The Monolith WAR hosts several Jakarta REST applications. Each application has its own servlet mapping in web.xml. The default web context is /Monolith; replace it and add any deployment prefix when constructing URLs.
| Application | Base URL | Responsibility |
|---|---|---|
| MonolithApplication | /Monolith/api |
Pixel, engines, projects, sessions, permissions, and integration APIs |
| GitHubApplication | /Monolith/github |
GitHub App setup, project links, callbacks, and push webhooks |
| MicrosoftGraphApplication | /Monolith/msgraph |
Microsoft mailbox/calendar subscriptions and notifications |
| HealthApplication | /Monolith/health |
Liveness, readiness, and resource status |
| TrustedTokenApplication | /Monolith/token |
Trusted integration token service |
| AdminApplication | /Monolith/adminconfig |
Initial administrator setup |
Paths below include the application base. {...} denotes an ID or other path parameter to replace; * denotes a route family for navigation, not a literal request URL. Engine IDs follow a hyphen in these routes: for example, /Monolith/api/storage-<storage-id>/list.
The tables describe registered routes and their main inputs. Resource implementations define the full contract, and operations still enforce the configured authentication, CSRF, and resource permissions. Dedicated applications apply their own checks and provider-verification rules.
Base: /Monolith/api. MonolithApplication registers the core resources below.
| Method and endpoint / route family | Purpose |
|---|---|
POST /Monolith/api/engine/runPixel |
Execute Pixel expressions in an Insight |
POST /Monolith/api/engine/runPixelAsync |
Submit asynchronous Pixel execution |
POST /Monolith/api/engine/pixelJobStreaming |
Poll Pixel job output |
POST /Monolith/api/engine/agentRunStreaming |
Drain live agent events and return a durable run snapshot |
/Monolith/api/session/* |
Session activity, cleanup, invalidation, and insights |
/Monolith/api/auth/* |
Login, logout, user identity, and provider callbacks |
Sources: NameServer, SessionResource, and UserResource. RunAgent is a Pixel operation submitted through the execution API; see agent runs.
DatabaseEngineResource serves /Monolith/api/database-{databaseId}.
| Method and endpoint | Inputs / purpose |
|---|---|
GET /Monolith/api/database-{databaseId}/type |
Return database type and catalog subtype |
POST /Monolith/api/database-{databaseId}/reload |
Reload the configured database through ReloadDatabase |
POST /Monolith/api/database-{databaseId}/query |
Required query; execute a query through the database engine |
StorageEngineResource serves /Monolith/api/storage-{storageId}.
| Method and endpoint | Inputs / purpose |
|---|---|
POST /Monolith/api/storage-{storageId}/list |
Required storagePath; list a storage path |
POST /Monolith/api/storage-{storageId}/listDetails |
Required storagePath; list entries with details |
POST /Monolith/api/storage-{storageId}/delete |
Required storagePath; delete the selected storage content |
VectorEngineResource serves /Monolith/api/vector-{vectorId}.
| Method and endpoint | Inputs / purpose |
|---|---|
POST /Monolith/api/vector-{vectorId}/query |
Required command; optional limit, paramValues; search the vector database |
POST /Monolith/api/vector-{vectorId}/listDocuments |
Optional paramValues; list indexed documents |
POST /Monolith/api/vector-{vectorId}/removeDocument |
Required fileNames; optional paramValues; remove indexed documents |
ModelEngineResource serves /Monolith/api/model-{modelId}.
| Method and endpoint | Inputs / purpose |
|---|---|
POST /Monolith/api/model-{modelId}/llm |
Required command; optional context, useHistory, paramValues, roomId, image, url; invoke LLM |
POST /Monolith/api/model-{modelId}/llmStreaming |
Stream the LLM operation as server-sent events |
POST /Monolith/api/model-{modelId}/embeddings |
Required values; optional paramValues; generate embeddings |
POST /Monolith/api/model-{modelId}/vision |
Required command, image; optional paramValues; invoke vision |
llmStreaming emits SEMOSS job payloads and ends with data: [DONE]. Use the compatibility endpoints below when a client expects a provider-specific response format. Supported generation, embeddings, media, and streaming capabilities depend on the selected model engine.
