# Hogpass ## Docs - [Credential & Policy Layer for AI Agents](https://hogpass.com/docs/index.md): Give your AI agents secure access to external services. Store credentials once, inject them at request time, and control what your agents can do. Your agents never see the keys. - [Quickstart](https://hogpass.com/docs/quickstart.md): Sign up for Hogpass and connect your first agent to external services in under five minutes. No code changes needed. - [How the Gateway Works: Credential Injection & Signing](https://hogpass.com/docs/how-it-works.md): Hogpass runs a transparent proxy that intercepts outgoing HTTP requests, checks them against your rules, and injects credentials from an encrypted vault. - [CLI Reference: Commands, Flags & Configuration](https://hogpass.com/docs/cli/onecli-cli.md): Full reference for the Hogpass command-line tool: installation, every command with flags, environment variables, and configuration. - [Self-hosted Hogpass](https://hogpass.com/docs/self-hosting/overview.md): Run Hogpass in your own infrastructure: the free Community edition or the fully featured Enterprise edition, each a single Docker image. - [Deploy Community Edition](https://hogpass.com/docs/self-hosting/community.md): Run the free, open source Hogpass edition with Docker Compose: full dashboard, bundled PostgreSQL, one command. - [Deploy Enterprise: all-in-one image](https://hogpass.com/docs/self-hosting/enterprise/all-in-one.md): Run the fully featured Hogpass Enterprise edition with Docker Compose: one container for the dashboard, API, and gateway, plus PostgreSQL. - [Configuration](https://hogpass.com/docs/self-hosting/configuration.md): Environment variables, authentication modes, and networking for the self-hosted Hogpass image. - [App credentials](https://hogpass.com/docs/self-hosting/app-credentials.md): Pre-configure OAuth app integrations on a self-hosted instance with environment variables, per app. - [Connect the CLI and agents](https://hogpass.com/docs/self-hosting/connect-agents.md): Point agents at your self-hosted Hogpass instance, with headless provisioning, org-wide app connections, and rules via the organization API key. - [Integrations: Connect Agents to External Services](https://hogpass.com/docs/integrations/index.md): Connect AI agents to external services through the Hogpass gateway. OAuth apps, API keys, and cloud platforms, all from one dashboard. - [App Connections: How OAuth & API Keys Work](https://hogpass.com/docs/integrations/app-connections.md): How Hogpass stores and injects OAuth tokens and API keys for connected apps. Token refresh, credential encryption, and the connection lifecycle. - [LLM Providers: Route Agents to Any Model](https://hogpass.com/docs/integrations/llms.md): Route AI agent traffic to Anthropic, OpenAI, Vertex AI, or any LLM provider. The gateway injects API keys so agents never see them. - [External Vaults: Connect Password Managers](https://hogpass.com/docs/vaults/overview.md): Connect Hogpass to Bitwarden and other password managers. Pull credentials from vaults you already use. Agents never see the secrets. - [Apollo.io Integration: Sales Intelligence for Agents](https://hogpass.com/docs/integrations/apollo-io.md): Agents can search contacts, enrich leads, manage sequences, and work with deals in Apollo.io. OAuth credentials are injected automatically. - [AWS for AI Agents: S3, EC2, Lambda & More](https://hogpass.com/docs/integrations/aws.md): Connect agents to AWS with automatic SigV4 request signing. Supports IAM access keys and cross-account roles with per-agent session policies. - [GitHub for AI Agents: Repos, PRs & Actions](https://hogpass.com/docs/integrations/github.md): Connect agents to GitHub via OAuth or a GitHub App. The gateway injects tokens into API calls and git-over-HTTPS, with per-action allow/ask/block controls. - [GitHub App Integration: Org-Approved Repository Access](https://hogpass.com/docs/integrations/github-app.md): Fine-grained, organization-approved access to repositories through GitHub App installation tokens. Tokens are refreshed and injected automatically. - [Datadog Integration: Monitoring & Logs for Agents](https://hogpass.com/docs/integrations/datadog.md): Let agents query Datadog metrics, check monitor status, and read incident timelines. API keys are injected by the gateway. - [HubSpot Integration: CRM for Agents](https://hogpass.com/docs/integrations/hubspot.md): Agents can manage contacts, companies, deals, and tickets in HubSpot CRM. OAuth credentials are injected automatically. - [Sentry Integration: Error Tracking for Agents](https://hogpass.com/docs/integrations/sentry.md): Agents can read errors, manage issues, and track releases in Sentry. OAuth credentials are injected automatically. - [Microsoft OneNote Integration: Notebooks for Agents](https://hogpass.com/docs/integrations/microsoft-onenote.md): Agents can read and manage notebooks, sections, and pages in Microsoft OneNote. OAuth credentials are injected automatically. - [Outlook Mail Integration: Email for Agents](https://hogpass.com/docs/integrations/outlook-mail.md): Agents can read, send, and organize email in Microsoft 365 mailboxes. OAuth tokens are managed and refreshed automatically. - [Outlook Calendar Integration: Scheduling for Agents](https://hogpass.com/docs/integrations/outlook-calendar.md): Let agents view, create, and manage calendar events in Microsoft 365. Works with shared calendars and room resources. - [Attio Integration: CRM for Agents](https://hogpass.com/docs/integrations/attio.md): Agents can manage contacts, companies, deals, lists, notes, and tasks in