Skip to main content

Endpoints

Base URL and authentication

The hosted deployment for internal preparation is https://tckg.factagora.com. Every path above is appended to the base URL. Bodies are JSON. Timestamps are ISO 8601, timezone included.
A hosted deployment is protected by API keys. Send Authorization: Bearer <api key> on every request; GET /v1/version is the only open route. Without a valid key you get 401 {"detail": {"error": "TCKG_UNAUTHORIZED"}}. The key selects the tenant. Every row you write carries the key’s tenant and every read, search, resolve and export is scoped to it, so two apps with different keys never see each other’s rows. There is nothing to send: no tenant field in a request is read. A local server without a key map is open and single-tenant (TCKG_TENANT).
Agents can use the same operations as MCP tools at /mcp, with the same key: Connect an agent.

The as_of rule

Every read (GET /v1/memories*, search, resolve, why, export) requires as_of. Without it:
A date-only value (YYYY-MM-DD) is widened to the end of that day in UTC. A full timestamp is used as is.

Shared shapes

NodeRow, returned by every read: Certificate, on every read response. Keys and meaning are in Concepts.

Errors

Everything else is 200, including a write with refused rows and a resolve that cannot answer. Look at refused, status, and reason in the body.

Idempotency

Writes are idempotent by content. Sending the same body twice writes nothing the second time and returns accepted: 0 with already_remembered warnings. Retry freely.