mepa8
Docs · API

Four calls. The same ones the screen uses.

Nothing the board can do is hidden from the API, and nothing the API can do bypasses the two-step kill. This page marks each call live or planned.

Status as of October 9, 2026

The Mepa8 API is the JSON surface behind the board. On the local product, all 4 calls below are live on 127.0.0.1:8787 and have been since October 8, 2026, with gates that run them on every build. On the hosted app the same 4 calls open with the Pro plan; until then the public site exposes exactly 2 routes, /api/health and the audit booking /api/audit, and nothing else answers. This page is kept honest by its change log.

The calls

# 1. the board as data
GET /api/board
→ { "ran": "2026-10-08T19:54:42", "totals": { "pace": 490.04, "budget": 1850, "critical": 4 }, "vendors": [ … ] }

# 2. re-run the checks now (never sends alerts; the schedule does that)
POST /api/run            { "by": "agent" }

# 3. propose a kill: returns the blast radius and a single-use token, valid 10 minutes
POST /api/kill/propose   { "vendor": "neon", "by": "agent" }
→ { "token": "…", "expires": 1791540000, "blast_radius": "every reader of the CRM database", "mode": "api" }

# 4. confirm it with the token; restore is the same shape
POST /api/kill/confirm   { "vendor": "neon", "token": "…", "by": "agent" }
POST /api/kill/restore   { "vendor": "neon", "by": "agent" }

There is a fifth, administrative call, POST /api/vendor, which adds or edits a vendor row. On the local product it accepts a credential as env:NAME only and refuses any value that looks like a secret. On the hosted app it accepts the key once, over HTTPS, and stores it encrypted as the security page describes.

Authentication

The local product binds to loopback and has no auth; the machine is the boundary. The hosted app uses a bearer token per agent, issued on the Settings page, sent as Authorization: Bearer <token>. Each token has 2 permissions you set at issue time: read, and kill. A read-only token can call the board and run; a kill-enabled token can propose and confirm, under the same 10-minute single-use kill token as a person. Every call carries a by field that lands in the audit log next to the token's name.

CallLocalHostedNeeds
GET /api/boardLivePlanned, Proread
POST /api/runLivePlanned, Proread
POST /api/kill/proposeLivePlanned, Prokill
POST /api/kill/confirm, /restoreLivePlanned, Prokill
POST /api/vendorLivePlanned, Prowrite
GET /api/healthLiveLivenone

Limits

Planned hosted limits: 60 reads a minute per token, 6 runs an hour per tenant because each run calls every vendor, and 10 kill proposals an hour per tenant. Bodies are capped at 8 kilobytes. A 429 carries a retry_after in seconds. These are written here before they are live so the first integration does not learn them from an error.

“Everything the screen does is a JSON call with the same rights.”Mepa8 How-to, 2026-10-08

Why an agent should call this

An agent that can call a metered API in a loop is the newest way to overspend, and the vendors will not stop it: ElevenLabs keeps answering past the credit limit when usage-based billing is on, per its pricing page. An agent that also reads its own vendor's pace, and can propose its own kill under the same two steps a person faces, is an agent with a cap it cannot talk its way past. The audit log records its name like anyone else's.

Questions people ask

Straight answers

Is the API live on the hosted app?

Only health is, as of October 9, 2026. The four board and kill calls are live on the local product on loopback and open on the hosted app with the Pro plan. The table above is updated the day each call goes live, with a change-log line.

Can an agent kill a vendor with the API?

Yes, if its token was issued with the kill permission, and only through the same two steps: propose, which returns a 10-minute single-use token and the blast radius, then confirm with that token. The agent's name is in the audit log on both steps.

What are the rate limits?

Planned: 60 reads a minute per token, 6 runs an hour per tenant, 10 kill proposals an hour per tenant, 8-kilobyte bodies. A 429 carries retry_after in seconds. The local product has no limits because it only answers on 127.0.0.1.

Sources

  1. ElevenLabs — pricing (usage-based billing) — read 2026-10-08
  2. Railway — public API guide (bearer and project tokens, the pattern Mepa8 follows) — read 2026-10-09

Change log: October 9, 2026 — First published. Hosted calls marked planned until the Pro plan opens.

Start here

Find out what you are paying before the next invoice does.

Five business days. Every vendor listed with real cost, every leak named with its fix, and a board you keep.

Book a vendor audit →See the plansNo card on the form. A person replies within one business day.