Attio CRM. Connect with OAuth or a scoped API key. - [Cloudflare Integration: DNS & Workers for Agents](https://hogpass.com/docs/integrations/cloudflare.md): Agents can manage DNS records, deploy Workers, and configure page rules. API tokens are injected at the gateway. - [Gmail Integration: Let Agents Read, Draft & Send Email](https://hogpass.com/docs/integrations/gmail.md): Search, read, draft, and send emails through the Gmail API. The gateway handles OAuth and token refresh so agents just make HTTP calls. - [Google Calendar Integration: Scheduling for Agents](https://hogpass.com/docs/integrations/google-calendar.md): Agents can list events, create meetings, check availability, and manage RSVPs. OAuth credentials are injected automatically. - [Google Drive Integration: File Access for Agents](https://hogpass.com/docs/integrations/google-drive.md): Search, read, create, and organize files and folders in Google Drive. Supports Docs, Sheets, and uploaded files. - [Google Docs Integration: Read & Edit Documents](https://hogpass.com/docs/integrations/google-docs.md): Read and edit Google Docs programmatically. Agents can create documents, insert text, and format content via the Docs API. - [Google Sheets: Spreadsheet Access for AI Agents](https://hogpass.com/docs/integrations/google-sheets.md): Read and write spreadsheet data through the Google Sheets API. Extract data, generate reports, or update tracking sheets. - [Google Slides Integration: Create & Edit Presentations](https://hogpass.com/docs/integrations/google-slides.md): Create and edit presentations through the Slides API. Agents can add slides, insert text and images, and update layouts. - [Google Forms: Form & Response Access for AI Agents](https://hogpass.com/docs/integrations/google-forms.md): Agents can create forms, read submissions, and analyze response data through the Google Forms API. OAuth handled by the gateway. - [Google Meet Integration: Meetings & Recordings](https://hogpass.com/docs/integrations/google-meet.md): Create meeting links, list upcoming calls, and read recording metadata through the Google Meet API. OAuth handled by the gateway. - [Google Photos Integration: Albums & Media Access](https://hogpass.com/docs/integrations/google-photos.md): Search, browse, and manage photos and albums. Agents can read image metadata, list albums, and upload media via the Photos API. - [Google Tasks: Task Management for AI Agents](https://hogpass.com/docs/integrations/google-tasks.md): Create, complete, and organize tasks and task lists through the Google Tasks API. OAuth credentials injected by the gateway. - [Google Admin Integration: Workspace User Management](https://hogpass.com/docs/integrations/google-admin.md): Manage users, groups, and organizational units in Google Workspace. Requires admin privileges on the Google account. - [Google Analytics: Traffic & Reporting for AI Agents](https://hogpass.com/docs/integrations/google-analytics.md): Query traffic reports, read key metrics, and pull audience data from GA4 properties. OAuth credentials injected by the gateway. - [Google Search Console Integration: SEO Data Access](https://hogpass.com/docs/integrations/google-search-console.md): Query search performance, inspect URLs, and check indexing status. Agents can pull click/impression data and identify crawl issues. - [Google Classroom: Education Access for AI Agents](https://hogpass.com/docs/integrations/google-classroom.md): Manage courses, assignments, and student rosters through the Classroom API. OAuth credentials injected by the gateway. - [YouTube Integration: Videos, Playlists & Analytics](https://hogpass.com/docs/integrations/youtube.md): List channels, search videos, manage playlists, and read analytics. The gateway injects YouTube Data API credentials. - [Notion Integration: Pages & Database Access](https://hogpass.com/docs/integrations/notion.md): Search, read, and write Notion pages and databases through the API. Agents connect via internal integration, credentials injected. - [Jira Integration: Issues, Sprints & Project Boards](https://hogpass.com/docs/integrations/jira.md): Create, update, and search Jira issues. Agents can manage sprints, transition statuses, and read project boards. - [Confluence: Wiki & Docs for AI Agents](https://hogpass.com/docs/integrations/confluence.md): Search, read, and create pages in Confluence spaces. Agents can reference internal documentation or publish content automatically. - [Todoist Integration: Task Management for Agents](https://hogpass.com/docs/integrations/todoist.md): Create, complete, and organize tasks and projects in Todoist. API tokens are injected by the gateway. Agents never see them. - [Dropbox Integration: Cloud Storage for Agents](https://hogpass.com/docs/integrations/dropbox.md): Agents can browse, download, upload, and share files in Dropbox. OAuth credentials are injected automatically. - [Fly.io Integration: Deploy & Manage Apps for Agents](https://hogpass.com/docs/integrations/flyio.md): Agents can deploy and manage applications, Machines, volumes, and secrets on Fly.io. API tokens are injected at the gateway. - [LinkedIn Integration: Social Engagement for Agents](https://hogpass.com/docs/integrations/linkedin.md): Agents can read your profile and create posts on LinkedIn. OAuth credentials are injected automatically. - [Monday.com Integration: Project Management for Agents](https://hogpass.com/docs/integrations/monday.md): Agents can manage boards, items, docs, and workspaces in Monday.com. OAuth credentials are injected automatically. - [MongoDB Atlas Integration: Database Administration