FunctionEngineResource serves /Monolith/api/function-{functionId}.
| Method and endpoint | Inputs / purpose |
|---|---|
POST /Monolith/api/function-{functionId}/execute |
Optional map or its alias inputs; execute the function using its configured input contract |
GET /Monolith/api/function-{functionId}/definition |
Return the function engine definition |
EngineRouteResource serves /Monolith/api/e-{engineId} for operations shared across engine catalogs.
| Method and endpoint | Purpose |
|---|---|
GET /Monolith/api/e-{engineId}/type |
Return engine type and subtype |
POST /Monolith/api/e-{engineId}/updateSmssFile |
Update engine configuration using the smss parameter |
POST /Monolith/api/e-{engineId}/image/upload |
Upload a catalog image using multipart field file |
GET /Monolith/api/e-{engineId}/image/download |
Download the engine catalog image |
See catalog image uploads for supported images and permission requirements. Guardrail and virtual-environment engines have no dedicated operation resource registered alongside the database/model/storage/vector/function resources in this application; use their supported Pixel operations and shared catalog routes where applicable.
ProjectResource serves /Monolith/api/project-{projectId}. Workspace agents and skills use their project IDs for these project operations.
| Method and endpoint | Purpose |
|---|---|
POST /Monolith/api/project-{projectId}/runReactor/{reactorName} |
Execute a project reactor |
POST /Monolith/api/project-{projectId}/updateSmssFile |
Update project configuration |
GET /Monolith/api/project-{projectId}/landing |
Serve the project landing content |
GET /Monolith/api/project-{projectId}/downloadProjectAsset/{relPath} |
Download a project asset |
POST /Monolith/api/project-{projectId}/image/upload |
Upload a project catalog image |
POST /Monolith/api/project-{projectId}/projectImage/upload |
Alias for project catalog image upload |
GET /Monolith/api/project-{projectId}/projectImage/download |
Download the project catalog image |
The same resource also defines embedded logos, insight images, and JDBC-format result routes. See its source for those request parameters and the project guide for project types and assets.
The database query, storage, vector, model, and function execution wrappers accept JSON or form-encoded bodies. Prefer JSON for nested maps and arrays. For example, send this JSON to POST /Monolith/api/vector-{vectorId}/query after replacing the vector ID:
{
"command": "Find documents about agent configuration",
"limit": 5,
"paramValues": {}
}These wrappers invoke the corresponding Pixel operations through ResourceUtility, with the authenticated user and a temporary Insight. Standard wrapper results use the SEMOSS Pixel response structure; Pixel errors or invalid syntax produce HTTP 400, and a missing session produces 401. Metadata, image, streaming, and compatibility routes have their own response contracts. Existing session state and permissions remain necessary when calling the typed routes directly.
These resources also belong to MonolithApplication and retain the /Monolith/api prefix.
| Resource | Endpoints |
|---|---|
| OpenAIEndpoints | POST /Monolith/api/model/openai/v1/chat/completions, POST /Monolith/api/model/openai/v1/responses, POST /Monolith/api/model/openai/v1/images/generations, POST /Monolith/api/model/openai/v1/embeddings, GET /Monolith/api/model/openai/v1/models, GET /Monolith/api/model/openai/v1/models/{modelId} |
| AnthropicEndpoints | POST /Monolith/api/model/anthropic/v1/messages |
| OllamaEndpoints | POST /Monolith/api/model/ollama/api/chat, POST /Monolith/api/model/ollama/api/generate, POST /Monolith/api/model/ollama/embeddings |
OpenAI also exposes the listed routes without /v1 and a legacy POST /Monolith/api/model/openai/completions route. Ollama exposes /chat and /generate aliases beneath /Monolith/api/model/ollama. The second /api in the Ollama chat/generate paths belongs to the compatibility route itself.
| Endpoint / route family | Purpose / implementation |
|---|---|
POST /Monolith/api/ext/mcp/{toolbox_id}/comms |
MCPResource tool communication |
GET /Monolith/api/ext/a2a/workspace/{workspaceId}/.well-known/agent-card.json |
A2AResource agent card |
POST /Monolith/api/ext/a2a/workspace/{workspaceId}/rpc |
A2A JSON-RPC operations |
/Monolith/api/browser-sessions/* |
RemoteBrowserSessionController sessions, steps, and recordings |
/Monolith/api/uploadFile/*, /Monolith/api/images/* |
FileUploader and ImageUploader |
/Monolith/api/authorization/* |
AuthorizationResource |
/Monolith/api/auth/engine/*, /Monolith/api/auth/project/*, /Monolith/api/auth/insight/*, /Monolith/api/auth/user/* |
Resource authorization services |
/Monolith/api/auth/group/*, /Monolith/api/auth/admin/* |
Group permissions and administrator operations in the main API |
/Monolith/api/exec/*, /Monolith/api/share/* |
ExecuteInsightResource and ShareInsightResource |
/Monolith/api/schedule/* |
SchedulerResource |
/Monolith/api/themes/* |
AdminThemeResource |
/Monolith/api/config/* |
ServerConfigurationResource |
/Monolith/api/form/* |
FormResource legacy forms |
NameServer also mounts legacy subresources at /Monolith/api/engine/i-{insightID}/* for frames and /Monolith/api/engine/e-{engine}/* for older engine operations. The shared engine catalog resource documented above is /Monolith/api/e-{engineId}/*.
