Skip to content
โ—‡ AirawatOS Developer
๐Ÿšง Under development โ€” this portal is being built track by track. Content will keep growing, and some sections are still placeholders.

Get Started

Services & APIs

The platform is a handful of small services, each with one job. Here's what each one is, and where its API lives.

AirawatOS isn't one big program โ€” it's a set of independent services that each do one thing and trust each other only through verified tokens and signatures. Two of them are the governed APIs you build against; the rest are supporting machinery. This page is the map, generated from the running services.

The two governed APIs

Almost everything a developer cares about is one of these two.

Because both are FastAPI, each serves its own live OpenAPI at /openapi.json โ€” the spec is generated from the code, so it never drifts. The committed copies live in platform-spec/spec/openapi/.

The supporting services

Small, single-purpose, mostly called by the kernel or the host โ€” not by your component directly. (These are lightweight HTTP services, so their specs in platform-spec/spec/openapi/ are derived from source rather than a live /openapi.json.)

ServiceAddressWhat it does
Identityidentity:8093The IdP. Per-tenant realms; issues the verified tokens every other service trusts (/jwks is the root of that trust).
File Storefilestore:8095Content-addressed blobs โ€” write-once, immutable, dedup by hash. Backs file uploads and component delivery.
Secretssecrets:8102Per-tenant, per-component credentials (Vault-backed). Injected at use; components never see raw values.
Schedulerscheduler:8103The clock-driven trigger โ€” fires platform.schedule entries on time (one of three ways work starts).
Workflowworkflow:8097Turns a case's workflow declaration into tasks routed to the Inbox (the lifecycle spine).
Decisiondecision:8096The single writer that turns a signed decision into governed outcomes (execution-engine seam).
Automationautomation:8098The event dispatcher โ€” the kernel emits events here; it fans them to subscribers.
Runtime Managerruntime-manager:8105The trusted runtime invoker โ€” mints run-tokens and runs a confined component.
Model Gatewaymodel-gateway:8104The confined path to an AI model provider; the kernel routes completions through it (keys stay in Vault).

Everything else

How this maps to the layers

If The Airawat Stack is the what (the layers and domains), this is the how it runs โ€” the processes those layers are made of. The kernel + network are the trusted core; the supporting services are the platform services around it; the app host is where distribution and apps meet the browser.

Browse it โ€” the API Explorer

โ†’ Open the API Explorer โ€” the actual API, browsable in the docs. Pick a service, expand any endpoint to see its parameters, request/response schemas, and examples. For the Kernel and Network it loads the live spec (always current) and lets you Try it out against the real gateway; the internal services show their source-derived spec.

Using the specs

The rule of thumb: build against the kernel (through the broker) and the network (governance). The rest of the services are the platform doing its job so you don't have to.