for Agents](https://hogpass.com/docs/integrations/mongodb-atlas.md): Agents can manage clusters, users, and projects via the Atlas Administration API. Client credentials are injected automatically. - [Resend: Transactional Email for AI Agents](https://hogpass.com/docs/integrations/resend.md): Send transactional emails and check delivery status via the Resend API. API keys injected by the gateway automatically. - [Supabase Integration: Database & Auth for Agents](https://hogpass.com/docs/integrations/supabase.md): Agents can manage Supabase projects, databases, edge functions, and storage. OAuth credentials are injected automatically. - [Vertex AI: Route Agents to Claude & Gemini on GCP](https://hogpass.com/docs/integrations/vertex-ai.md): Route agent requests to Vertex AI models on Google Cloud, including Claude and Gemini. Supports service account and ADC authentication. - [Zoom Integration: Meetings & Recordings for Agents](https://hogpass.com/docs/integrations/zoom.md): Agents can list meetings, schedule calls, access cloud recordings, and manage your Zoom calendar. OAuth credentials are injected automatically. - [Anthropic Integration: Claude API Key Injection](https://hogpass.com/docs/integrations/anthropic.md): Inject your Anthropic API key into agent requests so they can call Claude models without ever seeing or handling the key. - [OpenAI Integration: API Key & Codex OAuth](https://hogpass.com/docs/integrations/openai.md): Inject your OpenAI API key or Codex OAuth credentials into agent requests so they can call GPT, DALL-E, and embeddings without handling the key. - [Bitwarden Vault: Sync Secrets to the Gateway](https://hogpass.com/docs/vaults/bitwarden.md): Sync secrets from Bitwarden into Hogpass. Agents can access vault items without the Bitwarden CLI or direct API calls. - [1Password Vault: Service Account Integration](https://hogpass.com/docs/vaults/1password.md): Connect 1Password to Hogpass using Service Accounts. AI agents resolve secrets at runtime via op:// references. Credentials never leave your vault until the moment they're needed. - [Guides: Set Up Agents and Configure Hogpass](https://hogpass.com/docs/guides/index.md): Step-by-step guides for connecting AI agents, configuring projects, setting rules, and managing credentials with Hogpass. - [Hogpass Plugin for Claude Code](https://hogpass.com/docs/guides/claude-code-plugin.md): Install the Hogpass plugin for Claude Code to connect to external APIs with zero credential management. No CLI required. - [Set Up Coding Agents: Claude Code, Cursor & Windsurf](https://hogpass.com/docs/guides/coding-agents.md): Configure Claude Code, Cursor, Windsurf, and other coding agents to route through the Hogpass gateway. One command to set up. - [NanoClaw: Agent Orchestration with the Gateway](https://hogpass.com/docs/guides/nanoclaw.md): Run NanoClaw agents with Hogpass handling credential injection and policy enforcement. No code changes needed in the agent. - [GitHub App Setup: Fine-Grained Repo Access](https://hogpass.com/docs/guides/github-app.md): Install and configure the Hogpass GitHub App for fine-grained repo access. Supports org-level approval and per-repo scoping. - [Projects: Organize Agents & Connections](https://hogpass.com/docs/guides/projects.md): Group agents, connections, and rules into projects. Each project has its own dashboard, audit log, and team members. - [Rules: Control What Agents Can Do](https://hogpass.com/docs/guides/rules.md): Define allow/block/rate-limit rules that are evaluated before credential injection. Block destructive operations, require approval, or cap usage. - [User Provisioning: Add Team Members Programmatically](https://hogpass.com/docs/guides/user-provisioning.md): Add team members to Hogpass with pre-configured roles, API keys, and project access. Supports programmatic provisioning via the API. - [Credential Stubs for MCP Servers](https://hogpass.com/docs/guides/credential-stubs/general-app.md): Create placeholder credential files so MCP servers can start without real secrets. The gateway fills in values at request time. - [Gmail Credential Stubs](https://hogpass.com/docs/guides/credential-stubs/gmail.md): Set up Gmail credential stubs so MCP servers that need Google OAuth tokens can start without manual auth flows or token files. - [Vertex AI Credential Stubs](https://hogpass.com/docs/guides/credential-stubs/vertex-ai.md): Set up Vertex AI credential stubs so MCP servers that need Google Cloud service account keys can start without manual setup. - [API Reference](https://hogpass.com/docs/api-reference/index.md): Authenticate and interact with the Hogpass API to manage agents, secrets, policy rules, and app connections programmatically. - [Errors](https://hogpass.com/docs/api-reference/errors.md): Error codes, response format, and troubleshooting guidance for the Hogpass API. - [Partner API](https://hogpass.com/docs/api-reference/partner.md): Provision and manage Hogpass organizations on behalf of your customers with the Partner API. - [Environment Variables](https://hogpass.com/docs/reference/environment-variables.md): All environment variables recognized by the Hogpass gateway, CLI, and Docker image. Proxy config, auth, logging, and feature flags. - [Telemetry: What We Collect & How to Opt Out](https://hogpass.com/docs/reference/telemetry.md): What Hogpass collects, why, and how to opt out. No request bodies, credentials, or PII are ever transmitted. Fully transparent. - [List agents](https://hogpass.com/docs/api-reference/agents/list-agents.md): Returns all agents in the current project with secret and