete reference for the Tork Governance REST API.

Base URL

All API requests are made to the following base URL:

text
https://tork.network/api/v1

RESTful

Standard REST conventions

Authenticated

API key required

Rate Limited

1000 req/min default

Authentication

Include your API key in the Authorization header:

bash
curl -X GET "https://tork.network/api/v1/agents" \
  -H "Authorization: Bearer tork_sk_your_api_key" \
  -H "Content-Type: application/json"

Governance

Scan and redact PII from AI agent content in real-time.

POST/governScan content for PII

Request Body

ParameterTypeRequiredDescription
contentstringYesThe text content to scan for PII (max 100KB)
options.modestringNoAction mode: "detect", "redact" (default), or "deny"
regionstring[]NoRegional PII profiles to activate (e.g. ["AU", "AE"])
industrystringNoIndustry profile to activate (e.g. "healthcare", "finance", "legal")

Available Regions: AU, AE, BR, CN, DE, FR, GB, IN, JP, KR, NG, ZA. Each region activates country-specific PII patterns like Aadhaar (IN), Emirates ID (AE), CPF (BR), and more.

Response

FieldTypeDescription
actionstring"allow", "redact", or "deny"
outputstringRedacted content (or original if no PII found)
pii_detectedarrayArray of { type, count } for each PII type found. Includes regional types (e.g. "emirates_id", "aadhaar", "cpf") when region profiles are active
latency_msnumberProcessing time in milliseconds
receiptobjectCompliance receipt with receipt_id, timestamp, content_hash, hmac_signature, and fingerprint
governance_dnaobjectGovernance DNA with fingerprint, risk level, score, and applied policies
usageobjectUsage counters: calls_used, calls_limit, calls_remaining

Example: Basic Scan

bash
curl -X POST "https://tork.network/api/v1/govern" \
  -H "Authorization: Bearer tork_sk_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "content": "Contact sarah@acme.com or call 555-123-4567",
    "options": { "mode": "redact" }
  }'
json
{
  "action": "redact",
  "output": "Contact [EMAIL_REDACTED] or call [PHONE_REDACTED]",
  "pii_detected": [
    { "type": "email", "count": 1 },
    { "type": "phone", "count": 1 }
  ],
  "latency_ms": 6,
  "receipt": {
    "receipt_id": "rcpt_a1b2c3d4",
    "timestamp": "2026-02-12T10:30:00.000Z",
    "policy_version": "1.0.0",
    "content_hash": "sha256:...",
    "hmac_signature": "hmac:...",
    "fingerprint": "dna:..."
  },
  "usage": {
    "calls_used": 142,
    "calls_limit": 10000,
    "calls_remaining": 9858
  }
}

Example: Regional Detection

bash
curl -X POST "https://tork.network/api/v1/govern" \
  -H "Authorization: Bearer tork_sk_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "content": "Patient Aadhaar is 1234 5678 9012 and Emirates ID 784-1234-1234567-1",
    "region": ["IN", "AE"],
    "industry": "healthcare"
  }'
json
{
  "action": "redact",
  "output": "Patient [AADHAAR_REDACTED] and [EMIRATES_ID_REDACTED]",
  "pii_detected": [
    { "type": "aadhaar", "count": 1 },
    { "type": "emirates_id", "count": 1 }
  ],
  "latency_ms": 8,
  "receipt": {
    "receipt_id": "rcpt_e5f6g7h8",
    "timestamp": "2026-02-12T10:31:00.000Z",
    "policy_version": "1.0.0",
    "content_hash": "sha256:...",
    "hmac_signature": "hmac:...",
    "fingerprint": "dna:..."
  },
  "usage": {
    "calls_used": 143,
    "calls_limit": 10000,
    "calls_remaining": 9857
  }
}

Agents

Manage AI agent registrations and configurations.