GET /Monolith/api/config/endpoints lists HTTP methods, resource-relative paths, resource classes, operations, and declared content types for the main application's registered resources. The response includes contextPath, count, includesAdminResources, and endpoints.
Prefix each returned path with the deployment context and /api when building a URL. The current implementation omits resource classes whose names start with Admin unless the caller is an administrator. It inspects MonolithApplication's resources; use the separate application sections below for their routes. Subresource-locator children are not recursively enumerated.
Base: /Monolith/github. Registered resources: GitHubService and AdminGitHubService.
| Endpoint / route family | Purpose |
|---|---|
POST /Monolith/github/webhook |
Signature-verified GitHub App events; pushes dispatch linked-project synchronization |
GET /Monolith/github/available |
App configuration preflight |
/Monolith/github/manifest/* |
Administrator app creation, callback, configuration, and project-link inventory |
/Monolith/github/install/* |
Installation callback and repository/branch selection |
/Monolith/github/user/* |
GitHub user authorization and callback |
/Monolith/github/project/* |
Read/disconnect project links and update tracked branches |
See GitHub webhook and setup endpoints for every method, parameter, callback, and response. These paths start with /Monolith/github directly.
Base: /Monolith/msgraph. Registered resources: MicrosoftGraphNotificationService and MicrosoftGraphSubscriptionService.
| Method and endpoint | Purpose |
|---|---|
POST /Monolith/msgraph/notifications/messages |
Mailbox notifications and subscription validation |
POST /Monolith/msgraph/notifications/events |
Calendar notifications and subscription validation |
GET /Monolith/msgraph/available |
Microsoft identity, scope, and public-URL preflight |
POST /Monolith/msgraph/subscribe |
Create a mailbox/calendar subscription |
GET /Monolith/msgraph/subscriptions |
Compare recorded subscriptions with Microsoft's state |
POST /Monolith/msgraph/renew |
Renew an owned subscription |
DELETE /Monolith/msgraph/subscription |
Remove an owned subscription |
See Microsoft Graph notification endpoints for parameters, validation, persistence, and renewal. Receivers currently fetch and log changes; they do not automatically submit agent runs.
Base: /Monolith/health. Registered resource: HealthResource.
| Method and endpoint | Purpose |
|---|---|
GET /Monolith/health/ |
Liveness |
GET /Monolith/health/ready |
Startup readiness: 200 when ready, 503 otherwise |
GET /Monolith/health/details |
Required/enabled system-resource status |
Health probes use this dedicated application and do not require a user session.
Base: /Monolith/token. Registered resource: TrustedTokenService.
| Method and endpoint | Purpose |
|---|---|
POST /Monolith/token/getToken |
Request a trusted integration token using the configured client-credential flow |
GET /Monolith/token/getToken |
Legacy variant; rejected when client/secret validation is enabled |
The POST flow reads client_id and, when credential validation is enabled, secret_key. Configure trusted integrations through the deployment's token and filter settings. This application is separate from the login and resource-authorization APIs under /Monolith/api/auth.
Base: /Monolith/adminconfig. Registered resource: AdminConfigService.
| Method and endpoint | Purpose |
|---|---|
POST /Monolith/adminconfig/setInitialAdmins |
Initial administrator registration during deployment setup |
The startup filter and service restrict this setup path once the security database contains users. Ongoing administrator operations are served by the main API's /Monolith/api/auth/admin/* resources.
Direct servlet mappings, static assets, and WebSockets are outside these six REST applications. For example, SamlVerifierServlet is mapped at /Monolith/saml/config/fedletapplication. Consult web.xml and the relevant WebSocket implementation for those contracts.
When testing route changes in the local Docker image, verify the effective descriptor: the local build workflow preserves web.xml from the base image. See the core integration guide for request execution and agent boundaries.