connection counts. - [Create an agent](https://hogpass.com/docs/api-reference/agents/create-an-agent.md): Creates a new agent in the current project. The identifier must be lowercase alphanumeric with hyphens, starting with a letter or number (max 50 chars). - [Get default agent](https://hogpass.com/docs/api-reference/agents/get-default-agent.md): Returns the default agent for the current project. - [Rename an agent](https://hogpass.com/docs/api-reference/agents/rename-an-agent.md) - [Delete an agent](https://hogpass.com/docs/api-reference/agents/delete-an-agent.md) - [Set default agent](https://hogpass.com/docs/api-reference/agents/set-default-agent.md): Marks the specified agent as the project's default agent. - [Regenerate agent token](https://hogpass.com/docs/api-reference/agents/regenerate-agent-token.md): Generates a new access token for the agent. The previous token is immediately invalidated. - [Update agent secret mode](https://hogpass.com/docs/api-reference/agents/update-agent-secret-mode.md): Controls which secrets the agent can access: - `all` — the agent can use every secret in the project. - `selective` — only secrets explicitly assigned via `PUT /agents/{agentId}/secrets`. - [List agent's assigned secrets](https://hogpass.com/docs/api-reference/agents/list-agents-assigned-secrets.md): Returns the IDs of secrets assigned to this agent (relevant when secret mode is `selective`). - [Update agent's assigned secrets](https://hogpass.com/docs/api-reference/agents/update-agents-assigned-secrets.md): Replaces the full list of secrets assigned to this agent. - [List agent's app-connection assignments](https://hogpass.com/docs/api-reference/agents/list-agents-app-connection-assignments.md): Returns the agent's app-connection assignments and their per-connection granular-access policies. - [Update agent's app-connection assignments](https://hogpass.com/docs/api-reference/agents/update-agents-app-connection-assignments.md): Replaces the agent's app-connection assignments and their granular-access policies. - [List granular-access policies](https://hogpass.com/docs/api-reference/agents/list-granular-access-policies.md): Read-only overview of every agent → connection assignment in the project that carries a non-empty granular-access policy (e.g. GitHub repository or Dropbox folder scoping). Unrestricted assignments are omitted. - [List secrets](https://hogpass.com/docs/api-reference/secrets/list-secrets.md): Returns all secrets in the current project. Secret values are never returned. - [Create a secret](https://hogpass.com/docs/api-reference/secrets/create-a-secret.md): Creates a new secret. The gateway uses secrets to inject credentials into outbound requests matching the host and path patterns. - [Update a secret](https://hogpass.com/docs/api-reference/secrets/update-a-secret.md): Updates one or more fields on a secret. At least one field must be provided. - [Delete a secret](https://hogpass.com/docs/api-reference/secrets/delete-a-secret.md) - [List apps](https://hogpass.com/docs/api-reference/apps/list-apps.md): Returns all available apps with their current configuration and connection status. - [Get app details](https://hogpass.com/docs/api-reference/apps/get-app-details.md): Returns detailed information about a specific app, including setup instructions. - [Start OAuth flow](https://hogpass.com/docs/api-reference/apps/start-oauth-flow.md): Redirects the user to the app's OAuth authorization page. After the user authorizes, they are redirected back to the callback URL. - [Connect app with credentials](https://hogpass.com/docs/api-reference/apps/connect-app-with-credentials.md): Connects an app using direct credentials (API key, service account, etc.) rather than OAuth. - [List app permission definitions](https://hogpass.com/docs/api-reference/apps/list-app-permission-definitions.md): Returns the tool catalog of every app that has one — the read/write groups and tool IDs that the permissions endpoints operate on. Global data; works without a project context, so organization keys can call it without `X-Project-Id`. - [Get app permission definition](https://hogpass.com/docs/api-reference/apps/get-app-permission-definition.md): Returns the app's static tool catalog — the read/write groups and tool IDs that the permissions endpoints (`/rules/permissions/{provider}` and `/org/rules/permissions/{provider}`) operate on. Global data; works without a project context, so organization keys can call it without `X-Project-Id`. - [Get app configuration](https://hogpass.com/docs/api-reference/apps/get-app-configuration.md): Returns the non-secret configuration for a BYOC (Bring Your Own Credentials) app. - [Set app configuration](https://hogpass.com/docs/api-reference/apps/set-app-configuration.md): Creates or updates the BYOC configuration for an app. Existing connections may be disconnected when credentials change. - [Delete app configuration](https://hogpass.com/docs/api-reference/apps/delete-app-configuration.md) - [Toggle app configuration](https://hogpass.com/docs/api-reference/apps/toggle-app-configuration.md): Enables or disables a provider's BYOC configuration in the current project. - [List configured providers](https://hogpass.com/docs/api-reference/apps/list-configured-providers.md): Returns provider IDs with an enabled BYOC configuration in the current project. - [List providers with platform default credentials](https://hogpass.com/docs/api-reference/apps/list-providers-with-platform-default-credentials.md): Returns provider IDs whose OAuth credentials are supplied by the deployment's environment, so they work without