REST API
Authentication and endpoints
Every Andru API call goes to https://api.andru-ai.com. The full spec is at /docs/openapi.json (OpenAPI 3.1).
Authentication
Create an API key at Settings › Developer. Keys start with sk_live_, are shown once, are tied to your account, and can be revoked there at any time. Send the key in X-API-Key or as a bearer token.
Terminal
# Either header works
curl https://api.andru-ai.com/api/a2a/quota -H "X-API-Key: sk_live_your_key_here"
curl https://api.andru-ai.com/api/a2a/quota -H "Authorization: Bearer sk_live_your_key_here"Endpoints
| Method | Path | What it does |
|---|---|---|
GET | /.well-known/agent.json | A2A AgentCard discovery |
POST | /api/a2a/register | Get an API key for your Andru account |
GET | /api/a2a/capabilities | Machine-readable capabilities catalog |
POST | /api/a2a/tasks | Submit a task (JSON-RPC 2.0) |
GET | /api/a2a/tasks | List tasks for authenticated user |
GET | /api/a2a/tasks/{taskId} | Get task status and result |
POST | /api/a2a/tasks/{taskId}/cancel | Cancel a running task |
GET | /api/a2a/tasks/{taskId}/stream | Stream task updates (SSE) |
GET | /api/a2a/quota | Check free tier quota |
GET | /api/a2a/usage/summary | Current month usage overview |
GET | /api/a2a/usage/by-agent | Usage grouped by API key (agent) |
GET | /api/a2a/usage/by-tool | Usage grouped by tool |
GET | /api/a2a/usage/history | Daily usage time-series |
MCP clients do not call these directly; the MCP package uses /api/mcp/tools/list, /api/mcp/tools/call, /api/mcp/resources/list and /api/mcp/resources/read with the same key. See MCP set-up.
Rate limits
Per account, per 15 minutes. Past a limit the API answers 429; wait and retry.
| Call | Limit |
|---|---|
| Send a task (POST /api/a2a/tasks) | 50 |
| Read tasks (GET /api/a2a/tasks) | 100 |
| MCP tool call | 50 |
| MCP tool and resource lists | 100 |
| AP2 purchase | 50 |
| Register a key (POST /api/a2a/register) | 5 |
Errors
| Status | Meaning |
|---|---|
| 400 | The request is missing a field or names an unknown skill or tool. The reply says which. |
| 401 | No key, or the key is wrong or revoked. |
| 402 | The call is paid and the wallet cannot cover it (code INSUFFICIENT_FUNDS). Nothing was charged. |
| 404 | No task with that id on your account. |
| 429 | Rate limit reached. |