GET/agentsList all agents
POST/agentsRegister new agent
GET/agents/:idGet agent details
PUT/agents/:idUpdate agent (name, framework, permissions, is_active)
DELETE/agents/:idDelete agent
python
# Example: register a new agent (REST — there is no Python cloud SDK)
import os
import requests

response = requests.post(
    "https://tork.network/api/v1/agents",
    headers={"Authorization": f"Bearer {os.environ['TORK_API_KEY']}"},
    json={
        "agent_id": "support-bot",           # your stable identifier (required)
        "name": "Customer Support Bot",
        "framework": "langchain",
        "permissions": ["read_kb", "send_email"],
    },
    timeout=10,
)
agent = response.json()
print(f"Registered {agent['agent_id']} (row {agent['id']})")

Policies

Define and manage governance policies.

GET/policiesList all policies
POST/policiesCreate policy
GET/policies/:idGet policy details
PUT/policies/:idUpdate policy
DELETE/policies/:idDelete policy

There is no /policies/check. Content decisions come from POST /govern above; tool-call decisions come from POST /governance/check (agent_id, tool_name, optional target and parameters), which answers allowed, reason and warnings.

python
# Example: create a policy, then check a tool call against your registered tools
import os
import requests

headers = {"Authorization": f"Bearer {os.environ['TORK_API_KEY']}"}

requests.post(
    "https://tork.network/api/v1/policies",
    headers=headers,
    json={"name": "pii-protection", "yaml_content": "policies:\n  - name: pii-protection\n    action: REDACT\n"},
    timeout=10,
)

decision = requests.post(
    "https://tork.network/api/v1/governance/check",
    headers=headers,
    json={"agent_id": "agent-123", "tool_name": "send_email", "target": "user@example.com"},
    timeout=10,
).json()

if decision["allowed"]:
    proceed_with_action()
else:
    handle_blocked(decision["reason"])

Policy Envelopes

Receive a Tork Tower governance envelope (schema_version 2). The envelope is stored byte-exact and hashed with SHA-256 over the raw request body, so a later compliance receipt covers exactly what was sent. Separate from /policies, which is the YAML policy store.

POST/policy-envelopesSubmit a governance envelope

(tool_id, policy_version) identifies one version. Re-submitting identical bytes returns 200 with the existing record and writes nothing. Submitting different bytes under the same version returns 409 — a stored envelope is never overwritten, because a receipt may already cover it. Publish a new policy_version instead.

bash
curl -X POST https://tork.network/api/v1/policy-envelopes \
  -H "Authorization: Bearer $TORK_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @envelope.json

# 201 Created
# {
#   "status": "stored",
#   "id": "8f2c1e0a-....",
#   "org_id": "....",
#   "tool_id": "tower.underwriting.assistant",
#   "tenant_id": "acme",
#   "policy_version": "4.2.0",
#   "schema_version": 2,
#   "content_hash": "9b1f...e7",   # SHA-256 of the raw request body
#   "received_at": "2026-08-14T02:31:07.442Z"
# }

Send the envelope as raw JSON (--data-binary). The hash covers the exact bytes you transmit, so reformatting the document changes content_hash.

Budgets & Costs

Manage spending limits and track costs. Budgets live under /costs.

GET/costs/budgetsList budgets (?agent_id=, ?budget_id=, ?active_only=)
POST/costs/budgetsCreate budget (budgetName, budgetType, budgetAmount, ...)
PUT/costs/budgetsUpdate budget (budgetId + fields)
DELETE/costs/budgetsDelete budget (?budget_id=)
POST/costs/checkCheck whether a proposed spend fits (agentId, proposedCost)
GET/costs/summarySpend summary (?agent_id=, ?period=)
GET/costs/transactionsRaw cost transactions

Approvals

Human-in-the-loop approval workflows.

GET/approvalsList approval requests
GET/approvals/:idGet approval details
POST/approvals/:id/approveApprove request
POST/approvals/:id/rejectReject request

Audit Logs

Access compliance and audit records.

GET/audit-logsQuery audit logs (?agent_id=, ?since=, ?until=, ?limit=)
GET/audit?action=logsHash-chained immutable log entries
GET/audit?action=receipt&number=...Get one compliance receipt by number
GET/audit-logs/exportExport audit logs
GET/receipts/:idGet a governance receipt

Rate Limits: Default rate limit is 1000 requests per minute. Contact us for higher limits.

Documentation

Learn to integrate TORK

Upgrade Plan

Current: free

Support

Get help from our team