BYOC configuration. - [Get blocklist state](https://hogpass.com/docs/api-reference/apps/get-blocklist-state.md): Returns the blocklist state for a provider — the app's predefined hosts (with their activation state) and any custom rules. - [Activate or add a blocklist entry](https://hogpass.com/docs/api-reference/apps/activate-or-add-a-blocklist-entry.md): Provide either `{ hostId }` to activate one of the app's predefined blocklist hosts, or `{ name, hostPattern }` to add a custom blocklist rule. - [Toggle a blocklist rule](https://hogpass.com/docs/api-reference/apps/toggle-a-blocklist-rule.md) - [Remove a blocklist rule](https://hogpass.com/docs/api-reference/apps/remove-a-blocklist-rule.md) - [List connections](https://hogpass.com/docs/api-reference/connections/list-connections.md): Returns the project's app connections (including inherited organization connections) as a bare array. Filter with the `provider` query parameter. - [Rename a connection](https://hogpass.com/docs/api-reference/connections/rename-a-connection.md): Sets the display label of an app connection. - [Disconnect a connection](https://hogpass.com/docs/api-reference/connections/disconnect-a-connection.md): Permanently removes an app connection by ID. - [List policy rules](https://hogpass.com/docs/api-reference/rules/list-policy-rules.md): Returns all policy rules for the current project. - [Get a policy rule](https://hogpass.com/docs/api-reference/rules/get-a-policy-rule.md): Returns a single policy rule by ID. - [Create a policy rule](https://hogpass.com/docs/api-reference/rules/create-a-policy-rule.md): Creates a new policy rule. Rules control how agents interact with external services: - [Update a policy rule](https://hogpass.com/docs/api-reference/rules/update-a-policy-rule.md): Updates one or more fields on a rule. At least one field must be provided. - [Delete a policy rule](https://hogpass.com/docs/api-reference/rules/delete-a-policy-rule.md) - [Get app permissions (project)](https://hogpass.com/docs/api-reference/rules/get-app-permissions-project.md): Returns the layered tool-level permission states for a provider at the project scope: `defaults` holds the all-agents states, `byAgent` holds per-agent override layers. Tool IDs come from the app's permission definition (`GET /apps/{provider}/permission-definition`). - [Set app permissions (project)](https://hogpass.com/docs/api-reference/rules/set-app-permissions-project.md): Updates tool-level permissions for a provider at the project scope. - [Count overlapping custom rules (project)](https://hogpass.com/docs/api-reference/rules/count-overlapping-custom-rules-project.md): Counts custom project rules whose host patterns overlap the app's hosts — rules that may interfere with the app's permission settings. - [List projects](https://hogpass.com/docs/api-reference/projects/list-projects.md): Returns all projects in the authenticated user's organization. Cloud only. - [Get a project](https://hogpass.com/docs/api-reference/projects/get-a-project.md): Returns a single project by ID. - [Create a project](https://hogpass.com/docs/api-reference/projects/create-a-project.md): Creates a new project in the organization. Requires admin role. - [Update a project](https://hogpass.com/docs/api-reference/projects/update-a-project.md): Updates a project's name and slug. Requires admin role. - [Delete a project](https://hogpass.com/docs/api-reference/projects/delete-a-project.md): Permanently deletes a project and all its data (agents, secrets, connections, rules, audit logs). Requires admin role. Cannot delete the last project in the organization. - [Provision a team member](https://hogpass.com/docs/api-reference/team/provision-a-team-member.md): Pre-creates a user account with its own project, a usable API key, a default agent, and a claim link. The API key works immediately, so agents can make requests before the user signs up. The user later opens the claim link to bind the account to their identity. Unclaimed provisions expire after 7 da… - [Get current user](https://hogpass.com/docs/api-reference/user/get-current-user.md): Returns the profile of the authenticated user. - [Update user profile](https://hogpass.com/docs/api-reference/user/update-user-profile.md) - [Get API key](https://hogpass.com/docs/api-reference/user/get-api-key.md): Returns the current API key for the authenticated user in the current project. - [Regenerate API key](https://hogpass.com/docs/api-reference/user/regenerate-api-key.md): Generates a new API key, immediately invalidating the previous one. - [Health check](https://hogpass.com/docs/api-reference/utility/health-check.md): Returns the API's status and version. No authentication required. - [Get resource counts](https://hogpass.com/docs/api-reference/utility/get-resource-counts.md): Returns the current project's resource totals. - [List vault connections](https://hogpass.com/docs/api-reference/utility/list-vault-connections.md): Returns the project's external vault connections (e.g. 1Password). Vault pairing and disconnect are performed on the gateway process, not this API. - [Get container configuration](https://hogpass.com/docs/api-reference/agent-setup/get-container-configuration.md): Returns everything an agent orchestrator needs to route a container (or local process) through the Hogpass gateway: proxy environment variables, the gateway CA certificate, and any credential stub files. The server controls all env var names, values, and paths. - [List credential stub agents](https://hogpass.com/docs/api-reference/agent-setup/list-credential-stub-agents.md): Returns the agent