Scheduler APIs
Scheduled job management for tenant applications — cron, one-shot, and recurring-interval schedules that invoke an HTTP target on a timer.
Caller identity and tenant are derived from your credentials — you never pass user or tenant identifiers in the request body. Schedules are durable: they survive restarts, track their own execution history, and retry automatically on failure.
All endpoints use POST /api/v1/scheduler/<method> with a JSON request
body. Request and response bodies use protojson encoding (the JSON
representation of Protocol Buffer messages): enum fields are serialized as
their string names and timestamps as RFC 3339 strings.
See the Scheduled Jobs guide for concepts, examples, and retry behaviour.
Authentication
- API Key: apiKeyAuth
- API Key: onBehalfOf
- HTTP: Bearer Auth
Your API key. sk_… for backend-to-backend calls, pk_… for client apps.
Never valid on its own — see the combinations under Security below.
Security Scheme Type: | apiKey |
|---|---|
Header parameter name: | X-API-Key |
The end user this call acts for. Required with an sk_… key, because a secret
key identifies your tenant and not a user; omitting it returns
401 authenticated user_id is required. The key needs the users:impersonate
scope or the call fails with 403 insufficient_scope.
Security Scheme Type: | apiKey |
|---|---|
Header parameter name: | X-On-Behalf-Of |
The end user's own JWT, issued by the OIDC provider configured on the
publishable key. Required alongside a pk_… key, and supplies the user
identity in place of X-On-Behalf-Of.
Security Scheme Type: | http |
|---|---|
HTTP Authorization Scheme: | bearer |
Bearer format: | JWT |