HTTP APIs
For a source on the generic_rest connector, the gateway is a reverse proxy.
Send the agent’s requests to:
$GATEWAY/proxy/{source_id}/{path}Authorization: Bearer $API_KEYThe gateway strips the agent’s Authorization header, applies source roles by
method and path (http.get, http.post, http.delete and so on), applies
policy, forwards the request to the source’s base_url with the source’s own
credentials, redacts the response, and audits it.
GETandHEADare reads and can be cached.POSTis a low-risk write and runs;PUTandPATCHare medium andDELETEhigh, so they are queued for approval and answered202with the approval id.- Request and response bodies are size-limited; oversized ones are refused.
- Private and cloud-metadata addresses are refused unless the source allows private egress.
See the HTTP proxy contract.