frameworks that have credential stubs available. - [Get a credential stub](https://hogpass.com/docs/api-reference/agent-setup/get-a-credential-stub.md): Returns a placeholder credential file for the given agent framework (currently `codex`). The gateway injects real credentials at request time. - [Get the gateway skill](https://hogpass.com/docs/api-reference/agent-setup/get-the-gateway-skill.md): Returns the gateway skill as Markdown — instructions that teach a coding agent how to work behind the Hogpass gateway. Pass `agent_framework` for framework-specific content. - [Export data to Hogpass Cloud](https://hogpass.com/docs/api-reference/migration/export-data-to-hogpass-cloud.md): Exports the current self-hosted instance's data (secrets, agents, agent-secret assignments, rules) directly to Hogpass Cloud over HTTPS. Secrets are decrypted server-side and transmitted to Cloud; plaintext never reaches the caller. - [List pending approvals](https://hogpass.com/docs/api-reference/approvals/list-pending-approvals.md): Long-polls for manual-approval requests awaiting a decision in the current project. Returns immediately when any are pending, otherwise holds the connection open (up to `timeoutSeconds`) until one arrives or the poll times out. - [Submit an approval decision](https://hogpass.com/docs/api-reference/approvals/submit-an-approval-decision.md): Approve or deny a pending manual-approval request. Approving forwards the held request to its upstream service; denying blocks it. Scope the call to the request's project with a project API key or an `X-Project-Id` header. - [List organization secrets](https://hogpass.com/docs/api-reference/organization-secrets/list-organization-secrets.md): Returns all secrets scoped to the organization. Secret values are never returned. Available on Hogpass Cloud and self-hosted Enterprise. Requires the admin or owner role. - [Create an organization secret](https://hogpass.com/docs/api-reference/organization-secrets/create-an-organization-secret.md): Creates a new secret at the organization level. Organization secrets apply across all projects. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Update an organization secret](https://hogpass.com/docs/api-reference/organization-secrets/update-an-organization-secret.md): Updates one or more fields on an organization secret. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Delete an organization secret](https://hogpass.com/docs/api-reference/organization-secrets/delete-an-organization-secret.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [List organization rules](https://hogpass.com/docs/api-reference/organization-rules/list-organization-rules.md): Returns all policy rules scoped to the organization. Available on Hogpass Cloud and self-hosted Enterprise. Requires the admin or owner role. - [Get an organization rule](https://hogpass.com/docs/api-reference/organization-rules/get-an-organization-rule.md): Available on Hogpass Cloud and self-hosted Enterprise. Requires the admin or owner role. - [Create an organization rule](https://hogpass.com/docs/api-reference/organization-rules/create-an-organization-rule.md): Creates a new policy rule at the organization level. Organization rules apply across all projects and cannot be assigned to specific agents. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Update an organization rule](https://hogpass.com/docs/api-reference/organization-rules/update-an-organization-rule.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Delete an organization rule](https://hogpass.com/docs/api-reference/organization-rules/delete-an-organization-rule.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Get app permissions](https://hogpass.com/docs/api-reference/organization-rules/get-app-permissions.md): Returns the layered tool-level permission states for a provider at the organization level. The shape matches the project endpoint (`{ defaults, byAgent }`), but organization rules are agent-less, so `byAgent` is always empty. Readable by all members. Available on Hogpass Cloud and self-hosted Enterp… - [Set app permissions](https://hogpass.com/docs/api-reference/organization-rules/set-app-permissions.md): Updates tool-level permissions for a provider at the organization level. Organization permissions are agent-less: `agentId` and the `inherit` permission are not accepted here (they are project-scope concepts). Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Count overlapping custom rules (organization)](https://hogpass.com/docs/api-reference/organization-rules/count-overlapping-custom-rules-organization.md): Counts custom organization rules whose host patterns overlap the app's hosts. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [List organization connections](https://hogpass.com/docs/api-reference/organization-connections/list-organization-connections.md): Returns all app connections scoped to the organization. Filter with the `provider` query parameter. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Rename an organization connection](https://hogpass.com/docs/api-reference/organization-connections/rename-an-organization-connection.md): Sets the display label of an organization connection. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Disconnect an organization connection](https://hogpass.com/docs/api-reference/organization-connections/disconnect-an-organization-connection.