Endpoints
Base URL and authentication
The hosted deployment for internal preparation ishttps://tckg.factagora.com. Every path above is appended to the base URL. Bodies are JSON. Timestamps are ISO 8601, timezone included.
A hosted deployment is protected by API keys. Send
Authorization: Bearer <api key> on every request; GET /v1/version is the only open route. Without a valid key you get 401 {"detail": {"error": "TCKG_UNAUTHORIZED"}}.
The key selects the tenant. Every row you write carries the key’s tenant and every read, search, resolve and export is scoped to it, so two apps with different keys never see each other’s rows. There is nothing to send: no tenant field in a request is read. A local server without a key map is open and single-tenant (TCKG_TENANT)./mcp, with the same key: Connect an agent.
The as_of rule
Every read (GET /v1/memories*, search, resolve, why, export) requires as_of. Without it:
YYYY-MM-DD) is widened to the end of that day in UTC. A full timestamp is used as is.
Shared shapes
NodeRow, returned by every read:
Certificate, on every read response. Keys and meaning are in Concepts.
Errors
Everything else is
200, including a write with refused rows and a resolve that cannot answer. Look at refused, status, and reason in the body.
Idempotency
Writes are idempotent by content. Sending the same body twice writes nothing the second time and returnsaccepted: 0 with already_remembered warnings. Retry freely.