API Reference
Endpoint reference for the Aegis workers.
Authentication
Most endpoints require an authenticated session cookie (proxyAdminToken) or an app token supplied as Authorization: Bearer <token>. The Monitor worker uses HTTP Basic Auth. Specific requirements are listed on each module's page.
A small number of paths are intentionally public so that report links work from Slack — audit and QA report pages, and report images. Treat their contents accordingly.
How this reference is produced
These pages are generated directly from the worker source by npm run docs:generate, which now runs as part of every docs build. The generator clears each module's pages before regenerating, so an endpoint listed here exists in the code — and one removed from the code disappears from here on the next deploy.
Router API
The edge proxy itself — route resolution, ad-subdomain handling, GA4 validation, asset proxying and the config export used by the fallback node.
Admin API
The largest surface: routes, pixels, checkouts, users, app tokens, analytics queries, audit reports and the MCP edge router.
Analytics API
Inbound partner webhooks (Shopify, Elevar, Klaviyo, Meta, Google), on-site telemetry collection and the queue consumer.
Monitor API
Uptime checks, on-demand route tests, and visual capture and diffing. Also owns the retention cleanup crons.
QA Bot API
Authoring, versioning and sign-off for Markdown test specifications, plus GA framework configuration and run reports.
Compliance scanning is not an Aegis API
The compliance-ai worker was retired and spun out as Passmark, its own application. Aegis is a client of its public API rather than the owner of the endpoint, so there is nothing here to generate a reference from — see the Compliance Scanning guide.
Ecommerce API
The standalone storefront behind the cart widget: catalogue, cart, upsells, shipping and tax quoting, checkout and the Stripe webhook. Reads are public by design — the widget calls them cross-origin from landing pages.
Nudger API
Trello and Slack pipeline orchestration, brief parsing and checkout building. Low activity — deliberately defocused until the wider automation work.