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Start organization OAuth flow](https://hogpass.com/docs/api-reference/organization-app-config/start-organization-oauth-flow.md): Starts an OAuth flow that creates the connection at the organization level, shared by every project in the organization. Redirects to the app's OAuth authorization page; the flow completes on the shared `/apps/{provider}/callback` endpoint, so no extra redirect URI registration is needed. - [Connect app at the organization level](https://hogpass.com/docs/api-reference/organization-app-config/connect-app-at-the-organization-level.md): Connects an app using direct credentials (API key, service account, etc.) at the organization level. The connection is shared by every project in the organization. Available on Hogpass Cloud and self-hosted Enterprise. Requires admin role. - [List configured providers](https://hogpass.com/docs/api-reference/organization-app-config/list-configured-providers.md): Returns provider IDs with an enabled app configuration at the organization level. Available on Hogpass Cloud and self-hosted Enterprise. Requires the admin or owner role. - [Get organization app configuration](https://hogpass.com/docs/api-reference/organization-app-config/get-organization-app-configuration.md): Returns the non-secret configuration for a BYOC app at the organization level. Available on Hogpass Cloud and self-hosted Enterprise. Requires the admin or owner role. - [Set organization app configuration](https://hogpass.com/docs/api-reference/organization-app-config/set-organization-app-configuration.md): Creates or updates the BYOC configuration for an app at the organization level. The accepted field names are defined per app (e.g. `clientId`/`clientSecret` for OAuth apps); unknown keys are stripped. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Delete organization app configuration](https://hogpass.com/docs/api-reference/organization-app-config/delete-organization-app-configuration.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Toggle organization app configuration](https://hogpass.com/docs/api-reference/organization-app-config/toggle-organization-app-configuration.md): Enables or disables an organization app configuration. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Get organization blocklist state](https://hogpass.com/docs/api-reference/organization-app-config/get-organization-blocklist-state.md): Returns the blocklist state for a provider at the organization level. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Activate or add an organization blocklist entry](https://hogpass.com/docs/api-reference/organization-app-config/activate-or-add-an-organization-blocklist-entry.md): Provide either `{ hostId }` to activate a predefined blocklist host, or `{ name, hostPattern }` to add a custom rule — at the organization level. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Toggle an organization blocklist rule](https://hogpass.com/docs/api-reference/organization-app-config/toggle-an-organization-blocklist-rule.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Remove an organization blocklist rule](https://hogpass.com/docs/api-reference/organization-app-config/remove-an-organization-blocklist-rule.md): Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [List pending approvals across the organization](https://hogpass.com/docs/api-reference/organization-approvals/list-pending-approvals-across-the-organization.md): Long-polls for manual-approval requests awaiting a decision across **every** project in the organization. Returns immediately when any are pending, otherwise holds the connection open (up to `timeoutSeconds`) until one arrives or the poll times out. - [Get organization settings](https://hogpass.com/docs/api-reference/organization-settings/get-organization-settings.md): Returns the organization's settings. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [Update organization settings](https://hogpass.com/docs/api-reference/organization-settings/update-organization-settings.md): Updates the organization's policy mode. Requires admin role. Available on Hogpass Cloud and self-hosted Enterprise. - [List partner organizations](https://hogpass.com/docs/api-reference/partner-organizations/list-partner-organizations.md): Returns all organizations created by your partner account, including each one's claim status. Requires a Partner API key (`oc_partner_…`). - [Create an organization](https://hogpass.com/docs/api-reference/partner-organizations/create-an-organization.md): Creates an organization for a customer, with a default project, an organization-scoped API key, a project-scoped API key, a default agent token, and a claim link. - [Get an organization](https://hogpass.com/docs/api-reference/partner-organizations/get-an-organization.md): Returns a single organization you manage, including its claim status and projects. - [Delete an unclaimed organization](https://hogpass.com/docs/api-reference/partner-organizations/delete-an-unclaimed-organization.md): Permanently deletes an organization and all of its content. Only allowed while the organization is unclaimed. - [Reissue a claim link](https://hogpass.com/docs/api-reference/partner-organizations/reissue-a-claim-link.md): Generates a new claim link for an unclaimed organization, invalidating the previous one. Only allowed while the organization is unclaimed. - [Rotate organization tokens](https://hogpass.com/docs/api-reference/partner-organizations/rotate-organization-tokens.md): Mints a new organization-scoped API key and default project API key for an unclaimed organization. The previous keys stop working immediately. - [List projects](https://hogpass.com/docs/api-reference/partner-projects/list-projects.md): Returns the projects in an organization you manage. - [Create a