Sentrieve

API Reference

Last updated: September 2026

Sentrieve is a secure, permission-aware AI layer over your organization's private knowledge. This REST API gives programmatic access to the same grounded, cited answers and governed data your team uses in the app. Requests authenticate with your session cookie or a tenant-scoped bearer token, and every response stays within the caller's permissions.

Base URL: your Sentrieve deployment's host. Responses are JSON unless noted; the chat endpoint streams server-sent events.

Access model

The API is permission-aware. Every response is scoped to the requesting user's identity, role, and organization, so two users can ask the same question and receive different answers based on what they are authorized to see. Answers are grounded in authorized sources only, with citations back to those sources.

A member asks a questioncarrying their identity, role, and organizationIDENTITY AND PERMISSIONS CHECKEDAuthenticateRolesPermissionsContextPERMISSION-AWARE PLATFORMScoped retrievalGrounded RAGCitationsData isolationAuditsearches only authorized sources, grounds the answer, and logs the accessA RESPONSE SCOPED TO THEMGrounded answerdrawn only from sources they can accessCitationsshowing where the information came fromTwo people, the same question, different answerseach scoped to exactly what they are allowed to see
How role-based access shapes API responses.

Authentication

All API requests must include a valid session. For programmatic access, generate an API token from Dashboard → Settings → API Tokens (coming soon). Include it as:

Authorization: Bearer <your-token>

Health Check

GET /api/health

Response 200:
{
  "status": "ok",
  "db": "ok",
  "uptime": 1234.5
}

Chat

POST /api/chat
Content-Type: application/json

{
  "orgId": "your-org-id",
  "messages": [
    { "role": "user", "content": "What's our refund policy?" }
  ]
}

Response: text/event-stream (SSE)
Each chunk: data: {"text":"..."}

Organizations

GET /api/orgs
Response: { "orgs": [{ "id": "...", "name": "...", "role": "admin" }] }

POST /api/orgs
{ "name": "My Workspace" }
Response: { "org": { "id": "...", "name": "..." } }

Export validated extractions

Pull human-reviewed extraction results into another system. This endpoint authenticates with a tenant-scoped API key (not a session), so a request can only ever reach its own organization's data. It returns only validated results, never anything still pending or rejected.

GET /api/export/extractions?schemaId=<optional>
Authorization: Bearer <org-api-key>

Response 200:
{ "results": [ { "schemaId": "...", "fields": { "vendor": "...", "amount": "..." } } ] }

Rate Limits

API requests are rate-limited per user. Exceeded limits return HTTP 429 with a Retry-After header. Default limits: 60 requests/minute for most endpoints, 10 requests/minute for chat.

Errors

All error responses use a consistent shape:

{
  "error": "Human-readable error message"
}

Need something not listed here? Email api@sentrieve.com.