project](https://hogpass.com/docs/api-reference/partner-projects/create-a-project.md): Adds a project to an unclaimed organization. - [Delete a project](https://hogpass.com/docs/api-reference/partner-projects/delete-a-project.md): Removes a project from an unclaimed organization. An organization must keep at least one project. - [List partner secrets](https://hogpass.com/docs/api-reference/partner-secrets/list-partner-secrets.md): Returns the partner-level secrets inherited by every organization you manage. Secret values are never returned. - [Create a partner secret](https://hogpass.com/docs/api-reference/partner-secrets/create-a-partner-secret.md): Creates a partner-level secret inherited by every organization you manage. Partner secrets are the lowest-priority tier — project and organization secrets override them when host patterns overlap. - [Update a partner secret](https://hogpass.com/docs/api-reference/partner-secrets/update-a-partner-secret.md): Updates one or more fields on a partner secret. At least one field must be provided. - [Delete a partner secret](https://hogpass.com/docs/api-reference/partner-secrets/delete-a-partner-secret.md) - [List spend budgets for an organization](https://hogpass.com/docs/api-reference/partner-budgets/list-spend-budgets-for-an-organization.md): Returns the spend budgets set on your LLM keys for one organization, each with its current-period spend. Requires a Partner API key (`oc_partner_…`). - [Set or update a spend budget](https://hogpass.com/docs/api-reference/partner-budgets/set-or-update-a-spend-budget.md): Caps how much an organization can spend on one of your LLM keys. When the organization's spend reaches the limit, the gateway stops using that key for the organization until the budget is raised or reset. Creates the budget, or replaces the existing one. - [Remove a spend budget](https://hogpass.com/docs/api-reference/partner-budgets/remove-a-spend-budget.md): Removes the spend budget for an organization on one of your LLM keys. The key resumes with no cap for that organization. Only partner owners and admins can do this. - [List partner members](https://hogpass.com/docs/api-reference/partner-members/list-partner-members.md): Returns the people who can sign in to your partner portal. Requires a Partner API key (`oc_partner_…`) or a partner portal session. - [Add a partner member](https://hogpass.com/docs/api-reference/partner-members/add-a-partner-member.md): Adds a member to your partner by email; they sign in to the portal with that email. Only owners and admins can add members. The assignable roles are `admin` and `member` — the owner role is set at partner creation and can't be granted. - [Change a member's role](https://hogpass.com/docs/api-reference/partner-members/change-a-members-role.md): Moves a member between `admin` and `member`. Only owners and admins can do this, and the owner's role can't be changed. - [Remove a partner member](https://hogpass.com/docs/api-reference/partner-members/remove-a-partner-member.md): Removes a member from your partner. Only owners and admins can do this, and the owner can't be removed. - [List inherited partner secrets](https://hogpass.com/docs/api-reference/organization-partner/list-inherited-partner-secrets.md): Returns the partner-level secrets this organization inherits (read-only). Empty if the organization has no partner or has detached. Authenticate with your organization API key or session. - [Get partner status](https://hogpass.com/docs/api-reference/organization-partner/get-partner-status.md): Returns whether this organization is managed by a partner and whether it has detached. Requires the admin or owner role. - [Detach from partner](https://hogpass.com/docs/api-reference/organization-partner/detach-from-partner.md): Stops this organization from inheriting partner secrets while keeping its partner attribution. Requires the admin or owner role. - [SDKs: Route AI Agent Containers Through the Gateway](https://hogpass.com/docs/sdks/index.md): Route AI agent containers through the Hogpass gateway with official SDKs. Node.js available now, more languages coming soon. - [Node.js SDK: Container Config, Provisioning & Approval](https://hogpass.com/docs/sdks/node.md): Configure Docker containers to route through the Hogpass gateway from Node.js. Handles proxy setup, CA certs, and approval. - [Rust SDK (Coming Soon)](https://hogpass.com/docs/sdks/rust.md): Rust SDK for configuring containers to route through the Hogpass gateway. Currently in development. Follow GitHub for updates. - [Python SDK (Coming Soon)](https://hogpass.com/docs/sdks/python.md): Python SDK for configuring Docker containers to route through the Hogpass gateway. Currently in development. Coming soon. - [Go SDK (Coming Soon)](https://hogpass.com/docs/sdks/go.md): Go SDK for configuring containers to route through the Hogpass gateway. Currently in development. Follow GitHub for updates. - [Java / Kotlin SDK (Coming Soon)](https://hogpass.com/docs/sdks/java.md): Java SDK for configuring containers to route through the Hogpass gateway. Works with Kotlin and any JVM language. - [Ruby SDK (Coming Soon)](https://hogpass.com/docs/sdks/ruby.md): Ruby SDK for configuring containers to route through the Hogpass gateway. Currently in development. Follow GitHub for updates. - [.NET SDK (Coming Soon)](https://hogpass.com/docs/sdks/dotnet.md): .NET SDK for configuring containers to route through the Hogpass gateway. Works with C# and F# applications. Coming soon. ## OpenAPI Specs - [openapi](https://hogpass.com/docs/openapi.yaml) ## Optional - [GitHub](https://github.com/onecli)